Merge remote-tracking branch 'origin/master' into wdeg-working
@ -1,270 +1,12 @@
|
||||
{
|
||||
"build_entry_point": "",
|
||||
"need_generate_pdf": false,
|
||||
"need_generate_intellisense": false,
|
||||
"docsets_to_publish": [
|
||||
{
|
||||
"docset_name": "mdop-VSTS",
|
||||
"build_source_folder": "mdop",
|
||||
"build_output_subfolder": "mdop-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-manage-VSTS",
|
||||
"build_source_folder": "windows/manage",
|
||||
"build_output_subfolder": "windows-manage-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "smb-VSTS",
|
||||
"build_source_folder": "smb",
|
||||
"build_output_subfolder": "smb-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "surface-hub-VSTS",
|
||||
"build_source_folder": "devices/surface-hub",
|
||||
"build_output_subfolder": "surface-hub-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "microsoft-edge-VSTS",
|
||||
"build_source_folder": "browsers/edge",
|
||||
"build_output_subfolder": "microsoft-edge-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-development-VSTS",
|
||||
"build_source_folder": "windows/deployment",
|
||||
"build_output_subfolder": "win-development-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-plan-VSTS",
|
||||
"build_source_folder": "windows/plan",
|
||||
"build_output_subfolder": "windows-plan-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-client-management-VSTS",
|
||||
"build_source_folder": "windows/client-management",
|
||||
"build_output_subfolder": "win-client-management-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-threat-protection-VSTS",
|
||||
"build_source_folder": "windows/threat-protection",
|
||||
"build_output_subfolder": "win-threat-protection-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-app-management-VSTS",
|
||||
"build_source_folder": "windows/application-management",
|
||||
"build_output_subfolder": "win-app-management-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-deploy-VSTS",
|
||||
"build_source_folder": "windows/deploy",
|
||||
"build_output_subfolder": "windows-deploy-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "keep-secure-VSTS",
|
||||
"build_source_folder": "windows/keep-secure",
|
||||
"build_output_subfolder": "keep-secure-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "surface-VSTS",
|
||||
"build_source_folder": "devices/surface",
|
||||
"build_output_subfolder": "surface-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-hub-VSTS",
|
||||
"build_source_folder": "windows/hub",
|
||||
"build_output_subfolder": "windows-hub-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "internet-explorer-VSTS",
|
||||
"build_source_folder": "browsers/internet-explorer",
|
||||
"build_output_subfolder": "internet-explorer-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "bcs-VSTS",
|
||||
"build_source_folder": "bcs",
|
||||
"build_output_subfolder": "bcs-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": false,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
@ -273,40 +15,7 @@
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-access-protection-VSTS",
|
||||
"build_source_folder": "windows/access-protection",
|
||||
"build_output_subfolder": "win-access-protection-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-device-security-VSTS",
|
||||
"build_source_folder": "windows/device-security",
|
||||
"build_output_subfolder": "win-device-security-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
@ -315,7 +24,6 @@
|
||||
"build_output_subfolder": "education-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
@ -324,32 +32,31 @@
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "store-for-business-VSTS",
|
||||
"build_source_folder": "store-for-business",
|
||||
"build_output_subfolder": "store-for-business-VSTS",
|
||||
"docset_name": "gdpr",
|
||||
"build_source_folder": "gdpr",
|
||||
"build_output_subfolder": "gdpr",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": false,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "win-configuration-VSTS",
|
||||
"build_source_folder": "windows/configuration",
|
||||
"build_output_subfolder": "win-configuration-VSTS",
|
||||
"docset_name": "internet-explorer-VSTS",
|
||||
"build_source_folder": "browsers/internet-explorer",
|
||||
"build_output_subfolder": "internet-explorer-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
@ -358,40 +65,7 @@
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-update-VSTS",
|
||||
"build_source_folder": "windows/update",
|
||||
"build_output_subfolder": "windows-update-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-whats-new-VSTS",
|
||||
"build_source_folder": "windows/whats-new",
|
||||
"build_output_subfolder": "win-whats-new-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
@ -400,7 +74,6 @@
|
||||
"build_output_subfolder": "itpro-hololens-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
@ -409,15 +82,15 @@
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-configure-VSTS",
|
||||
"build_source_folder": "windows/configure",
|
||||
"build_output_subfolder": "windows-configure-VSTS",
|
||||
"docset_name": "keep-secure-VSTS",
|
||||
"build_source_folder": "windows/keep-secure",
|
||||
"build_output_subfolder": "keep-secure-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
@ -426,6 +99,24 @@
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "mdop-VSTS",
|
||||
"build_source_folder": "mdop",
|
||||
"build_output_subfolder": "mdop-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
@ -434,7 +125,6 @@
|
||||
"build_output_subfolder": "microsoft-365",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_groups": [],
|
||||
"open_to_public_contributors": false,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
@ -443,6 +133,330 @@
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "microsoft-edge-VSTS",
|
||||
"build_source_folder": "browsers/edge",
|
||||
"build_output_subfolder": "microsoft-edge-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "smb-VSTS",
|
||||
"build_source_folder": "smb",
|
||||
"build_output_subfolder": "smb-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "store-for-business-VSTS",
|
||||
"build_source_folder": "store-for-business",
|
||||
"build_output_subfolder": "store-for-business-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "surface-hub-VSTS",
|
||||
"build_source_folder": "devices/surface-hub",
|
||||
"build_output_subfolder": "surface-hub-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "surface-VSTS",
|
||||
"build_source_folder": "devices/surface",
|
||||
"build_output_subfolder": "surface-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-access-protection-VSTS",
|
||||
"build_source_folder": "windows/access-protection",
|
||||
"build_output_subfolder": "win-access-protection-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-app-management-VSTS",
|
||||
"build_source_folder": "windows/application-management",
|
||||
"build_output_subfolder": "win-app-management-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-client-management-VSTS",
|
||||
"build_source_folder": "windows/client-management",
|
||||
"build_output_subfolder": "win-client-management-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-configuration-VSTS",
|
||||
"build_source_folder": "windows/configuration",
|
||||
"build_output_subfolder": "win-configuration-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-development-VSTS",
|
||||
"build_source_folder": "windows/deployment",
|
||||
"build_output_subfolder": "win-development-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-device-security-VSTS",
|
||||
"build_source_folder": "windows/device-security",
|
||||
"build_output_subfolder": "win-device-security-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-configure-VSTS",
|
||||
"build_source_folder": "windows/configure",
|
||||
"build_output_subfolder": "windows-configure-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-deploy-VSTS",
|
||||
"build_source_folder": "windows/deploy",
|
||||
"build_output_subfolder": "windows-deploy-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-hub-VSTS",
|
||||
"build_source_folder": "windows/hub",
|
||||
"build_output_subfolder": "windows-hub-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-manage-VSTS",
|
||||
"build_source_folder": "windows/manage",
|
||||
"build_output_subfolder": "windows-manage-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-plan-VSTS",
|
||||
"build_source_folder": "windows/plan",
|
||||
"build_output_subfolder": "windows-plan-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-update-VSTS",
|
||||
"build_source_folder": "windows/update",
|
||||
"build_output_subfolder": "windows-update-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-threat-protection-VSTS",
|
||||
"build_source_folder": "windows/threat-protection",
|
||||
"build_output_subfolder": "win-threat-protection-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
},
|
||||
{
|
||||
"docset_name": "win-whats-new-VSTS",
|
||||
"build_source_folder": "windows/whats-new",
|
||||
"build_output_subfolder": "win-whats-new-VSTS",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes",
|
||||
"moniker_groups": [],
|
||||
"version": 0
|
||||
}
|
||||
],
|
||||
@ -452,9 +466,11 @@
|
||||
"branches_to_filter": [
|
||||
""
|
||||
],
|
||||
"git_repository_url_open_to_public_contributors": "https://cpubwin.visualstudio.com/_git/it-client",
|
||||
"git_repository_url_open_to_public_contributors": "https://github.com/MicrosoftDocs/windows-itpro-docs",
|
||||
"git_repository_branch_open_to_public_contributors": "master",
|
||||
"skip_source_output_uploading": false,
|
||||
"need_preview_pull_request": true,
|
||||
"resolve_user_profile_using_github": true,
|
||||
"dependent_repositories": [
|
||||
{
|
||||
"path_to_root": "_themes.pdf",
|
||||
@ -480,7 +496,8 @@
|
||||
]
|
||||
},
|
||||
"need_generate_pdf_url_template": true,
|
||||
"resolve_user_profile_using_github": true,
|
||||
"need_generate_pdf": false,
|
||||
"need_generate_intellisense": false,
|
||||
"Targets": {
|
||||
"Pdf": {
|
||||
"template_folder": "_themes.pdf"
|
||||
|
@ -227,7 +227,12 @@
|
||||
},
|
||||
{
|
||||
"source_path": "windows/manage/set-up-a-device-for-anyone-to-use.md",
|
||||
"redirect_url": "/windows/configuration/set-up-a-device-for-anyone-to-use",
|
||||
"redirect_url": "/windows/configuration/kiosk-shared-pc",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/set-up-a-device-for-anyone-to-use.md",
|
||||
"redirect_url": "/windows/configuration/kiosk-shared-pc",
|
||||
"redirect_document_id": true
|
||||
},
|
||||
{
|
||||
|
59
bcs/images/icon_video.svg
Normal file
@ -0,0 +1,59 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 150 105">
|
||||
<defs>
|
||||
<style>
|
||||
.cls-1 {
|
||||
fill: #556a8a;
|
||||
}
|
||||
|
||||
.cls-2 {
|
||||
fill: #fff;
|
||||
}
|
||||
|
||||
.cls-3 {
|
||||
fill: none;
|
||||
stroke: #556a8a;
|
||||
stroke-miterlimit: 10;
|
||||
stroke-width: 2px;
|
||||
}
|
||||
|
||||
.cls-4 {
|
||||
fill: #2bc7f4;
|
||||
}
|
||||
|
||||
.cls-5 {
|
||||
fill: #e5e5e5;
|
||||
}
|
||||
</style>
|
||||
</defs>
|
||||
<title> 5</title>
|
||||
<g id="Illustrations">
|
||||
<g>
|
||||
<g>
|
||||
<g>
|
||||
<rect class="cls-1" x="34" y="22" width="82" height="61" rx="2" ry="2"/>
|
||||
<g>
|
||||
<rect class="cls-2" x="36" y="24" width="7" height="7"/>
|
||||
<rect class="cls-2" x="36" y="34" width="7" height="7"/>
|
||||
<rect class="cls-2" x="36" y="44" width="7" height="7"/>
|
||||
<rect class="cls-2" x="36" y="54" width="7" height="7"/>
|
||||
<rect class="cls-2" x="36" y="64" width="7" height="7"/>
|
||||
<rect class="cls-2" x="36" y="74" width="7" height="7"/>
|
||||
</g>
|
||||
<g>
|
||||
<rect class="cls-2" x="107" y="24" width="7" height="7"/>
|
||||
<rect class="cls-2" x="107" y="34" width="7" height="7"/>
|
||||
<rect class="cls-2" x="107" y="44" width="7" height="7"/>
|
||||
<rect class="cls-2" x="107" y="54" width="7" height="7"/>
|
||||
<rect class="cls-2" x="107" y="64" width="7" height="7"/>
|
||||
<rect class="cls-2" x="107" y="74" width="7" height="7"/>
|
||||
</g>
|
||||
<rect class="cls-2" x="45" y="24" width="60" height="57"/>
|
||||
<path class="cls-3" d="M91.18,51.7A16.19,16.19,0,0,1,75,67.89a15.91,15.91,0,0,1-5-.79A16.18,16.18,0,1,1,91.18,51.7Z"/>
|
||||
</g>
|
||||
<polygon class="cls-4" points="69 62.15 69 41.26 87 51.7 69 62.15"/>
|
||||
</g>
|
||||
<rect class="cls-5" x="45" y="24" width="60" height="7"/>
|
||||
<rect class="cls-5" x="45" y="74" width="60" height="7"/>
|
||||
</g>
|
||||
</g>
|
||||
</svg>
|
After Width: | Height: | Size: 1.9 KiB |
82
bcs/images/partner-fastrack-3.svg
Normal file
@ -0,0 +1,82 @@
|
||||
<svg id="Illustrations" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 140">
|
||||
<defs>
|
||||
<style>
|
||||
.cls-1 {
|
||||
fill: none;
|
||||
stroke: #bad80a;
|
||||
}
|
||||
|
||||
.cls-1, .cls-2, .cls-3, .cls-6, .cls-9 {
|
||||
stroke-miterlimit: 10;
|
||||
stroke-width: 2px;
|
||||
}
|
||||
|
||||
.cls-2, .cls-3, .cls-6, .cls-8, .cls-9 {
|
||||
fill: #fff;
|
||||
}
|
||||
|
||||
.cls-2 {
|
||||
stroke: #ababab;
|
||||
}
|
||||
|
||||
.cls-3 {
|
||||
stroke: #55d2f6;
|
||||
}
|
||||
|
||||
.cls-4 {
|
||||
fill: #ffc52b;
|
||||
}
|
||||
|
||||
.cls-5 {
|
||||
fill: #ffb900;
|
||||
}
|
||||
|
||||
.cls-6 {
|
||||
stroke: #2bc7f4;
|
||||
}
|
||||
|
||||
.cls-7 {
|
||||
fill: #2bc7f4;
|
||||
}
|
||||
|
||||
.cls-9 {
|
||||
stroke: #556a8a;
|
||||
}
|
||||
|
||||
.cls-10 {
|
||||
fill: #c2c2c2;
|
||||
}
|
||||
</style>
|
||||
</defs>
|
||||
<title>ms365enterprise-partner-fastrack-3</title>
|
||||
<g>
|
||||
<polyline class="cls-1" points="212.84 92.22 212.84 46.89 255 71.03 212.62 92.66"/>
|
||||
<g>
|
||||
<g>
|
||||
<polygon class="cls-2" points="224.55 18 236.93 39.5 224.55 61 199.8 61 187.42 39.5 199.8 18 224.55 18"/>
|
||||
<polygon class="cls-3" points="281.75 50 294.13 71.5 281.75 93 257 93 244.62 71.5 257 50 281.75 50"/>
|
||||
</g>
|
||||
<polygon class="cls-2" points="224.55 78 236.93 99.5 224.55 121 199.8 121 187.42 99.5 199.8 78 224.55 78"/>
|
||||
</g>
|
||||
<g>
|
||||
<path class="cls-4" d="M281,57.35,291.17,40.5H279L262.9,63.83h11.66l-10.8,20.06,10-8.89,3.82-3.41L294,57.35Z"/>
|
||||
<path class="cls-5" d="M281,57.35,291.17,40.5h-7L268.08,63.83h11.66l-6,11.17,3.82-3.41L294,57.35Z"/>
|
||||
</g>
|
||||
<polygon class="cls-6" points="170.5 34 192 71 170.5 108 127.5 108 106 71 127.5 34 170.5 34"/>
|
||||
<g>
|
||||
<path class="cls-7" d="M170,74h-5V53l3-4-3-10h-4l-3,10,3,4V74h-5v6h3c0,2-2,4-3,4.08V96.5c0,3.3,2,5.5,4,5.5h6c2,0,4-2.7,4-6V84c-1,0-3-2-3-4h3Z"/>
|
||||
<rect class="cls-8" x="160" y="82" width="2" height="17"/>
|
||||
<rect class="cls-8" x="164" y="82" width="2" height="17"/>
|
||||
<path class="cls-9" d="M150,50.5a12,12,0,0,0-7-10.91V47.5l-5,4-5-4V39.59a12,12,0,0,0,0,21.81V96.5a4,4,0,0,0,4,4h1a4,4,0,0,0,4-4V61.8A12,12,0,0,0,150,50.5Z"/>
|
||||
<rect class="cls-10" x="134" y="91" width="7" height="5"/>
|
||||
</g>
|
||||
<g>
|
||||
<circle class="cls-9" cx="212.18" cy="34.18" r="7.71"/>
|
||||
<path class="cls-9" d="M200.18,54.18a12,12,0,0,1,24,0"/>
|
||||
</g>
|
||||
<g>
|
||||
<circle class="cls-9" cx="212.18" cy="93.86" r="7.71"/>
|
||||
<path class="cls-9" d="M200.18,113.86a12,12,0,0,1,24,0"/>
|
||||
</g>
|
||||
</g>
|
||||
</svg>
|
After Width: | Height: | Size: 2.4 KiB |
123
bcs/images/partner-news-2.svg
Normal file
@ -0,0 +1,123 @@
|
||||
<svg id="Illustrations" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 140">
|
||||
<defs>
|
||||
<style>
|
||||
.cls-1, .cls-14, .cls-5 {
|
||||
fill: #fff;
|
||||
}
|
||||
|
||||
.cls-1, .cls-6 {
|
||||
stroke: #556a8a;
|
||||
}
|
||||
|
||||
.cls-1, .cls-12, .cls-14, .cls-6 {
|
||||
stroke-miterlimit: 10;
|
||||
stroke-width: 2px;
|
||||
}
|
||||
|
||||
.cls-2 {
|
||||
fill: #80def9;
|
||||
opacity: 0.7;
|
||||
}
|
||||
|
||||
.cls-3 {
|
||||
fill: #556a8a;
|
||||
}
|
||||
|
||||
.cls-4 {
|
||||
fill: #e5e5e5;
|
||||
}
|
||||
|
||||
.cls-5 {
|
||||
opacity: 0.8;
|
||||
}
|
||||
|
||||
.cls-12, .cls-6, .cls-7 {
|
||||
fill: none;
|
||||
}
|
||||
|
||||
.cls-8 {
|
||||
fill: #7750a3;
|
||||
}
|
||||
|
||||
.cls-9 {
|
||||
fill: #9273b6;
|
||||
}
|
||||
|
||||
.cls-10 {
|
||||
fill: #2bc7f4;
|
||||
}
|
||||
|
||||
.cls-11 {
|
||||
fill: #ababab;
|
||||
}
|
||||
|
||||
.cls-12 {
|
||||
stroke: #ababab;
|
||||
}
|
||||
|
||||
.cls-13 {
|
||||
fill: #55d2f6;
|
||||
}
|
||||
|
||||
.cls-14 {
|
||||
stroke: #00bcf2;
|
||||
}
|
||||
|
||||
.cls-15 {
|
||||
fill: #3a96dd;
|
||||
}
|
||||
|
||||
.cls-16 {
|
||||
fill: #e6e6e6;
|
||||
}
|
||||
|
||||
.cls-17 {
|
||||
fill: #f2f2f2;
|
||||
}
|
||||
|
||||
.cls-18 {
|
||||
fill: #bad80a;
|
||||
}
|
||||
</style>
|
||||
</defs>
|
||||
<title>ms365enterprise-partner-news-2</title>
|
||||
<g>
|
||||
<path class="cls-1" d="M116.21,115h0Z"/>
|
||||
<path class="cls-2" d="M185.9,67.69a39.37,39.37,0,0,1,77.71-1.23,26.79,26.79,0,0,1,43,13.62,23.42,23.42,0,1,1,5.56,46.16H180.43C167.06,123.52,157,111.12,157,97A29.27,29.27,0,0,1,185.9,67.69Z"/>
|
||||
<path class="cls-2" d="M80.75,41.86a33.72,33.72,0,0,1,66.56-1.06,22.95,22.95,0,0,1,36.86,11.66A20.06,20.06,0,1,1,188.93,92H76.07C64.62,89.68,56,79.06,56,66.93A25.07,25.07,0,0,1,80.75,41.86Z"/>
|
||||
<g>
|
||||
<g>
|
||||
<path class="cls-3" d="M126,21.43H112.21c-1.36,0-3.21,1.11-3.21,2.47v84c0,5.06,1.35,7.07,5.16,7.07,5.42,0,11.84-9.35,11.84-19.83Z"/>
|
||||
<path class="cls-4" d="M230,17v88.6c0,6.5-2,9.39-9.19,9.39H113c1.21,0,8-.71,8-7.1,0-6.72-.06-75.29,0-90.89Z"/>
|
||||
<polygon class="cls-5" points="230 17 230 86 158.48 17 230 17"/>
|
||||
<path class="cls-6" d="M121,17c-.06,15.6,0,84.17,0,90.89,0,6.39-6.79,7.05-8,7.1H220.81c7.23,0,9.19-2.89,9.19-9.39V17Z"/>
|
||||
<rect class="cls-7" x="108" y="-1" width="128" height="128" transform="translate(344 126) rotate(-180)"/>
|
||||
</g>
|
||||
<rect class="cls-8" x="135" y="32" width="78" height="8"/>
|
||||
<rect class="cls-9" x="135" y="74" width="48" height="8"/>
|
||||
<rect class="cls-10" x="135" y="47" width="29" height="20"/>
|
||||
<rect class="cls-11" x="190" y="74" width="23" height="27"/>
|
||||
<line class="cls-12" x1="170" y1="48" x2="212" y2="48"/>
|
||||
<line class="cls-12" x1="171" y1="66" x2="213" y2="66"/>
|
||||
<line class="cls-12" x1="136" y1="90" x2="183" y2="90"/>
|
||||
<line class="cls-12" x1="136" y1="99" x2="183" y2="99"/>
|
||||
<line class="cls-12" x1="170" y1="57" x2="212" y2="57"/>
|
||||
<polygon class="cls-13" points="164 47 164 64 147 47 164 47"/>
|
||||
</g>
|
||||
</g>
|
||||
<path class="cls-14" d="M310.65,59.88a16.11,16.11,0,0,0-2.9-4.86,22.4,22.4,0,0,0-6.16-5.45V49A18.08,18.08,0,0,0,283.54,31.2,17.75,17.75,0,0,0,274,33.87a24.17,24.17,0,0,0-19.4-9.81A23.79,23.79,0,0,0,230.7,47.47c0,.89.22,1.56.22,2.45C224,53.27,220,59.06,220,66.42c0,10.52,8.27,18.94,19.23,19.56,1,7.3,10.21,13,21.42,13,9.55,0,17.64-4.15,20.45-9.9a22.31,22.31,0,0,0,29.54-29.23Z"/>
|
||||
<path class="cls-3" d="M239.3,72.9h3.41l-.09-18H239.3c-2.2,0-4.65,4.35-4.62,9S237.1,72.92,239.3,72.9Z"/>
|
||||
<path class="cls-15" d="M237.26,64c0-5,1.74-9,3.94-9A14,14,0,0,1,243,55c1.91.67,2.25,4.46,2.27,8.93s.22,8.36-1.72,9c-.17.05-2,0-2.22,0C239.09,73,237.28,69,237.26,64Z"/>
|
||||
<path class="cls-6" d="M261,67.65h-2.7a7.65,7.65,0,1,0,0,15.3H261a7.65,7.65,0,1,0,0-15.3Z"/>
|
||||
<path class="cls-16" d="M281.69,64v-.08c0-8.74,1-15.81,3-19-3.7,1.91-12.29,4.88-22.83,7.61-5,1.3-19.12,3.36-19.17,3.39-1.53,1.53-1.9,5.59-2,7.37,0,.27,0,.48,0,.63,0,1.13.24,6.24,2,8,0,0,14.21,2.09,19.17,3.39,10.54,2.73,19.13,5.7,22.83,7.61-1.6-2.54-2.56-7.62-2.87-14.07C281.73,67.32,281.69,65.69,281.69,64Z"/>
|
||||
<g>
|
||||
<path class="cls-17" d="M284.67,82.95c-3.7-1.91-12.29-4.88-22.83-7.61-5-1.3-19.12-3.36-19.17-3.39-1.76-1.76-2-8.36-1.65-7.8,0,0,12,1.55,18.65,2.8s22,6,22,6C281.65,78.57,283.07,80.41,284.67,82.95Z"/>
|
||||
<path class="cls-6" d="M281.69,63.95v0c0-8,.83-14.61,2.5-18.08.15-.32-.38,0-.21-.3-.47.24.81-.56.19-.28a168.81,168.81,0,0,1-22.33,7.31c-5,1.3-19.12,3.36-19.17,3.39-1.76,1.76-2,6.87-2,8s.24,6.24,2,8c.05,0,14.21,2.09,19.17,3.39,10.54,2.73,17.5,5.11,21.2,7-.25-.39,1,.61.75.09-1.52-3.58-2.1-10.83-2.1-18.47Z"/>
|
||||
<path class="cls-18" d="M293.2,64c0,8.33-2.32,15.48-4.24,18.7-.68,1.15-1.45,1.8-2.25,1.8a2.59,2.59,0,0,1-2-1.36c-1.58-2.27-2.81-7.18-3.29-13.28-.15-1.86-.23-3.82-.23-5.86s.08-4,.23-5.9c.49-6.08,1.71-11,3.29-13.23a2.58,2.58,0,0,1,2-1.37c.8,0,1.57.64,2.25,1.81C290.88,48.5,293.2,55.66,293.2,64Z"/>
|
||||
<path class="cls-3" d="M288.67,63.95a6,6,0,0,1-6,6,6.09,6.09,0,0,1-1.22-.12c-.15-1.86-.23-3.82-.23-5.86s.08-4,.23-5.9a6.08,6.08,0,0,1,1.22-.12A6,6,0,0,1,288.67,63.95Z"/>
|
||||
<path class="cls-6" d="M293.2,64c0,8.33-2.32,15.48-4.24,18.7-.68,1.15-1.45,1.8-2.25,1.8a2.57,2.57,0,0,1-2-1.36c-2.06-3-3.52-10.4-3.52-19.14s1.46-16.17,3.52-19.13a2.59,2.59,0,0,1,2-1.37c.8,0,1.57.65,2.25,1.81C290.88,48.49,293.2,55.66,293.2,64Z"/>
|
||||
</g>
|
||||
<line class="cls-6" x1="297.2" y1="63.47" x2="320.2" y2="63.47"/>
|
||||
<line class="cls-6" x1="297.42" y1="56.47" x2="317.2" y2="44.73"/>
|
||||
<line class="cls-6" x1="317.2" y1="82.21" x2="297.42" y2="70.47"/>
|
||||
</svg>
|
After Width: | Height: | Size: 5.3 KiB |
72
bcs/images/partner-resource-training-1.svg
Normal file
@ -0,0 +1,72 @@
|
||||
<svg id="Illustrations" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 140">
|
||||
<defs>
|
||||
<style>
|
||||
.cls-1, .cls-5 {
|
||||
fill: #fff;
|
||||
}
|
||||
|
||||
.cls-2 {
|
||||
fill: #80def9;
|
||||
opacity: 0.7;
|
||||
}
|
||||
|
||||
.cls-3, .cls-6 {
|
||||
fill: none;
|
||||
stroke-miterlimit: 10;
|
||||
stroke-width: 2px;
|
||||
}
|
||||
|
||||
.cls-3 {
|
||||
stroke: #556a8a;
|
||||
}
|
||||
|
||||
.cls-4 {
|
||||
fill: #556a8a;
|
||||
}
|
||||
|
||||
.cls-5 {
|
||||
opacity: 0.2;
|
||||
}
|
||||
|
||||
.cls-6 {
|
||||
stroke: #868787;
|
||||
}
|
||||
|
||||
.cls-7 {
|
||||
fill: #e5e5e5;
|
||||
}
|
||||
|
||||
.cls-8 {
|
||||
fill: #bad80a;
|
||||
}
|
||||
</style>
|
||||
</defs>
|
||||
<title>ms365enterprise-partner-resource-training-1</title>
|
||||
<g>
|
||||
<path class="cls-1" d="M287,26v76a2,2,0,0,1-2,2H167a2,2,0,0,1-2-2V26a2,2,0,0,1,2-2H285A2,2,0,0,1,287,26Z"/>
|
||||
<path class="cls-2" d="M180,25v79H167a2,2,0,0,1-1-.29V25Z"/>
|
||||
<path class="cls-2" d="M273,25v79h13a2,2,0,0,0,1-.29V25Z"/>
|
||||
<rect class="cls-3" x="165.04" y="24" width="122" height="80" rx="2" ry="2"/>
|
||||
<rect class="cls-4" x="159" y="21" width="135" height="5"/>
|
||||
<path class="cls-4" d="M101,92.93V131.5h11.09c1.54-13.16,3.6-30.57,3.94-32.83.43-2.76,4.7-2.76,5.12,0,.35,2.26,2.74,19.67,4.45,32.83H136v-41h6l-.33-12.33L141,53l8.42,2.19a4.54,4.54,0,0,0,1.93.25,4.49,4.49,0,0,0,1.48-.38l19-9.45a4.54,4.54,0,1,0-3.75-8.27l-16.63,6.83-15.9-4.68c-.93-.28-1.91-.57-2.94-.86l0,0c-2.06-.58-4.18-1.16-5.79-1.59l-2.7-.72-6,12.48H118l-6-12.48s-5.77,1.3-9.89,2.39l-1.63.44A8.84,8.84,0,0,0,95,43.48a11.43,11.43,0,0,0-1.28,4.42c-.61,6.36-.6,20.59-1.12,26.31-.19,2-.2,8.56,2.07,11.48A88.76,88.76,0,0,0,101,92.93Z"/>
|
||||
<path class="cls-5" d="M171.84,45.58l-19,9.45a4.49,4.49,0,0,1-1.48.38,4.54,4.54,0,0,1-1.93-.25L141,53l.67,25.2L142,90.5l-47-47a8.84,8.84,0,0,1,5.55-4.38l1.63-.44c4.12-1.09,9.89-2.39,9.89-2.39l6,12.48h.1l6-12.48,2.7.72c1.61.43,3.73,1,5.79,1.59l0,0c1,.29,2,.58,2.94.86l15.9,4.68,16.63-6.83a4.54,4.54,0,1,1,3.75,8.27Z"/>
|
||||
<ellipse class="cls-4" cx="117.98" cy="20.96" rx="10" ry="12.46"/>
|
||||
<g>
|
||||
<path class="cls-4" d="M200.36,50h-1.44V39.11a3.34,3.34,0,0,1-.49.38,8,8,0,0,1-.72.43q-.4.21-.84.4a6.13,6.13,0,0,1-.87.29V39.15a8.37,8.37,0,0,0,1-.36q.53-.22,1-.5t1-.58a7.71,7.71,0,0,0,.79-.59h.54Z"/>
|
||||
<path class="cls-4" d="M201.88,58.7a2.62,2.62,0,0,0-.18-1,2,2,0,0,0-1.23-1.14,2.87,2.87,0,0,0-.91-.14,3,3,0,0,0-.83.11,4,4,0,0,0-.79.32,4.94,4.94,0,0,0-.74.48,5.4,5.4,0,0,0-.66.62V56.4a4.3,4.3,0,0,1,1.36-.9,4.78,4.78,0,0,1,1.83-.31,4.42,4.42,0,0,1,1.43.22,3.28,3.28,0,0,1,1.14.65,3,3,0,0,1,.76,1.06,3.6,3.6,0,0,1,.28,1.45,5,5,0,0,1-.17,1.35,4.22,4.22,0,0,1-.52,1.14,5.51,5.51,0,0,1-.87,1,12.39,12.39,0,0,1-1.24,1q-.89.63-1.46,1.08a6.36,6.36,0,0,0-.91.84,2.4,2.4,0,0,0-.47.78,2.71,2.71,0,0,0-.14.9h6.28V68h-7.78v-.62a5.2,5.2,0,0,1,.18-1.42,3.7,3.7,0,0,1,.58-1.17,6.45,6.45,0,0,1,1.06-1.11q.65-.55,1.6-1.25a10,10,0,0,0,1.15-.94,4.85,4.85,0,0,0,.74-.9,3.19,3.19,0,0,0,.4-.91A3.88,3.88,0,0,0,201.88,58.7Z"/>
|
||||
<path class="cls-4" d="M203.47,83.43a3.67,3.67,0,0,1-.32,1.55,3.43,3.43,0,0,1-.9,1.2,4.19,4.19,0,0,1-1.4.77,5.67,5.67,0,0,1-1.8.27,5.24,5.24,0,0,1-2.87-.69V85a4.59,4.59,0,0,0,2.92,1,4,4,0,0,0,1.19-.17,2.66,2.66,0,0,0,.91-.48,2.15,2.15,0,0,0,.59-.76,2.4,2.4,0,0,0,.21-1q0-2.47-3.52-2.47h-1V79.87h1q3.11,0,3.11-2.32,0-2.14-2.37-2.14a4,4,0,0,0-2.5.9v-1.4a5.48,5.48,0,0,1,2.87-.72,4.4,4.4,0,0,1,1.43.22,3.28,3.28,0,0,1,1.1.62,2.71,2.71,0,0,1,.71.95,2.91,2.91,0,0,1,.25,1.22,3.08,3.08,0,0,1-2.51,3.2v0a4,4,0,0,1,1.19.31,3.17,3.17,0,0,1,.94.63,2.82,2.82,0,0,1,.62.91A2.92,2.92,0,0,1,203.47,83.43Z"/>
|
||||
<line class="cls-6" x1="212" y1="45" x2="245" y2="45"/>
|
||||
<line class="cls-6" x1="212" y1="62" x2="245" y2="62"/>
|
||||
<line class="cls-6" x1="212" y1="79" x2="245" y2="79"/>
|
||||
</g>
|
||||
<g>
|
||||
<rect class="cls-4" x="252" y="83.57" width="2" height="25" rx="0.5" ry="0.5"/>
|
||||
<path class="cls-1" d="M307,84.5,278,73.57,249,84.5l9,4v15.74c0,5.56,9.16,10.26,20,10.26s20-4.7,20-10.26V88.5Z"/>
|
||||
<polygon class="cls-7" points="249.52 84.5 278.52 73.57 306.52 84.5 278.52 96.5 249.52 84.5"/>
|
||||
<polygon class="cls-8" points="299.09 88.18 278.52 96.94 259.09 88.73 258.82 93.27 278.52 101.6 299.09 92.91 299.09 88.18"/>
|
||||
<path class="cls-3" d="M308,84.5,279,73.57,250,84.5l9,4v15.74c0,5.56,9.16,10.26,20,10.26s20-4.7,20-10.26V88.5Z"/>
|
||||
<path class="cls-4" d="M251,109v-4c0-2.2.72-4,1.6-4h.8c.88,0,1.6,1.8,1.6,4v4Z"/>
|
||||
<polyline class="cls-3" points="257.73 87.91 278.52 96.5 301.27 87.45"/>
|
||||
</g>
|
||||
</g>
|
||||
</svg>
|
After Width: | Height: | Size: 4.4 KiB |
632
bcs/index.md
@ -3,6 +3,7 @@ layout: HubPage
|
||||
hide_bc: true
|
||||
author: CelesteDG
|
||||
ms.author: celested
|
||||
keywords: Microsoft 365 Business, Microsoft 365, business, Microsoft 365 Business documentation, docs, documentation
|
||||
ms.topic: hub-page
|
||||
ms.localizationpriority: high
|
||||
audience: microsoft-business
|
||||
@ -123,6 +124,7 @@ description: Learn about the product documentation and resources available for M
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<!--
|
||||
<li>
|
||||
<a href="#user-mgmt">User management</a>
|
||||
<ul id="user-mgmt" class="cardsC">
|
||||
@ -171,14 +173,72 @@ description: Learn about the product documentation and resources available for M
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
-->
|
||||
<li>
|
||||
<a href="#device-mgmt">Device management</a>
|
||||
<ul id="device-mgmt" class="cardsC">
|
||||
<a href="#user-device-mgmt">User and device management</a>
|
||||
<ul id="user-device-mgmt" class="cardsC">
|
||||
<li class="fullSpan">
|
||||
<div class="container intro">
|
||||
<p>Find help on managing your organization's devices from the Microsoft 365 Business admin center.</p>
|
||||
<p>Manage customers/users in your organization and find help on managing your organization's devices from the Microsoft 365 Business admin center.</p>
|
||||
</div>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/96153102-1db1-4df8-bca5-38cea80b65ce" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-user-management-add-customer-1.svg" alt="Add a new user and assign licenses" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Add a new customer/user</h3>
|
||||
<p>Onboarding a new user? Use the admin center to add a new user and assign licenses.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/d5155593-3bac-4d8d-9d8b-f4513a81479e" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-user-management-remove-customer-2.svg" alt="Follow the links to remove a customer/user" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Remove a customer/user</h3>
|
||||
<p>Need to remove a user? You'll need to <a href="https://support.office.com/article/80bdae57-f8bc-4e40-a58c-956007117ecb">remove company data from devices</a> and <a href="https://support.office.com/article/c4db6caf-74df-4734-b1dd-53e371c7a3c3">reset Windows 10 devices to their factory settings</a>.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/2d7ff45e-0da0-4caa-89a9-48cabf41f193" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-upgrade-2.svg" alt="Upgrade to Windows 10" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Set up Windows devices for Microsoft 365 Business users</h3>
|
||||
<p>Once you've upgraded your device to Windows 10 Pro, join it to your organization's Azure AD, and get it ready for use.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/ed34fff3-2881-4ed4-9906-1ba6bb8dd804" target="_blank">
|
||||
<div class="cardSize">
|
||||
@ -272,12 +332,88 @@ description: Learn about the product documentation and resources available for M
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-policies-set-device-config-1.svg" alt="Set device configurations for Windows 10 PCs" />
|
||||
<img src="images/bcs-partner-policies-set-device-config-1.svg" alt="Set device protection settings for Windows 10 PCs" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Set device configurations for Windows 10 PCs</h3>
|
||||
<p>Learn how to create, edit, or delete an app management policy in Microsoft 365 Business.</p>
|
||||
<h3>Set device protection settings for Windows 10 PCs</h3>
|
||||
<p>Learn how to secure Windows 10 PCs and what settings you can configure.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/02e74022-44af-414b-9d74-0ebf5c2197f0" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-policies-set-device-config-1.svg" alt="Set app protection settings for Windows 10 devices" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Set app protection settings for Windows 10 devices</h3>
|
||||
<p>Learn how to create and assign app protection settings for Windows 10 devices and what settings you can configure.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/6f2b80b4-81c3-4714-a7bc-ae69313e8a33" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-iw-devicesetup-setup-1.svg" alt="Set app protection settings for Android or iOS devices" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Set app protection settings for Android or iOS devices</h3>
|
||||
<p>Learn how to create, edit, or delete an app management policy for Android or iOS devices, and what settings you can configure.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/f3433b6b-02f7-447f-9d62-306bf03638b0" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-password-3.svg" alt="Validate app protection settings on Android devices" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Validate app protection settings on Android devices</h3>
|
||||
<p>Follow the steps to confirm that the settings you chose are working on Android devices.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/2ec03d29-cc1d-4e74-a985-fb55a4b62966" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-password-3.svg" alt="Validate app protection settings on iOS devices" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Validate app protection settings on iOS devices</h3>
|
||||
<p>Follow the steps to confirm that the settings you chose are working on iOS devices.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
@ -370,161 +506,6 @@ description: Learn about the product documentation and resources available for M
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/2d7ff45e-0da0-4caa-89a9-48cabf41f193" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-upgrade-2.svg" alt="Upgrade to Windows 10" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Upgrade to Windows 10</h3>
|
||||
<p>Set up Windows 10 PCs for Microsoft 365 Business users.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li>
|
||||
<a href="#troub-support">Troubleshooting and support</a>
|
||||
<ul id="troub-support" class="cardsC">
|
||||
<li class="fullSpan">
|
||||
<div class="container intro">
|
||||
<p>Looking for help or can't find what you need? Try these resources.</p>
|
||||
</div>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://www.microsoft.com/solution-providers/search" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-find-partner-1.svg" alt="Find a Microsoft-certified service provider" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Find a Partner</h3>
|
||||
<p>Visit the Microsoft Partner Center to locate a Microsoft-certified solution provider who can help you locally or remotely. </p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/496e690b-b75d-4ff5-bf34-cc32905d0364#bkmk_support" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-technical-support-4.svg" alt="Submit a technical support request for Microsoft 365 Business" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Microsoft Technical Support</h3>
|
||||
<p>Submit a technical support request for Microsoft 365 Business.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="#">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-troubleshooting-3.svg" alt="Find solutions for common Microsoft 365 Business issues" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Troubleshoot problems - Coming soon</h3>
|
||||
<p>Find solutions for common Microsoft 365 Business issues.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li>
|
||||
<a href="#adv-mgmt">Advanced management</a>
|
||||
<ul id="adv-mgmt" class="cardsC">
|
||||
<li class="fullSpan">
|
||||
<div class="container intro">
|
||||
<p>See these links for more in-depth information about these products and features.</p>
|
||||
</div>
|
||||
</li>
|
||||
<!--
|
||||
<li>
|
||||
<a href="https://docs.microsoft.com/intune">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-intune-1.svg" alt="Microsoft Intune" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Microsoft Intune</h3>
|
||||
<p>Need to update other policies or take advantage of the full Intune capabilities? </p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
-->
|
||||
<li>
|
||||
<a href="https://docs.microsoft.com/en-us/windows/windows-10/" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-windows10-2.svg" alt="Learn more about Windows 10" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Windows 10</h3>
|
||||
<p>Find out what's new, how to apply custom configurations to devices, managing apps, deployment, and more.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://msdn.microsoft.com/partner-center/autopilot" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-auto-pilot-3.svg" alt="Use Windows AutoPilot to deploy Windows 10 devices" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Set up Windows 10 devices using Windows AutoPilot</h3>
|
||||
<p>Deploy Windows 10 devices using Windows AutoPilot from the Partner Center.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li>
|
||||
@ -573,27 +554,6 @@ description: Learn about the product documentation and resources available for M
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<!--
|
||||
<li>
|
||||
<a href="#">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management- management-4_placeholder.svg" alt="Manage changes" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Change management</h3>
|
||||
<p>tbd</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
-->
|
||||
<li>
|
||||
<a href="https://support.office.com/article/74a1ef8b-3844-4d08-9980-9f8f7a36000f" target="_blank">
|
||||
<div class="cardSize">
|
||||
@ -696,6 +656,314 @@ description: Learn about the product documentation and resources available for M
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li>
|
||||
<a href="#adv-mgmt">Advanced management</a>
|
||||
<ul id="adv-mgmt" class="cardsC">
|
||||
<li class="fullSpan">
|
||||
<div class="container intro">
|
||||
<p>See these links for more in-depth information about these products and features.</p>
|
||||
</div>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://docs.microsoft.com/en-us/windows/windows-10/" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-windows10-2.svg" alt="Learn more about Windows 10" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Windows 10</h3>
|
||||
<p>Find out what's new, how to apply custom configurations to devices, managing apps, deployment, and more.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://msdn.microsoft.com/partner-center/autopilot" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-auto-pilot-3.svg" alt="Use Windows AutoPilot to deploy Windows 10 devices" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Set up Windows 10 devices using Windows AutoPilot</h3>
|
||||
<p>Deploy Windows 10 devices using Windows AutoPilot from the Partner Center.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li>
|
||||
<a href="#trouble-support">Troubleshooting and support</a>
|
||||
<ul id="trouble-support" class="cardsC">
|
||||
<li class="fullSpan">
|
||||
<div class="container intro">
|
||||
<p>Looking for help or can't find what you need? Try these resources.</p>
|
||||
</div>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://www.microsoft.com/solution-providers/search" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-find-partner-1.svg" alt="Find a Microsoft-certified service provider" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Find a Partner</h3>
|
||||
<p>Visit the Microsoft Partner Center to locate a Microsoft-certified solution provider who can help you locally or remotely. </p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/496e690b-b75d-4ff5-bf34-cc32905d0364#bkmk_support" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-technical-support-4.svg" alt="Submit a technical support request for Microsoft 365 Business" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Microsoft Technical Support</h3>
|
||||
<p>Submit a technical support request for Microsoft 365 Business.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="#">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/bcs-partner-advanced-management-troubleshooting-3.svg" alt="Find solutions for common Microsoft 365 Business issues" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Troubleshoot problems - Coming soon</h3>
|
||||
<p>Find solutions for common Microsoft 365 Business issues.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li>
|
||||
<a href="#videos">Video tutorials</a>
|
||||
<ul id="videos" class="cardsG">
|
||||
<li class="fullSpan">
|
||||
<div class="container intro">
|
||||
<p>Some of the tasks covered in the step-by-step guides are also available as video tutorials. Follow these links to start watching.</p>
|
||||
</div>
|
||||
</li>
|
||||
<li>
|
||||
<a href="http://videoplayercdn.osi.office.net/embed/0705c337-f3e8-4d28-bb6c-530cd28e99f2_1280x720_3400.mp4" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/icon_video.svg" alt="Set up Microsoft 365 Business" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Set up Microsoft 365 Business</h3>
|
||||
<p>Watch how you can quickly set up Microsoft 365 Business using the setup wizard from the Microsoft 365 Business admin center.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="http://videoplayercdn.osi.office.net/embed/a5734146-620a-4cec-8618-536b3ca37972_1280x720_3400.mp4" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/icon_video.svg" alt="Secure Windows 10 devices with Microsoft 365 Business" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Secure Windows 10 devices with Microsoft 365 Business</h3>
|
||||
<p>Check out how to use a policy to secure Windows 10 devices and how to verify the policy is applied correctly.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="http://videoplayercdn.osi.office.net/embed/e0ee7052-e0f4-4c42-a4f1-5e91b9776ce9_1280x720_3400.mp4" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/icon_video.svg" alt="Secure Microsoft Office apps on iOS devices with Microsoft 365 Business" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Secure Microsoft Office apps on iOS devices with Microsoft 365 Business</h3>
|
||||
<p>See how you can use a policy to secure Office apps on iOS devices and how to verify the policy is working.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://youtu.be/oJpeTq0Dyxk" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/icon_video.svg" alt="Set up Windows devices for Microsoft 365 Business" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Set up Windows devices for Microsoft 365 Business</h3>
|
||||
<p>Upgrade your Windows 7, 8, or 8.1 Pro devices to Windows 10 Pro, and get your devices set up and joined to your organization.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://www.youtube.com/watch?v=qoDIyUOtZ6o" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/icon_video.svg" alt="Demo: Microsoft 365 Business first run experience" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Demo: Microsoft 365 Business first run experience</h3>
|
||||
<p>Watch one of our customers show you how easy it is to set up Microsoft 365 Business.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://www.youtube.com/watch?v=5kH-4gX-4NU" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/icon_video.svg" alt="Demo: Secure data and end user devices with Microsoft 365 Business" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Demo: Secure data and end user devices with Microsoft 365 Business</h3>
|
||||
<p>See how your users can set up their mobile devices and how to remove company data once your employee leaves the organization.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li>
|
||||
<a data-default="true" href="#partner-resources">Partner resources</a>
|
||||
<ul id="partner-resources" class="cardsC">
|
||||
<li class="fullSpan">
|
||||
<div class="container intro">
|
||||
<p>Looking for resources available to Microsoft 365 Business partners? Start here.</p>
|
||||
</div>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://partners.office.com/smb" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/partner-resource-training-1.svg" alt="SMB resources and training" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>SMB resources and training</h3>
|
||||
<p>Find the latest training offerings and updates, and other resources.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://partners.office.com/news" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/partner-news-2.svg" alt="News for partners" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>News articles</h3>
|
||||
<p>Read the latest news articles on Office 365 and Microsoft 365.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<!--
|
||||
<li>
|
||||
<a href="https://office365partnerportal-staging.azurewebsites.net/fasttrack-and-partners" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="media/hub-partner/partner-fastrack-3.svg" alt="FastTrack and partners" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>FastTrack and partners</h3>
|
||||
<p>Get the full suite of best practices, tools, remote assistance, and resources to help you and your customers move to Microsoft 365.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
-->
|
||||
</ul>
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li>
|
||||
|
@ -1,4 +1,4 @@
|
||||
---
|
||||
---
|
||||
title: Microsoft 365 Business Frequently Asked Questions
|
||||
description: Find answers to the most frequently asked questions about Microsoft 365 Business, a new solution designed for small and midsize businesses (SMB).
|
||||
author: CelesteDG
|
||||
@ -11,6 +11,7 @@ keywords: Microsoft 365 Business, Microsoft 365, SMB, FAQ, frequently asked ques
|
||||
ms.date: 08/04/2017
|
||||
---
|
||||
|
||||
|
||||
# Microsoft 365 Business Frequently Asked Questions
|
||||
|
||||
## Introduction
|
||||
|
@ -23,7 +23,7 @@ Microsoft Edge is the new, default web browser for Windows 10, helping you to e
|
||||
Microsoft Edge lets you stay up-to-date through the Windows Store and to manage your enterprise through Group Policy or your mobile device management (MDM) tools.
|
||||
|
||||
>[!Note]
|
||||
>For more info about the potential impact of using Microsoft Edge in a large organization, you can download an infographic from here: [Total Economic Impact of Microsoft Edge: Infographic](https://www.microsoft.com/en-us/download/details.aspx?id=53892).
|
||||
>For more info about the potential impact of using Microsoft Edge in a large organization, you can download an infographic from here: [Total Economic Impact of Microsoft Edge: Infographic](https://www.microsoft.com/download/details.aspx?id=55956). For a detailed report that provides you with a framework to evaluate the potential financial impact of adopting Microsoft Edge within your organization, you can download the full study here: [Total Economic Impact of Microsoft Edge: Forrester Study](https://www.microsoft.com/download/details.aspx?id=55847).
|
||||
|
||||
>Also, if you've arrived here looking for Internet Explorer 11 content, you'll need to go to the [Internet Explorer 11 (IE11)](https://docs.microsoft.com/en-us/internet-explorer/) area.
|
||||
|
||||
@ -37,6 +37,7 @@ Microsoft Edge lets you stay up-to-date through the Windows Store and to manage
|
||||
| [Available policies for Microsoft Edge](available-policies.md) |Microsoft Edge works with Group Policy and Microsoft Intune to help you manage your organization's computer settings.<br><br>Group Policy objects (GPO's) can include registry-based Administrative Template policy settings, security settings, software deployment information, scripts, folder redirection, and preferences. By using Group Policy and Intune, you can set up a policy setting once, and then copy that setting onto many computers. For example, you can set up multiple security settings in a GPO that's linked to a domain, and then apply all of those settings to every computer in the domain. |
|
||||
| [Use Enterprise Mode to improve compatibility](emie-to-improve-compatibility.md) |If you have specific web sites and apps that you know have compatibility problems with Microsoft Edge, you can use the Enterprise Mode site list so that the web sites will automatically open using Internet Explorer 11. Additionally, if you know that your intranet sites aren't going to work properly with Microsoft Edge, you can set all intranet sites to automatically open using IE11.<br><br>Using Enterprise Mode means that you can continue to use Microsoft Edge as your default browser, while also ensuring that your apps continue working on IE11. |
|
||||
| [Security enhancements for Microsoft Edge](security-enhancements-microsoft-edge.md) |Microsoft Edge is designed with significant security improvements over existing browsers, helping to defend people from increasingly sophisticated and prevalent web-based attacks against Windows. |
|
||||
|[Microsoft Edge Frequently Asked Questions (FAQs)](microsoft-edge-faq.md)|Answering frequently asked questions about Microsoft Edge features, integration, support, and potential problems.
|
||||
|
||||
## Interoperability goals and enterprise guidance
|
||||
|
||||
@ -58,7 +59,9 @@ You'll need to keep running them using IE11. If you don't have IE11 installed an
|
||||
|
||||
## Related topics
|
||||
|
||||
- [Total Economic Impact of Microsoft Edge: Infographic](https://www.microsoft.com/en-us/download/details.aspx?id=53892)
|
||||
- [Total Economic Impact of Microsoft Edge: Infographic](https://www.microsoft.com/download/details.aspx?id=55956)
|
||||
|
||||
- [Total Economic Impact of Microsoft Edge: Forrester Study](https://www.microsoft.com/download/details.aspx?id=55847)
|
||||
|
||||
- [Download Internet Explorer 11](https://go.microsoft.com/fwlink/p/?linkid=290956)
|
||||
|
||||
|
@ -5,4 +5,5 @@
|
||||
##[Available policies for Microsoft Edge](available-policies.md)
|
||||
##[Use Enterprise Mode to improve compatibility](emie-to-improve-compatibility.md)
|
||||
##[Security enhancements for Microsoft Edge](security-enhancements-microsoft-edge.md)
|
||||
##[Microsoft Edge Frequently Asked Questions (FAQs)](microsoft-edge-faq.md)
|
||||
|
||||
|
@ -21,7 +21,7 @@ Microsoft Edge works with Group Policy and Microsoft Intune to help you manage y
|
||||
By using Group Policy and Intune, you can set up a policy setting once, and then copy that setting onto many computers. For example, you can set up multiple security settings in a GPO that's linked to a domain, and then apply all of those settings to every computer in the domain.
|
||||
|
||||
> [!NOTE]
|
||||
> For more info about Group Policy, see the [Group Policy TechCenter](https://go.microsoft.com/fwlink/p/?LinkId=214514). This site provides links to the latest technical documentation, videos, and downloads for Group Policy. For more info about the tools you can use to change your Group Policy objects, see the Internet Explorer 11 topics, [Group Policy and the Group Policy Management Console (GPMC)](https://go.microsoft.com/fwlink/p/?LinkId=617921), [Group Policy and the Local Group Policy Editor](https://go.microsoft.com/fwlink/p/?LinkId=617922), [Group Policy and the Advanced Group Policy Management (AGPM)](https://go.microsoft.com/fwlink/p/?LinkId=617923), and [Group Policy and Windows PowerShell](https://go.microsoft.com/fwlink/p/?LinkId=617924).
|
||||
> For more info about the tools you can use to change your Group Policy objects, see the Internet Explorer 11 topics, [Group Policy and the Group Policy Management Console (GPMC)](https://go.microsoft.com/fwlink/p/?LinkId=617921), [Group Policy and the Local Group Policy Editor](https://go.microsoft.com/fwlink/p/?LinkId=617922), [Group Policy and the Advanced Group Policy Management (AGPM)](https://go.microsoft.com/fwlink/p/?LinkId=617923), and [Group Policy and Windows PowerShell](https://go.microsoft.com/fwlink/p/?LinkId=617924).
|
||||
|
||||
## Group Policy settings
|
||||
Microsoft Edge works with these Group Policy settings (`Computer Configuration\Administrative Templates\Windows Components\Microsoft Edge\`) to help you manage your company's web browser configurations:
|
||||
@ -1027,5 +1027,4 @@ These are additional Windows 10-specific MDM policy settings that work with Mic
|
||||
- **1 (default).** Employees can sync between PCs.
|
||||
|
||||
## Related topics
|
||||
* [Group Policy TechCenter](https://go.microsoft.com/fwlink/p/?LinkId=214514)
|
||||
* [Mobile Device Management (MDM) settings]( https://go.microsoft.com/fwlink/p/?LinkId=722885)
|
@ -12,6 +12,11 @@ This topic lists new and updated topics in the Microsoft Edge documentation for
|
||||
|
||||
For a detailed feature list of what's in the current Microsoft Edge releases, the Windows Insider Preview builds, and what was introduced in previous releases, see the [Microsoft Edge changelog](https://developer.microsoft.com/microsoft-edge/platform/changelog/).
|
||||
|
||||
## September 2017
|
||||
|New or changed topic | Description |
|
||||
|---------------------|-------------|
|
||||
|[Microsoft Edge - Frequently Asked Questions (FAQs) for IT Pros](microsoft-edge-faq.md) | New |
|
||||
|
||||
## February 2017
|
||||
|New or changed topic | Description |
|
||||
|----------------------|-------------|
|
||||
|
84
browsers/edge/microsoft-edge-faq.md
Normal file
@ -0,0 +1,84 @@
|
||||
---
|
||||
title: Microsoft Edge - Frequently Asked Questions (FAQs) for IT Pros (Microsoft Edge for IT Pros)
|
||||
description: Answering frequently asked questions about Microsoft Edge features, integration, support, and potential problems.
|
||||
author: eross-msft
|
||||
ms.author: lizross
|
||||
ms.prod: edge
|
||||
ms.mktglfcycl: general
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: high
|
||||
ms.date: 09/07/2017
|
||||
---
|
||||
|
||||
# Microsoft Edge - Frequently Asked Questions (FAQs) for IT Pros
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 10 Mobile
|
||||
|
||||
**Q: What is the difference between Microsoft Edge and Internet Explorer 11? How do I know which one to use?**
|
||||
|
||||
**A:** Microsoft Edge is the default browser for all Windows 10 devices. It is built to be highly compatible with the modern web. For some enterprise web apps and a small set of sites on the web that were built to work with older technologies like ActiveX, [you can use Enterprise Mode](https://docs.microsoft.com/en-us/microsoft-edge/deploy/emie-to-improve-compatibility) to automatically send users to Internet Explorer 11 for those sites.
|
||||
|
||||
For more information on how Internet Explorer and Microsoft Edge can work together to support your legacy web apps, while still defaulting to the higher bar for security and modern experiences enabled by Microsoft Edge, see [Legacy apps in the enterprise](https://blogs.windows.com/msedgedev/2017/04/07/legacy-web-apps-enterprise/#RAbtRvJSYFaKu2BI.97).
|
||||
|
||||
**Q: Does Microsoft Edge work with Enterprise Mode?**
|
||||
|
||||
**A:** [Enterprise Mode](https://docs.microsoft.com/en-us/internet-explorer/ie11-deploy-guide/enterprise-mode-overview-for-ie11) offers better backward compatibility and enables customers to run many legacy web applications. Microsoft Edge and Internet Explorer can be configured to use the same Enterprise Mode Site List, switching seamlessly between browsers to support both modern and legacy web apps. For guidance and additional resources, please visit the [Microsoft Edge IT Center](https://technet.microsoft.com/en-us/microsoft-edge).
|
||||
|
||||
|
||||
**Q: I have Windows 10, but I don’t seem to have Microsoft Edge. Why?**
|
||||
|
||||
**A:** Long-Term Servicing Branch (LTSB) versions of Windows, including Windows Server 2016, don't include Microsoft Edge or many other Universal Windows Platform (UWP) apps. These apps and their services are frequently updated with new functionality and can't be supported on systems running LTSB operating systems. For customers who require the LTSB for specialized devices, we recommend using Internet Explorer 11.
|
||||
|
||||
**Q: How do I get the latest Canary/Beta/Preview version of Microsoft Edge?**
|
||||
|
||||
**A:** You can access the latest preview version of Microsoft Edge by updating to the latest Windows 10 preview via the [Windows Insider Program](https://insider.windows.com/). To run the preview version of Microsoft Edge on a stable version of Windows 10 (or any other OS), you can download a [Virtual Machine](https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/windows/) that we provide or use the upcoming RemoteEdge service.
|
||||
|
||||
**Q: How do I customize Microsoft Edge and related settings for my organization?**
|
||||
|
||||
**A:** You can use Group Policy or Microsoft Intune to manage settings related to Microsoft Edge, such as security settings, folder redirection, and preferences. See [Group Policy and Mobile Device Management (MDM) settings for Microsoft Edge](https://docs.microsoft.com/en-us/microsoft-edge/deploy/available-policies) for a list of available policies for Microsoft Edge.
|
||||
|
||||
**Q: Is Adobe Flash supported in Microsoft Edge?**
|
||||
|
||||
**A:** Currently, Adobe Flash is supported as a built-in feature of Microsoft Edge on devices running the desktop version of Windows 10. In July 2017, Adobe announced that Flash will no longer be supported after 2020. We will phase out Flash from Microsoft Edge and Internet Explorer, culminating in the removal of Flash from Windows entirely by the end of 2020. This process began already for Microsoft Edge with [Click-to-Run for Flash](https://blogs.windows.com/msedgedev/2016/12/14/edge-flash-click-run/) in the Windows 10 Creators Update.
|
||||
|
||||
For more information about the phasing out of Flash, read the [End of an Era – Next Steps for Adobe Flash](https://blogs.windows.com/msedgedev/2017/07/25/flash-on-windows-timeline/#85ZBy7aiVlDQHebO.97) blog post.
|
||||
|
||||
**Q: Does Microsoft Edge support ActiveX controls or BHOs like Silverlight or Java?**
|
||||
|
||||
**A:** No, ActiveX controls and BHOs such as Silverlight or Java are not supported in Microsoft Edge. The need for ActiveX controls has been significantly reduced by modern web standards, which are more interoperable across browsers. We are working on plans for an extension model based on the modern web platform in Microsoft Edge. We look forward to sharing more details on these plans soon. Not supporting legacy controls in Microsoft Edge provides many benefits including better interoperability with other modern browsers, as well as increased performance, security, and reliability.
|
||||
|
||||
**Q: How often will Microsoft Edge be updated?**
|
||||
|
||||
**A:** In Windows 10, we are delivering Windows as a service, updated on a cadence driven by quality and the availability of new features. Microsoft Edge security updates are released every two to four weeks, and the bigger feature updates are currently pushed out with the Windows 10 releases on a semi-annual cadence.
|
||||
|
||||
**Q: How can I provide feedback on Microsoft Edge?**
|
||||
|
||||
**A:** Microsoft Edge is an evergreen browser and we will continue to evolve both the web platform and the user interface with regular updates. To send feedback on user experience, or on broken or malicious sites, you can use the **Send Feedback** option under the ellipses icon (**...**) in the Microsoft Edge toolbar. You can also provide feedback through the [Microsoft Edge Dev Twitter](https://twitter.com/MSEdgeDev) account.
|
||||
|
||||
**Q: Will Internet Explorer 11 continue to receive updates?**
|
||||
|
||||
**A:** We will continue to deliver security updates to Internet Explorer 11 through its supported lifespan. To ensure consistent behavior across Windows versions, we will evaluate Internet Explorer 11 bugs for servicing on a case by case basis. The latest features and platform updates will only be available in Microsoft Edge.
|
||||
|
||||
**Q: I loaded a web page and Microsoft Edge sent me to Internet Explorer - what happened?**
|
||||
|
||||
**A:** In some cases, Internet Explorer loads automatically for sites that still rely on legacy technologies such as ActiveX. For more information, read [Legacy web apps in the enterprise](https://blogs.windows.com/msedgedev/2017/04/07/legacy-web-apps-enterprise/#uHpbs94kAaVsU1qB.97).
|
||||
|
||||
**Q: Why is Do Not Track (DNT) off by default in Microsoft Edge?**
|
||||
|
||||
**A:** When Microsoft first set the Do Not Track setting to “On” by default in Internet Explorer 10, industry standards had not yet been established. We are now making this default change as the World Wide Web Consortium (W3C) formalizes industry standards to recommend that default settings allow customers to actively indicate whether they want to enable DNT. As a result, DNT will not be enabled by default in upcoming versions of Microsoft’s browsers, but we will provide customers with clear information on how to turn this feature on in the browser settings should you wish to do so.
|
||||
|
||||
**Q: How do I find out what version of Microsoft Edge I have?**
|
||||
|
||||
**A:** Open Microsoft Edge. In the upper right corner click the ellipses icon (**…**), and then click **Settings**. Look in the **About this app** section to find your version.
|
||||
|
||||
**Q: What is Microsoft EdgeHTML?**
|
||||
|
||||
**A:** Microsoft EdgeHTML is the new web rendering engine that powers the Microsoft Edge web browser and Windows 10 web app platform, and that helps web developers build and maintain a consistent site across all modern browsers. The Microsoft EdgeHTML engine also helps to defend against hacking through support for the W3C standard for [Content Security Policy (CSP)](https://developer.microsoft.com/microsoft-edge/platform/documentation/dev-guide/security/content-Security-Policy), which can help web developers defend their sites against cross-site scripting attacks, and support for the [HTTP Strict Transport Security (HSTS)](https://developer.microsoft.com/microsoft-edge/platform/documentation/dev-guide/security/HSTS/) security feature (IETF-standard compliant), which helps ensure that connections to important sites, such as to your bank, are always secured.
|
||||
|
||||
**Q: Will Windows 7 or Windows 8.1 users get Microsoft Edge or the new Microsoft EdgeHTML rendering engine?**
|
||||
|
||||
**A:** Microsoft Edge has been designed and built to showcase Windows 10 features like Cortana, and is built on top of the Universal Windows Platform. Although we don’t have any plans to bring Microsoft Edge to Windows 7 or Windows 8.1 at this time, you can test Microsoft Edge with older versions of Internet Explorer using [free virtual machines](https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/).
|
||||
|
@ -40,6 +40,7 @@
|
||||
### [Using a room control system](use-room-control-system-with-surface-hub.md)
|
||||
## [PowerShell for Surface Hub](appendix-a-powershell-scripts-for-surface-hub.md)
|
||||
## [How Surface Hub addresses Wi-Fi Direct security issues](surface-hub-wifi-direct.md)
|
||||
## [Top support solutions for Surface Hub](support-solutions-surface-hub.md)
|
||||
## [Troubleshoot Microsoft Surface Hub](troubleshoot-surface-hub.md)
|
||||
## [Troubleshoot Miracast on Surface Hub](miracast-troubleshooting.md)
|
||||
## [Useful downloads for Surface Hub administrators](surface-hub-downloads.md)
|
||||
|
@ -9,7 +9,7 @@ ms.sitesec: library
|
||||
ms.pagetype: surfacehub
|
||||
author: jdeckerms
|
||||
ms.author: jdecker
|
||||
ms.date: 08/16/2017
|
||||
ms.date: 09/25/2017
|
||||
ms.localizationpriority: medium
|
||||
---
|
||||
|
||||
@ -298,11 +298,6 @@ PrintSuccess "Connected to Lync Server Remote PowerShell"
|
||||
Import-PSSession $sessExchange -AllowClobber -WarningAction SilentlyContinue
|
||||
Import-PSSession $sessLync -AllowClobber -WarningAction SilentlyContinue
|
||||
|
||||
# In case there was any uncaught errors
|
||||
ExitIfError("Remote connections failed. Please check your credentials and try again.")
|
||||
|
||||
|
||||
|
||||
## Create the Exchange mailbox ##
|
||||
# Note: These exchange commandlets do not always throw their errors as exceptions
|
||||
|
||||
@ -670,11 +665,6 @@ catch
|
||||
Import-PSSession $sessExchange -AllowClobber -WarningAction SilentlyContinue
|
||||
Import-PSSession $sessCS -AllowClobber -WarningAction SilentlyContinue
|
||||
|
||||
# In case there was any uncaught errors
|
||||
ExitIfError "Remote connection failed. Please check your credentials and try again."
|
||||
|
||||
|
||||
|
||||
## Create the Exchange mailbox ##
|
||||
# Note: These exchange commandlets do not always throw their errors as exceptions
|
||||
|
||||
@ -1571,8 +1561,7 @@ catch
|
||||
|
||||
Import-PSSession $sessCS -AllowClobber
|
||||
|
||||
# In case there was any uncaught errors
|
||||
ExitIfError("Remote connection failed. Please check your credentials and try again.")
|
||||
|
||||
Write-Host "--------------------------------------------------------------." -foregroundcolor "magenta"
|
||||
|
||||
# Getting registrar pool
|
||||
|
@ -8,7 +8,7 @@ ms.sitesec: library
|
||||
ms.pagetype: surfacehub
|
||||
author: jdeckerms
|
||||
ms.author: jdecker
|
||||
ms.date: 08/17/2017
|
||||
ms.date: 09/25/2017
|
||||
ms.localizationpriority: medium
|
||||
---
|
||||
|
||||
@ -16,6 +16,13 @@ ms.localizationpriority: medium
|
||||
|
||||
This topic lists new and updated topics in the [Surface Hub Admin Guide]( surface-hub-administrators-guide.md).
|
||||
|
||||
## September 2017
|
||||
|
||||
New or changed topic | Description
|
||||
--- | ---
|
||||
[Top support solutions for Surface Hub](support-solutions-surface-hub.md) | New
|
||||
[PowerShell for Surface Hub](appendix-a-powershell-scripts-for-surface-hub.md) | Updated account creation scripts
|
||||
|
||||
## August 2017
|
||||
|
||||
|
||||
|
@ -114,6 +114,7 @@ Use this procedure if you use Exchange on-prem.
|
||||
|
||||
Next, you enable the device account with [Skype for Business Online](#skype-for-business-online), [Skype for Business on-prem](#skype-for-business-on-prem), or [Skype for Business hybrid](#skype-for-business-hybrid).
|
||||
|
||||
<span id="sfb-online"/>
|
||||
### Skype for Business Online
|
||||
|
||||
To enable Skype for Business online, your tenant users must have Exchange mailboxes (at least one Exchange mailbox in the tenant is required). The following table explains which plans or additional services you need.
|
||||
@ -309,18 +310,10 @@ Use this procedure if you use Exchange online.
|
||||
|
||||
Next, you enable the device account with [Skype for Business Online](#sfb-online), [Skype for Business on-prem](#sfb-onprem), or [Skype for Business hybrid](#sfb-hybrid).
|
||||
|
||||
<span id="sfb-online"/>
|
||||
|
||||
### Skype for Business Online
|
||||
|
||||
In order to enable Skype for Business, your environment will need to meet the following prerequisites:
|
||||
|
||||
- You'll need to have Lync Online (Plan 2) or higher in your O365 plan. The plan needs to support conferencing capability.
|
||||
|
||||
- If you need Enterprise Voice (PSTN telephony) using telephony service providers for the Surface Hub, you need Lync Online (Plan 3).
|
||||
|
||||
- Your tenant users must have Exchange mailboxes (at least one Exchange mailbox in the tenant is required).
|
||||
|
||||
- Your Surface Hub account does require a Lync Online (Plan 2) or Lync Online (Plan 3) license, but it does not require an Exchange Online license.
|
||||
In order to enable Skype for Business, your environment will need to meet the [prerequisites for Skype for Business online](#sfb-online).
|
||||
|
||||
1. Start by creating a remote PowerShell session to the Skype for Business online environment from a PC.
|
||||
|
||||
|
@ -44,6 +44,7 @@ In some ways, adding your new Surface Hub is just like adding any other Microsof
|
||||
| [Manage Microsoft Surface Hub](manage-surface-hub.md) | How to manage your Surface Hub after finishing the first-run program. |
|
||||
| [PowerShell for Surface Hub](appendix-a-powershell-scripts-for-surface-hub.md) |
|
||||
| [How Surface Hub addresses Wi-Fi Direct security issues](surface-hub-wifi-direct.md) | This topic provides guidance on Wi-Fi Direct security risks, how the Surface Hub has addressed those risks, and how Surface Hub administrators can configure the device for the highest level of security. | PowerShell scripts to help set up and manage your Surface Hub. |
|
||||
| [Top support solutions for Surface Hub](support-solutions-surface-hub.md) | These are the top Microsoft Support solutions for common issues experienced using Surface Hub. |
|
||||
| [Troubleshoot Microsoft Surface Hub](troubleshoot-surface-hub.md) | Troubleshoot common problems, including setup issues, Exchange ActiveSync errors. |
|
||||
| [Troubleshoot Miracast on Surface Hub](miracast-troubleshooting.md) | Learn how to resolve Miracast issues. |
|
||||
| [Useful downloads for Surface Hub administrators](surface-hub-downloads.md) | This topic provides links to useful Surface Hub documents, such as product datasheets, the site readiness guide, and user's guide. |
|
||||
|
@ -40,3 +40,6 @@ Learn about managing and updating Surface Hub.
|
||||
| [Miracast on existing wireless network or LAN](miracast-over-infrastructure.md) | You can use Miracast on your wireless network or LAN to connect to Surface Hub. |
|
||||
| [Using a room control system]( https://technet.microsoft.com/itpro/surface-hub/use-room-control-system-with-surface-hub) | Room control systems can be used with your Microsoft Surface Hub.|
|
||||
|
||||
## Related topics
|
||||
|
||||
- [View Power BI presentation mode on Surface Hub & Windows 10](https://powerbi.microsoft.com/documentation/powerbi-mobile-win10-app-presentation-mode/)
|
@ -83,10 +83,7 @@ If you have a pure, online (O365) deployment, then you can [use the provided Pow
|
||||
Set-MsolUser -UserPrincipalName 'HUB01@contoso.com' -PasswordNeverExpires $true
|
||||
```
|
||||
|
||||
7. Surface Hub requires a license for Skype for Business functionality.
|
||||
- Your Surface Hub account requires a Lync Online (Plan 2) or Lync Online (Plan 3) license, but it does not require an Exchange Online license.
|
||||
- You'll need to have Lync Online (Plan 2) or higher in your O365 plan. The plan needs to support conferencing capability.
|
||||
- If you need Enterprise Voice (PSTN telephony) using telephony service providers for the Surface Hub, you need Lync Online (Plan 3).
|
||||
7. Surface Hub requires a license for Skype for Business functionality. In order to enable Skype for Business, your environment will need to meet the [prerequisites for Skype for Business online](hybrid-deployment-surface-hub-device-accounts.md#sfb-online).
|
||||
|
||||
Next, you can use `Get-MsolAccountSku` to retrieve a list of available SKUs for your O365 tenant.
|
||||
|
||||
|
50
devices/surface-hub/support-solutions-surface-hub.md
Normal file
@ -0,0 +1,50 @@
|
||||
---
|
||||
title: Top support solutions for Microsoft Surface Hub
|
||||
description: Find top solutions for common issues using Surface Hub.
|
||||
ms.assetid: CF58F74D-8077-48C3-981E-FCFDCA34B34A
|
||||
keywords: Troubleshoot common problems, setup issues
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: support
|
||||
ms.sitesec: library
|
||||
ms.pagetype: surfacehub
|
||||
author: kaushika-msft
|
||||
ms.author: jdecker
|
||||
ms.date: 09/07/2017
|
||||
ms.localizationpriority: medium
|
||||
---
|
||||
|
||||
# Top support solutions for Microsoft Surface Hub
|
||||
|
||||
Microsoft regularly releases both updates and solutions for Surface Hub. To ensure your devices can receive future updates, including security updates, it's important to keep your Surface Hub devices updated. For a complete listing of the update history, see [Surface Hub update history](https://www.microsoft.com/surface/support/surface-hub/surface-hub-update-history) and [Known issues and additional information about Microsoft Surface Hub](https://support.microsoft.com/help/4025643).
|
||||
|
||||
|
||||
These are the top Microsoft Support solutions for common issues experienced when using Surface Hub.
|
||||
|
||||
## Setup and install issues
|
||||
|
||||
- [Setup troubleshooting](troubleshoot-surface-hub.md#setup-troubleshooting)
|
||||
- [Exchange ActiveSync errors](troubleshoot-surface-hub.md#exchange-activesync-errors)
|
||||
|
||||
## Miracast issues
|
||||
|
||||
- [Troubleshoot Miracast on Surface Hub](miracast-troubleshooting.md)
|
||||
|
||||
## Download updates issues
|
||||
|
||||
- [Surface Hub can't download updates from Windows Update](https://support.microsoft.com/help/3191418/surface-hub-can-t-download-updates-from-windows-update)
|
||||
|
||||
## Connect app issues
|
||||
|
||||
- [The Connect app in Surface Hub exits unexpectedly](https://support.microsoft.com/help/3157417/the-connect-app-in-surface-hub-exits-unexpectedly)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
@ -20,8 +20,6 @@ Troubleshoot common problems, including setup issues, Exchange ActiveSync errors
|
||||
|
||||
Common issues are listed in the following table, along with causes and possible fixes. The [Setup troubleshooting](#setup-troubleshooting) section contains a listing of on-device problems, along with several types of issues that may be encountered during the first-run experience. The [Exchange ActiveSync errors](#exchange-activesync-errors) section lists common errors the device may encounter when trying to synchronize with an Microsoft Exchange ActiveSync server.
|
||||
|
||||
- [Setup troubleshooting](#setup-troubleshooting)
|
||||
- [Exchange ActiveSync errors](#exchange-activesync-errors)
|
||||
|
||||
## Setup troubleshooting
|
||||
|
||||
|
@ -26,6 +26,7 @@
|
||||
### [Use System Center Configuration Manager to manage devices with SEMM](use-system-center-configuration-manager-to-manage-devices-with-semm.md)
|
||||
## [Surface Diagnostic Toolkit](surface-diagnostic-toolkit.md)
|
||||
## [Surface Data Eraser](microsoft-surface-data-eraser.md)
|
||||
## [Top support solutions for Surface devices](support-solutions-surface.md)
|
||||
## [Change history for Surface documentation](change-history-for-surface.md)
|
||||
|
||||
|
||||
|
@ -11,6 +11,12 @@ author: jdeckerms
|
||||
|
||||
This topic lists new and updated topics in the Surface documentation library.
|
||||
|
||||
## September 2017
|
||||
|
||||
New or changed topic | Description
|
||||
--- | ---
|
||||
[Top support solutions for Surface devices](support-solutions-surface.md) | New
|
||||
|
||||
## June 2017
|
||||
|
||||
|New or changed topic | Description |
|
||||
|
@ -1,6 +1,6 @@
|
||||
---
|
||||
title: Deploy Surface app with Microsoft Store for Business or Microsoft Store for Education (Surface)
|
||||
description: Find out how to add and download Surface app with Windows Store for Business or Microsoft Store for Education, as well as install Surface app with PowerShell and MDT.
|
||||
description: Find out how to add and download Surface app with Microsoft Store for Business or Microsoft Store for Education, as well as install Surface app with PowerShell and MDT.
|
||||
keywords: surface app, app, deployment, customize
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
@ -31,7 +31,7 @@ The Surface app is a lightweight Windows Store app that provides control of many
|
||||
|
||||
* Quick access to support documentation and information for your device
|
||||
|
||||
If your organization is preparing images that will be deployed to your Surface devices, you may want to include the Surface app (formerly called the Surface Hub) in your imaging and deployment process instead of requiring users of each individual device to download and install the app from the Windows Store or your Windows Store for Business.
|
||||
If your organization is preparing images that will be deployed to your Surface devices, you may want to include the Surface app (formerly called the Surface Hub) in your imaging and deployment process instead of requiring users of each individual device to download and install the app from the Windows Store or your Microsoft Store for Business.
|
||||
|
||||
##Surface app overview
|
||||
|
||||
@ -45,11 +45,11 @@ Before users can install or deploy an app from a company’s Microsoft Store for
|
||||
|
||||
2. Log on to the portal.
|
||||
|
||||
3. Enable offline licensing: click **Manage->Store settings**, and then select the **Show offline licensed apps to people shopping in the store** checkbox, as shown in Figure 1. For more information about Microsoft Store for Business app licensing models, see [Apps in Windows Store for Business](https://technet.microsoft.com/itpro/windows/manage/apps-in-windows-store-for-business#licensing_model).<br/> <br/>
|
||||
3. Enable offline licensing: click **Manage->Store settings**, and then select the **Show offline licensed apps to people shopping in the store** checkbox, as shown in Figure 1. For more information about Microsoft Store for Business app licensing models, see [Apps in Microsoft Store for Business](https://technet.microsoft.com/itpro/windows/manage/apps-in-windows-store-for-business#licensing_model).<br/> <br/>
|
||||
<br/>
|
||||
*Figure 1. Enable apps for offline use*
|
||||
|
||||
4. Add Surface app to your Micrososft Store for Business account by following this procedure:
|
||||
4. Add Surface app to your Microsoft Store for Business account by following this procedure:
|
||||
* Click the **Shop** menu.
|
||||
* In the search box, type **Surface app**, and then click the search icon.
|
||||
* After the Surface app is presented in the search results, click the app’s icon.
|
||||
@ -68,9 +68,9 @@ Before users can install or deploy an app from a company’s Microsoft Store for
|
||||
* Click **OK**.
|
||||
|
||||
##Download Surface app from a Microsoft Store for Business account
|
||||
After you add an app to the Windows Store for Business account in Offline mode, you can download and add the app as an AppxBundle to a deployment share.
|
||||
After you add an app to the Microsoft Store for Business account in Offline mode, you can download and add the app as an AppxBundle to a deployment share.
|
||||
1. Log on to the Microsoft Store for Business account at https://businessstore.microsoft.com.
|
||||
2. Click **Manage->Apps & software**. A list of all of your company’s apps is displayed, including the Surface app you added in the [Add Surface app to a Windows Store for Business account](#add-surface-app-to-a-windows-store-for-business-account) section of this article.
|
||||
2. Click **Manage->Apps & software**. A list of all of your company’s apps is displayed, including the Surface app you added in the [Add Surface app to a Microsoft Store for Business account](#add-surface-app-to-a-microsoft-store-for-business-account) section of this article.
|
||||
3. Under **Actions**, click the ellipsis (**…**), and then click **Download for offline use** for the Surface app.
|
||||
4. Select the desired **Platform** and **Architecture** options from the available selections for the selected app, as shown in Figure 4.
|
||||
|
||||
@ -78,7 +78,7 @@ After you add an app to the Windows Store for Business account in Offline mode,
|
||||
|
||||
*Figure 4. Download the AppxBundle package for an app*
|
||||
5. Click **Download**. The AppxBundle package will be downloaded. Make sure you note the path of the downloaded file because you’ll need that later in this article.
|
||||
6. Click either the **Encoded license** or **Unencoded license** option. Use the Encoded license option with management tools like System Center Configuration Manager or when you use Windows Imaging and Configuration Designer (Windows ICD). Select the Unencoded license option when you use Deployment Image Servicing and Management (DISM) or deployment solutions based on imaging, including the Microsoft Deployment Toolkit (MDT).
|
||||
6. Click either the **Encoded license** or **Unencoded license** option. Use the Encoded license option with management tools like System Center Configuration Manager or when you use Windows Configuration Designer to create a provisioning package. Select the Unencoded license option when you use Deployment Image Servicing and Management (DISM) or deployment solutions based on imaging, including the Microsoft Deployment Toolkit (MDT).
|
||||
7. Click **Generate** to generate and download the license for the app. Make sure you note the path of the license file because you’ll need that later in this article.
|
||||
|
||||
>[!NOTE]
|
||||
@ -102,9 +102,12 @@ To download the required frameworks for the Surface app, follow these steps:
|
||||
|
||||
##Install Surface app on your computer with PowerShell
|
||||
The following procedure provisions the Surface app onto your computer and makes it available for any user accounts created on the computer afterwards.
|
||||
1. Using the procedure described in the [How to download Surface app from a Windows Store for Business account](#download-surface-app-from-a-windows-store-for-business-account) section of this article, download the Surface app AppxBundle and license file.
|
||||
1. Using the procedure described in the [How to download Surface app from a Microsoft Store for Business account](#download-surface-app-from-a-microsoft-store-for-business-account) section of this article, download the Surface app AppxBundle and license file.
|
||||
2. Begin an elevated PowerShell session.
|
||||
>**Note:** If you don’t run PowerShell as an Administrator, the session won’t have the required permissions to install the app.
|
||||
|
||||
>[!NOTE]
|
||||
>If you don’t run PowerShell as an Administrator, the session won’t have the required permissions to install the app.
|
||||
|
||||
3. In the elevated PowerShell session, copy and paste the following command:
|
||||
```
|
||||
Add-AppxProvisionedPackage –Online –PackagePath <DownloadPath>\ Microsoft.SurfaceHub_10.0.342.0_neutral_~_8wekyb3d8bbwe.AppxBundle –LicensePath <DownloadPath>\ Microsoft.SurfaceHub_8wekyb3d8bbwe_a53ef8ab-9dbd-dec1-46c5-7b664d4dd003.xml
|
||||
@ -118,7 +121,9 @@ The following procedure provisions the Surface app onto your computer and makes
|
||||
```
|
||||
|
||||
4. The Surface app will now be available on your current Windows computer.
|
||||
|
||||
Before the Surface app is functional on the computer where it has been provisioned, you must also provision the frameworks described earlier in this article. To provision these frameworks, use the following procedure in the elevated PowerShell session you used to provision the Surface app.
|
||||
|
||||
5. In the elevated PowerShell session, copy and paste the following command:
|
||||
```
|
||||
Add-AppxProvisionedPackage –Online –SkipLicense –PackagePath <DownloadPath>\Microsoft.VCLibs.140.00_14.0.23816.0_x64__8wekyb3d8bbwe.Appx
|
||||
@ -130,7 +135,7 @@ Before the Surface app is functional on the computer where it has been provision
|
||||
|
||||
##Install Surface app with MDT
|
||||
The following procedure uses MDT to automate installation of the Surface app at the time of deployment. The application is provisioned automatically by MDT during deployment and thus you can use this process with existing images. This is the recommended process to deploy the Surface app as part of a Windows deployment to Surface devices because it does not reduce the cross platform compatibility of the Windows image.
|
||||
1. Using the procedure described [earlier in this article](#download-surface-app-from-a-windows-store-for-business-account), download the Surface app AppxBundle and license file.
|
||||
1. Using the procedure described [earlier in this article](#download-surface-app-from-a-microsoft-store-for-business-account), download the Surface app AppxBundle and license file.
|
||||
2. Using the New Application Wizard in the MDT Deployment Workbench, import the downloaded files as a new **Application with source files**.
|
||||
3. On the **Command Details** page of the New Application Wizard, specify the default **Working Directory** and for the **Command** specify the file name of the AppxBundle, as follows:
|
||||
|
||||
|
@ -30,6 +30,7 @@ For more information on planning for, deploying, and managing Surface devices in
|
||||
| [Surface Enterprise Management Mode](surface-enterprise-management-mode.md) | See how this feature of Surface devices with Surface UEFI allows you to secure and manage firmware settings within your organization. |
|
||||
| [Surface Diagnostic Toolkit](surface-diagnostic-toolkit.md) | Find out how you can use the Microsoft Surface Diagnostic Toolkit to test the hardware of your Surface device. |
|
||||
| [Surface Data Eraser](microsoft-surface-data-eraser.md) | Find out how the Microsoft Surface Data Eraser tool can help you securely wipe data from your Surface devices. |
|
||||
| [Top support solutions for Surface devices](support-solutions-surface.md) | These are the top Microsoft Support solutions for common issues experienced using Surface devices in an enterprise. |
|
||||
| [Change history for Surface documentation](change-history-for-surface.md) | This topic lists new and updated topics in the Surface documentation library. |
|
||||
|
||||
|
||||
|
64
devices/surface/support-solutions-surface.md
Normal file
@ -0,0 +1,64 @@
|
||||
---
|
||||
title: Top support solutions for Surface devices
|
||||
description: Find top solutions for common issues using Surface devices in the enterprise.
|
||||
ms.assetid: CF58F74D-8077-48C3-981E-FCFDCA34B34A
|
||||
keywords: Troubleshoot common problems, setup issues
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: support
|
||||
ms.sitesec: library
|
||||
ms.pagetype: surfacehub
|
||||
author: kaushika-msft
|
||||
ms.author: jdecker
|
||||
ms.date: 09/07/2017
|
||||
ms.localizationpriority: medium
|
||||
---
|
||||
|
||||
# Top support solutions for Surface devices
|
||||
|
||||
Microsoft regularly releases both updates and solutions for Surface devices. To ensure your devices can receive future updates, including security updates, it's important to keep your Surface devices updated. For a complete listing of the update history, see [Surface update history](https://www.microsoft.com/surface/support/install-update-activate/surface-update-history) and [Install Surface and Windows updates](https://www.microsoft.com/surface/support/performance-and-maintenance/install-software-updates-for-surface?os=windows-10&=undefined).
|
||||
|
||||
|
||||
These are the top Microsoft Support solutions for common issues experienced when using Surface devices in an enterprise.
|
||||
|
||||
## Screen cracked or scratched issues
|
||||
|
||||
- [Cracked screen and physical damage](https://www.microsoft.com/surface/support/warranty-service-and-recovery/surface-is-damaged)
|
||||
|
||||
|
||||
##Device cover or keyboard issues
|
||||
|
||||
- [Troubleshoot your Surface Type Cover or keyboard](https://www.microsoft.com/surface/support/hardware-and-drivers/troubleshoot-surface-keyboards)
|
||||
- [Troubleshoot problems with Surface Keyboard, Surface Ergonomic Keyboard, and Microsoft Modern Keyboard with Fingerprint ID](https://www.microsoft.com/surface/support/touch-mouse-and-search/surface-keyboard-troubleshooting)
|
||||
- [Set up Microsoft Modern Keyboard with Fingerprint ID](https://www.microsoft.com/surface/support/touch-mouse-and-search/microsoft-modern-keyboard-fingerprintid-set-up)
|
||||
- [Enabling Surface Laptop keyboard during MDT deployment](https://blogs.technet.microsoft.com/askcore/2017/08/18/enabling-surface-laptop-keyboard-during-mdt-deployment/)
|
||||
|
||||
|
||||
## Device won't wake from sleep or hibernation issues
|
||||
|
||||
- [Surface won’t turn on or wake from sleep](https://www.microsoft.com/surface/support/warranty-service-and-recovery/surface-wont-turn-on-or-wake-from-sleep?os=windows-10&=undefined)
|
||||
- [Surface Pro 4 or Surface Book doesn't hibernate in Windows 10](https://support.microsoft.com/help/3122682)
|
||||
- [Surface Pro 3 doesn't hibernate after four hours in connected standby](https://support.microsoft.com/help/2998588/surface-pro-3-doesn-t-hibernate-after-four-hours-in-connected-standby)
|
||||
- [Surface Pro 3 Hibernation Doesn’t Occur on Enterprise Install](https://blogs.technet.microsoft.com/askcore/2014/11/05/surface-pro-3-hibernation-doesnt-occur-on-enterprise-install/)
|
||||
|
||||
|
||||
## Other common issues
|
||||
|
||||
- [Trouble installing Surface updates](https://www.microsoft.com/surface/support/performance-and-maintenance/troubleshoot-updates?os=windows-10&=undefined)
|
||||
- [Troubleshooting common Surface Pro 3 issues post-deployment](http://blogs.technet.com/b/askcore/archive/2015/03/19/troubleshooting-common-surface-pro-3-issues-post-deployment.aspx)
|
||||
- [Surface Pro 3 hibernation doesn't occur on enterprise install](https://blogs.technet.microsoft.com/askcore/2014/11/05/surface-pro-3-hibernation-doesnt-occur-on-enterprise-install/)
|
||||
- [Reusing the same NIC for multiple PXE initiated deployments in System Center Configuration Manger OSD](https://blogs.technet.microsoft.com/system_center_configuration_manager_operating_system_deployment_support_blog/2015/08/27/reusing-the-same-nic-for-multiple-pxe-initiated-deployments-in-system-center-configuration-manger-osd)
|
||||
- [Troubleshoot docking stations for Surface Pro and Surface 3](https://www.microsoft.com/surface/support/hardware-and-drivers/troubleshoot-docking-station?os=windows-8.1-update-1&=undefined)
|
||||
- [What to do if Surface is running slower](https://www.microsoft.com/surface/support/performance-and-maintenance/what-to-do-if-surface-is-running-slower?os=windows-10&=undefined)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
@ -1,7 +1,6 @@
|
||||
# [Get started: Deploy and manage a full cloud IT solution with Microsoft Education](get-started-with-microsoft-education.md)
|
||||
## [Set up an Office 365 education tenant](set-up-office365-edu-tenant.md)
|
||||
## [Use School Data Sync to import student data](use-school-data-sync.md)
|
||||
## [Enable Microsoft Teams for your school](enable-microsoft-teams.md)
|
||||
## [Configure Microsoft Store for Education](configure-microsoft-store-for-education.md)
|
||||
## [Use Intune for Education to manage groups, apps, and settings](use-intune-for-education.md)
|
||||
## [Set up Windows 10 education devices](set-up-windows-10-education-devices.md)
|
||||
|
@ -15,6 +15,10 @@ ms.date: 07/10/2017
|
||||
|
||||
# Configure Microsoft Store for Education
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[<< Use School Data Sync to import student data](use-school-data-sync.md)
|
||||
[Use Intune for Education to manage groups, apps, and settings >>](use-intune-for-education.md)
|
||||
|
||||
You'll need to configure Microsoft Store for Education to accept the services agreement and make sure your Microsoft Store account is associated with Intune for Education.
|
||||
|
||||
You can watch the video to see how this is done, or follow the step-by-step guide. </br>
|
||||
@ -58,7 +62,7 @@ Your Microsoft Store for Education account is now linked to Intune for Education
|
||||
-->
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[<< Enable Microsoft Teams for your school](enable-microsoft-teams.md)
|
||||
[<< Use School Data Sync to import student data](use-school-data-sync.md)
|
||||
[Use Intune for Education to manage groups, apps, and settings >>](use-intune-for-education.md)
|
||||
|
||||
|
||||
|
@ -14,6 +14,10 @@ ms.date: 07/10/2017
|
||||
---
|
||||
|
||||
# Finish Windows 10 device setup and other tasks
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[<< Set up Windows 10 education devices](set-up-windows-10-education-devices.md)
|
||||
|
||||
Once you've set up your Windows 10 education device, it's worth checking to verify the following:
|
||||
|
||||
> [!div class="checklist"]
|
||||
@ -70,6 +74,7 @@ You can follow the rest of the walkthrough to finish setup and complete other ta
|
||||
> * Update group settings in Intune for Education
|
||||
> * Configure Azure settings
|
||||
> * Complete Office 365 for Education setup
|
||||
> * Enable Microsoft teams for your school
|
||||
> * Add more users
|
||||
> * Connect other devices, like BYOD devices, to your cloud infrastructure
|
||||
|
||||
@ -136,6 +141,38 @@ Follow the steps in this section to ensure that settings for the each user follo
|
||||
## Complete Office 365 for Education setup
|
||||
Now that your basic cloud infrastructure is up and running, it's time to complete the rest of the Office 365 for Education setup. You can find detailed information about completing Office 365 setup, services and applications, troubleshooting, and more by reading the <a href="https://support.office.com/en-US/Article/set-up-Office-365-for-business-6a3a29a0-e616-4713-99d1-15eda62d04fa#ID0EAAAABAAA=Education" target="_blank">Office 365 admin documentation</a>.
|
||||
|
||||
## Enable Microsoft Teams for your school
|
||||
Microsoft Teams is a digital hub that brings conversations, content, and apps together in one place. Because it's built on Office 365, schools benefit from integration with their familiar Office apps and services. Your institution can use Microsoft Teams to create collaborative classrooms, connect in professional learning communities, and communicate with school staff all from a single experience in Office 365 for Education.
|
||||
|
||||
To get started, IT administrators need to use the Office 365 Admin Center to enable Microsoft Teams for your school.
|
||||
|
||||
**To enable Microsoft Teams for your school**
|
||||
|
||||
1. Sign in to <a href="https://portal.office.com" target="_blank">Office 365</a> with your work or school account.
|
||||
2. Click **Admin** to go to the Office 365 admin center.
|
||||
3. Go to **Settings > Services & add-ins**.
|
||||
4. On the **Services & add-ins** page, select **Microsoft Teams**.
|
||||
|
||||
**Figure 1** - Select Microsoft Teams from the list of services & add-ins
|
||||
|
||||

|
||||
|
||||
5. On the Microsoft Teams settings screen, select the license that you want to configure, **Student** or **Faculty and Staff**. Select **Faculty and Staff**.
|
||||
|
||||
**Figure 2** - Select the license that you want to configure
|
||||
|
||||

|
||||
|
||||
6. After you select the license type, set the toggle to turn on Microsoft Teams for your organization.
|
||||
|
||||
**Figure 3** - Turn on Microsoft Teams for your organization
|
||||
|
||||

|
||||
|
||||
7. Click **Save**.
|
||||
|
||||
You can find more info about how to control which users in your school can use Microsoft Teams, turn off group creation, configure tenant-level settings, and more by reading the *Guide for IT admins* getting started guide in the <a href="https://aka.ms/MeetTeamsEdu" target="_blank">Meet Microsoft Teams</a> page.
|
||||
|
||||
## Add more users
|
||||
After your cloud infrastructure is set up and you have a device management strategy in place, you may need to add more users and you want the same policies to apply to these users. You can add new users to your tenant simply by adding them to the Office 365 groups. Adding new users to Office 365 groups automatically adds them to the corresponding groups in Intune for Education.
|
||||
|
||||
@ -174,5 +211,9 @@ Adding a new device to your cloud-based tenant is easy. For new devices, you can
|
||||
It may take several minutes before the new device shows up so check again later.
|
||||
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[<< Set up Windows 10 education devices](set-up-windows-10-education-devices.md)
|
||||
|
||||
|
||||
## Related topic
|
||||
[Get started: Deploy and manage a full cloud IT solution with Microsoft Education](get-started-with-microsoft-education.md)
|
||||
|
@ -10,7 +10,7 @@ ms.localizationpriority: high
|
||||
ms.pagetype: edu
|
||||
author: CelesteDG
|
||||
ms.author: celested
|
||||
ms.date: 07/10/2017
|
||||
ms.date: 08/29/2017
|
||||
---
|
||||
|
||||
# Get started: Deploy and manage a full cloud IT solution with Microsoft Education
|
||||
@ -43,21 +43,20 @@ With Microsoft Education, schools can:
|
||||
Go to the <a href="https://www.microsoft.com/en-us/education" target="_blank">Microsoft Education site</a> to learn more. See <a href="https://www.microsoft.com/en-us/education/buy-license/overview-of-how-to-buy/default.aspx?tabshow=schools" target="_blank">How to buy</a> to learn about pricing and purchasing options for schools, students, and teachers as well as academic pricing and offers for qualified K-12 and higher education institutions.
|
||||
|
||||
## What we're doing
|
||||
In this walkthrough, we'll show you the basics on how to:
|
||||
> [!div class="checklist"]
|
||||
> * Acquire an Office 365 for Education tenant, if you don't already have one
|
||||
> * Import school, student, teacher, and class data using School Data Sync (SDS)
|
||||
> * Deploy Microsoft Teams to enable groups and teams in your school to communicate and collaborate
|
||||
> * Manage apps and settings deployment with Intune for Education
|
||||
> * Acquire additional apps in Microsoft Store for Education
|
||||
> * Use the Set up School PCs app to quickly set up and provision your Windows 10 education devices
|
||||
> * Log in and use the devices
|
||||
The end-to-end process for deploying and managing a full cloud IT solution with Microsoft Education is outlined here. Depending on your [setup scenario](#setup-options), you may not need to implement all these steps.
|
||||
|
||||
This diagram shows a high-level view of what we cover in this walkthrough. The numbers correspond to the sections in the walkthrough and roughly correspond to the flow of the overall process; but, note that not all sections in this walkthrough are shown in the diagram.
|
||||
Click the link to watch the video or follow the step-by-step guidance for each.
|
||||
|
||||
1. [Set up an Office 365 education tenant](set-up-office365-edu-tenant.md)
|
||||
2. [Use School Data Sync to import student data](use-school-data-sync.md)
|
||||
3. [Configure Microsoft Store for Education](configure-microsoft-store-for-education.md)
|
||||
4. [Use Intune for Education to manage groups, apps, and settings](use-intune-for-education.md)
|
||||
5. [Set up Windows 10 education devices](set-up-windows-10-education-devices.md)
|
||||
6. [Finish Windows 10 device setup and other tasks](finish-setup-and-other-tasks.md)
|
||||
|
||||
**Figure 1** - Microsoft Education IT administrator workflow
|
||||
|
||||

|
||||

|
||||
|
||||
## Prerequisites
|
||||
Complete these tasks before you start the walkthrough:
|
||||
@ -130,19 +129,6 @@ Already have an Office 365 for Education verified tenant? Just sign in with your
|
||||
3. Enter your Office 365 global admin credentials to apply the Intune for Education trial to your tenant.
|
||||
4. If you don't already have Microsoft Teams deployed to your tenant, you can start with [Enable Microsoft Teams for your school](enable-microsoft-teams.md) and then follow the rest of the instructions in this walkthrough.
|
||||
|
||||
## End-to-end process
|
||||
The end-to-end process for deploying and managing a full cloud IT solution with Microsoft Education is outlined here. Depending on scenario, you may not need to implement all these steps.
|
||||
|
||||
Click the link to watch the video or follow the step-by-step guidance for each.
|
||||
|
||||
1. [Set up an Office 365 education tenant](set-up-office365-edu-tenant.md)
|
||||
2. [Use School Data Sync to import student data](use-school-data-sync.md)
|
||||
3. [Enable Microsoft Teams for your school](enable-microsoft-teams.md)
|
||||
4. [Configure Microsoft Store for Education](configure-microsoft-store-for-education.md)
|
||||
5. [Use Intune for Education to manage groups, apps, and settings](use-intune-for-education.md)
|
||||
6. [Set up Windows 10 education devices](set-up-windows-10-education-devices.md)
|
||||
7. [Finish Windows 10 device setup and other tasks](finish-setup-and-other-tasks.md)
|
||||
|
||||
## Get more info
|
||||
|
||||
### Microsoft Education documentation and resources hub
|
||||
|
BIN
education/get-started/images/MSES_Get_Started_IT_082917.png
Normal file
After Width: | Height: | Size: 662 KiB |
@ -15,6 +15,10 @@ ms.date: 07/10/2017
|
||||
|
||||
# Set up an Office 365 Education tenant
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[<< Get started: Deploy and manage a full cloud IT solution with Microsoft Education](get-started-with-microsoft-education.md)
|
||||
[Use School Data Sync to import student data >>](use-school-data-sync.md)
|
||||
|
||||
Schools can use Office 365 to save time and be more productive. Built with powerful tools and accessible from any device, setting it up is the first step in getting your school to the cloud.
|
||||
|
||||
Don't have an Office 365 for Education verified tenant or just starting out? Follow these steps to set up an Office 365 for Education tenant. [Learn more about Office 365 for Education plans and pricing](https://products.office.com/en-us/academic/compare-office-365-education-plans). </br>
|
||||
|
@ -15,6 +15,10 @@ ms.date: 07/10/2017
|
||||
|
||||
# Set up Windows 10 education devices
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[<< Use Intune for Education to manage groups, apps, and settings](use-intune-for-education.md)
|
||||
[Finish setup and other tasks >>](finish-setup-and-other-tasks.md)
|
||||
|
||||
We recommend using the latest build of Windows 10, version 1703 on your education devices.
|
||||
|
||||
To set up new Windows 10 devices and enroll them to your education tenant, choose from one of these options and follow the link to watch the video or follow the step-by-step guide:
|
||||
|
@ -15,6 +15,10 @@ ms.date: 07/10/2017
|
||||
|
||||
# Use Intune for Education to manage groups, apps, and settings
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[<< Configure Microsoft Store for Education](configure-microsoft-store-for-education.md)
|
||||
[Set up Windows 10 education devices >>](set-up-windows-10-education-devices.md)
|
||||
|
||||
Intune for Education is a streamlined device management solution for educational institutions that can be used to quickly set up and manage Windows 10 devices for your school. It provides a new streamlined UI with the enterprise readiness and resiliency of the Intune service. You can learn more about Intune for Education by reading the <a href="https://docs.microsoft.com/intune-education" target="_blank">Intune for Education documentation</a>.
|
||||
|
||||
## Example - Set up Intune for Education, buy apps from the Store, and install the apps
|
||||
|
@ -15,6 +15,10 @@ ms.date: 07/10/2017
|
||||
|
||||
# Use School Data Sync to import student data
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[<< Set up an Office 365 education tenant](set-up-office365-edu-tenant.md)
|
||||
[Configure Microsoft Store for Education >>](configure-microsoft-store-for-education.md)
|
||||
|
||||
School Data Sync (SDS) helps you import Student Information System (SIS) data into Office 365. It helps automate the process for importing and integrating SIS data that you can use with Office 365 and apps like OneNote Class Notebooks.
|
||||
|
||||
Follow all the steps in this section to use SDS and sample CSV files in a trial environment. To use SDS in a production environment, see step 2 in [Try out Microsoft Education in a production environment](https://docs.microsoft.com/en-us/education/get-started/get-started-with-microsoft-education#setup-options) instead.
|
||||
@ -177,7 +181,7 @@ That's it for importing sample school data using SDS.
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[<< Set up an Office 365 education tenant](set-up-office365-edu-tenant.md)
|
||||
[Enable Microsoft Teams for your school >>](enable-microsoft-teams.md)
|
||||
[Configure Microsoft Store for Education >>](configure-microsoft-store-for-education.md)
|
||||
|
||||
## Related topic
|
||||
[Get started: Deploy and manage a full cloud IT solution with Microsoft Education](get-started-with-microsoft-education.md)
|
171
education/images/M365-education.svg
Normal file
@ -0,0 +1,171 @@
|
||||
<svg id="ICONS" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 140">
|
||||
<defs>
|
||||
<style>
|
||||
.cls-1 {
|
||||
fill: #80def9;
|
||||
}
|
||||
|
||||
.cls-14, .cls-2 {
|
||||
fill: none;
|
||||
}
|
||||
|
||||
.cls-3 {
|
||||
fill: #556a8a;
|
||||
}
|
||||
|
||||
.cls-4 {
|
||||
fill: #868787;
|
||||
}
|
||||
|
||||
.cls-5 {
|
||||
fill: #e5e5e5;
|
||||
}
|
||||
|
||||
.cls-6 {
|
||||
fill: #b72b2b;
|
||||
}
|
||||
|
||||
.cls-7 {
|
||||
fill: #a80000;
|
||||
}
|
||||
|
||||
.cls-15, .cls-8, .cls-9 {
|
||||
fill: #fff;
|
||||
}
|
||||
|
||||
.cls-9 {
|
||||
stroke: #5b7484;
|
||||
}
|
||||
|
||||
.cls-14, .cls-15, .cls-9 {
|
||||
stroke-miterlimit: 10;
|
||||
stroke-width: 2px;
|
||||
}
|
||||
|
||||
.cls-10 {
|
||||
fill: #e6e6e6;
|
||||
}
|
||||
|
||||
.cls-11 {
|
||||
fill: #b8c1ce;
|
||||
}
|
||||
|
||||
.cls-12 {
|
||||
fill: #ccc;
|
||||
}
|
||||
|
||||
.cls-13 {
|
||||
fill: #5b7484;
|
||||
}
|
||||
|
||||
.cls-14 {
|
||||
stroke: #556a8a;
|
||||
}
|
||||
|
||||
.cls-15 {
|
||||
stroke: #00bcf2;
|
||||
}
|
||||
|
||||
.cls-16 {
|
||||
fill: #008272;
|
||||
}
|
||||
|
||||
.cls-17 {
|
||||
fill: #bad80a;
|
||||
}
|
||||
</style>
|
||||
</defs>
|
||||
<title>M365-education</title>
|
||||
<g>
|
||||
<g>
|
||||
<g>
|
||||
<path class="cls-1" d="M113.2,39.53v-.35a13.84,13.84,0,0,0-.29-3.47,12.49,12.49,0,0,0-20.56-8.94A14.53,14.53,0,0,0,80.18,21C71,21,64,29,63.88,38.09c0,.62.16,1.09.16,1.72-4.84,2.34-7.64,6.4-7.64,11.55,0,7.36,5.79,13.26,13.46,13.69.71,5.11,5.29,9.86,13.14,9.86,6.62,0,10.57.54,15.4-4.9a16.27,16.27,0,0,0,7.7,2.1c9.28,0,16.64-8.22,16.64-17.5A16.19,16.19,0,0,0,113.2,39.53Z"/>
|
||||
<path class="cls-1" d="M293,56.2a15.9,15.9,0,0,1,8.13,2.24A21,21,0,0,1,340,56.25c.34,0,.68-.05,1-.05a17.91,17.91,0,0,1,18,17.9C359,84,350.94,91,341,91H297c-8.84,0-20-3.9-20-18.9A15.91,15.91,0,0,1,293,56.2Z"/>
|
||||
<rect class="cls-2" x="64.2" y="3" width="271" height="148"/>
|
||||
<g>
|
||||
<polygon class="cls-3" points="264.39 25 129.4 25 79 53 313 53 264.39 25"/>
|
||||
<polygon class="cls-4" points="86.72 52 129.92 27 263.85 27 305.52 52 86.72 52"/>
|
||||
<rect class="cls-3" x="79" y="53" width="234" height="68"/>
|
||||
<rect class="cls-5" x="163.5" y="-28.5" width="65" height="230" transform="translate(282.5 -109.5) rotate(90)"/>
|
||||
<polygon class="cls-3" points="196.5 16.5 195.5 16.5 145 53 145 121 247 121 247 53 196.5 16.5"/>
|
||||
<polygon class="cls-6" points="147 121 147 54.03 196 18.6 245 53 245 121 147 121"/>
|
||||
<rect class="cls-7" x="185.2" y="91" width="22" height="30"/>
|
||||
<rect class="cls-8" x="187" y="93" width="18" height="28"/>
|
||||
<circle class="cls-9" cx="195.9" cy="35" r="11"/>
|
||||
</g>
|
||||
<rect class="cls-3" x="89" y="61" width="19" height="22"/>
|
||||
<rect class="cls-10" x="89.5" y="64.5" width="18" height="15" transform="translate(170.5 -26.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="91" y="63" width="15" height="4"/>
|
||||
<rect class="cls-11" x="91" y="72" width="15" height="4"/>
|
||||
<rect class="cls-7" x="154" y="61" width="22" height="32"/>
|
||||
<rect class="cls-12" x="151" y="68" width="28" height="18" transform="translate(242 -88) rotate(90)"/>
|
||||
<rect class="cls-3" x="91" y="71" width="15" height="2"/>
|
||||
<g>
|
||||
<rect class="cls-3" x="118" y="61" width="19" height="22"/>
|
||||
<rect class="cls-10" x="118.5" y="64.5" width="18" height="15" transform="translate(199.5 -55.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="120" y="63" width="15" height="4"/>
|
||||
<rect class="cls-11" x="120" y="72" width="15" height="4"/>
|
||||
<rect class="cls-3" x="120" y="71" width="15" height="2"/>
|
||||
</g>
|
||||
<rect class="cls-3" x="89" y="88" width="19" height="22"/>
|
||||
<rect class="cls-10" x="89.5" y="91.5" width="18" height="15" transform="translate(197.5 0.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="91" y="90" width="15" height="4"/>
|
||||
<rect class="cls-11" x="91" y="99" width="15" height="4"/>
|
||||
<rect class="cls-3" x="91" y="98" width="15" height="2"/>
|
||||
<g>
|
||||
<rect class="cls-3" x="118" y="88" width="19" height="22"/>
|
||||
<rect class="cls-10" x="118.5" y="91.5" width="18" height="15" transform="translate(226.5 -28.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="120" y="90" width="15" height="4"/>
|
||||
<rect class="cls-11" x="120" y="99" width="15" height="4"/>
|
||||
<rect class="cls-3" x="120" y="98" width="15" height="2"/>
|
||||
</g>
|
||||
<rect class="cls-13" x="255" y="61" width="19" height="22"/>
|
||||
<rect class="cls-10" x="255.5" y="64.5" width="18" height="15" transform="translate(336.5 -192.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="257" y="63" width="15" height="4"/>
|
||||
<rect class="cls-11" x="257" y="72" width="15" height="4"/>
|
||||
<rect class="cls-13" x="257" y="71" width="15" height="2"/>
|
||||
<g>
|
||||
<rect class="cls-13" x="284" y="61" width="19" height="22"/>
|
||||
<rect class="cls-10" x="284.5" y="64.5" width="18" height="15" transform="translate(365.5 -221.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="286" y="63" width="15" height="4"/>
|
||||
<rect class="cls-11" x="286" y="73" width="15" height="4"/>
|
||||
<rect class="cls-13" x="286" y="71" width="15" height="2"/>
|
||||
</g>
|
||||
<rect class="cls-13" x="255" y="88" width="19" height="22"/>
|
||||
<rect class="cls-10" x="255.5" y="91.5" width="18" height="15" transform="translate(363.5 -165.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="257" y="90" width="15" height="4"/>
|
||||
<rect class="cls-11" x="257" y="99" width="15" height="4"/>
|
||||
<rect class="cls-13" x="257" y="98" width="15" height="2"/>
|
||||
<g>
|
||||
<rect class="cls-13" x="284" y="88" width="19" height="22"/>
|
||||
<rect class="cls-10" x="284.5" y="91.5" width="18" height="15" transform="translate(392.5 -194.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="286" y="90" width="15" height="4"/>
|
||||
<rect class="cls-11" x="286" y="99" width="15" height="4"/>
|
||||
<rect class="cls-13" x="286" y="98" width="15" height="2"/>
|
||||
</g>
|
||||
<rect class="cls-7" x="156" y="66" width="18" height="2"/>
|
||||
<rect class="cls-7" x="156.2" y="86" width="18" height="2"/>
|
||||
<rect class="cls-7" x="164" y="68" width="2" height="19"/>
|
||||
<rect class="cls-8" x="156" y="88" width="18" height="3"/>
|
||||
<rect class="cls-8" x="156" y="63" width="18" height="3"/>
|
||||
<rect class="cls-7" x="185" y="61" width="22" height="26"/>
|
||||
<rect class="cls-12" x="185" y="65" width="22" height="18" transform="translate(270 -122) rotate(90)"/>
|
||||
<rect class="cls-7" x="187" y="66" width="18" height="2"/>
|
||||
<rect class="cls-7" x="195" y="67" width="2" height="19"/>
|
||||
<rect class="cls-8" x="187" y="63" width="18" height="3"/>
|
||||
<rect class="cls-7" x="217" y="61" width="22" height="32"/>
|
||||
<rect class="cls-12" x="214" y="68" width="28" height="18" transform="translate(305 -151) rotate(90)"/>
|
||||
<rect class="cls-7" x="219" y="66" width="18" height="2"/>
|
||||
<rect class="cls-7" x="219" y="86" width="18" height="2"/>
|
||||
<rect class="cls-7" x="227" y="68" width="2" height="19"/>
|
||||
<rect class="cls-8" x="219" y="88" width="18" height="3"/>
|
||||
<rect class="cls-8" x="219" y="63" width="18" height="3"/>
|
||||
<rect class="cls-11" x="187" y="93" width="18" height="5"/>
|
||||
<polyline class="cls-14" points="203 35 196 35 196 28"/>
|
||||
</g>
|
||||
<path class="cls-15" d="M342.2,80.16v-.22a9,9,0,0,0-.4-2.19,8,8,0,0,0-13.15-5.64,9.23,9.23,0,0,0-7.71-3.64c-5.82,0-10.21,5.07-10.31,10.79,0,.39.1.69.1,1.08a7.89,7.89,0,0,0-4.83,7.29,8.74,8.74,0,0,0,8.5,8.65c.45,3.23,3.34,6.23,8.3,6.23,4.18,0,6.68.34,9.73-3.09a10.28,10.28,0,0,0,4.86,1.33c5.86,0,10.72-5.19,10.72-11.05A11.52,11.52,0,0,0,342.2,80.16Z"/>
|
||||
</g>
|
||||
<path class="cls-16" d="M102.69,111.2a7.84,7.84,0,0,0,1.31-4.37,7.4,7.4,0,0,0-5.64-7.37A9.1,9.1,0,0,0,99,96.1c0-4.74-3.58-8.59-8-8.59a7.5,7.5,0,0,0-3.27.76A10.17,10.17,0,0,0,78,80c-5.52,0-10,4.8-10,10.73,0,.39,0,.77.06,1.15A7.35,7.35,0,0,0,62,99.32a7.87,7.87,0,0,0,1.09,4c-4.74,1.6-8.09,5.44-8.09,9.93C55,119.2,60.82,124,68,124H99c3,0,6.85-4.3,6.85-7.51A5.86,5.86,0,0,0,102.69,111.2Z"/>
|
||||
<path class="cls-17" d="M83.64,107A6,6,0,0,0,76,99.36a6,6,0,0,0-11.83-.61,7,7,0,0,0-9.81,8.36A8.94,8.94,0,0,0,44,116c0,5,4,8,9,8H82c4.42,0,9-4.58,9-9A8,8,0,0,0,83.64,107Z"/>
|
||||
</g>
|
||||
</svg>
|
After Width: | Height: | Size: 8.1 KiB |
@ -1,7 +1,7 @@
|
||||
---
|
||||
layout: HubPage
|
||||
hide_bc: true
|
||||
title: Microsoft Education documentation and resources | Microsoft Docs
|
||||
title: Microsoft 365 Education documentation and resources | Microsoft Docs
|
||||
description: Learn about product documentation and resources available for school IT administrators, teachers, students, and education app developers.
|
||||
author: CelesteDG
|
||||
ms.author: celested
|
||||
@ -10,7 +10,7 @@ ms.author: celested
|
||||
<div class="container">
|
||||
<ul class="cardsY panelContent featuredContent">
|
||||
<li>
|
||||
<a href="http://www.microsoft.com/education">
|
||||
<a href="http://www.microsoft.com/education" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -28,7 +28,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://docs.microsoft.com/education/get-started/get-started-with-microsoft-education">
|
||||
<a href="https://docs.microsoft.com/education/get-started/get-started-with-microsoft-education" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -46,7 +46,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/education/windows/test-windows10s-for-edu">
|
||||
<a href="/education/windows/test-windows10s-for-edu" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -75,7 +75,26 @@ ms.author: celested
|
||||
<a href="#itpro-all"></a>
|
||||
<ul id="itpro-all" class="cardsC">
|
||||
<li>
|
||||
<a href="https://docs.microsoft.com/education/get-started/get-started-with-microsoft-education">
|
||||
<a href="https://www.microsoft.com/en-us/education/buy-license/microsoft365/default.aspx" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="images/M365-education.svg" alt="Learn about Microsoft 365 Education" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<h3>Microsoft 365 Education</h3>
|
||||
<p>Find out how to empower educators to unlock creativity, promote teamwork, and provide a simple and safe experience in a single, affordable solution built for education.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://docs.microsoft.com/education/get-started/get-started-with-microsoft-education" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -94,7 +113,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/en-us/article/Set-up-Office-365-for-business-6a3a29a0-e616-4713-99d1-15eda62d04fa?ui=en-US&rs=en-US&ad=US&fromAR=1#ID0EAAAAEAAA=Education">
|
||||
<a href="https://support.office.com/en-us/article/Set-up-Office-365-for-business-6a3a29a0-e616-4713-99d1-15eda62d04fa?ui=en-US&rs=en-US&ad=US&fromAR=1#ID0EAAAAEAAA=Education" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -113,7 +132,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/intune-education">
|
||||
<a href="/intune-education" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -132,7 +151,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/education/windows">
|
||||
<a href="/education/windows" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -151,7 +170,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://support.office.com/article/Overview-of-School-Data-Sync-f3d1147b-4ade-4905-8518-508e729f2e91">
|
||||
<a href="https://support.office.com/article/Overview-of-School-Data-Sync-f3d1147b-4ade-4905-8518-508e729f2e91" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -170,7 +189,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/azure/active-directory/">
|
||||
<a href="/azure/active-directory/" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -189,7 +208,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/microsoft-store/index?toc=/microsoft-store/education/toc.json">
|
||||
<a href="/microsoft-store/index?toc=/microsoft-store/education/toc.json" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -208,7 +227,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/education/windows/school-get-minecraft">
|
||||
<a href="/education/windows/school-get-minecraft" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -227,7 +246,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/education/windows/use-set-up-school-pcs-app">
|
||||
<a href="/education/windows/use-set-up-school-pcs-app" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -246,7 +265,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://onedrive.live.com/view.aspx?resid=91F4E618548FC604!2261&ithint=file%2cdocx&app=Word&authkey=!AOgLvpbaerOOfwM">
|
||||
<a href="https://onedrive.live.com/view.aspx?resid=91F4E618548FC604!2261&ithint=file%2cdocx&app=Word&authkey=!AOgLvpbaerOOfwM" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -275,7 +294,7 @@ ms.author: celested
|
||||
<a href="#teachers-all"></a>
|
||||
<ul id="teachers-all" class="cardsC">
|
||||
<li>
|
||||
<a href="http://support.microsoft.com/products/education">
|
||||
<a href="http://support.microsoft.com/products/education" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -294,7 +313,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="http://support.office.com">
|
||||
<a href="http://support.office.com" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -313,7 +332,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="http://support.microsoft.com/products/windows">
|
||||
<a href="http://support.microsoft.com/products/windows" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -332,7 +351,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/microsoft-store/index?toc=/microsoft-store/education/toc.json">
|
||||
<a href="/microsoft-store/index?toc=/microsoft-store/education/toc.json" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -351,7 +370,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/education/windows/teacher-get-minecraft">
|
||||
<a href="/education/windows/teacher-get-minecraft" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -370,7 +389,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="http://education.microsoft.com">
|
||||
<a href="http://education.microsoft.com" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -389,7 +408,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://education.microsoft.com/courses-and-resources/resources/meet-microsoft-teams">
|
||||
<a href="https://education.microsoft.com/courses-and-resources/resources/meet-microsoft-teams" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -408,7 +427,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/education/windows/use-set-up-school-pcs-app">
|
||||
<a href="/education/windows/use-set-up-school-pcs-app" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -437,7 +456,7 @@ ms.author: celested
|
||||
<a href="#students-all"></a>
|
||||
<ul id="students-all" class="cardsC">
|
||||
<li>
|
||||
<a href="http://support.microsoft.com/products/education">
|
||||
<a href="http://support.microsoft.com/products/education" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -456,7 +475,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="http://support.office.com">
|
||||
<a href="http://support.office.com" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -475,7 +494,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="http://support.microsoft.com/products/windows">
|
||||
<a href="http://support.microsoft.com/products/windows" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -494,7 +513,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="http://imagine.microsoft.com">
|
||||
<a href="http://imagine.microsoft.com" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -523,7 +542,7 @@ ms.author: celested
|
||||
<a href="#developer-all"></a>
|
||||
<ul id="developer-all" class="cardsC">
|
||||
<li>
|
||||
<a href="/windows/uwp/apps-for-education/">
|
||||
<a href="/windows/uwp/apps-for-education/" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -542,7 +561,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="/windows/uwp/apps-for-education/take-a-test-api">
|
||||
<a href="/windows/uwp/apps-for-education/take-a-test-api" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -561,7 +580,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://dev.office.com/industry-verticals/edu">
|
||||
<a href="https://dev.office.com/industry-verticals/edu" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -590,7 +609,7 @@ ms.author: celested
|
||||
<a href="#partner-all"></a>
|
||||
<ul id="partner-all" class="cardsC">
|
||||
<li>
|
||||
<a href="https://www.mepn.com">
|
||||
<a href="https://www.mepn.com" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -609,7 +628,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://www.mepn.com/MEPN/AEPHome.aspx">
|
||||
<a href="https://www.mepn.com/MEPN/AEPHome.aspx" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -628,7 +647,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://www.mepn.com/MEPN/AEPSearch.aspx">
|
||||
<a href="https://www.mepn.com/MEPN/AEPSearch.aspx" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
@ -647,7 +666,7 @@ ms.author: celested
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://www.yammer.com/mepn/">
|
||||
<a href="https://www.yammer.com/mepn/" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
|
@ -15,6 +15,12 @@ ms.date: 08/01/2017
|
||||
|
||||
This topic lists new and updated topics in the [Windows 10 for Education](index.md) documentation.
|
||||
|
||||
## September 2017
|
||||
|
||||
| New or changed topic | Description |
|
||||
| --- | ---- |
|
||||
| [Use the Set up School PCs app ](use-set-up-school-pcs-app.md) | Updated the prerequisites to provide more clarification. |
|
||||
|
||||
## August 2017
|
||||
|
||||
| New or changed topic | Description |
|
||||
|
@ -26,7 +26,7 @@ In Windows 10, version 1703 (Creators Update), it is straightforward to configur
|
||||
|
||||
| Area | How to configure | What this does | Windows 10 Education | Windows 10 Pro Education | Windows 10 S |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
| **Diagnostic Data** | **SetEduPolicies** | Sets Diagnostic Data to [Basic](https://technet.microsoft.com/itpro/windows/configure/configure-windows-telemetry-in-your-organization) | This is already set | This is already set | The policy must be set |
|
||||
| **Diagnostic Data** | **AllowTelemetry** | Sets Diagnostic Data to [Basic](https://docs.microsoft.com/en-us/windows/configuration/configure-windows-telemetry-in-your-organization) | This is already set | This is already set | The policy must be set |
|
||||
| **Microsoft consumer experiences** | **SetEduPolicies** | Disables suggested content from Windows such as app recommendations | This is already set | This is already set | The policy must be set |
|
||||
| **Cortana** | **AllowCortana** | Disables Cortana </br></br> * Cortana is enabled by default on all editions in Windows 10, version 1703 | If using Windows 10 Education, upgrading from Windows 10, version 1607 to Windows 10, version 1703 will enable Cortana. </br></br> See the [Recommended configuration](#recommended-configuration) section below for recommended Cortana settings. | If using Windows 10 Pro Education, upgrading from Windows 10, version 1607 to Windows 10, version 1703 will enable Cortana. </br></br> See the [Recommended configuration](#recommended-configuration) section below for recommended Cortana settings. | See the [Recommended configuration](#recommended-configuration) section below for recommended Cortana settings. |
|
||||
| **Safe search** | **SetEduPolicies** | Locks Bing safe search to Strict in Microsoft Edge | This is already set | This is already set | The policy must be set |
|
||||
|
@ -23,9 +23,9 @@ Applies to: IT admins
|
||||
|
||||
By default, when a teacher with a work or school account acquires Minecraft: Education Edition,they are automatically signed up for Window Store for Business, and the **Basic Purchaser** role is assigned to them. **Basic Purchaser** role allows teachers to acquire Minecraft: Education Edition and to distribute it to students.
|
||||
|
||||
However, tenant admins can control whether or not teachers automatically sign up for Windows Store for Business, and get the **Basic Purchaser** role. You can configure this with **Allow educators in my organization to sign up for the Windows Store for Business.** You'll find this on the **Permissions** page.
|
||||
However, tenant admins can control whether or not teachers automatically sign up for Microsoft Store for Business, and get the **Basic Purchaser** role. You can configure this with **Allow educators in my organization to sign up for the Microsoft Store for Business.** You'll find this on the **Permissions** page.
|
||||
|
||||
**To manage educator access to Windows Store for Business**
|
||||
**To manage educator access to Microsoft Store for Education**
|
||||
1. Sign in to [Microsoft Store for Education](https://educationstore.microsoft.com)
|
||||
2. Click **Manage**, and then click **Permissions**.
|
||||
3. Select, or clear **Allow teachers in my organization to sign up for the Microsoft Store for Education**.
|
||||
@ -50,7 +50,7 @@ Applies to: IT admins
|
||||
2. Click **Settings**, and then choose **Permissions**.
|
||||
3. Click **Add people**, type a name, select the correct person, choose the role you want to assign, and click **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||
Micrososft Store updates the list of people and permissions.
|
||||
|
||||
@ -84,7 +84,7 @@ For education organizations, domain verification ensures you are on the academic
|
||||
## Acquire apps
|
||||
Applies to: IT admins and teachers
|
||||
|
||||
Find apps for your school using Windows Store for Business. Admins in an education setting can use the same processes as Admins in an enterprise setting to find and acquire apps.
|
||||
Find apps for your school using Microsoft Store for Business. Admins in an education setting can use the same processes as Admins in an enterprise setting to find and acquire apps.
|
||||
|
||||
**To acquire apps**
|
||||
- For info on how to acquire apps, see [Acquire apps in Microsoft Store for Business](https://docs.microsoft.com/microsoft-store/acquire-apps-windows-store-for-business#acquire-apps)
|
||||
@ -99,7 +99,7 @@ For more information on payment options, see [payment options](https://docs.micr
|
||||
For more information on tax rates, see [tax information](https://docs.microsoft.com/microsoft-store/update-windows-store-for-business-account-settings#organization-tax-information).
|
||||
|
||||
### Get started with Minecraft: Education Edition
|
||||
Teachers and IT administrators can now get trials or subscriptions to Minecraft: Education Edition and add it to Windows Store for Business for distribution.
|
||||
Teachers and IT administrators can now get trials or subscriptions to Minecraft: Education Edition and add it to Microsoft Store for Business for distribution.
|
||||
- [Get started with Minecraft: Education Edition](https://docs.microsoft.com/education/windows/get-minecraft-for-education)
|
||||
- [For IT admins – Minecraft: Education Edition](https://docs.microsoft.com/education/windows/school-get-minecraft)
|
||||
- [For teachers – Minecraft: Education Edition](https://docs.microsoft.com/education/windows/teacher-get-minecraft)
|
||||
@ -161,14 +161,14 @@ You'll have a summary of current license availability.
|
||||
|
||||
**Minecraft: Education Edition subscriptions**
|
||||
|
||||
Similarly, you can purchase additional subscriptions of **Minecraft: Education Edition** through Windows Store for Business. Find **Minecraft: Education Edition** in your inventory and use the previous steps for purchasing additional app licenses.
|
||||
Similarly, you can purchase additional subscriptions of **Minecraft: Education Edition** through Microsoft Store for Business. Find **Minecraft: Education Edition** in your inventory and use the previous steps for purchasing additional app licenses.
|
||||
|
||||
## Manage order history
|
||||
Applies to: IT admins and teachers
|
||||
|
||||
You can manage your orders through Windows Store for Business. For info on order history and how to refund an order, see [Manage app orders in Windows Store for Business](https://technet.microsoft.com/itpro/windows/manage/manage-orders-windows-store-for-business).
|
||||
You can manage your orders through Microsoft Store for Business. For info on order history and how to refund an order, see [Manage app orders in Microsoft Store for Business](https://technet.microsoft.com/itpro/windows/manage/manage-orders-windows-store-for-business).
|
||||
|
||||
It can take up to 24 hours after a purchase, before a receipt is available on your **Order history page**.
|
||||
|
||||
> [!NOTE]
|
||||
For **Minecraft: Education Edition**, you can request a refund through Windows Store for Business for two months from the purchase date. After two months, refunds require a support call.
|
||||
For **Minecraft: Education Edition**, you can request a refund through Microsoft Store for Business for two months from the purchase date. After two months, refunds require a support call.
|
@ -26,7 +26,7 @@ ms.author: celested
|
||||
<li><a href="https://technet.microsoft.com/en-us/windows/mt723346" target="_blank">Deploy a custom Windows 10 Start menu</a></li>
|
||||
<li><a href="https://technet.microsoft.com/en-us/windows/mt723347" target="_blank">Manage Windows 10 updates and upgrades</a></li>
|
||||
<li><a href="https://technet.microsoft.com/en-us/windows/mt723344" target="_blank">Reprovision devices at the end of the school year</a></li> <li><a href="https://technet.microsoft.com/en-us/windows/mt723343" target="_blank">Use MDT to deploy Windows 10</a></li>
|
||||
<li><a href="https://technet.microsoft.com/en-us/windows/mt723348" target="_blank">Use Windows Store for Business</a></li>
|
||||
<li><a href="https://technet.microsoft.com/en-us/windows/mt723348" target="_blank">Use Microsoft Store for Business</a></li>
|
||||
</ul>
|
||||
</p>
|
||||
|
||||
|
@ -9,7 +9,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: high
|
||||
author: CelesteDG
|
||||
ms.author: celested
|
||||
ms.date: 08/07/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Test Windows 10 S on existing Windows 10 education devices
|
||||
@ -77,32 +77,22 @@ Make sure all drivers are installed and working properly on your device running
|
||||
|
||||
Check with your device manufacturer before trying Windows 10 S on your device to see if the drivers are available and supported by the device manufacturer.
|
||||
|
||||
<!--
|
||||
| | | |
|
||||
| - | - | - |
|
||||
| [Acer](https://www.acer.com/ac/en/US/content/windows10s-compatible-list) | [American Future Tech](https://www.ibuypower.com/Support/Support) | [Asus](https://www.asus.com/event/2017/win10S/) |
|
||||
| [Atec](http://www.atec.kr/contents/ms_info.html) | [Axdia](https://www.odys.de/web/web_lan_en_hmp_1_win10s_ja.html) | [Casper](http://www.casper.com.tr/window10sdestegi) |
|
||||
| [Cyberpower](https://www.cyberpowerpc.com/support/) | [Daewoo](http://www.lucoms.com/v2/cs/cs_windows10.asp) | [Fujitsu](http://support.ts.fujitsu.com/IndexProdSupport.asp?OpenTab=win10_update) |
|
||||
| [Global K](http://compaq.com.br/sistemas-compativeis-com-windows-10-s.html) | [HP](https://support.hp.com/us-en/document/c05588871) | [LANIT Trading](http://irbis-digital.ru/support/podderzhka-windows-10-s/) |
|
||||
| [Lenovo](https://support.lenovo.com/us/en/solutions/ht504589) | [LG](http://www.lg.com/us/content/html/hq/windows10update/Win10S_UpdateInfo.html) | [MCJ](https://www2.mouse-jp.co.jp/ssl/user_support2/info.asp?N_ID=361) |
|
||||
| [Micro P/Exertis](http://support.linxtablets.com/WindowsSupport/Articles/Windows_10_S_Supported_Devices.aspx) | [Microsoft](https://www.microsoft.com/surface/en-us/support/windows-and-office/surface-devices-that-work-with-windows-10-s) | [MSI](https://www.msi.com/Landing/Win10S) |
|
||||
| [Panasonic](https://panasonic.net/cns/pc/Windows10S/) | [Positivo SA](http://www.positivoinformatica.com.br/atualizacao-windows-10) | [Positivo da Bahia](http://www.br.vaio.com/atualizacao-windows-10/) |
|
||||
| [Samsung](http://www.samsung.com/us/support/windows10s/) | [Toshiba](http://win10upgrade.toshiba.com/win10s/information?region=TAIS&country=US&lang=en) | [Trekstor](http://www.trekstor.de/windows-10-s-en.html) |
|
||||
| [Trigem](http://www.trigem.co.kr/windows/win10S.html) | [Vaio](http://us.vaio.com/support/knowledge-base/windows-10-s-compatibility-information/) | [Wortmann](https://www.wortmann.de/en-gb/content/+windows-10-s-supportinformation/windows-10-s-supportinformation.aspx) |
|
||||
-->
|
||||
|
||||
| | | |
|
||||
| - | - | - |
|
||||
| <a href="https://www.acer.com/ac/en/US/content/windows10s-compatible-list" target="_blank">Acer</a> | <a href="https://www.ibuypower.com/Support/Support" target="_blank">American Future Tech</a> | <a href="https://www.asus.com/event/2017/win10S/" target="_blank">Asus</a> |
|
||||
| <a href="http://www.atec.kr/contents/ms_info.html" target="_blank">Atec</a> | <a href="https://www.odys.de/web/web_lan_en_hmp_1_win10s_ja.html" target="_blank">Axdia</a> | <a href="http://www.casper.com.tr/window10sdestegi" target="_blank">Casper</a> |
|
||||
| <a href="https://www.cyberpowerpc.com/support/" target="_blank">Cyberpower</a> | <a href="http://www.lucoms.com/v2/cs/cs_windows10.asp" target="_blank">Daewoo</a> | <a href="http://www.daten.com.br/suportes/windows10s/" target="_blank">Daten</a> |
|
||||
| <a href="http://support.ts.fujitsu.com/IndexProdSupport.asp?OpenTab=win10_update" target="_blank">Fujitsu</a> | <a href="http://compaq.com.br/sistemas-compativeis-com-windows-10-s.html" target="_blank">Global K</a> | <a href="https://support.hp.com/us-en/document/c05588871" target="_blank">HP</a> |
|
||||
| <a href="https://www.acer.com/ac/en/US/content/windows10s-compatible-list" target="_blank">Acer</a> | <a href="http://www.51cube.com/ch/win10s-help.php" target="_blank">Alldocube</a> | <a href="https://www.ibuypower.com/site/computer/windows-10-s" target="_blank">American Future Tech</a> |
|
||||
| <a href="http://www.prestigio.com/support/compatibility-with-windows-10-s/" target="_blank">ASBISC</a> | <a href="https://www.asus.com/event/2017/win10S/" target="_blank">Asus</a> | <a href="http://www.atec.kr/contents/ms_info.html" target="_blank">Atec</a> |
|
||||
| <a href="https://www.odys.de/web/web_lan_en_hmp_1_win10s_ja.html" target="_blank">Axdia</a> | <a href="http://www.casper.com.tr/window10sdestegi" target="_blank">Casper</a> | <a href="https://www.cyberpowerpc.com/page/Windows-10-S/" target="_blank">Cyberpower</a> |
|
||||
| <a href="http://www.lucoms.com/v2/cs/cs_windows10.asp" target="_blank">Daewoo</a> | <a href="http://www.daten.com.br/suportes/windows10s/" target="_blank">Daten</a> | <a href="http://www.dell.com/support/article/us/en/19/sln307174/dell-computers-tested-for-windows-10-s?lang=en" target="_blank">Dell</a> |
|
||||
| <a href="http://www.epson.jp/support/misc/windows10s.htm" target="_blank">Epson</a> | <a href="http://exo.com.ar/actualizaciones-de-windows-10" target="_blank">EXO</a> | <a href="http://www.fujitsu.com/au/products/computing/pc/microsoft/s-compatible/" target="_blank">Fujitsu</a> |
|
||||
| <a href="http://apac.getac.com/support/windows10s.html" target="_blank">Getac</a> | <a href="http://compaq.com.br/sistemas-compativeis-com-windows-10-s.html" target="_blank">Global K</a> | <a href="https://support.hp.com/us-en/document/c05588871" target="_blank">HP</a> |
|
||||
| <a href="http://consumer.huawei.com/cn/support/notice/detail/index.htm?id=1541" target="_blank">Huawei</a> | <a href="http://www.inet-tek.com/en/product-qadetail-86.html" target="_blank">iNET</a> | <a href="https://www.intel.com/content/www/us/en/support/boards-and-kits/000025096.html" target="_blank">Intel</a> |
|
||||
| <a href="http://irbis-digital.ru/support/podderzhka-windows-10-s/" target="_blank">LANIT Trading</a> | <a href="https://support.lenovo.com/us/en/solutions/ht504589" target="_blank">Lenovo</a> | <a href="http://www.lg.com/us/content/html/hq/windows10update/Win10S_UpdateInfo.html" target="_blank">LG</a> |
|
||||
| <a href="https://www2.mouse-jp.co.jp/ssl/user_support2/info.asp?N_ID=361" target="_blank">MCJ</a> | <a href="http://support.linxtablets.com/WindowsSupport/Articles/Windows_10_S_Supported_Devices.aspx" target="_blank">Micro P/Exertis</a> | <a href="https://www.microsoft.com/surface/en-us/support/windows-and-office/surface-devices-that-work-with-windows-10-s" target="_blank">Microsoft</a> |
|
||||
| <a href="https://www.msi.com/Landing/Win10S" target="_blank">MSI</a> | <a href="https://panasonic.net/cns/pc/Windows10S/" target="_blank">Panasonic</a> | <a href="http://www.positivoinformatica.com.br/atualizacao-windows-10" target="_blank">Positivo SA</a> |
|
||||
| <a href="http://www.br.vaio.com/atualizacao-windows-10/" target="_blank">Positivo da Bahia</a> | <a href="http://www.samsung.com/us/support/windows10s/" target="_blank">Samsung</a> | <a href="http://www.tongfangpc.com/service/win10.aspx" target="_blank">Tongfang</a> |
|
||||
| <a href="https://www.msi.com/Landing/Win10S" target="_blank">MSI</a> | <a href="https://panasonic.net/cns/pc/Windows10S/" target="_blank">Panasonic</a> | <a href="http://www.bangho.com.ar/windows10s" target="_blank">PC Arts</a> |
|
||||
| <a href="http://www.positivoinformatica.com.br/atualizacao-windows-10" target="_blank">Positivo SA</a> | <a href="http://www.br.vaio.com/atualizacao-windows-10/" target="_blank">Positivo da Bahia</a> | <a href="http://www.samsung.com/us/support/windows10s/" target="_blank">Samsung</a> |
|
||||
| <a href="http://www.teclast.com/zt/aboutwin10s/" target="_blank">Teclast</a> | <a href="http://www.dospara.co.jp/support/share.php?contents=about_windows10s" target="_blank">Thirdwave</a> | <a href="http://www.tongfangpc.com/service/win10.aspx" target="_blank">Tongfang</a> |
|
||||
| <a href="http://win10upgrade.toshiba.com/win10s/information?region=TAIS&country=US&lang=en" target="_blank">Toshiba</a> | <a href="http://www.trekstor.de/windows-10-s-en.html" target="_blank">Trekstor</a> | <a href="http://www.trigem.co.kr/windows/win10S.html" target="_blank">Trigem</a> |
|
||||
| <a href="http://us.vaio.com/support/knowledge-base/windows-10-s-compatibility-information/" target="_blank">Vaio</a> | <a href="https://www.wortmann.de/en-gb/content/+windows-10-s-supportinformation/windows-10-s-supportinformation.aspx" target="_blank">Wortmann</a> |
|
||||
| <a href="http://us.vaio.com/support/knowledge-base/windows-10-s-compatibility-information/" target="_blank">Vaio</a> | <a href="https://www.wortmann.de/en-gb/content/+windows-10-s-supportinformation/windows-10-s-supportinformation.aspx" target="_blank">Wortmann</a> | <a href="http://www.yifangdigital.com/Customerservice/win10s.aspx" target="_blank">Yifang</a> |
|
||||
|
||||
|
||||
> [!NOTE]
|
||||
|
@ -9,7 +9,7 @@ ms.pagetype: edu
|
||||
ms.localizationpriority: high
|
||||
author: CelesteDG
|
||||
ms.author: celested
|
||||
ms.date: 08/01/2017
|
||||
ms.date: 09/18/2017
|
||||
---
|
||||
|
||||
# Use the Set up School PCs app
|
||||
@ -103,7 +103,10 @@ You can watch the descriptive audio version here: [Microsoft Education: Use the
|
||||
|
||||
- [Download the latest Set up School PCs app from the Microsoft Store](https://www.microsoft.com/store/apps/9nblggh4ls40).
|
||||
- Install the app on your work PC and make sure you're connected to your school's network.
|
||||
- You must be an administrator on Office 365 and Azure Active Directory, and have Microsoft Store for Education configured. It's best if you sign up for and configure Intune for Education before using the Set up School PCs app.
|
||||
- You must have Office 365 and Azure Active Directory.
|
||||
- You must have the Microsoft Store for Education configured.
|
||||
- You must be a global admin, store admin, or purchaser in the Microsoft Store for Education.
|
||||
- It's best if you sign up for and [configure Intune for Education](../get-started/use-intune-for-education.md) before using the Set up School PCs app.
|
||||
- Have a USB drive, 1 GB or larger, to save the provisioning package. We recommend an 8 GB or larger USB drive if you're installing Office.
|
||||
|
||||
## Set up School PCs step-by-step
|
||||
|
1
gdpr/TOC.md
Normal file
@ -0,0 +1 @@
|
||||
# [Index](index.md)
|
40
gdpr/docfx.json
Normal file
@ -0,0 +1,40 @@
|
||||
{
|
||||
"build": {
|
||||
"content": [
|
||||
{
|
||||
"files": [
|
||||
"**/*.md"
|
||||
],
|
||||
"exclude": [
|
||||
"**/obj/**",
|
||||
"**/includes/**",
|
||||
"README.md",
|
||||
"LICENSE",
|
||||
"LICENSE-CODE",
|
||||
"ThirdPartyNotices"
|
||||
]
|
||||
}
|
||||
],
|
||||
"resource": [
|
||||
{
|
||||
"files": [
|
||||
"**/*.png",
|
||||
"**/*.jpg"
|
||||
],
|
||||
"exclude": [
|
||||
"**/obj/**",
|
||||
"**/includes/**"
|
||||
]
|
||||
}
|
||||
],
|
||||
"overwrite": [],
|
||||
"externalReference": [],
|
||||
"globalMetadata": {
|
||||
"author": "eross-msft",
|
||||
"ms.author": "lizross"
|
||||
},
|
||||
"fileMetadata": {},
|
||||
"template": [],
|
||||
"dest": "gdpr"
|
||||
}
|
||||
}
|
1
gdpr/index.md
Normal file
@ -0,0 +1 @@
|
||||
# placeholder
|
@ -128,6 +128,20 @@ If different encryption strengths are used, MBAM will report the machine as **no
|
||||
As of HF02, the MBAM Self-Service Portal automatically adds the '-' on Key ID entry.
|
||||
**Note:** The Server has to be reconfigured for the Javascript to take effect.
|
||||
|
||||
### MBAM 2.5 Sp1 Reports does not work / render properly
|
||||
Reports Page does not render properly when SSRS is hosted on SQL Server 2016 edition.
|
||||
For example – Browsing to Helpdesk – Clicking on Reports – ( Highlighted portion have “x” on it )
|
||||
Digging this further with Fiddler – it does look like once we click on Reports – it calls the SSRS page with HTML 4.0 rendering format.
|
||||
|
||||
**Workaround:** Looking at the site.master code and noticed the X-UA mode was dictated as IE8. As IE8 is WAY past the end of life, and customer is using IE11. Update the setting to the below code. This allows the site to utilize IE11 rendering technologies
|
||||
|
||||
<meta http-equiv="X-UA-Compatible" content="IE=Edge" />
|
||||
|
||||
Original setting is:
|
||||
<meta http-equiv="X-UA-Compatible" content="IE=8" />
|
||||
|
||||
This is the reason why the issue was not seen with other browsers like Chrome, Firefox etc.
|
||||
|
||||
## Got a suggestion for MBAM?
|
||||
|
||||
|
||||
|
171
microsoft-365/images/M365-education.svg
Normal file
@ -0,0 +1,171 @@
|
||||
<svg id="ICONS" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 140">
|
||||
<defs>
|
||||
<style>
|
||||
.cls-1 {
|
||||
fill: #80def9;
|
||||
}
|
||||
|
||||
.cls-14, .cls-2 {
|
||||
fill: none;
|
||||
}
|
||||
|
||||
.cls-3 {
|
||||
fill: #556a8a;
|
||||
}
|
||||
|
||||
.cls-4 {
|
||||
fill: #868787;
|
||||
}
|
||||
|
||||
.cls-5 {
|
||||
fill: #e5e5e5;
|
||||
}
|
||||
|
||||
.cls-6 {
|
||||
fill: #b72b2b;
|
||||
}
|
||||
|
||||
.cls-7 {
|
||||
fill: #a80000;
|
||||
}
|
||||
|
||||
.cls-15, .cls-8, .cls-9 {
|
||||
fill: #fff;
|
||||
}
|
||||
|
||||
.cls-9 {
|
||||
stroke: #5b7484;
|
||||
}
|
||||
|
||||
.cls-14, .cls-15, .cls-9 {
|
||||
stroke-miterlimit: 10;
|
||||
stroke-width: 2px;
|
||||
}
|
||||
|
||||
.cls-10 {
|
||||
fill: #e6e6e6;
|
||||
}
|
||||
|
||||
.cls-11 {
|
||||
fill: #b8c1ce;
|
||||
}
|
||||
|
||||
.cls-12 {
|
||||
fill: #ccc;
|
||||
}
|
||||
|
||||
.cls-13 {
|
||||
fill: #5b7484;
|
||||
}
|
||||
|
||||
.cls-14 {
|
||||
stroke: #556a8a;
|
||||
}
|
||||
|
||||
.cls-15 {
|
||||
stroke: #00bcf2;
|
||||
}
|
||||
|
||||
.cls-16 {
|
||||
fill: #008272;
|
||||
}
|
||||
|
||||
.cls-17 {
|
||||
fill: #bad80a;
|
||||
}
|
||||
</style>
|
||||
</defs>
|
||||
<title>M365-education</title>
|
||||
<g>
|
||||
<g>
|
||||
<g>
|
||||
<path class="cls-1" d="M113.2,39.53v-.35a13.84,13.84,0,0,0-.29-3.47,12.49,12.49,0,0,0-20.56-8.94A14.53,14.53,0,0,0,80.18,21C71,21,64,29,63.88,38.09c0,.62.16,1.09.16,1.72-4.84,2.34-7.64,6.4-7.64,11.55,0,7.36,5.79,13.26,13.46,13.69.71,5.11,5.29,9.86,13.14,9.86,6.62,0,10.57.54,15.4-4.9a16.27,16.27,0,0,0,7.7,2.1c9.28,0,16.64-8.22,16.64-17.5A16.19,16.19,0,0,0,113.2,39.53Z"/>
|
||||
<path class="cls-1" d="M293,56.2a15.9,15.9,0,0,1,8.13,2.24A21,21,0,0,1,340,56.25c.34,0,.68-.05,1-.05a17.91,17.91,0,0,1,18,17.9C359,84,350.94,91,341,91H297c-8.84,0-20-3.9-20-18.9A15.91,15.91,0,0,1,293,56.2Z"/>
|
||||
<rect class="cls-2" x="64.2" y="3" width="271" height="148"/>
|
||||
<g>
|
||||
<polygon class="cls-3" points="264.39 25 129.4 25 79 53 313 53 264.39 25"/>
|
||||
<polygon class="cls-4" points="86.72 52 129.92 27 263.85 27 305.52 52 86.72 52"/>
|
||||
<rect class="cls-3" x="79" y="53" width="234" height="68"/>
|
||||
<rect class="cls-5" x="163.5" y="-28.5" width="65" height="230" transform="translate(282.5 -109.5) rotate(90)"/>
|
||||
<polygon class="cls-3" points="196.5 16.5 195.5 16.5 145 53 145 121 247 121 247 53 196.5 16.5"/>
|
||||
<polygon class="cls-6" points="147 121 147 54.03 196 18.6 245 53 245 121 147 121"/>
|
||||
<rect class="cls-7" x="185.2" y="91" width="22" height="30"/>
|
||||
<rect class="cls-8" x="187" y="93" width="18" height="28"/>
|
||||
<circle class="cls-9" cx="195.9" cy="35" r="11"/>
|
||||
</g>
|
||||
<rect class="cls-3" x="89" y="61" width="19" height="22"/>
|
||||
<rect class="cls-10" x="89.5" y="64.5" width="18" height="15" transform="translate(170.5 -26.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="91" y="63" width="15" height="4"/>
|
||||
<rect class="cls-11" x="91" y="72" width="15" height="4"/>
|
||||
<rect class="cls-7" x="154" y="61" width="22" height="32"/>
|
||||
<rect class="cls-12" x="151" y="68" width="28" height="18" transform="translate(242 -88) rotate(90)"/>
|
||||
<rect class="cls-3" x="91" y="71" width="15" height="2"/>
|
||||
<g>
|
||||
<rect class="cls-3" x="118" y="61" width="19" height="22"/>
|
||||
<rect class="cls-10" x="118.5" y="64.5" width="18" height="15" transform="translate(199.5 -55.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="120" y="63" width="15" height="4"/>
|
||||
<rect class="cls-11" x="120" y="72" width="15" height="4"/>
|
||||
<rect class="cls-3" x="120" y="71" width="15" height="2"/>
|
||||
</g>
|
||||
<rect class="cls-3" x="89" y="88" width="19" height="22"/>
|
||||
<rect class="cls-10" x="89.5" y="91.5" width="18" height="15" transform="translate(197.5 0.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="91" y="90" width="15" height="4"/>
|
||||
<rect class="cls-11" x="91" y="99" width="15" height="4"/>
|
||||
<rect class="cls-3" x="91" y="98" width="15" height="2"/>
|
||||
<g>
|
||||
<rect class="cls-3" x="118" y="88" width="19" height="22"/>
|
||||
<rect class="cls-10" x="118.5" y="91.5" width="18" height="15" transform="translate(226.5 -28.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="120" y="90" width="15" height="4"/>
|
||||
<rect class="cls-11" x="120" y="99" width="15" height="4"/>
|
||||
<rect class="cls-3" x="120" y="98" width="15" height="2"/>
|
||||
</g>
|
||||
<rect class="cls-13" x="255" y="61" width="19" height="22"/>
|
||||
<rect class="cls-10" x="255.5" y="64.5" width="18" height="15" transform="translate(336.5 -192.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="257" y="63" width="15" height="4"/>
|
||||
<rect class="cls-11" x="257" y="72" width="15" height="4"/>
|
||||
<rect class="cls-13" x="257" y="71" width="15" height="2"/>
|
||||
<g>
|
||||
<rect class="cls-13" x="284" y="61" width="19" height="22"/>
|
||||
<rect class="cls-10" x="284.5" y="64.5" width="18" height="15" transform="translate(365.5 -221.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="286" y="63" width="15" height="4"/>
|
||||
<rect class="cls-11" x="286" y="73" width="15" height="4"/>
|
||||
<rect class="cls-13" x="286" y="71" width="15" height="2"/>
|
||||
</g>
|
||||
<rect class="cls-13" x="255" y="88" width="19" height="22"/>
|
||||
<rect class="cls-10" x="255.5" y="91.5" width="18" height="15" transform="translate(363.5 -165.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="257" y="90" width="15" height="4"/>
|
||||
<rect class="cls-11" x="257" y="99" width="15" height="4"/>
|
||||
<rect class="cls-13" x="257" y="98" width="15" height="2"/>
|
||||
<g>
|
||||
<rect class="cls-13" x="284" y="88" width="19" height="22"/>
|
||||
<rect class="cls-10" x="284.5" y="91.5" width="18" height="15" transform="translate(392.5 -194.5) rotate(90)"/>
|
||||
<rect class="cls-11" x="286" y="90" width="15" height="4"/>
|
||||
<rect class="cls-11" x="286" y="99" width="15" height="4"/>
|
||||
<rect class="cls-13" x="286" y="98" width="15" height="2"/>
|
||||
</g>
|
||||
<rect class="cls-7" x="156" y="66" width="18" height="2"/>
|
||||
<rect class="cls-7" x="156.2" y="86" width="18" height="2"/>
|
||||
<rect class="cls-7" x="164" y="68" width="2" height="19"/>
|
||||
<rect class="cls-8" x="156" y="88" width="18" height="3"/>
|
||||
<rect class="cls-8" x="156" y="63" width="18" height="3"/>
|
||||
<rect class="cls-7" x="185" y="61" width="22" height="26"/>
|
||||
<rect class="cls-12" x="185" y="65" width="22" height="18" transform="translate(270 -122) rotate(90)"/>
|
||||
<rect class="cls-7" x="187" y="66" width="18" height="2"/>
|
||||
<rect class="cls-7" x="195" y="67" width="2" height="19"/>
|
||||
<rect class="cls-8" x="187" y="63" width="18" height="3"/>
|
||||
<rect class="cls-7" x="217" y="61" width="22" height="32"/>
|
||||
<rect class="cls-12" x="214" y="68" width="28" height="18" transform="translate(305 -151) rotate(90)"/>
|
||||
<rect class="cls-7" x="219" y="66" width="18" height="2"/>
|
||||
<rect class="cls-7" x="219" y="86" width="18" height="2"/>
|
||||
<rect class="cls-7" x="227" y="68" width="2" height="19"/>
|
||||
<rect class="cls-8" x="219" y="88" width="18" height="3"/>
|
||||
<rect class="cls-8" x="219" y="63" width="18" height="3"/>
|
||||
<rect class="cls-11" x="187" y="93" width="18" height="5"/>
|
||||
<polyline class="cls-14" points="203 35 196 35 196 28"/>
|
||||
</g>
|
||||
<path class="cls-15" d="M342.2,80.16v-.22a9,9,0,0,0-.4-2.19,8,8,0,0,0-13.15-5.64,9.23,9.23,0,0,0-7.71-3.64c-5.82,0-10.21,5.07-10.31,10.79,0,.39.1.69.1,1.08a7.89,7.89,0,0,0-4.83,7.29,8.74,8.74,0,0,0,8.5,8.65c.45,3.23,3.34,6.23,8.3,6.23,4.18,0,6.68.34,9.73-3.09a10.28,10.28,0,0,0,4.86,1.33c5.86,0,10.72-5.19,10.72-11.05A11.52,11.52,0,0,0,342.2,80.16Z"/>
|
||||
</g>
|
||||
<path class="cls-16" d="M102.69,111.2a7.84,7.84,0,0,0,1.31-4.37,7.4,7.4,0,0,0-5.64-7.37A9.1,9.1,0,0,0,99,96.1c0-4.74-3.58-8.59-8-8.59a7.5,7.5,0,0,0-3.27.76A10.17,10.17,0,0,0,78,80c-5.52,0-10,4.8-10,10.73,0,.39,0,.77.06,1.15A7.35,7.35,0,0,0,62,99.32a7.87,7.87,0,0,0,1.09,4c-4.74,1.6-8.09,5.44-8.09,9.93C55,119.2,60.82,124,68,124H99c3,0,6.85-4.3,6.85-7.51A5.86,5.86,0,0,0,102.69,111.2Z"/>
|
||||
<path class="cls-17" d="M83.64,107A6,6,0,0,0,76,99.36a6,6,0,0,0-11.83-.61,7,7,0,0,0-9.81,8.36A8.94,8.94,0,0,0,44,116c0,5,4,8,9,8H82c4.42,0,9-4.58,9-9A8,8,0,0,0,83.64,107Z"/>
|
||||
</g>
|
||||
</svg>
|
After Width: | Height: | Size: 8.1 KiB |
@ -1,11 +1,12 @@
|
||||
---
|
||||
layout: HubPage
|
||||
hide_bc: true
|
||||
author: v-kents
|
||||
author: CelesteDG
|
||||
ms.author: celested
|
||||
ms.topic: hub-page
|
||||
keywords: Microsoft 365, Microsoft 365 documentation, Microsoft 365 for business, Microsoft 365 for enterprise, Microsoft 365 for education, enterprise, business, education, docs, documentation
|
||||
title: Microsoft 365 Documentation
|
||||
description: Microsoft 365 is a complete, intelligent solution, including Office 365, Windows 10, and Enterprise Mobility + Security, that empowers everyone to be creative and work together, securely.
|
||||
description: Find documentation and resources for Microsoft 365--a complete, intelligent solution, including Office 365, Windows 10, and Enterprise Mobility + Security, that empowers everyone to be creative and work together, securely.
|
||||
---
|
||||
<div id="main" class="v2">
|
||||
<div class="container">
|
||||
@ -20,13 +21,13 @@ description: Microsoft 365 is a complete, intelligent solution, including Office
|
||||
<li class="fullSpan intro">[Microsoft 365](https://www.microsoft.com/microsoft-365/default.aspx) is a complete, intelligent solution, including Office 365, Windows 10, and Enterprise Mobility + Security, that empowers everyone to be creative and work together, securely.
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://docs.microsoft.com/microsoft-365-enterprise/">
|
||||
<a href="https://docs.microsoft.com/microsoft-365-enterprise/" target="blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="/media/hubs/microsoft365/M365-enterprise.svg" alt="" />
|
||||
<img src="/media/hubs/microsoft365/M365-enterprise.svg" alt="Microsoft 365 Enterprise documentation and resources" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
@ -40,19 +41,39 @@ description: Microsoft 365 is a complete, intelligent solution, including Office
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://docs.microsoft.com/microsoft-365-business/">
|
||||
<a href="https://docs.microsoft.com/microsoft-365-business/" target="blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="/media/hubs/microsoft365/M365-business.svg" alt="" />
|
||||
<img src="/media/hubs/microsoft365/M365-business.svg" alt="Microsoft 365 Business documentation and resources" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<br />
|
||||
<h3>Microsoft 365 Business</h3>
|
||||
<p>Microsoft 365 Business is designed for small- to medium-sized businesses with up to 300 users and integrates Office 365 Business Premium with tailored security and management features from Windows 10, and Enterprise Mobility + Security. </p>
|
||||
<p>Microsoft 365 Business is a new solution designed for small and midsize businesses (SMB), bringing together the best-in-class productivity and collaboration capabilities of Office 365 with device management and security solutions to safeguard business data.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://docs.microsoft.com/education/" target="blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
<div class="cardImageOuter">
|
||||
<div class="cardImage bgdAccent1">
|
||||
<img src="/media/hubs/microsoft365/M365-education.svg" alt="Microsoft 365 Education documentation and resources" />
|
||||
</div>
|
||||
</div>
|
||||
<div class="cardText">
|
||||
<br />
|
||||
<h3>Microsoft 365 Education</h3>
|
||||
<p>Microsoft 365 Education empowers educators to unlock creativity, promote teamwork, and provide a simple and safe experience in a single, affordable solution built for education.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
@ -7,21 +7,21 @@ ms.sitesec: library
|
||||
ms.pagetype: store
|
||||
author: TrudyHa
|
||||
ms.author: TrudyHa
|
||||
ms.date: 07/05/2107
|
||||
ms.date: 09/12/2017
|
||||
ms.localizationpriority: high
|
||||
---
|
||||
|
||||
# Manage Windows device deployment with Windows AutoPilot Deployment
|
||||
|
||||
**Applies to**
|
||||
|
||||
- Windows 10
|
||||
|
||||
> [!IMPORTANT]
|
||||
> This topic has been updated to reflect the latest functionality, which we are releasing to customers in stages. You may not see all of the options described here until you receive the update.
|
||||
|
||||
Windows AutoPilot Deployment Program simplifies device set up for IT Admins. For an overview of benefits, scenarios, and prerequisites, see [Overview of Windows AutoPilot](https://docs.microsoft.com/windows/deployment/windows-10-auto-pilot).
|
||||
|
||||
Watch this video to learn more about Windows AutoPilot in Micrsoft Store for Business.
|
||||
|
||||
<iframe width="560" height="315" src="https://www.youtube.com/embed/IpLIZU_j7Z0" frameborder="0" allowfullscreen></iframe>
|
||||
|
||||
## What is Windows AutoPilot Deployment Program?
|
||||
In Microsoft Store for Business, you can manage devices for your organization and apply an *AutoPilot deployment profile* to your devices. When people in your organization run the out-of-box experience on the device, the profile configures Windows based on the AutoPilot deployment profile you applied to the device.
|
||||
|
||||
@ -54,9 +54,13 @@ To manage devices through Microsoft Store for Business and Education, you'll nee
|
||||
|
||||
### Device information file format
|
||||
Columns in the device information file need to use this naming and be in this order:
|
||||
- Column 1: Device Serial Number
|
||||
- Column 2: Windows Product ID
|
||||
- Column 3: Hardware Hash
|
||||
- Column A: Device Serial Number
|
||||
- Column B: Windows Product ID
|
||||
- Column C: Hardware Hash
|
||||
|
||||
Here's a sample device information file:
|
||||
|
||||

|
||||
|
||||
When you add devices, you need to add them to an *AutoPilot deployment group*. Use these groups to apply AutoPilot deployment profiles to a group of devices. The first time you add devices to a group, you'll need to create an AutoPilot deployment group.
|
||||
|
||||
|
@ -22,7 +22,7 @@ You can manage all apps that you've acquired on your **Apps & software** page. T
|
||||
|
||||
All of these apps are treated the same once they are in your inventory and you can perform app lifecycle tasks for them: distribute apps, add apps to private store, review license details, and reclaim app licenses.
|
||||
|
||||
<!---  -->
|
||||
<!---  -->
|
||||
|
||||
Microsoft Store for Business and Education shows this info for each app in your inventory:
|
||||
- Name
|
||||
|
@ -2,6 +2,6 @@
|
||||
tocHref: /
|
||||
topicHref: /
|
||||
items:
|
||||
- name: Windows Store for Business
|
||||
- name: Microsoft Store for Business
|
||||
tocHref: /microsoft-store
|
||||
topicHref: /microsoft-store/index
|
@ -1,6 +1,6 @@
|
||||
---
|
||||
title: Configure an MDM provider (Windows 10)
|
||||
description: For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Windows Store for Business inventory to manage apps with offline licenses.
|
||||
description: For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Microsoft Store for Business inventory to manage apps with offline licenses.
|
||||
ms.assetid: B3A45C8C-A96C-4254-9659-A9B364784673
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: manage
|
||||
@ -16,7 +16,7 @@ ms.localizationpriority: high
|
||||
- Windows 10
|
||||
- Windows 10 Mobile
|
||||
|
||||
For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Windows Store for Business inventory to manage apps with offline licenses. Store for Business management tool services work with your third-party management tool to manage content.
|
||||
For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Microsoft Store for Business inventory to manage apps with offline licenses. Store for Business management tool services work with your third-party management tool to manage content.
|
||||
|
||||
Your management tool needs to be installed and configured with Azure AD, in the same directory that you are using for Store for Business. Once that's done, you can configure it to work with Store for Business
|
||||
|
||||
@ -35,7 +35,7 @@ After your management tool is added to your Azure AD directory, you can configur
|
||||
3. From the list of MDM tools, select the one you want to synchronize with Microsoft Store, and then click **Activate.**
|
||||
|
||||
Your MDM tool is ready to use with Microsoft Store. To learn how to configure synchronization and deploy apps, see these topics:
|
||||
- [Manage apps you purchased from Windows Store for Business with Microsoft Intune](https://technet.microsoft.com/library/mt676514.aspx)
|
||||
- [Manage apps from Windows Store for Business with System Center Configuration Manager](https://docs.microsoft.com/sccm/apps/deploy-use/manage-apps-from-the-windows-store-for-business)
|
||||
- [Manage apps you purchased from Microsoft Store for Business with Microsoft Intune](https://technet.microsoft.com/library/mt676514.aspx)
|
||||
- [Manage apps from Microsoft Store for Business with System Center Configuration Manager](https://docs.microsoft.com/sccm/apps/deploy-use/manage-apps-from-the-windows-store-for-business)
|
||||
|
||||
For third-party MDM providers or management servers, check your product documentation.
|
@ -28,7 +28,7 @@ You can make an app available in your private store when you acquire the app, or
|
||||
|
||||
2. Click an app, choose the license type, and then click **Get the app** to acquire the app for your organization.
|
||||
|
||||
<!---  -->
|
||||
<!---  -->
|
||||
|
||||
Microsoft Store adds the app to **Apps & software**. Click **Manage**, **Apps & software** for app distribution options.
|
||||
|
||||
@ -37,7 +37,7 @@ Microsoft Store adds the app to **Apps & software**. Click **Manage**, **Apps &
|
||||
1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com).
|
||||
2. Click **Manage**, and then choose **Apps & software**.
|
||||
|
||||
<!---  -->
|
||||
<!---  -->
|
||||
|
||||
3. Use **Refine results** to search for online-licensed apps under **License type**.
|
||||
4. From the list of online-licensed apps, click the ellipses for the app you want, and then choose **Add to private store**.
|
||||
|
@ -22,7 +22,7 @@ You can configure a mobile device management (MDM) tool to synchronize your Micr
|
||||
|
||||
Your MDM tool needs to be installed and configured in Azure AD, in the same Azure AD directory used with Microsoft Store.
|
||||
|
||||
In Azure AD management portal, find the MDM application, and then add it to your directory. Once the MDM has been configured in Azure AD, you can authorize the tool to work with the Microsoft Store for Business or Microsoft Store for Education. This allows the MDM tool to call Microsoft Store management tool services. For more information, see [Configure MDM provider](configure-mdm-provider-windows-store-for-business.md) and [Manage apps you purchased from the Windows Store for Business with Microsoft Intune](https://docs.microsoft.com/intune/deploy-use/manage-apps-you-purchased-from-the-windows-store-for-business-with-microsoft-intune).
|
||||
In Azure AD management portal, find the MDM application, and then add it to your directory. Once the MDM has been configured in Azure AD, you can authorize the tool to work with the Microsoft Store for Business or Microsoft Store for Education. This allows the MDM tool to call Microsoft Store management tool services. For more information, see [Configure MDM provider](configure-mdm-provider-windows-store-for-business.md) and [Manage apps you purchased from the Microsoft Store for Business with Microsoft Intune](https://docs.microsoft.com/intune/deploy-use/manage-apps-you-purchased-from-the-windows-store-for-business-with-microsoft-intune).
|
||||
|
||||
Microsoft Store services provide:
|
||||
|
||||
@ -44,11 +44,11 @@ MDM tool requirements:
|
||||
|
||||
## Distribute offline-licensed apps
|
||||
|
||||
If your vendor doesn’t support the ability to synchronize applications from the management tool services, or can't connect to the management tool services, your vendor may support the ability to deploy offline licensed applications by downloading the application and license from the store and then deploying the app through your MDM. For more information on online and offline licensing with Store for Business, see [Apps in the Windows Store for Business.](apps-in-windows-store-for-business.md#licensing-model)
|
||||
If your vendor doesn’t support the ability to synchronize applications from the management tool services, or can't connect to the management tool services, your vendor may support the ability to deploy offline licensed applications by downloading the application and license from the store and then deploying the app through your MDM. For more information on online and offline licensing with Store for Business, see [Apps in the Microsoft Store for Business.](apps-in-windows-store-for-business.md#licensing-model)
|
||||
|
||||
This diagram shows how you can use a management tool to distribute offline-licensed app to employees in your organization. Once synchronized from Store for Business, management tools can use the Windows Management framework to distribute applications to devices.
|
||||
|
||||

|
||||

|
||||
|
||||
## Distribute online-licensed apps
|
||||
|
||||
@ -60,12 +60,3 @@ This diagram shows how you can use a management tool to distribute an online-lic
|
||||
|
||||
[Configure MDM Provider](configure-mdm-provider-windows-store-for-business.md)
|
||||
[Manage apps you purchased from the Microsoft Store for Business and Education with Microsoft Intune](https://technet.microsoft.com/library/mt676514.aspx)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
Before Width: | Height: | Size: 9.1 KiB After Width: | Height: | Size: 7.9 KiB |
BIN
store-for-business/images/msfb-autopilot-csv.png
Normal file
After Width: | Height: | Size: 8.3 KiB |
@ -89,7 +89,7 @@ These permissions allow people to:
|
||||
|
||||
3. Click **Add people**, type a name, choose the role you want to assign, and click **Save** .
|
||||
|
||||
<!---  -->
|
||||
<!---  -->
|
||||
|
||||
4. If you don't find the name you want, you might need to add people to your Azure AD directory. For more information, see [Manage user accounts in Microsoft Store for Business and Education](manage-users-and-groups-windows-store-for-business.md).
|
||||
|
||||
|
@ -49,7 +49,7 @@ Admins need to invite developer or ISVs to become an LOB publisher.
|
||||
|
||||
**To invite a developer to become an LOB publisher**
|
||||
|
||||
1. Sign in to the [Windows Store for Business]( https://go.microsoft.com/fwlink/p/?LinkId=623531).
|
||||
1. Sign in to the [Microsoft Store for Business]( https://go.microsoft.com/fwlink/p/?LinkId=623531).
|
||||
2. Click **Manage**, click **Permissions**, and then choose **Line-of-business publishers**.
|
||||
3. On the Line-of business publishers page, click **Invite** to send an email invitation to a developer.
|
||||
>[!Note]
|
||||
@ -98,7 +98,7 @@ After an ISV submits the LOB app for your company or school, someone with Micros
|
||||
|
||||
After you add the app to your inventory, you can choose how to distribute the app. For more information, see:
|
||||
|
||||
- [Distribute apps to your employees from the Windows Store for Business](distribute-apps-to-your-employees-windows-store-for-business.md)
|
||||
- [Distribute apps to your employees from the Microsoft Store for Business](distribute-apps-to-your-employees-windows-store-for-business.md)
|
||||
|
||||
- [Distribute apps from your private store](distribute-apps-from-your-private-store.md)
|
||||
|
||||
|
@ -18,23 +18,77 @@ author: brianlic-msft
|
||||
Prefer video? See [Credentials Protected by Windows Defender Credential Guard](https://mva.microsoft.com/en-us/training-courses/deep-dive-into-credential-guard-16651?l=mD3geLJyC_8304300474)
|
||||
in the **Deep Dive into Windows Defender Credential Guard** video series.
|
||||
|
||||
- Passwords are still weak so we recommend that your organization deploy Windows Defender Credential Guard and move away from passwords and to other authentication methods, such as physical smart cards, virtual smart cards, or Windows Hello for Business.
|
||||
- Some 3rd party Security Support Providers (SSPs and APs) might not be compatible with Windows Defender Credential Guard because it does not allow third-party SSPs to ask for password hashes from LSA. However, SSPs and APs still get notified of the password when a user logs on and/or changes their password. Any use of undocumented APIs within custom SSPs and APs are not supported. We recommend that custom implementations of SSPs/APs are tested against Windows Defender Credential Guard to ensure that the SSPs and APs do not depend on any undocumented or unsupported behaviors. For example, using the KerbQuerySupplementalCredentialsMessage API is not supported. You should not replace the NTLM or Kerberos SSPs with custom SSPs and APs. For more info, see [Restrictions around Registering and Installing a Security Package](http://msdn.microsoft.com/library/windows/desktop/dn865014.aspx) on MSDN.
|
||||
- As the depth and breadth of protections provided by Windows Defender Credential Guard are increased, subsequent releases of Windows 10 with Windows Defender Credential Guard running may impact scenarios that were working in the past. For example, Windows Defender Credential Guard may block the use of a particular type of credential or a particular component to prevent malware from taking advantage of vulnerabilities. Therefore, we recommend that scenarios required for operations in an organization are tested before upgrading a device that has Windows Defender Credential Guard running.
|
||||
Passwords are still weak. We recommend that in addition to deploying Windows Defender Credential Guard, organizations move away from passwords to other authentication methods, such as physical smart cards, virtual smart cards, or Windows Hello for Business.
|
||||
|
||||
- Starting with Windows 10, version 1511, domain credentials that are stored with Credential Manager are protected with Windows Defender Credential Guard. Credential Manager allows you to store credentials, such as user names and passwords that you use to log on to websites or other computers on a network. The following considerations apply to the Windows Defender Credential Guard protections for Credential Manager:
|
||||
- Credentials saved by Remote Desktop Services cannot be used to remotely connect to another machine without supplying the password. Attempts to use saved credentials will fail, displaying the error message "Logon attempt failed".
|
||||
- Applications that extract derived domain credentials from Credential Manager will no longer be able to use those credentials.
|
||||
- You cannot restore credentials using the Credential Manager control panel if the credentials were backed up from a PC that has Windows Defender Credential Guard turned on. If you need to back up your credentials, you must do this before you enable Windows Defender Credential Guard. Otherwise, you won't be able to restore those credentials.
|
||||
- Windows Defender Credential Guard uses hardware security, so some features such as Windows To Go, are not supported.
|
||||
Windows Defender Credential Guard uses hardware security, so some features such as Windows To Go, are not supported.
|
||||
|
||||
## Wi-fi and VPN Considerations
|
||||
When you enable Windows Defender Credential Guard, you can no longer use NTLM v1 authentication. If you are using WiFi and VPN endpoints that are based on MS-CHAPv2, they are subject to similar attacks as for NTLMv1. For WiFi and VPN connections, Microsoft recommends that organizations move from MSCHAPv2-based connections such as PEAP-MSCHAPv2 and EAP-MSCHAPv2, to certificate-based authentication such as PEAP-TLS or EAP-TLS.
|
||||
|
||||
When you enable Windows Defender Credential Guard, you can no longer use NTLM classic deployment model authentication. If you are using WiFi and VPN endpoints that are based on MS-CHAPv2, they are subject to similar attacks as for NTLMv1. For WiFi and VPN connections, Microsoft recommends that organizations move from MSCHAPv2-based connections such as PEAP-MSCHAPv2 and EAP-MSCHAPv2, to certificate-based authentication such as PEAP-TLS or EAP-TLS.
|
||||
|
||||
## Kerberos Considerations
|
||||
|
||||
When you enable Windows Defender Credential Guard, you can no longer use Kerberos unconstrained delegation or DES encryption. Unconstrained delegation could allow attackers to extract Kerberos keys from the isolated LSA process. You must use constrained or resource-based Kerberos delegation instead.
|
||||
When you enable Windows Defender Credential Guard, you can no longer use Kerberos unconstrained delegation or DES encryption. Unconstrained delegation could allow attackers to extract Kerberos keys from the isolated LSA process. Use constrained or resource-based Kerberos delegation instead.
|
||||
|
||||
## 3rd Party Security Support Providers Considerations
|
||||
Some 3rd party Security Support Providers (SSPs and APs) might not be compatible with Windows Defender Credential Guard because it does not allow third-party SSPs to ask for password hashes from LSA. However, SSPs and APs still get notified of the password when a user logs on and/or changes their password. Any use of undocumented APIs within custom SSPs and APs are not supported. We recommend that custom implementations of SSPs/APs are tested with Windows Defender Credential Guard. SSPs and APs that depend on any undocumented or unsupported behaviors fail. For example, using the KerbQuerySupplementalCredentialsMessage API is not supported. Replacing the NTLM or Kerberos SSPs with custom SSPs and APs. For more info, see [Restrictions around Registering and Installing a Security Package](http://msdn.microsoft.com/library/windows/desktop/dn865014.aspx) on MSDN.
|
||||
|
||||
## Upgrade Considerations
|
||||
As the depth and breadth of protections provided by Windows Defender Credential Guard are increased, subsequent releases of Windows 10 with Windows Defender Credential Guard running may impact scenarios that were working in the past. For example, Windows Defender Credential Guard may block the use of a particular type of credential or a particular component to prevent malware from taking advantage of vulnerabilities. Test scenarios required for operations in an organization before upgrading a device using Windows Defender Credential Guard.
|
||||
|
||||
### Saved Windows Credentials Protected
|
||||
|
||||
Starting with Windows 10, version 1511, domain credentials that are stored with Credential Manager are protected with Windows Defender Credential Guard. Credential Manager allows you to store three types of credentials: Windows credentials, certificate-based credentials, and generic credentials. Generic credentials such as user names and passwords that you use to log on to websites are not protected since the applications require your cleartext password. If the application does not need a copy of the password, they can save domain credentials as Windows credentials that are protected. Windows credentials are used to connect to other computers on a network. The following considerations apply to the Windows Defender Credential Guard protections for Credential Manager:
|
||||
- Windows credentials saved by Remote Desktop Client cannot be sent to a remote host. Attempts to use saved Windows credentials fail, displaying the error message "Logon attempt failed."
|
||||
- Applications that extract Windows credentials fail.
|
||||
- When credentials are backed up from a PC that has Windows Defender Credential Guard enabled, the Windows credentials cannot be restored. If you need to back up your credentials, you must do this before you enable Windows Defender Credential Guard. Otherwise, you cannot restore those credentials.
|
||||
|
||||
## Clearing TPM Considerations
|
||||
Virtualization-based Security (VBS) uses the TPM to protect its key. So when the TPM is cleared then the TPM protected key used to encrypt VBS secrets is lost.
|
||||
|
||||
>[!WARNING]
|
||||
> Clearing the TPM results in loss of protected data for all features that use VBS to protect data. <br>
|
||||
> When a TPM is cleared ALL features, which use VBS to protect data can no longer decrypt their protected data.
|
||||
|
||||
As a result Credential Guard can no longer decrypt protected data. VBS creates a new TPM protected key for Credential Guard. Credential Guard uses the new key to protect new data. However, the previously protected data is lost forever.
|
||||
|
||||
>[!NOTE]
|
||||
> Credential Guard obtains the key during initialization. So the data loss will only impact persistent data and occur after the next system startup.
|
||||
|
||||
### Windows credentials saved to Credential Manager
|
||||
Since Credential Manager cannot decrypt saved Windows Credentials, they are deleted. Applications should prompt for credentials that were previously saved. If saved again, then Windows credentials are protected Credential Guard.
|
||||
|
||||
### Domain-joined device’s automatically provisioned public key
|
||||
Beginning with Windows 10 and Windows Server 2016, domain-devices automatically provision a bound public key, for more information about automatic public key provisioning, see [Domain-joined Device Public Key Authentication](https://docs.microsoft.com/windows-server/security/kerberos/domain-joined-device-public-key-authentication).
|
||||
|
||||
Since Credential Guard cannot decrypt the protected private key, Windows uses the domain-joined computer's password for authentication to the domain. Unless additional policies are deployed, there should not be a loss of functionality. If a device is configured to only use public key, then it cannot authenticate with password until that policy disabled. For more information on Configuring device to only use public key, see [Domain-joined Device Public Key Authentication](https://docs.microsoft.com/windows-server/security/kerberos/domain-joined-device-public-key-authentication).
|
||||
|
||||
Also if any access control checks including authentication policies require devices to have either the KEY TRUST IDENTITY (S-1-18-4) or FRESH PUBLIC KEY IDENTITY (S-1-18-3) well-known SIDs, then those access checks fail. For more information about authentication policies, see [Authentication Policies and Authentication Policy Silos](https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos). For more information about well-known SIDs, see [[MS-DTYP] Section 2.4.2.4 Well-known SID Structures](https://msdn.microsoft.com/en-us/library/cc980032.aspx).
|
||||
|
||||
### Breaking DPAPI on domain-joined devices
|
||||
On domain-joined devices, DPAPI can recover user keys using a domain controller from the user's domain. If a domain-joined device has no connectivity to a domain controller, then recovery is not possible.
|
||||
|
||||
>[!IMPORTANT]
|
||||
> Best practice when clearing a TPM on a domain-joined device is to be on a network with connectivity to domain controllers. This ensures DPAPI functions and the user does not experience strange behavior. <br>
|
||||
Auto VPN configuration is protected with user DPAPI. User may not be able to use VPN to connect to domain controllers since the VPN configurations are lost.
|
||||
|
||||
If you must clear the TPM on a domain-joined device without connectivity to domain controllers, then you should consider the following.
|
||||
|
||||
Domain user sign-in on a domain-joined device after clearing a TPM for as long as there is no connectivity to a domain controller:
|
||||
|
||||
|Credential Type | Windows 10 version | Behavior
|
||||
|---|---|---|
|
||||
| Certificate (smart card or Windows Hello for Business) | All | All data protected with user DPAPI is unusable and user DPAPI does not work at all. |
|
||||
| Password | Windows 10 v1709 or later | If the user signed-in with a certificate or password prior to clearing the TPM, then they can sign-in with password and user DPAPI is unaffected.
|
||||
| Password | Windows 10 v1703 | If the user signed-in with a password prior to clearing the TPM, then they can sign-in with that password and are unaffected.
|
||||
| Password | Windows 10 v1607 or earlier | Existing user DPAPI protected data is unusable. User DPAPI is able to protect new data.
|
||||
|
||||
Once the device has connectivity to the domain controllers, DPAPI recovers the user's key and data protected prior to clearing the TPM can be decrypted.
|
||||
|
||||
#### Impact of DPAPI failures on Windows Information Protection
|
||||
When data protected with user DPAPI is unusable, then the user loses access to all work data protected by Windows Information Protection. The impact includes: Outlook 2016 is unable to start and work protected documents cannot be opened. If DPAPI is working, then newly created work data is protected and can be accessed.
|
||||
|
||||
**Workaround:** Users can resolve the problem by connecting their device to the domain and rebooting or using their Encrypting File System Data Recovery Agent certificate. For more information about Encrypting File System Data Recovery Agent certificate, see [Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate](https://docs.microsoft.com/en-us/windows/threat-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate).
|
||||
|
||||
|
||||
## See also
|
||||
|
||||
|
@ -9,7 +9,7 @@ ms.pagetype: security, mobile
|
||||
author: DaniHalfin
|
||||
ms.localizationpriority: high
|
||||
ms.author: daniha
|
||||
ms.date: 07/07/2017
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Prepare and Deploy Windows Server 2016 Active Directory Federation Services
|
||||
|
||||
@ -36,7 +36,7 @@ Prepare the Active Directory Federation Services deployment by installing and up
|
||||
|
||||
Sign-in the federation server with _local admin_ equivalent credentials.
|
||||
1. Ensure Windows Server 2016 is current by running **Windows Update** from **Settings**. Continue this process until no further updates are needed. If you’re not using Windows Update for updates, please advise the [Windows Server 2016 update history page](https://support.microsoft.com/help/4000825/windows-10-windows-server-2016-update-history) to make sure you have the latest updates available installed.
|
||||
2. Ensure the latest server updates to the federation server includes [KB4022723](https://support.microsoft.com/en-us/help/4022723).
|
||||
2. Ensure the latest server updates to the federation server includes [KB4034658 (14393.1593)](https://support.microsoft.com/en-us/help/4034658).
|
||||
|
||||
>[!IMPORTANT]
|
||||
>The above referenced updates are mandatory for Windows Hello for Business all on-premises deployment and hybrid certificate trust deployments for domain joined computers.
|
||||
|
@ -36,12 +36,12 @@ Sign-in using _Enterprise Admin_ equivalent credentials on Windows Server 2012 o
|
||||
1. Open an elevated Windows PowerShell prompt.
|
||||
2. Use the following command to install the Active Directory Certificate Services role.
|
||||
```PowerShell
|
||||
Add-WindowsFeature Adcs-Cert-Authority -IncludeManageTools
|
||||
Add-WindowsFeature Adcs-Cert-Authority -IncludeManagementTools
|
||||
```
|
||||
|
||||
3. Use the following command to configure the Certificate Authority using a basic certificate authority configuration.
|
||||
```PowerShell
|
||||
Install-AdcsCertificateAuthority
|
||||
Install-AdcsCertificationAuthority
|
||||
```
|
||||
|
||||
## Configure a Production Public Key Infrastructure
|
||||
|
@ -9,7 +9,7 @@ ms.pagetype: security, mobile
|
||||
author: DaniHalfin
|
||||
ms.localizationpriority: high
|
||||
ms.author: daniha
|
||||
ms.date: 07/07/2017
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Windows Hello for Business Deployment Guide
|
||||
|
||||
@ -47,8 +47,10 @@ Hybrid deployments are for enterprises that use Azure Active Directory. On-prem
|
||||
The trust model determines how you want users to authentication to the on-premises Active Directory. Remember hybrid environments use Azure Active Directory and on-premises Active Directory. The key-trust model is for enterprises who do not want to issue end-entity certificates to their users and they have an adequate number of 2016 domain controllers in each site to support the authentication. The certificate-trust model is for enterprise that do want to issue end-entity certificates to their users and have the benefits of certificate expiration and renewal, similar to how smart cards work today. The certificate trust model is also enterprise who are not ready to deploy Windows Server 2016 domain controllers.
|
||||
|
||||
Following are the various deployment guides included in this topic:
|
||||
* [Hybrid Certificate Trust Deployment](hello-hybrid-cert-trust.md)
|
||||
* [On Premises Certificate Trust Deployment](hello-deployment-cert-trust.md)
|
||||
|
||||
|
||||
## Provisioning
|
||||
|
||||
The Windows Hello for Business provisioning begins immediately after the user has signed in, after the user profile is loaded, but before the user receives their desktop. Windows only launches the provisioning experience if all the prerequisite checks pass. You can determine the status of the prerequisite checks by viewing the **User Device Registration** in the **Event Viewer** under **Applications and Services Logs\Microsoft\Windows**.
|
||||
|
@ -0,0 +1,144 @@
|
||||
---
|
||||
title: Windows Hello for Business Trust New Installation (Windows Hello for Business)
|
||||
description: Windows Hello for Business Hybrid baseline deployment
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
localizationpriority: high
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Windows Hello for Business Certificate Trust New Installation
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
Windows Hello for Business involves configuring distributed technologies that may or may not exist in your current infrastructure. Hybrid certificate trust deployments of Windows Hello for Business rely on these technolgies
|
||||
|
||||
* [Active Directory](#active-directory)
|
||||
* [Public Key Infrastructure](#public-key-infrastructure)
|
||||
* [Azure Active Directory](#azure-active-directory)
|
||||
* [Directory Synchronization](#directory-synchronization)
|
||||
* [Active Directory Federation Services](#active-directory-federation-services)
|
||||
|
||||
|
||||
New installations are considerably more involved than existing implementations because you are building the entire infrastructure. Microsoft recommends you review the new installation baseline to validate your exsting envrionment has all the needed configurations to support your hybrid certificate trust Windows Hello for Business deployment. If your environment meets these needs, you can read the [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md) section to prepare your Windows Hello for Business deployment by configuring Azure device registration.
|
||||
|
||||
The new installation baseline begins with a basic Active Directory deployment and enterprise PKI. This document expects you have Active Directory deployed using Windows Server 2008 R2 or later domain controllers.
|
||||
|
||||
## Active Directory ##
|
||||
Production environments should follow Active Directory best practices regarding the number and placement of domain controllers to ensure adequate authentication throughout the organization.
|
||||
|
||||
Lab environments and isolated proof of concepts may want to limit the number of domain controllers. The purpose of these environments is to experiment and learn. Reducing the number of domain controllers can prevent troubleshooting issue, such as Active Directory replication, which is unrelated to activity's goal.
|
||||
|
||||
### Section Review
|
||||
|
||||
> [!div class="checklist"]
|
||||
> * Minimum Windows Server 2008 R2 domain controllers
|
||||
> * Minimum Windows Server 2008 R2 domain and forest functional level
|
||||
> * Functional networking, name resolution, and Active Directory replication
|
||||
|
||||
## Public Key Infrastructure
|
||||
|
||||
Windows Hello for Business must have a public key infrastructure regardless of the deployment or trust model. All trust models depend on the domain controllers having a certificate. The certificate serves as a root of trust for clients to ensure they are not communicating with a rogue domain controller. The certificate trust model extends certificate issuance to client computers. During Windows Hello for Business provisioning, the user receives a sign-in certificate.
|
||||
|
||||
This guide assumes most enterprises have an existing public key infrastructure. Windows Hello for Business depends on a Windows enterprise public key infrastructure running the Active Directory Certificate Services role from Windows Server 2012 or later.
|
||||
|
||||
### Lab-based public key infrastructure
|
||||
|
||||
The following instructions may be used to deploy simple public key infrastructure that is suitable for a lab environment.
|
||||
|
||||
Sign-in using _Enterprise Admin_ equivalent credentials on Windows Server 2012 or later server where you want the certificate authority installed.
|
||||
|
||||
>[!NOTE]
|
||||
>Never install a certificate authority on a domain controller in a production environment.
|
||||
|
||||
1. Open an elevated Windows PowerShell prompt.
|
||||
2. Use the following command to install the Active Directory Certificate Services role.
|
||||
```PowerShell
|
||||
Add-WindowsFeature Adcs-Cert-Authority -IncludeManageTools
|
||||
```
|
||||
|
||||
3. Use the following command to configure the Certificate Authority using a basic certificate authority configuration.
|
||||
```PowerShell
|
||||
Install-AdcsCertificateAuthority
|
||||
```
|
||||
|
||||
## Configure a Production Public Key Infrastructure
|
||||
|
||||
If you do have an existing public key infrastructure, please review [Certification Authority Guidance](https://technet.microsoft.com/library/hh831574.aspx) from Microsoft TechNet to properly design your infrastructure. Then, consult the [Test Lab Guide: Deploying an AD CS Two-Tier PKI Hierarchy](https://technet.microsoft.com/library/hh831348.aspx) for instructions on how to configure your public key infrastructure using the information from your design session.
|
||||
|
||||
### Section Review ###
|
||||
|
||||
> [!div class="checklist"]
|
||||
> * Miniumum Windows Server 2012 Certificate Authority.
|
||||
> * Enterprise Certificate Authority.
|
||||
> * Functioning public key infrastructure.
|
||||
|
||||
## Azure Active Directory ##
|
||||
You’ve prepared your Active Directory. Hybrid Windows Hello for Business deployment needs Azure Active Directory to host your cloud-based identities.
|
||||
|
||||
The next step of the deployment is to follow the [Creating an Azure AD tenant](https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-howto-tenant) process to provision an Azure tenant for your organization.
|
||||
|
||||
### Section Review
|
||||
|
||||
> [!div class="checklist"]
|
||||
> * Review the different ways to establish an Azure Active Directory tenant.
|
||||
> * Create an Azure Active Directory Tenant.
|
||||
> * Purchase the appropriate Azure Active Directory subscription or licenses, if necessary.
|
||||
|
||||
## Multifactor Authentication Services ##
|
||||
Windows Hello for Business uses multifactor authentication during provisioning and during user initiated PIN reset scenarios, such as when a user forgets their PIN. There are two preferred multifactor authentication configurations with hybrid deployments—Azure MFA and AD FS using Azure MFA
|
||||
|
||||
Review the [What is Azure Multi-Factor Authentication](https://docs.microsoft.com/en-us/azure/multi-factor-authentication/multi-factor-authentication) topic to familiarize yourself its purpose and how it works.
|
||||
|
||||
### Azure Multi-Factor Authentication (MFA) Cloud ###
|
||||
> [!IMPORTANT]
|
||||
As long as your users have licenses that include Azure Multi-Factor Authentication, there's nothing that you need to do to turn on Azure MFA. You can start requiring two-step verification on an individual user basis. The licenses that enable Azure MFA are:
|
||||
> * Azure Multi-Factor Authentication
|
||||
> * Azure Active Directory Premium
|
||||
> * Enterprise Mobility + Security
|
||||
>
|
||||
> If you have one of these subscriptions or licenses, skip the Azure MFA Adapter section.
|
||||
|
||||
#### Azure MFA Provider ####
|
||||
If your organization uses Azure MFA on a per-consumption model (no licenses), then review the [Create a Multifactor Authentication Provider](https://docs.microsoft.com/en-us/azure/multi-factor-authentication/multi-factor-authentication-get-started-auth-provider) section to create an Azure MFA Authentication provider and associate it with your Azure tenant.
|
||||
|
||||
#### Configure Azure MFA Settings ####
|
||||
Once you have created your Azure MFA authentication provider and associated it with an Azure tenant, you need to configure the multi-factor authentication settings. Review the [Configure Azure Multi-Factor Authentication settings](https://docs.microsoft.com/en-us/azure/multi-factor-authentication/multi-factor-authentication-whats-next) section to configure your settings.
|
||||
|
||||
#### Azure MFA User States ####
|
||||
After you have completed configuring your Azure MFA settings, you want to review configure [User States](https://docs.microsoft.com/en-us/azure/multi-factor-authentication/multi-factor-authentication-get-started-user-states) to understand user states. User states determine how you enable Azure MFA for your users.
|
||||
|
||||
### Azure MFA via ADFS 2016 ###
|
||||
Alternatively, you can configure Windows Server 2016 Active Directory Federation Services (AD FS) to provide additional multi-factor authentication. To configure, read the [Configure AD FS 2016 and Azure MFA](https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-ad-fs-2016-and-azure-mfa) section
|
||||
|
||||
### Section Review
|
||||
|
||||
> [!div class="checklist"]
|
||||
> * Review the overview and uses of Azure Multifactor Authentication.
|
||||
> * Review your Azure Active Directory subscription for Azure Multifactor Authentication.
|
||||
> * Create an Azure Multifactor Authentication Provider, if necessary.
|
||||
> * Configure Azure Multufactor Authentiation features and settings.
|
||||
> * Understand the different User States and their effect on Azure Multifactor Authentication.
|
||||
> * Consider using Azure Multifactor Authentication or a third-party multifactor authentication provider with Windows Server 2016 Active Directory Federation Services, if necessary.
|
||||
|
||||
> [!div class="nextstepaction"]
|
||||
> [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. New Installation Baseline (*You are here*)
|
||||
4. [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. [Configure Windows Hello for Business settings](hello-hybrid-cert-whfb-settings.md)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
@ -0,0 +1,518 @@
|
||||
---
|
||||
title: Configure Device Registration for Hybrid Windows Hello for Business
|
||||
description: Azure Device Registration for Hybrid Certificate Trust Deployment (Windows Hello for Business)
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB, hybrid, cert-trust, device, registration
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
localizationpriority: high
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Configure Device Registration for Hybrid Windows Hello for Business
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
>[!IMPORTANT]
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
You're environment is federated and you are ready to configure device registration for your hybrid environment. Hybrid Windows Hello for Business deployment needs device registration and device write-back to enable proper device authentication.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> If your environment is not federated, review the [New Installation baseline](hello-hybrid-cert-new-install.md) section of this deployment document to learn how to federate your environment for your Windows Hello for Business deployment.
|
||||
|
||||
Use this three phased approach for configuring device registration.
|
||||
1. [Configure devices to register in Azure](#configure-azure-for-device-registration)
|
||||
2. [Synchronize devices to on-premises Active Directory](#configure-active-directory-to-support-azure-device-syncrhonization)
|
||||
3. [Configure AD FS to use cloud devices](#configure-ad-fs-to-use-azure-registered-devices)
|
||||
|
||||
> [!NOTE]
|
||||
> Before proceeding, you should familiarize yourself with device regisration concepts such as:
|
||||
> * Azure AD registered devices
|
||||
> * Azure AD joined devices
|
||||
> * Hybrid Azure AD joined devices
|
||||
>
|
||||
> You can learn about this and more by reading [Introduction to Device Management in Azure Active Directory.](https://docs.microsoft.com/en-us/azure/active-directory/device-management-introduction)
|
||||
|
||||
## Configure Azure for Device Registration
|
||||
Begin configuring device registration to support Hybrid Windows Hello for Business by configuring device registration capabilities in Azure AD.
|
||||
|
||||
To do this, follow the **Configure device settings** steps under [Setting up Azure AD Join in your organization](https://azure.microsoft.com/en-us/documentation/articles/active-directory-azureadjoin-setup/)
|
||||
|
||||
## Configure Active Directory to support Azure device syncrhonization
|
||||
|
||||
Azure Active Directory is now configured for device registration. Next, you need to configure the on-premises Active Directory to support synchronizing hybrid Azure AD joined devices. Begin with upgrading the Active Directory Schema
|
||||
|
||||
### Upgrading Active Directory to the Windows Server 2016 Schema
|
||||
|
||||
To use Windows Hello for Business with Hybrid Azure AD joined devices, you must first upgrade your Active Directory schema to Windows Server 2016.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> If you already have a Windows Server 2016 domain controller in your forest, you can skip **Upgrading Active Directory to the Windows Server 2016 Schema** (this section).
|
||||
|
||||
#### Identify the schema role domain controller
|
||||
|
||||
To locate the schema master role holder, open and command prompt and type:
|
||||
|
||||
```Netdom query fsmo | findstr -i schema```
|
||||
|
||||

|
||||
|
||||
The command should return the name of the domain controller where you need to adprep.exe. Update the schema locally on the domain controller hosting the Schema master role.
|
||||
|
||||
#### Updating the Schema
|
||||
|
||||
Windows Hello for Business uses asymmetric keys as user credentials (rather than passwords). During enrollment, the public key is registered in an attribute on the user object in Active Directory. The schema update adds this new attribute to Active Directory.
|
||||
|
||||
Manually updating Active Directory uses the command-line utility **adprep.exe** located at **\<drive>:\support\adprep** on the Windows Server 2016 DVD or ISO. Before running adprep.exe, you must identify the domain controller hosting the schema master role.
|
||||
|
||||
Sign-in to the domain controller hosting the schema master operational role using Enterprise Admin equivalent credentials.
|
||||
|
||||
1. Open an elevated command prompt.
|
||||
2. Type ```cd /d x:\support\adprep``` where *x* is the drive letter of the DVD or mounted ISO.
|
||||
3. To update the schema, type ```adprep /forestprep```.
|
||||
4. Read the Adprep Warning. Type the letter **C*** and press **Enter** to update the schema.
|
||||
5. Close the Command Prompt and sign-out.
|
||||
|
||||
> [!NOTE]
|
||||
> If you installed Azure AD Connect prior to upgrading the schema, you will need to re-run the Azure AD Connect installation and refresh the on-premises AD schema to ensure the synchronization rule for msDS-KeyCredentialLink is configured.
|
||||
|
||||
|
||||
### Setup Active Directory Federation Services
|
||||
If you are new to AD FS and federation services, you should review [Understanding Key AD FS Concepts](https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/technical-reference/understanding-key-ad-fs-concepts) to prior to designing and deploying your federation service.
|
||||
Review the [AD FS Design guide](https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/design/ad-fs-design-guide-in-windows-server-2012-r2) to plan your federation service.
|
||||
|
||||
Once you have your AD FS design ready, review [Deploying a Federation Server farm](https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/deploying-a-federation-server-farm) to configure AD FS in your environment.
|
||||
> [!IMPORTANT]
|
||||
> During your AD FS deployment, skip the **Configure a federation server with Device Registration Service** and the **Configure Corporate DNS for the Federation Service and DRS** procedures.
|
||||
|
||||
The AD FS farm used with Windows Hello for Business must be Windows Server 2016 with minimum update of [KB4034658 (14393.1593)](https://support.microsoft.com/en-us/help/4034658), which is automatically downloaded and installed through Windows Update. If your AD FS farm is not running the AD FS role with updates from Windows Server 2016, then read [Upgrading to AD FS in Windows Server 2016](https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/upgrading-to-ad-fs-in-windows-server-2016)
|
||||
|
||||
#### ADFS Web Proxy ###
|
||||
Federation server proxies are computers that run AD FS software that have been configured manually to act in the proxy role. You can use federation server proxies in your organization to provide intermediary services between an Internet client and a federation server that is behind a firewall on your corporate network.
|
||||
Use the [Setting of a Federation Proxy](https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/checklist--setting-up-a-federation-server-proxy) checklist to configure AD FS proxy servers in your environment.
|
||||
|
||||
### Deploy Azure AD Connect
|
||||
Next, you need to synchronizes the on-premises Active Directory with Azure Active Directory. To do this, first review the [Integrating on-prem directories with Azure Active Directory](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect) and [hardware and prerequisites](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-prerequisites) needed and then [download the software](http://go.microsoft.com/fwlink/?LinkId=615771).
|
||||
|
||||
When you are ready to install, follow the **Configuring federation with AD FS** section of [Custom installation of Azure AD Connect](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-get-started-custom). Select the **Federation with AD FS** option on the **User sign-in** page. At the **AD FS Farm** page, select the use an existing option and click **Next**.
|
||||
|
||||
### Create AD objects for AD FS Device Authentication
|
||||
If your AD FS farm is not already configured for Device Authentication (you can see this in the AD FS Management console under Service -> Device Registration), use the following steps to create the correct AD DS objects and configuration.
|
||||
|
||||

|
||||
|
||||
> [!NOTE]
|
||||
> The below commands require Active Directory administration tools, so if your federation server is not also a domain controller, first install the tools using step 1 below. Otherwise you can skip step 1.
|
||||
|
||||
1. Run the **Add Roles & Features** wizard and select feature **Remote Server Administration Tools** -> **Role Administration Tools** -> **AD DS and AD LDS Tools** -> Choose both the **Active Directory module for Windows PowerShell** and the **AD DS Tools**.
|
||||
|
||||

|
||||
|
||||
2. On your AD FS primary server, ensure you are logged in as AD DS user with Enterprise Admin (EA ) privileges and open an elevated Windows PowerShell prompt. Then, run the following commands:
|
||||
|
||||
`Import-module activedirectory`
|
||||
`PS C:\> Initialize-ADDeviceRegistration -ServiceAccountName "<your service account>" `
|
||||
3. On the pop-up window click **Yes**.
|
||||
|
||||
> [!NOTE]
|
||||
> If your AD FS service is configured to use a GMSA account, enter the account name in the format "domain\accountname$"
|
||||
|
||||

|
||||
|
||||
The above PSH creates the following objects:
|
||||
|
||||
|
||||
- RegisteredDevices container under the AD domain partition
|
||||
- Device Registration Service container and object under Configuration --> Services --> Device Registration Configuration
|
||||
- Device Registration Service DKM container and object under Configuration --> Services --> Device Registration Configuration
|
||||
|
||||

|
||||
|
||||
4. Once this is done, you will see a successful completion message.
|
||||
|
||||

|
||||
|
||||
### Create Service Connection Point (SCP) in Active Directory
|
||||
If you plan to use Windows 10 domain join (with automatic registration to Azure AD) as described here, execute the following commands to create a service connection point in AD DS
|
||||
1. Open Windows PowerShell and execute the following:
|
||||
|
||||
`PS C:>Import-Module -Name "C:\Program Files\Microsoft Azure Active Directory Connect\AdPrep\AdSyncPrep.psm1" `
|
||||
|
||||
> [!NOTE]
|
||||
> If necessary, copy the AdSyncPrep.psm1 file from your Azure AD Connect server. This file is located in Program Files\Microsoft Azure Active Directory Connect\AdPrep
|
||||
|
||||

|
||||
|
||||
2. Provide your Azure AD global administrator credentials
|
||||
|
||||
`PS C:>$aadAdminCred = Get-Credential`
|
||||
|
||||

|
||||
|
||||
3. Run the following PowerShell command
|
||||
|
||||
`PS C:>Initialize-ADSyncDomainJoinedComputerSync -AdConnectorAccount [AD connector account name] -AzureADCredentials $aadAdminCred `
|
||||
|
||||
Where the [AD connector account name] is the name of the account you configured in Azure AD Connect when adding your on-premises AD DS directory.
|
||||
|
||||
The above commands enable Windows 10 clients to find the correct Azure AD domain to join by creating the serviceConnectionpoint object in AD DS.
|
||||
|
||||
### Prepare AD for Device Write Back
|
||||
To ensure AD DS objects and containers are in the correct state for write back of devices from Azure AD, do the following.
|
||||
|
||||
1. Open Windows PowerShell and execute the following:
|
||||
|
||||
`PS C:>Initialize-ADSyncDeviceWriteBack -DomainName <AD DS domain name> -AdConnectorAccount [AD connector account name] `
|
||||
|
||||
Where the [AD connector account name] is the name of the account you configured in Azure AD Connect when adding your on-premises AD DS directory in domain\accountname format
|
||||
|
||||
The above command creates the following objects for device write back to AD DS, if they do not exist already, and allows access to the specified AD connector account name
|
||||
|
||||
- RegisteredDevices container in the AD domain partition
|
||||
- Device Registration Service container and object under Configuration --> Services --> Device Registration Configuration
|
||||
|
||||
### Enable Device Write Back in Azure AD Connect
|
||||
If you have not done so before, enable device write back in Azure AD Connect by running the wizard a second time and selecting **"Customize Synchronization Options"**, then checking the box for device write back and selecting the forest in which you have run the above cmdlets
|
||||
|
||||
## Configure AD FS to use Azure registered devices
|
||||
|
||||
### Configure issuance of claims
|
||||
|
||||
In a federated Azure AD configuration, devices rely on Active Directory Federation Services (AD FS) or a 3rd party on-premises federation service to authenticate to Azure AD. Devices authenticate to get an access token to register against the Azure Active Directory Device Registration Service (Azure DRS).
|
||||
|
||||
Windows current devices authenticate using Integrated Windows Authentication to an active WS-Trust endpoint (either 1.3 or 2005 versions) hosted by the on-premises federation service.
|
||||
|
||||
> [!NOTE]
|
||||
> When using AD FS, either **adfs/services/trust/13/windowstransport** or **adfs/services/trust/2005/windowstransport** must be enabled. If you are using the Web Authentication Proxy, also ensure that this endpoint is published through the proxy. You can see what end-points are enabled through the AD FS management console under **Service > Endpoints**.
|
||||
>
|
||||
> If you don't have AD FS as your on-premises federation service, follow the instructions of your vendor to make sure they support WS-Trust 1.3 or 2005 end-points and that these are published through the Metadata Exchange file (MEX).
|
||||
|
||||
The following claims must exist in the token received by Azure DRS for device registration to complete. Azure DRS will create a device object in Azure AD with some of this information which is then used by Azure AD Connect to associate the newly created device object with the computer account on-premises.
|
||||
|
||||
* `http://schemas.microsoft.com/ws/2012/01/accounttype`
|
||||
* `http://schemas.microsoft.com/identity/claims/onpremobjectguid`
|
||||
* `http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid`
|
||||
|
||||
If you have more than one verified domain name, you need to provide the following claim for computers:
|
||||
|
||||
* `http://schemas.microsoft.com/ws/2008/06/identity/claims/issuerid`
|
||||
|
||||
If you are already issuing an ImmutableID claim (e.g., alternate login ID) you need to provide one corresponding claim for computers:
|
||||
|
||||
* `http://schemas.microsoft.com/LiveID/Federation/2008/05/ImmutableID`
|
||||
|
||||
In the following sections, you find information about:
|
||||
|
||||
- The values each claim should have
|
||||
- How a definition would look like in AD FS
|
||||
|
||||
The definition helps you to verify whether the values are present or if you need to create them.
|
||||
|
||||
> [!NOTE]
|
||||
> If you don't use AD FS for your on-premises federation server, follow your vendor's instructions to create the appropriate configuration to issue these claims.
|
||||
|
||||
#### Issue account type claim
|
||||
|
||||
**`http://schemas.microsoft.com/ws/2012/01/accounttype`** - This claim must contain a value of **DJ**, which identifies the device as a domain-joined computer. In AD FS, you can add an issuance transform rule that looks like this:
|
||||
|
||||
@RuleName = "Issue account type for domain-joined computers"
|
||||
c:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(
|
||||
Type = "http://schemas.microsoft.com/ws/2012/01/accounttype",
|
||||
Value = "DJ"
|
||||
);
|
||||
|
||||
#### Issue objectGUID of the computer account on-premises
|
||||
|
||||
**`http://schemas.microsoft.com/identity/claims/onpremobjectguid`** - This claim must contain the **objectGUID** value of the on-premises computer account. In AD FS, you can add an issuance transform rule that looks like this:
|
||||
|
||||
@RuleName = "Issue object GUID for domain-joined computers"
|
||||
c1:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
&&
|
||||
c2:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(
|
||||
store = "Active Directory",
|
||||
types = ("http://schemas.microsoft.com/identity/claims/onpremobjectguid"),
|
||||
query = ";objectguid;{0}",
|
||||
param = c2.Value
|
||||
);
|
||||
|
||||
#### Issue objectSID of the computer account on-premises
|
||||
|
||||
**`http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid`** - This claim must contain the the **objectSid** value of the on-premises computer account. In AD FS, you can add an issuance transform rule that looks like this:
|
||||
|
||||
@RuleName = "Issue objectSID for domain-joined computers"
|
||||
c1:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
&&
|
||||
c2:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(claim = c2);
|
||||
|
||||
#### Issue issuerID for computer when multiple verified domain names in Azure AD
|
||||
|
||||
**`http://schemas.microsoft.com/ws/2008/06/identity/claims/issuerid`** - This claim must contain the Uniform Resource Identifier (URI) of any of the verified domain names that connect with the on-premises federation service (AD FS or 3rd party) issuing the token. In AD FS, you can add issuance transform rules that look like the ones below in that specific order after the ones above. Please note that one rule to explicitly issue the rule for users is necessary. In the rules below, a first rule identifying user vs. computer authentication is added.
|
||||
|
||||
@RuleName = "Issue account type with the value User when its not a computer"
|
||||
NOT EXISTS(
|
||||
[
|
||||
Type == "http://schemas.microsoft.com/ws/2012/01/accounttype",
|
||||
Value == "DJ"
|
||||
]
|
||||
)
|
||||
=> add(
|
||||
Type = "http://schemas.microsoft.com/ws/2012/01/accounttype",
|
||||
Value = "User"
|
||||
);
|
||||
|
||||
@RuleName = "Capture UPN when AccountType is User and issue the IssuerID"
|
||||
c1:[
|
||||
Type == "http://schemas.xmlsoap.org/claims/UPN"
|
||||
]
|
||||
&&
|
||||
c2:[
|
||||
Type == "http://schemas.microsoft.com/ws/2012/01/accounttype",
|
||||
Value == "User"
|
||||
]
|
||||
=> issue(
|
||||
Type = "http://schemas.microsoft.com/ws/2008/06/identity/claims/issuerid",
|
||||
Value = regexreplace(
|
||||
c1.Value,
|
||||
".+@(?<domain>.+)",
|
||||
"http://${domain}/adfs/services/trust/"
|
||||
)
|
||||
);
|
||||
|
||||
@RuleName = "Issue issuerID for domain-joined computers"
|
||||
c:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(
|
||||
Type = "http://schemas.microsoft.com/ws/2008/06/identity/claims/issuerid",
|
||||
Value = "http://<verified-domain-name>/adfs/services/trust/"
|
||||
);
|
||||
|
||||
|
||||
In the claim above,
|
||||
|
||||
- `$<domain>` is the AD FS service URL
|
||||
- `<verified-domain-name>` is a placeholder you need to replace with one of your verified domain names in Azure AD
|
||||
|
||||
For more details about verified domain names, see [Add a custom domain name to Azure Active Directory](https://docs.microsoft.com/en-us/azure/active-directory/active-directory-add-domain).
|
||||
To get a list of your verified company domains, you can use the [Get-MsolDomain](https://docs.microsoft.com/en-us/powershell/module/msonline/get-msoldomain?view=azureadps-1.0) cmdlet.
|
||||
|
||||
#### Issue ImmutableID for computer when one for users exist (e.g. alternate login ID is set)
|
||||
|
||||
**`http://schemas.microsoft.com/LiveID/Federation/2008/05/ImmutableID`** - This claim must contain a valid value for computers. In AD FS, you can create an issuance transform rule as follows:
|
||||
|
||||
@RuleName = "Issue ImmutableID for computers"
|
||||
c1:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
&&
|
||||
c2:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(
|
||||
store = "Active Directory",
|
||||
types = ("http://schemas.microsoft.com/LiveID/Federation/2008/05/ImmutableID"),
|
||||
query = ";objectguid;{0}",
|
||||
param = c2.Value
|
||||
);
|
||||
|
||||
#### Helper script to create the AD FS issuance transform rules
|
||||
|
||||
The following script helps you with the creation of the issuance transform rules described above.
|
||||
|
||||
$multipleVerifiedDomainNames = $false
|
||||
$immutableIDAlreadyIssuedforUsers = $false
|
||||
$oneOfVerifiedDomainNames = 'example.com' # Replace example.com with one of your verified domains
|
||||
|
||||
$rule1 = '@RuleName = "Issue account type for domain-joined computers"
|
||||
c:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(
|
||||
Type = "http://schemas.microsoft.com/ws/2012/01/accounttype",
|
||||
Value = "DJ"
|
||||
);'
|
||||
|
||||
$rule2 = '@RuleName = "Issue object GUID for domain-joined computers"
|
||||
c1:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
&&
|
||||
c2:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(
|
||||
store = "Active Directory",
|
||||
types = ("http://schemas.microsoft.com/identity/claims/onpremobjectguid"),
|
||||
query = ";objectguid;{0}",
|
||||
param = c2.Value
|
||||
);'
|
||||
|
||||
$rule3 = '@RuleName = "Issue objectSID for domain-joined computers"
|
||||
c1:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
&&
|
||||
c2:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(claim = c2);'
|
||||
|
||||
$rule4 = ''
|
||||
if ($multipleVerifiedDomainNames -eq $true) {
|
||||
$rule4 = '@RuleName = "Issue account type with the value User when it is not a computer"
|
||||
NOT EXISTS(
|
||||
[
|
||||
Type == "http://schemas.microsoft.com/ws/2012/01/accounttype",
|
||||
Value == "DJ"
|
||||
]
|
||||
)
|
||||
=> add(
|
||||
Type = "http://schemas.microsoft.com/ws/2012/01/accounttype",
|
||||
Value = "User"
|
||||
);
|
||||
|
||||
@RuleName = "Capture UPN when AccountType is User and issue the IssuerID"
|
||||
c1:[
|
||||
Type == "http://schemas.xmlsoap.org/claims/UPN"
|
||||
]
|
||||
&&
|
||||
c2:[
|
||||
Type == "http://schemas.microsoft.com/ws/2012/01/accounttype",
|
||||
Value == "User"
|
||||
]
|
||||
=> issue(
|
||||
Type = "http://schemas.microsoft.com/ws/2008/06/identity/claims/issuerid",
|
||||
Value = regexreplace(
|
||||
c1.Value,
|
||||
".+@(?<domain>.+)",
|
||||
"http://${domain}/adfs/services/trust/"
|
||||
)
|
||||
);
|
||||
|
||||
@RuleName = "Issue issuerID for domain-joined computers"
|
||||
c:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(
|
||||
Type = "http://schemas.microsoft.com/ws/2008/06/identity/claims/issuerid",
|
||||
Value = "http://' + $oneOfVerifiedDomainNames + '/adfs/services/trust/"
|
||||
);'
|
||||
}
|
||||
|
||||
$rule5 = ''
|
||||
if ($immutableIDAlreadyIssuedforUsers -eq $true) {
|
||||
$rule5 = '@RuleName = "Issue ImmutableID for computers"
|
||||
c1:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
|
||||
Value =~ "-515$",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
&&
|
||||
c2:[
|
||||
Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname",
|
||||
Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$"
|
||||
]
|
||||
=> issue(
|
||||
store = "Active Directory",
|
||||
types = ("http://schemas.microsoft.com/LiveID/Federation/2008/05/ImmutableID"),
|
||||
query = ";objectguid;{0}",
|
||||
param = c2.Value
|
||||
);'
|
||||
}
|
||||
|
||||
$existingRules = (Get-ADFSRelyingPartyTrust -Identifier urn:federation:MicrosoftOnline).IssuanceTransformRules
|
||||
|
||||
$updatedRules = $existingRules + $rule1 + $rule2 + $rule3 + $rule4 + $rule5
|
||||
|
||||
$crSet = New-ADFSClaimRuleSet -ClaimRule $updatedRules
|
||||
|
||||
Set-AdfsRelyingPartyTrust -TargetIdentifier urn:federation:MicrosoftOnline -IssuanceTransformRules $crSet.ClaimRulesString
|
||||
|
||||
#### Remarks
|
||||
|
||||
- This script appends the rules to the existing rules. Do not run the script twice because the set of rules would be added twice. Make sure that no corresponding rules exist for these claims (under the corresponding conditions) before running the script again.
|
||||
|
||||
- If you have multiple verified domain names (as shown in the Azure AD portal or via the Get-MsolDomains cmdlet), set the value of **$multipleVerifiedDomainNames** in the script to **$true**. Also make sure that you remove any existing issuerid claim that might have been created by Azure AD Connect or via other means. Here is an example for this rule:
|
||||
|
||||
|
||||
c:[Type == "http://schemas.xmlsoap.org/claims/UPN"]
|
||||
=> issue(Type = "http://schemas.microsoft.com/ws/2008/06/identity/claims/issuerid", Value = regexreplace(c.Value, ".+@(?<domain>.+)", "http://${domain}/adfs/services/trust/"));
|
||||
|
||||
- If you have already issued an **ImmutableID** claim for user accounts, set the value of **$immutableIDAlreadyIssuedforUsers** in the script to **$true**.
|
||||
|
||||
#### Configure Device Authentication in AD FS
|
||||
Using an elevated PowerShell command window, configure AD FS policy by executing the following command
|
||||
|
||||
`PS C:>Set-AdfsGlobalAuthenticationPolicy -DeviceAuthenticationEnabled $true -DeviceAuthenticationMethod All`
|
||||
|
||||
#### Check your configuration
|
||||
For your reference, below is a comprehensive list of the AD DS devices, containers and permissions required for device write-back and authentication to work
|
||||
|
||||
- object of type ms-DS-DeviceContainer at CN=RegisteredDevices,DC=<domain>
|
||||
- read access to the AD FS service account
|
||||
- read/write access to the Azure AD Connect sync AD connector account
|
||||
- Container CN=Device Registration Configuration,CN=Services,CN=Configuration,DC=<domain>
|
||||
- Container Device Registration Service DKM under the above container
|
||||
|
||||

|
||||
|
||||
- object of type serviceConnectionpoint at CN=<guid>, CN=Device Registration
|
||||
- Configuration,CN=Services,CN=Configuration,DC=<domain>
|
||||
- read/write access to the specified AD connector account name on the new object
|
||||
- object of type msDS-DeviceRegistrationServiceContainer at CN=Device Registration Services,CN=Device Registration Configuration,CN=Services,CN=Configuration,DC=<domain>
|
||||
- object of type msDS-DeviceRegistrationService in the above container
|
||||
|
||||
>[!div class="nextstepaction"]
|
||||
[Configure Windows Hello for Business settings](hello-hybrid-cert-whfb-settings.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. Configure Azure Device Registration (*You are here*)
|
||||
5. [Configure Windows Hello for Business settings](hello-hybrid-cert-whfb-settings.md)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
@ -0,0 +1,139 @@
|
||||
---
|
||||
title: Hybrid Windows Hello for Business Prerequistes (Windows Hello for Business)
|
||||
description: Prerequisites for Hybrid Windows Hello for Business Deployments
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB, hybrid, certificate-trust
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
localizationpriority: high
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Hybrid Windows Hello for Business Prerequisites
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
Hybrid environments are distributed systems that enable organizations to use on-premises and Azure-based identities and resources. Windows Hello for Business uses the existing distributed system as a foundation on which organizations can provide two-factor authentication that provides a single sign-in like experience to modern resources.
|
||||
|
||||
The distributed systems on which these technologies were built involved several pieces of on-premises and cloud infrastructure. High-level pieces of the infrastructure include:
|
||||
* [Directories](#directories)
|
||||
* [Public Key Infrastucture](#public-key-infastructure)
|
||||
* [Directory Synchronization](#directory-synchronization)
|
||||
* [Federation](#federation)
|
||||
* [MultiFactor Authetication](#multifactor-authentication)
|
||||
* [Device Registration](#device-registration)
|
||||
|
||||
## Directories ##
|
||||
Hybrid Windows Hello for Business needs two directories: on-premises Active Directory and a cloud Azure Active Directory. The minimum required domain controller, domain functional level, and forest functional level for Windows Hello for Business deployment is Windows Server 2008 R2.
|
||||
|
||||
A hybrid Windows Hello for Busines deployment needs an Azure Active Directory subscription. Different deployment configurations are supported by different Azure subscriptions. The hybrid-certificate trust deployment needs an Azure Active Directory premium subscription because it uses the device write-back synchronization feature. Other deployments, such as the hybrid key-trust deployment, may not require Azure Active Directory premium subscription.
|
||||
|
||||
Windows Hello for Business can be deployed in any environment with Windows Server 2008 R2 or later domain controllers. Azure device registration and Windows Hello for Business require the Windows Server 2016 Active Directory schema.
|
||||
|
||||
Review these requirements and those from the Windows Hello for Business planning guide and worksheet. Based on your deployment decisions you may need to upgrade your on-premises Active Directory or your Azure Active Directory subscription to meet your needs.
|
||||
|
||||
### Section Review ###
|
||||
|
||||
> [!div class="checklist"]
|
||||
> * Active Directory Domain Functional Level
|
||||
> * Active Directory Forest Functional Level
|
||||
> * Domain Controller version
|
||||
> * Windows Server 2016 Schema
|
||||
> * Azure Active Directory subscription
|
||||
> * Correct subscription for desired features and outcomes
|
||||
|
||||
<br>
|
||||
|
||||
## Public Key Infrastructure ##
|
||||
The Windows Hello for Business deployment depends on an enterprise public key infrastructure as trust anchor for authentication. Domain controllers for hybrid deployments need a certificate in order for Windows 10 devices to trust the domain controller.
|
||||
|
||||
Certificate trust deployments need an enterprise public key infrastructure and a certificate registration authority to issue authentication certificates to users. When using Group Policy, hybrid certificate trust deployment use the Windows Server 2016 Active Directory Federation Server (AS FS) as a certificate registration authority.
|
||||
|
||||
The minimum required enterprise certificate authority that can be used with Windows Hello for Business is Windows Server 2012.
|
||||
|
||||
### Section Review
|
||||
> [!div class="checklist"]
|
||||
> * Windows Server 2012 Issuing Certificate Authority
|
||||
> * Windows Server 2016 Active Directory Federation Services
|
||||
|
||||
<br>
|
||||
|
||||
## Directory Synchronization ##
|
||||
The two directories used in hybrid deployments must be synchronized. You need Azure Active Directory Connect to synchronize user accounts in the on-premises Active Directory with Azure Active Directory.
|
||||
|
||||
Organizations using older directory synchronization technology, such as DirSync or Azure AD sync need to upgrade to Azure AD Connect
|
||||
|
||||
### Section Review
|
||||
> [!div class="checklist"]
|
||||
> * Azure Active Directory Connect directory synchronization
|
||||
> * [Upgrade from DirSync](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-dirsync-upgrade-get-started)
|
||||
> * [Upgrade from Azure AD Sync](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-upgrade-previous-version)
|
||||
|
||||
<br>
|
||||
|
||||
## Federation ##
|
||||
Federating your on-premises Active Directory with Azure Active Directory ensures all identities have access to all resources regardless if they reside in cloud or on-premises. Windows Hello for Business hybrid certificate trust needs Windows Server 2016 Active Directory Federation Services. All nodes in the AD FS farm must run the same version of AD FS. Additionally, you need to configure your AD FS farm to support Azure registered devices.
|
||||
|
||||
The AD FS farm used with Windows Hello for Business must be Windows Server 2016 with minimum update of [KB4034658 (14393.1593)](https://support.microsoft.com/en-us/help/4034658), which is automatically downloaded and installed through Windows Update. If your AD FS farm is not running the AD FS role with updates from Windows Server 2016, then read [Upgrading to AD FS in Windows Server 2016](https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/upgrading-to-ad-fs-in-windows-server-2016)
|
||||
|
||||
### Section Review ###
|
||||
> [!div class="checklist"]
|
||||
> * Windows Server 2016 Active Directory Federation Services
|
||||
> * Minimum update of [KB4034658 (14393.1593)](https://support.microsoft.com/en-us/help/4034658)
|
||||
|
||||
<br>
|
||||
|
||||
## Multifactor Authentication ##
|
||||
Windows Hello for Business is a strong, two-factor credential the helps organizations reduce their dependency on passwords. The provisioning process lets a user enroll in Windows Hello for Business using their username and password as one factor. but needs a second factor of authentication.
|
||||
|
||||
Hybrid Windows Hello for Business deployments can use Azure’s Multifactor Authentication service or they can use multifactor authentication provides by Windows Server 2016 Active Directory Federation Services, which includes an adapter model that enables third parties to integrate their multifactor authentication into AD FS.
|
||||
|
||||
### Section Review
|
||||
> [!div class="checklist"]
|
||||
> * Azure MFA Service
|
||||
> * Windows Server 2016 AD FS and Azure
|
||||
> * Windows Server 2016 AD FS and third party MFA Adapter
|
||||
|
||||
<br>
|
||||
|
||||
## Device Registration ##
|
||||
Organizations wanting to deploy hybrid certificate trust need thier domain joined devices to register to Azure Active Directory. Just as a computer has an identity in Active Directory, that same computer has an identity in the cloud. This ensures that only approved computers are used with that Azure Active Directory. Each computer registers its identity in Azure Active Directory.
|
||||
|
||||
Hybrid certificate trust deployments need the device write back feature. Authentication to the Windows Server 2016 Active Directory Federation Services needs both the user and the computer to authenticate. Typically the users are synchronized, but not devices. This prevents AD FS from authenticating the computer and results in Windows Hello for Business certificate enrollment failures. For this reason, Windows Hello for Business deployments need device writeback, which is an Azure Active Directory premium feature.
|
||||
|
||||
### Section Checklist ###
|
||||
> [!div class="checklist"]
|
||||
> * Azure Active Directory Device writeback
|
||||
> * Azure Active Directory Premium subscription
|
||||
|
||||
<br>
|
||||
|
||||
### Next Steps ###
|
||||
Follow the Windows Hello for Business hybrid certificate trust deployment guide. For proof-of-concepts, labs, and new installations, choose the **New Installation Basline**.
|
||||
|
||||
If your environment is already federated, but does not include Azure device registration, choose **Configure Azure Device Registration**.
|
||||
|
||||
If your environment is already federated and supports Azure device registration, choose **Configure Windows Hello for Business settings**.
|
||||
|
||||
> [!div class="op_single_selector"]
|
||||
> - [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
> - [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
> - [Configure Windows Hello for Business settings](hello-hybrid-cert-whfb-settings.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. Prerequistes (*You are here*)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. [Configure Windows Hello for Business settings](hello-hybrid-cert-whfb-settings.md)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
@ -0,0 +1,51 @@
|
||||
---
|
||||
title: Hybrid Certificate Trust Deployment (Windows Hello for Business)
|
||||
description: Hybrid Certificate Trust Deployment Overview
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB, hybrid, cert-trust
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
localizationpriority: high
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Hybrid Azure AD joined Certificate Trust Deployment
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
|
||||
Windows Hello for Business replaces username and password sign-in to Windows with strong user authentication based on asymmetric key pair. The following deployment guide provides the information needed to successfully deploy Windows Hello for Business in a hybrid certificate trust scenario.
|
||||
|
||||
It is recommended that you review the Windows Hello for Business planning guide prior to using the deployment guide. The planning guide helps you make decisions by explaining the available options with each aspect of the deployment and explains the potential outcomes based on each of these decisions. You can review the [planning guide](https://docs.microsoft.com/en-us/windows/access-protection/hello-for-business/hello-planning-guide) and download the [planning worksheet](https://go.microsoft.com/fwlink/?linkid=852514).
|
||||
|
||||
This deployment guide provides guidance for new deployments and customers who are already federated with Office 365. These two scenarios provide a baseline from which you can begin your deployment.
|
||||
|
||||
## New Deployment Baseline ##
|
||||
The new deployment baseline helps organizations who are moving to Azure and Office 365 to include Windows Hello for Business as part of their deployments. This baseline is good for organizations who are looking to deploy proof of concepts as well as IT professionals who want to familiarize themselves Windows Hello for Business by deploying a lab environment.
|
||||
|
||||
This baseline provides detailed procedures to move your environment from an on-premises only environment to a hybrid environment using Windows Hello for Business to authenticate to Azure Active Directory and to your on-premises Active Directory using a single Windows sign-in.
|
||||
|
||||
## Federated Baseline ##
|
||||
The federated baseline helps organizations that have completed their federation with Azure Active Directory and Office 365 and enables them to introduce Windows Hello for Business into their hybrid environment. This baseline exclusively focuses on the procedures needed to add Azure Device Registration and Windows Hello for Business to an existing hybrid deployment.
|
||||
|
||||
Regardless of the baseline you choose, you’re next step is to familiarize yourself with the prerequisites needed for the deployment. Many of the prerequisites will be new for organizations and individuals pursuing the new deployment baseline. Organizations and individuals starting from the federated baseline will likely be familiar with most of the prerequisites, but should validate they are using the proper versions that include the latest updates.
|
||||
|
||||
> [!div class="nextstepaction"]
|
||||
> [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. Overview (*You are here*)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. [Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. [Configure Windows Hello for Business settings](hello-hybrid-cert-whfb-settings.md)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
@ -0,0 +1,75 @@
|
||||
---
|
||||
title: Hybrid Windows Hello for Business Provisioning (Windows Hello for Business)
|
||||
description: Provisioning for Hybrid Windows Hello for Business Deployments
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB, hybrid, certificate-trust
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
localizationpriority: high
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Hybrid Windows Hello for Business Provisioning
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
## Provisioning
|
||||
The Windows Hello for Business provisioning begins immediately after the user has signed in, after the user profile is loaded, but before the user receives their desktop. Windows only launches the provisioning experience if all the prerequisite checks pass. You can determine the status of the prerequisite checks by viewing the **User Device Registration** in the **Event Viewer** under **Applications and Services Logs\Microsoft\Windows**.
|
||||
|
||||

|
||||
|
||||
The first thing to validate is the computer has processed device registration. You can view this from the User device registration logs where the check **Device is AAD joined (AADJ or DJ++): Yes** appears. Additionally, you can validate this using the **dsregcmd /status** command from a console prompt where the value for **EnterpriseJoined** reads **Yes**.
|
||||
|
||||

|
||||
|
||||
|
||||
Windows Hello for Business provisioning begins with a full screen page with the title **Setup a PIN** and button with the same name. The user clicks **Setup a PIN**.
|
||||
|
||||

|
||||
|
||||
The provisioning flow proceeds to the Multi-Factor authentication portion of the enrollment. Provisioning informs the user that it is actively attempting to contact the user through their configured form of MFA. The provisioning process does not proceed until authentication succeeds, fails or times out. A failed or timeout MFA results in an error and asks the user to retry.
|
||||
|
||||

|
||||
|
||||
After a successful MFA, the provisioning flow asks the user to create and validate a PIN. This PIN must observe any PIN complexity requirements that you deployed to the environment.
|
||||
|
||||
<createaPin.png>
|
||||
|
||||
The provisioning flow has all the information it needs to complete the Windows Hello for Business enrollment.
|
||||
* A successful single factor authentication (username and password at sign-in)
|
||||
* A device that has successfully completed device registration
|
||||
* A fresh, successful multi-factor authentication
|
||||
* A validated PIN that meets the PIN complexity requirements
|
||||
|
||||
The remainder of the provisioning includes Windows Hello for Business requesting an asymmetric key pair for the user, preferably from the TPM (or required if explicitly set through policy). Once the key pair is acquired, Windows communicates with Azure Active Directory to register the public key. AAD Connect syncrhonizes the user's key to the on-prem Active Directory.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> The minimum time needed to syncrhonize the user's public key from Azure Active Directory to the on-premises Active Directory is 30 minutes. This synchronization latency delays the certificate enrollment for the user. After the user's public key has synchronized to Active Directory, the user's certificate enrolls automatically as long as the user's session is active (actively working or locked, but still signed-in). Also, the Action Center notifies the user thier PIN is ready for use.
|
||||
|
||||
> [!NOTE]
|
||||
> Microsoft is actively investigating ways to reduce the syncrhonization latency and delays in certificate enrollment with the goal to make certificate enrollment occur real-time.
|
||||
|
||||
After a successful key registration, Windows creates a certificate request using the same key pair to request a certificate. Windows send the certificate request to the AD FS server for certificate enrollment.
|
||||
|
||||
The AD FS registration authority verifies the key used in the certificate request matches the key that was previously registered. On a successful match, the AD FS registration authority signs the certificate request using its enrollment agent certificate and sends it to the certificate authority.
|
||||
|
||||
The certificate authority validates the certificate was signed by the registration authority. On successful validation of the signature, it issues a certificate based on the request and returns the certificate to the AD FS registration authority. The registration authority returns the certificate to Windows where it then installs the certificate in the current user’s certificate store. Once this process completes, the Windows Hello for Business provisioning workflow informs the user they can use their PIN to sign-in through the Windows Action Center.
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. [Configure Windows Hello for Business policy settings](hello-hybrid-cert-whfb-settings-policy.md)
|
||||
6. Sign-in and Provision(*You are here*)
|
||||
|
@ -0,0 +1,81 @@
|
||||
---
|
||||
title: Configuring Hybrid Windows Hello for Business - Active Directory (AD)
|
||||
description: Discussing the configuration of Active Directory (AD) in a Hybrid deployment of Windows Hello for Business
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB, ad
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
localizationpriority: high
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Configuring Windows Hello for Business: Active Directory
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
>[!div class="step-by-step"]
|
||||
[< Configure Windows Hello for Business](hello-hybrid-cert-whfb-settings.md)
|
||||
[Configure Azure AD Connect >](hello-hybrid-cert-whfb-settings-dir-sync.md)
|
||||
|
||||
The key synchronization process for the hybrid deployment of Windows Hello for Business needs the Windows Server 2016 Active Directory schema.
|
||||
|
||||
>[!IMPORTANT]
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
### Creating Security Groups
|
||||
|
||||
Windows Hello for Business uses several security groups to simplify the deployment and managment.
|
||||
|
||||
> [!Important]
|
||||
> If your environment has one or more Windows Server 2016 domain controllers in the domain to which you are deploying Windows Hello for Business, then skip the **Create the KeyCredentials Admins Security Group**. Domains that include Windows Server 2016 domain controllers use the KeyAdmins group, which is created during the installation of the first Windows Server 2016 domain controller.
|
||||
|
||||
#### Create the KeyCredential Admins Security Group
|
||||
|
||||
Azure Active Directory Connect synchronizes the public key on the user object created during provisioning. You assign write and read permission to this group to the Active Directory attribute to ensure the Azure AD Connect service can add and remove keys as part of its normal workflow.
|
||||
|
||||
Sign-in a domain controller or management workstation with *Domain Admin* equivalent credentials.
|
||||
|
||||
1. Open **Active Directory Users and Computers**.
|
||||
2. Click **View** and click **Advance Features**.
|
||||
3. Expand the domain node from the navigation pane.
|
||||
4. Right-click the **Users** container. Click **New**. Click **Group**.
|
||||
5. Type **KeyCredential Admins** in the **Group Name** text box.
|
||||
6. Click **OK**.
|
||||
|
||||
#### Create the Windows Hello for Business Users Security Group
|
||||
|
||||
The Windows Hello for Business Users group is used to make it easy to deploy Windows Hello for Business in phases. You assign Group Policy and Certificate template permissions to this group to simplify the deployment by simply adding the users to the group. This provides users with the proper permissions to provision Windows Hello for Business and to enroll in the Windows Hello for Business authentication certificate.
|
||||
|
||||
Sign-in a domain controller or management workstation with *Domain Admin* equivalent credentials.
|
||||
|
||||
1. Open **Active Directory Users and Computers**.
|
||||
2. Click **View** and click **Advanced Features**.
|
||||
3. Expand the domain node from the navigation pane.
|
||||
4. Right-click the **Users** container. Click **New**. Click **Group**.
|
||||
5. Type **Windows Hello for Business Users** in the **Group Name** text box.
|
||||
6. Click **OK**.
|
||||
|
||||
### Section Review
|
||||
|
||||
> [!div class="checklist"]
|
||||
> * Create the KeyCredential Admins Security group (optional)
|
||||
> * Create the Windows Hello for Business Users group
|
||||
|
||||
>[!div class="step-by-step"]
|
||||
[< Configure Windows Hello for Business](hello-hybrid-cert-whfb-settings.md)
|
||||
[Configure Azure AD Connect >](hello-hybrid-cert-whfb-settings-dir-sync.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. Configure Windows Hello for Business settings: Active Directory (*You are here*)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
@ -0,0 +1,89 @@
|
||||
---
|
||||
title: Configuring Hybrid Windows Hello for Business - Active Directory Federation Services (ADFS)
|
||||
description: Discussing the configuration of Active Directory Federation Services (ADFS) in a Hybrid deployment of Windows Hello for Business
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB, adfs
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
localizationpriority: high
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Configure Windows Hello for Business: Active Directory Federation Services
|
||||
|
||||
**Applies to**
|
||||
- Windows10
|
||||
|
||||
## Federation Services
|
||||
|
||||
>[!IMPORTANT]
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
>[!div class="step-by-step"]
|
||||
[< Configure PKI >](hello-hybrid-cert-whfb-settings-pki.md)
|
||||
[Configure policy settings >](hello-hybrid-cert-whfb-settings-policy.md)
|
||||
|
||||
|
||||
The Windows Server 2016 Active Directory Fedeartion Server Certificate Registration Authority (AD FS RA) enrolls for an enrollment agent certificate. Once the registration authority verifies the certificate request, it signs the certificate request using its enrollment agent certificate and sends it to the certificate authority.
|
||||
|
||||
The Windows Hello for Business Authentication certificate template is configured to only issue certificates to certificate requests that have been signed with an enrollment agent certificate.
|
||||
|
||||
### Configure the Registration Authority
|
||||
|
||||
Sign-in the AD FS server with *Domain Admin* equivalent credentials.
|
||||
|
||||
1. Open a **Windows PowerShell** prompt.
|
||||
2. Type the following command
|
||||
|
||||
```PowerShell
|
||||
Set-AdfsCertificateAuthority -EnrollmentAgent -EnrollmentAgentCertificateTemplate WHFBEnrollmentAgent -WindowsHelloCertificateTemplate WHFBAuthentication
|
||||
```
|
||||
|
||||
|
||||
The `Set-AdfsCertificateAuthority` cmdlet should show the following warning:
|
||||
>WARNING: PS0343: Issuing Windows Hello certificates requires enabling a permitted strong authentication provider, but no usable providers are currently configured. These authentication providers are not supported for Windows Hello certificates: CertificateAuthentication,MicrosoftPassportAuthentication. Windows Hello certificates will not be issued until a permitted strong authentication provider is configured.
|
||||
|
||||
This warning indicates that you have not configured multi-factor authentication in AD FS and until it is configured, the AD FS server will not issue Windows Hello certificates. Windows 10, version 1703 clients check this configuration during prerequisite checks. If detected, the prerequisite check will not succeed and the user will not provision Windows Hello for Business on sign-in.
|
||||
|
||||
>[!NOTE]
|
||||
> If you gave your Windows Hello for Business Enrollment Agent and Windows Hello for Business Authentication certificate templates different names, then replace **WHFBEnrollmentAgent** and WHFBAuthentication in the above command with the name of your certificate templates. It's important that you use the template name rather than the template display name. You can view the template name on the **General** tab of the certificate template using the **Certificate Template** management console (certtmpl.msc). Or, you can view the template name using the **Get-CATemplate** ADCS Administration Windows PowerShell cmdlet on a Windows Server 2012 or later certificate authority.
|
||||
|
||||
|
||||
### Group Memberships for the AD FS Service Account
|
||||
|
||||
The Windows Hello for Business group provides the AD FS service with the permissions needed to enroll a Windows Hello for Business authentication certificate on behalf of the provisioning user.
|
||||
|
||||
Sign-in a domain controller or management workstation with _Domain Admin_ equivalent credentials.
|
||||
|
||||
1. Open **Active Directory Users and Computers**.
|
||||
2. Click the **Users** container in the navigation pane.
|
||||
3. Right-click **Windows Hello for Business Users** group
|
||||
4. Click the **Members** tab and click **Add**
|
||||
5. In the **Enter the object names to select** text box, type **adfssvc**. Click **OK**.
|
||||
6. Click **OK** to return to **Active Directory Users and Computers**.
|
||||
7. Restart the AD FS server.
|
||||
|
||||
### Section Review
|
||||
> [!div class="checklist"]
|
||||
> * Configure the registration authority
|
||||
> * Update group memberships for the AD FS service account
|
||||
|
||||
|
||||
>[!div class="step-by-step"]
|
||||
[< Configure PKI >](hello-hybrid-cert-whfb-settings-pki.md)
|
||||
[Configure policy settings >](hello-hybrid-cert-whfb-settings-policy.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. Configure Windows Hello for Business settings: AD FS (*You are here*)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
||||
|
@ -0,0 +1,86 @@
|
||||
---
|
||||
title: Configuring Hybrid Windows Hello for Business - Directory Synchronization
|
||||
description: Discussing Directory Synchronization in a Hybrid deployment of Windows Hello for Business
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB, dirsync, connect
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
localizationpriority: high
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Configure Hybrid Windows Hello for Business: Directory Synchronization
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
>[!div class="step-by-step"]
|
||||
[< Configure Active Directory](hello-hybrid-cert-whfb-settings-ad.md)
|
||||
[Configure PKI >](hello-hybrid-cert-whfb-settings-pki.md)
|
||||
|
||||
## Directory Syncrhonization
|
||||
|
||||
>[!IMPORTANT]
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
In hybrid deployments, users register the public portion of their Windows Hello for Business crednetial with Azure. Azure AD Connect syncrhonizes the Windows Hello for Business public key to Active Directory.
|
||||
|
||||
The key-trust model needs Windows Server 2016 domain controllers, which configures the key registration permissions automatically; however, the certificate-trust model does not and requires you to add the permissions manually.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> If you already have a Windows Server 2016 domain controller in your domain, you can skip **Configure Permissions for Key Synchronization**.
|
||||
|
||||
### Configure Permissions for Key Syncrhonization
|
||||
|
||||
Sign-in a domain controller or management workstations with *Domain Admin* equivalent credentials.
|
||||
|
||||
1. Open **Active Directory Users and Computers**.
|
||||
2. Right-click your domain name from the navigation pane and click **Properties**.
|
||||
3. Click **Security** (if the Security tab is missing, turn on Advanced Features from the View menu).
|
||||
4. Click **Advanced**. Click **Add**. Click **Select a principal**.
|
||||
5. The **Select User, Computer, Service Account, or Group** dialog box appears. In the **Enter the object name to select** text box, type **KeyCredential Admins**. Click **OK**.
|
||||
6. In the **Applies to** list box, select **Descendant User objects**.
|
||||
7. Using the scroll bar, scroll to the bottom of the page and click **Clear all**.
|
||||
8. In the **Properties** section, select **Read msDS-KeyCredentialLink** and **Write msDS-KeyCrendentialLink**.
|
||||
9. Click **OK** three times to complete the task.
|
||||
|
||||
|
||||
### Group Memberships for the Azure AD Connect Service Account
|
||||
|
||||
The KeyAdmins or KeyCredential Admins global group provides the Azure AD Connect service with the permissions needed to read and write the public key to Active Directory.
|
||||
|
||||
Sign-in a domain controller or management workstation with _Domain Admin_ equivalent credentials.
|
||||
|
||||
1. Open **Active Directory Users and Computers**.
|
||||
2. Click the **Users** container in the navigation pane.
|
||||
>[!IMPORTANT]
|
||||
> If you already have a Windows Server 2016 domain controller in your domain, use the Keyadmins group in the next step, otherwise use the KeyCredential admins group you previously created.
|
||||
|
||||
3. Right-click either the **KeyAdmins** or **KeyCredential Admins** in the details pane and click **Properties**.
|
||||
4. Click the **Members** tab and click **Add**
|
||||
5. In the **Enter the object names to select** text box, type the name of the Azure AD Connect service account. Click **OK**.
|
||||
6. Click **OK** to return to **Active Directory Users and Computers**.
|
||||
|
||||
### Section Review
|
||||
|
||||
> [!div class="checklist"]
|
||||
> * Configure Permissions for Key Synchronization
|
||||
> * Configure group membership for Azure AD Connect
|
||||
|
||||
>[!div class="step-by-step"]
|
||||
[< Configure Active Directory](hello-hybrid-cert-whfb-settings-ad.md)
|
||||
[Configure PKI >](hello-hybrid-cert-whfb-settings-pki.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. Configure Windows Hello for Business settings: Directory Syncrhonization (*You are here*)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
@ -0,0 +1,199 @@
|
||||
---
|
||||
title: Configuring Hybrid Windows Hello for Business - Public Key Infrastructure (PKI)
|
||||
description: Discussing the configuration of the Public Key Infrastructure (PKI) in a Hybrid deployment of Windows Hello for Business
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB, PKI
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
localizationpriority: high
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
|
||||
# Configure Hybrid Windows Hello for Business: Public Key Infrastructure
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[< Configure Azure AD Connect](hello-hybrid-cert-whfb-settings-dir-sync.md)
|
||||
[Configure AD FS >](hello-hybrid-cert-whfb-settings-adfs.md)
|
||||
|
||||
>[!IMPORTANT]
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
Windows Hello for Business deployments rely on certificates. Hybrid deployments uses publicly issued server authentication certifcates to validate the name of the server to which they are connecting and to encyrpt the data that flows them and the client computer.
|
||||
|
||||
All deployments use enterprise issed certificates for domain controllers as a root of trust. Hybrid certificate trust deployments issue users sign-in certificate that enables them to authenticate using Windows Hello for Business credentials to non-Windows Server 2016 domain controllers. Additionally, hybrid certificate trust deployments issue certificate to registration authorites to provide defenese-in-depth security for issueing user authentication certificates.
|
||||
|
||||
## Certifcate Templates
|
||||
|
||||
This section has you configure certificate templates on your Windows Server 2012 or later issuing certificate authtority.
|
||||
|
||||
### Domain Controller certificate template
|
||||
|
||||
Clients need to trust domain controllers and the best way to do this is to ensure each domain controller has a Kerberos Authentication certificate. Installing a certificate on the domain controller enables the Key Distribution Center (KDC) to prove its identity to other members of the domain. This provides clients a root of trust external to the domain - namely the enterprise certificate authority.
|
||||
|
||||
Domain controllers automatically request a domain controller certificate (if published) when they discover an enterprise certificate authority is added to Active Directory. However, certificates based on the *Domain Controller* and *Domain Controller Authentication* certificate templates do not include the **KDC Authentication** object identifier (OID), which was later added to the Kerberos RFC. Therefore, domain controllers need to request a certificate based on the Kerberos Authentication certificate template.
|
||||
|
||||
By default, the Active Directory Certificate Authority provides and publishes the Kerberos Authentication certificate template. However, the cryptography configuration included in the provided template is based on older and less performant cryptography APIs. To ensure domain controllers request the proper certificate with the best available cryptography, use the **Kerberos Authentication** certificate template a baseline to create an updated domain controller certificate template.
|
||||
|
||||
#### Create a Domain Controller Authentication (Kerberos) Certificate Template
|
||||
|
||||
Sign-in a certificate authority or management workstations with _Domain Admin_ equivalent credentials.
|
||||
|
||||
1. Open the **Certificate Authority** management console.
|
||||
2. Right-click **Certificate Templates** and click **Manage**.
|
||||
3. In the **Certificate Template Console**, right-click the **Kerberos Authentication** template in the details pane and click **Duplicate Template**.
|
||||
4. On the **Compatibility** tab, clear the **Show resulting changes** check box. Select **Windows Server 2012** or **Windows Server 2012 R2** from the **Certification Authority** list. Select **Windows Server 2012** or **Windows Server 2012 R2** from the **Certification Recipient** list.
|
||||
5. On the **General** tab, type **Domain Controller Authentication (Kerberos)** in Template display name. Adjust the validity and renewal period to meet your enterprise's needs.
|
||||
**Note**If you use different template names, you'll need to remember and substitute these names in different portions of the lab.
|
||||
6. On the **Subject** tab, select the **Build from this Active Directory information** button if it is not already selected. Select **None** from the **Subject name format** list. Select **DNS name** from the **Include this information in alternate subject** list. Clear all other items.
|
||||
7. On the **Cryptography** tab, select **Key Storage Provider** from the **Provider Category** list. Select **RSA** from the **Algorithm name** list. Type **2048** in the **Minimum key size** text box. Select **SHA256** from the **Request hash** list. Click **OK**.
|
||||
8. Close the console.
|
||||
|
||||
#### Configure Certificate Suspeding for the Domain Controller Authentication (Kerberos) Certificate Template
|
||||
|
||||
Many domain controllers may have an existing domain controller certificate. The Active Directory Certificate Services provides a default certificate template for domain controllers--the domain controller certificate template. Later releases provided a new certificate template--the domain controller authentication certificate template. These certificate templates were provided prior to update of the Kerberos specification that stated Key Distribution Centers (KDCs) performing certificate authentication needed to include the **KDC Authentication** extension.
|
||||
|
||||
The Kerberos Authentication certificate template is the most current certificate template designated for domain controllers and should be the one you deploy to all your domain controllers (2008 or later).
|
||||
|
||||
The autoenrollment feature in Windows enables you to effortlessly replace these domain controller certificates. You can use the following configuration to replace older domain controller certificates with a new certificate using the Kerberos Authentication certificate template.
|
||||
|
||||
Sign-in a certificate authority or management workstations with _Enterprise Admin_ equivalent credentials.
|
||||
|
||||
1. Open the **Certificate Authority** management console.
|
||||
2. Right-click **Certificate Templates** and click **Manage**.
|
||||
3. In the **Certificate Template Console**, right-click the **Domain Controller Authentication (Kerberos)** (or the name of the certificate template you created in the previous section) template in the details pane and click **Properties**.
|
||||
4. Click the **Superseded Templates** tab. Click **Add**.
|
||||
5. From the **Add Superseded Template** dialog, select the **Domain Controller** certificate template and click **OK**. Click **Add**.
|
||||
6. From the **Add Superseded Template** dialog, select the **Domain Controller Authentication** certificate template and click **OK**.
|
||||
7. From the **Add Superseded Template dialog**, select the **Kerberos Authentication** certificate template and click **OK**.
|
||||
8. Add any other enterprise certificate templates that were previously configured for domain controllers to the **Superseded Templates** tab.
|
||||
9. Click **OK** and close the **Certificate Templates** console.
|
||||
|
||||
The certificate template is configured to supersede all the certificate templates provided in the certificate templates superseded templates list. However, the certificate template and the superseding of certificate templates is not active until you publish the certificate template to one or more certificate authorities.
|
||||
|
||||
### Enrollment Agent certificate template
|
||||
|
||||
Active Directory Federation Server used for Windows Hello for Business certificate enrollment performs its own certificate lifecycle management. Once the registration authority is configured with the proper certificate template, the AD FS server attempts to enroll the certificate on the first certificate request or when the service first starts.
|
||||
|
||||
Approximately 60 days prior to enrollment agent certificate's expiration, the AD FS service attempts to renew the certificate until it is successful. If the certificate fails to renew, and the certificate expires, the AD FS server will request a new enrollment agent certificate. You can view the AD FS event logs to determine the status of the enrollment agent certificate.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Follow the procedures below based on the AD FS service account used in your environment.
|
||||
|
||||
#### Creating an Enrollment Agent certificate for Group Managed Service Accounts
|
||||
|
||||
Sign-in a certificate authority or management workstations with _Domain Admin_ equivalent credentials.
|
||||
|
||||
1. Open the **Certificate Authority Management** console.
|
||||
2. Right-click **Certificate Templates** and click **Manage**.
|
||||
3. In the **Certificate Template Console**, right click on the **Exchange Enrollment Agent (Offline request)** template details pane and click **Duplicate Template**.
|
||||
4. On the **Compatibility** tab, clear the **Show resulting changes** check box. Select **Windows Server 2012** or **Windows Server 2012 R2** from the **Certification Authority** list. Select **Windows Server 2012** or **Windows Server 2012 R2** from the **Certification Recipient** list.
|
||||
5. On the **General** tab, type **WHFB Enrollment Agent** in **Template display name**. Adjust the validity and renewal period to meet your enterprise's needs.
|
||||
6. On the **Subject** tab, select the **Supply in the request** button if it is not already selected.
|
||||
**Note:** The preceding step is very important. Group Managed Service Accounts (GMSA) do not support the Build from this Active Directory information option and will result in the AD FS server failing to enroll the enrollment agent certificate. You must configure the certificate template with Supply in the request to ensure that AD FS servers can perform the automatic enrollment and renewal of the enrollment agent certificate.
|
||||
|
||||
7. On the **Cryptography** tab, select **Key Storage Provider** from the **Provider Category** list. Select **RSA** from the **Algorithm name** list. Type **2048** in the **Minimum key size** text box. Select **SHA256** from the **Request hash** list.
|
||||
8. On the **Security** tab, click **Add**.
|
||||
9. Click **Object Types**. Select the **Service Accounts** check box and click **OK**.
|
||||
10. Type **adfssvc** in the **Enter the object names to select** text box and click **OK**.
|
||||
11. Click the **adfssvc** from the **Group or users names** list. In the **Permissions for adfssvc** section, In the **Permissions for adfssvc** section, select the **Allow** check box for the **Enroll** permission. Excluding the **adfssvc** user, clear the **Allow** check box for the **Enroll** and **Autoenroll** permissions for all other items in the **Group or users names** list if the check boxes are not already cleared. Click **OK**.
|
||||
12. Close the console.
|
||||
|
||||
#### Creating an Enrollment Agent certificate for typical Service Acconts
|
||||
|
||||
Sign-in a certificate authority or management workstations with *Domain Admin* equivalent credentials.
|
||||
|
||||
1. Open the **Certificate Authority** management console.
|
||||
2. Right-click **Certificate Templates** and click **Manage**.
|
||||
3. In the **Certificate Template** console, right-click the **Exchange Enrollment Agent** template in the details pane and click **Duplicate Template**.
|
||||
4. On the **Compatibility** tab, clear the **Show resulting changes** check box. Select **Windows Server 2012** or **Windows Server 2012 R2** from the **Certification Authority** list. Select **Windows Server 2012** or **Windows Server 2012 R2** from the **Certification Recipient** list.
|
||||
5. On the **General** tab, type **WHFB Enrollment Agent** in **Template display name**. Adjust the validity and renewal period to meet your enterprise's needs.
|
||||
6. On the **Subject** tab, select the **Build from this Active Directory information** button if it is not already selected. Select **Fully distinguished name** from the **Subject name format** list if **Fully distinguished name** is not already selected. Select the **User Principal Name (UPN)** check box under **Include this information in alternative subject name**.
|
||||
7. On the **Cryptography** tab, select **Key Storage Provider** from the **Provider Category** list. Select **RSA** from the **Algorithm name** list. Type **2048** in the **Minimum key size** text box. Select **SHA256** from the **Request hash** list.
|
||||
8. On the **Security** tab, click **Add**. Type **adfssvc** in the **Enter the object names to select text box** and click **OK**.
|
||||
9. Click the **adfssvc** from the **Group or users names** list. In the **Permissions for adfssvc** section, select the **Allow** check box for the **Enroll** permission. Excluding the **adfssvc** user, clear the **Allow** check boxes for the **Enroll** and **Autoenroll** permissions for all other items in the **Group or users names** list if the check boxes are not already cleared. Click **OK**.
|
||||
10. Close the console.
|
||||
|
||||
### Creating Windows Hello for Business authentication certificate template
|
||||
|
||||
During Windows Hello for Business provisioning, the Windows 10, version 1703 client requests an authentication certificate from the Active Directory Federation Service, which requests the authentication certificate on behalf of the user. This task configures the Windows Hello for Business authentication certificate template. You use the name of the certificate template when configuring.
|
||||
|
||||
Sign-in a certificate authority or management workstations with _Domain Admin equivalent_ credentials.
|
||||
|
||||
1. Open the **Certificate Authority** management console.
|
||||
2. Right-click **Certificate Templates** and click **Manage**.
|
||||
3. Right-click the **Smartcard Logon** template and choose **Duplicate Template**.
|
||||
4. On the **Compatibility** tab, clear the **Show resulting changes** check box. Select **Windows Server 2012** or **Windows Server 2012 R2** from the **Certification Authority** list. Select **Windows Server 2012** or **Windows Server 2012 R2** from the **Certification Recipient** list.
|
||||
5. On the **General** tab, type **WHFB Authentication** in **Template display name**. Adjust the validity and renewal period to meet your enterprise's needs.
|
||||
**Note:** If you use different template names, you'll need to remember and substitute these names in different portions of the deployment.
|
||||
6. On the **Cryptography** tab, select **Key Storage Provider** from the **Provider Category** list. Select **RSA** from the **Algorithm name** list. Type **2048** in the **Minimum key size** text box. Select **SHA256** from the **Request hash** list.
|
||||
7. On the **Extensions** tab, verify the **Application Policies** extension includes **Smart Card Logon**.
|
||||
8. On the **Issuance Requirements** tab, select the T**his number of authorized signatures** check box. Type **1** in the text box.
|
||||
* Select **Application policy** from the **Policy type required in signature**. Select **Certificate Request Agent** from in the **Application policy** list. Select the **Valid existing certificate** option.
|
||||
9. On the **Subject** tab, select the **Build from this Active Directory information** button if it is not already selected. Select **Fully distinguished name** from the **Subject name format** list if **Fully distinguished name** is not already selected. Select the **User Principal Name (UPN)** check box under **Include this information in alternative subject name**.
|
||||
10. On the **Request Handling** tab, select the **Renew with same key** check box.
|
||||
11. On the **Security** tab, click **Add**. Type **Window Hello for Business Users** in the **Enter the object names to select** text box and click **OK**.
|
||||
12. Click the **Windows Hello for Business Users** from the **Group or users names** list. In the **Permissions for Windows Hello for Business Users** section, select the **Allow** check box for the **Enroll** permission. Excluding the **Windows Hello for Business Users** group, clear the **Allow** check box for the **Enroll** and **Autoenroll** permissions for all other entries in the **Group or users names** section if the check boxes are not already cleared. Click **OK**.
|
||||
13. If you previously issued Windows Hello for Business sign-in certificates using Configuration Manger and are switching to an AD FS registration authority, then on the **Superseded Templates** tab, add the previously used **Windows Hello for Business Authentication** template(s), so they will be superseded by this template for the users that have Enroll permission for this template.
|
||||
14. Click on the **Apply** to save changes and close the console.
|
||||
|
||||
#### Mark the template as the Windows Hello Sign-in template
|
||||
|
||||
Sign-in to an **AD FS Windows Server 2016** computer with _Enterprise Admin_ equivalent credentials.
|
||||
1. Open an elevated command prompt.
|
||||
2. Run `certutil -dsTemplate WHFBAuthentication msPKI-Private-Key-Flag +CTPRIVATEKEY_FLAG_HELLO_LOGON_KEY`
|
||||
|
||||
>[!NOTE]
|
||||
>If you gave your Windows Hello for Business Authentication certificate template a different name, then replace **WHFBAuthentication** in the above command with the name of your certificate template. It's important that you use the template name rather than the template display name. You can view the template name on the **General** tab of the certificate template using the Certificate Template management console (certtmpl.msc). Or, you can view the template name using the **Get-CATemplate** ADCS Administration Windows PowerShell cmdlet on our Windows Server 2012 or later certificate authority.
|
||||
Publish Templates
|
||||
|
||||
### Publish Certificate Templates to a Certificate Authority
|
||||
|
||||
The certificate authority may only issue certificates for certificate templates that are published to that certificate authority. If you have more than one certificate authority and you want that certificate authority to issue certificates based on a specific certificate template, then you must publish the certificate template to all certificate authorities that are expected to issue the certificate.
|
||||
|
||||
### Unpublish Superseded Certificate Templates
|
||||
|
||||
The certificate authority only issues certificates based on published certificate templates. For defense in depth security, it is a good practice to unpublish certificate templates that the certificate authority is not configured to issue. This includes the pre-published certificate template from the role installation and any superseded certificate templates.
|
||||
|
||||
The newly created domain controller authentication certificate template supersedes previous domain controller certificate templates. Therefore, you need to unpublish these certificate templates from all issuing certificate authorities.
|
||||
|
||||
Sign-in to the certificate authority or management workstation with _Enterprise Admin_ equivalent credentials.
|
||||
|
||||
1. Open the **Certificate Authority** management console.
|
||||
2. Expand the parent node from the navigation pane.
|
||||
3. Click **Certificate Templates** in the navigation pane.
|
||||
4. Right-click the **Domain Controller** certificate template in the content pane and select **Delete**. Click **Yes** on the **Disable certificate templates** window.
|
||||
5. Repeat step 4 for the **Domain Controller Authentication** and **Kerberos Authentication** certificate templates.
|
||||
|
||||
### Section Review
|
||||
> [!div class="checklist"]
|
||||
> * Domain Controller certificate template
|
||||
> * Configure superseded domain controller certificate templates
|
||||
> * Enrollment Agent certifcate template
|
||||
> * Windows Hello for Business Authentication certificate template
|
||||
> * Mark the certifcate template as Windows Hello for Business sign-in template
|
||||
> * Publish Certificate templates to certificate authorities
|
||||
> * Unpublish superseded certificate templates
|
||||
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[< Configure Azure AD Connect](hello-hybrid-cert-whfb-settings-dir-sync.md)
|
||||
[Configure AD FS >](hello-hybrid-cert-whfb-settings-adfs.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. Configure Windows Hello for Business settings: PKI (*You are here*)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
||||
|
@ -0,0 +1,204 @@
|
||||
---
|
||||
title: Configuring Hybrid Windows Hello for Business - Group Policy
|
||||
description: Discussing the configuration of Group Policy in a Hybrid deployment of Windows Hello for Business
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
localizationpriority: high
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Configure Hybrid Windows Hello for Business: Group Policy
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[< Configure AD FS](hello-hybrid-cert-whfb-settings-adfs.md)
|
||||
|
||||
|
||||
## Policy Configuration
|
||||
|
||||
>[!IMPORTANT]
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
You need a Windows 10, version 1703 workstation to run the Group Policy Management Console, which provides the latest Windows Hello for Business and PIN Complexity Group Policy settings. To run the Group Policy Management Console, you need to install the Remote Server Administration Tools for Windows 10. You can download these tools from the [Microsoft Download Center](https://www.microsoft.com/en-us/download/details.aspx?id=45520).
|
||||
Install the Remote Server Administration Tools for Windows 10 on a computer running Windows 10, version 1703.
|
||||
|
||||
Alternatively, you can create copy the .ADMX and .ADML files from a Windows 10 Creators Edition (1703) to their respective language folder on a Windows Server or you can create a Group Policy Central Store and copy them their respective language folder. See [How to create and manage the Central Store for Group Policy Administrative Templates in Windows](https://support.microsoft.com/help/3087759/how-to-create-and-manage-the-central-store-for-group-policy-administrative-templates-in-windows) for more information.
|
||||
|
||||
Domain controllers of Windows Hello for Business deployments need one Group Policy setting, which enables automatic certificate enrollment for the newly create domain controller authentication certificate. This policy setting ensures domain controllers (new and existing) autoamtically request and renew the correct domain controller certifcate.
|
||||
|
||||
Domain joined clients of hybrid certificate-based deployments of Windows Hello for Business needs three Group Policy settings:
|
||||
* Enable Windows Hello for Business
|
||||
* Use certificate for on-premises authentication
|
||||
* Enable automatic enrollment of certificates
|
||||
|
||||
### Configure Domain Controllers for Automatic Certificate Enrollment
|
||||
|
||||
Domain controllers automatically request a certificate from the *Domain Controller* certificate template. However, the domain controller is unaware of newer certificate templates or superseded configurations on certificate templates.
|
||||
|
||||
To continue automatic enrollment and renewal of domain controller certificates that understand newer certificate template and superseded certificate template configurations, create and configure a Group Policy object for automatic certificate enrollment and link the Group Policy object to the Domain Controllers OU.
|
||||
|
||||
#### Create a Domain Controller Automatic Certifiacte Enrollment Group Policy object
|
||||
|
||||
Sign-in a domain controller or management workstations with _Domain Admin_ equivalent credentials.
|
||||
|
||||
1. Start the **Group Policy Management Console** (gpmc.msc)
|
||||
2. Expand the domain and select the **Group Policy Object** node in the navigation pane.
|
||||
3. Right-click **Group Policy object** and select **New**
|
||||
4. Type *Domain Controller Auto Certificate Enrollment* in the name box and click **OK**.
|
||||
5. Right-click the **Domain Controller Auto Certificate Enrollment** Group Policy object and click **Edit**.
|
||||
6. In the navigation pane, expand **Policies** under **Computer Configuration**.
|
||||
7. Expand **Windows Settings**, **Security Settings**, and click **Public Key Policies**.
|
||||
8. In the details pane, right-click **Certificate Services Client <20> Auto-Enrollment** and select **Properties**.
|
||||
9. Select **Enabled** from the **Configuration Model** list.
|
||||
10. Select the **Renew expired certificates**, **update pending certificates**, and **remove revoked certificates** check box.
|
||||
11. Select the **Update certificates that use certificate templates** check box.
|
||||
12. Click **OK**. Close the **Group Policy Management Editor**.
|
||||
|
||||
#### Deploy the Domain Controller Auto Certificate Enrollment Group Policy Object
|
||||
|
||||
Sign-in a domain controller or management workstations with _Domain Admin_ equivalent credentials.
|
||||
|
||||
1. Start the **Group Policy Management Console** (gpmc.msc)
|
||||
2. In the navigation pane, expand the domain and expand the node that has your Active Directory domain name. Right-click the **Domain Controllers** organizational unit and click **Link an existing GPO<50>**
|
||||
3. In the **Select GPO** dialog box, select **Domain Controller Auto Certificate Enrollment** or the name of the domain controller certificate enrollment Group Policy object you previously created and click **OK**.
|
||||
|
||||
### Windows Hello for Business Group Policy
|
||||
|
||||
The Windows Hello for Business Group Policy object delivers the correct Group Policy settings to the user, which enables them to enroll and use Windows Hello for Business to authenticate to Azure and Active Directory
|
||||
|
||||
#### Enable Windows Hello for Business
|
||||
|
||||
The Enable Windows Hello for Business Group Policy setting is the configuration needed for Windows to determine if a user should be attempt to enroll for Windows Hello for Business. A user will only attempt enrollment if this policy setting is configured to enabled.
|
||||
|
||||
You can configure the Enable Windows Hello for Business Group Policy setting for computer or users. Deploying this policy setting to computers results in ALL users that sign-in that computer to attempt a Windows Hello for Business enrollment. Deploying this policy setting to a user results in only that user attempting a Windows Hello for Business enrollment. Additionally, you can deploy the policy setting to a group of users so only those users attempt a Windows Hello for Business enrollment. If both user and computer policy settings are deployed, the user policy setting has precedence.
|
||||
|
||||
#### Use certificate for on-premises authentication
|
||||
|
||||
The Use certificate for on-premises authentication Group Policy setting determines if the on-premises deployment uses the key-trust or certificate trust on-premises authentication model. You must configure this Group Policy setting to configure Windows to enroll for a Windows Hello for Business authentication certificate. If you do not configure this policy setting, Windows considers the deployment to use key-trust on-premises authentication, which requires a sufficient number of Windows Server 2016 domain controllers to handle the Windows Hello for Business key-trust authentication requests.
|
||||
|
||||
You can configure this Group Policy setting for computer or users. Deploying this policy setting to computers results in ALL users requesting a Windows Hello for Business authentication certificate. Deploying this policy setting to a user results in only that user requesting a Windows Hello for Business authentication certificate. Additionally, you can deploy the policy setting to a group of users so only those users request a Windows Hello for Business authentication certificate. If both user and computer policy settings are deployed, the user policy setting has precedence.
|
||||
|
||||
#### Enable automatic enrollment of certificates
|
||||
|
||||
Windows Hello for Business provisioning performs the initial enrollment of the Windows Hello for Business authentication certificate. This certificate expires based on the duration configured in the Windows Hello for Business authentication certificate template. The Windows 10, version 1703 certificate auto enrollment was updated to renew these certificates before they expire, which significantly reduces user authentication failures from expired user certificates.
|
||||
|
||||
The process requires no user interaction provided the user signs-in using Windows Hello for Business. The certificate is renewed in the background before it expires.
|
||||
|
||||
#### Create the Windows Hello for Business Group Policy object
|
||||
|
||||
The Group Policy object contains the policy settings needed to trigger Windows Hello for Business provisioning and to ensure Windows Hello for Business authentication certificates are automatically renewed.
|
||||
|
||||
Sign-in a domain controller or management workstations with _Domain Admin_ equivalent credentials.
|
||||
|
||||
1. Start the **Group Policy Management Console** (gpmc.msc)
|
||||
2. Expand the domain and select the **Group Policy Object** node in the navigation pane.
|
||||
3. Right-click **Group Policy object** and select **New**.
|
||||
4. Type *Enable Windows Hello for Business* in the name box and click **OK**.
|
||||
5. In the content pane, right-click the **Enable Windows Hello for Business** Group Policy object and click **Edit**.
|
||||
6. In the navigation pane, expand **Policies** under **User Configuration**.
|
||||
7. Expand **Administrative Templates > Windows Component**, and select **Windows Hello for Business**.
|
||||
8. In the content pane, double-click **Use Windows Hello for Business**. Click **Enable** and click **OK**.
|
||||
9. Double-click **Use certificate for on-premises authentication**. Click **Enable** and click **OK**. Close the **Group Policy Management Editor**.
|
||||
|
||||
#### Configure Automatic Certificate Enrollment
|
||||
|
||||
1. Start the **Group Policy Management Console** (gpmc.msc).
|
||||
2. Expand the domain and select the **Group Policy Object** node in the navigation pane.
|
||||
3. Right-click the **Enable Windows Hello for Business** Group Policy object and click **Edit**.
|
||||
4. In the navigation pane, expand **Policies** under **User Configuration**.
|
||||
5. Expand **Windows Settings > Security Settings**, and click **Public Key Policies**.
|
||||
6. In the details pane, right-click **Certificate Services Client <20> Auto-Enrollment** and select **Properties**.
|
||||
7. Select **Enabled** from the **Configuration Model** list.
|
||||
8. Select the **Renew expired certificates**, **update pending certificates**, and **remove revoked certificates** check box.
|
||||
9. Select the **Update certificates that use certificate templates** check box.
|
||||
10. Click **OK**. Close the **Group Policy Management Editor**.
|
||||
|
||||
#### Configure Security in the Windows Hello for Business Group Policy object
|
||||
|
||||
The best way to deploy the Windows Hello for Business Group Policy object is to use security group filtering. The enables you to easily manage the users that should receive Windows Hello for Business by simply adding them to a group. This enables you to deploy Windows Hello for Business in phases.
|
||||
1. Start the **Group Policy Management Console** (gpmc.msc)
|
||||
2. Expand the domain and select the **Group Policy Object** node in the navigation pane.
|
||||
3. Double-click the **Enable Windows Hello for Business** Group Policy object.
|
||||
4. In the **Security Filtering** section of the content pane, click **Add**. Type *Windows Hello for Business Users* or the name of the security group you previously created and click **OK**.
|
||||
5. Click the **Delegation** tab. Select **Authenticated Users** and click **Advanced**.
|
||||
6. In the **Group or User names** list, select **Authenticated Users**. In the **Permissions for Authenticated Users** list, clear the **Allow** check box for the **Apply Group Policy** permission. Click **OK**.
|
||||
|
||||
#### Deploy the Windows Hello for Business Group Policy object
|
||||
|
||||
The application of the Windows Hello for Business Group Policy object uses security group filtering. This enables you to link the Group Policy object at the domain, ensuring the Group Policy object is within scope to all users. However, the security group filtering ensures only the users included in the *Windows Hello for Business Users* global group receive and apply the Group Policy object, which results in the provisioning of Windows Hello for Business.
|
||||
1. Start the **Group Policy Management Console** (gpmc.msc)
|
||||
2. In the navigation pane, expand the domain and right-click the node that has your Active Directory domain name and click **Link an existing GPO<50>**
|
||||
3. In the **Select GPO** dialog box, select **Enable Windows Hello for Business** or the name of the Windows Hello for Business Group Policy object you previously created and click **OK**.
|
||||
|
||||
Just to reassure, linking the **Windows Hello for Business** Group Policy object to the domain ensures the Group Policy object is in scope for all domain users. However, not all users will have the policy settings applied to them. Only users who are members of the Windows Hello for Business group receive the policy settings. All others users ignore the Group Policy object.
|
||||
|
||||
## Other Related Group Policy settings
|
||||
|
||||
### Windows Hello for Business
|
||||
|
||||
There are other Windows Hello for Business policy settings you can configure to manage your Windows Hello for Business deployment. These policy settings are computer-based policy setting; so they are applicable to any user that sign-in from a computer with these policy settings.
|
||||
|
||||
#### Use a hardware security device
|
||||
|
||||
The default configuration for Windows Hello for Business is to prefer hardware protected credentials; however, not all computers are able to create hardware protected credentials. When Windows Hello for Business enrollment encounters a computer that cannot create a hardware protected credential, it will create a software-based credential.
|
||||
|
||||
You can enable and deploy the **Use a hardware security device** Group Policy Setting to force Windows Hello for Business to only create hardware protected credentials. Users that sign-in from a computer incapable of creating a hardware protected credential do not enroll for Windows Hello for Business.
|
||||
|
||||
Another policy setting becomes available when you enable the **Use a hardware security device** Group Policy setting that enables you to prevent Windows Hello for Business enrollment from using version 1.2 Trusted Platform Modules (TPM). Version 1.2 TPMs typically perform cryptographic operations slower than version 2.0 TPMs and are more unforgiven during anti-hammering and PIN lockout activities. Therefore, some organization may want not want slow sign-in performance and management overhead associated with version 1.2 TPMs. To prevent Windows Hello for Business from using version 1.2 TPMs, simply select the TPM 1.2 check box after you enable the Use a hardware security device Group Policy object.
|
||||
|
||||
#### Use biometrics
|
||||
|
||||
Windows Hello for Business provides a great user experience when combined with the use of biometrics. Rather than providing a PIN to sign-in, a user can use a fingerprint or facial recognition to sign-in to Windows, without sacrificing security.
|
||||
|
||||
The default Windows Hello for Business enables users to enroll and use biometrics. However, some organization may want more time before using biometrics and want to disable their use until they are ready. To not allow users to use biometrics, configure the **Use biometrics** Group Policy setting to disabled and apply it to your computers. The policy setting disabled all biometrics. Currently, Windows does not provide granular policy setting that enable you to disable specific modalities of biometrics such as allow facial recognition, but disallow fingerprint.
|
||||
|
||||
### PIN Complexity
|
||||
|
||||
PIN complexity is not specific to Windows Hello for Business. Windows 10 enables users to use PINs outside of Windows Hello for Business. PIN Complexity Group Policy settings apply to all uses of PINs, even when Windows Hello for Business is not deployed.
|
||||
|
||||
Windows 10 provides eight PIN Complexity Group Policy settings that give you granular control over PIN creation and management. You can deploy these policy settings to computers, where they affect all users creating PINs on that computer; or, you can deploy these settings to users, where they affect those users creating PINs regardless of the computer they use. If you deploy both computer and user PIN complexity Group Policy settings, the user policy settings have precedence over computer policy settings. Also, this conflict resolution is based on the last applied policy. Windows does not merge the policy settings automatically; however, you can deploy Group Policy to provide to accomplish a variety of configurations. The policy settings included are:
|
||||
* Require digits
|
||||
* Require lowercase letters
|
||||
* Maximum PIN length
|
||||
* Minimum PIN length
|
||||
* Expiration
|
||||
* History
|
||||
* Require special characters
|
||||
* Require uppercase letters
|
||||
|
||||
Starting with Windows 10, version 1703, the PIN complexity Group Policy settings have moved to remove misunderstanding that PIN complexity policy settings were exclusive to Windows Hello for Business. The new location of these Group Policy settings is under **Computer Configuration\Administrative Templates\System\PIN Complexity** of the Group Policy editor.
|
||||
|
||||
## Add users to the Windows Hello for Business Users group
|
||||
|
||||
Users must receive the Windows Hello for Business group policy settings and have the proper permission to enroll for the Wwindows Hello for Business Authentication certificate. You can provide users with these settings and permissions by adding the group used synchronize users to the Windows Hello for Business Users group. Users and groups who are not members of this group will not attempt to enroll for Windows Hello for Business.
|
||||
|
||||
### Section Review
|
||||
> [!div class="checklist"]
|
||||
> * Configure domain controllers for automatic certificate enrollment.
|
||||
> * Create Windows Hello for Business Group Policy object.
|
||||
> * Enable the Use Windows Hello for Business policy setting.
|
||||
> * Enable the Use certificate for on-premises authentication policy setting.
|
||||
> * Enable user automatic certificate enrollment.
|
||||
> * Add users or groups to the Windows Hello for Business group
|
||||
|
||||
|
||||
> [!div class="nextstepaction"]
|
||||
[Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. Configure Windows Hello for Business policy settings (*You are here*)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
@ -0,0 +1,50 @@
|
||||
---
|
||||
title: Configure Hybrid Windows Hello for Business Settings (Windows Hello for Business)
|
||||
description: Configuring Windows Hello for Business Settings in Hybrid deployment
|
||||
keywords: identity, PIN, biometric, Hello, passport, WHFB, hybrid, certificate-trust
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
localizationpriority: high
|
||||
author: mikestephens-MS
|
||||
ms.author: mstephen
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Configure Windows Hello for Business
|
||||
|
||||
**Applies to**
|
||||
- Windows 10
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[Configure Active Directory >](hello-hybrid-cert-whfb-settings-ad.md)
|
||||
|
||||
>[!IMPORTANT]
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
You're environment is federated and you are ready to configure your hybrid environment for Windows Hello for business using the certificate trust model.
|
||||
> [!IMPORTANT]
|
||||
> If your environment is not federated, review the [New Installation baseline](hello-hybrid-cert-new-install.md) section of this deployment document to learn how to federate your environment for your Windows Hello for Business deployment.
|
||||
|
||||
The configuration for Windows Hello for Business is grouped in four categories. These categories are:
|
||||
* [Active Directory](hello-hybrid-cert-whfb-settings-ad.md)
|
||||
* [Public Key Infrastructure](hello-hybrid-cert-whfb-settings-pki.md)
|
||||
* [Active Directory Federation Services](hello-hybrid-cert-whfb-settings-adfs.md)
|
||||
* [Group Policy](hello-hybrid-cert-whfb-settings-policy.md)
|
||||
|
||||
For the most efficent deployment, configure these technologies in order beginning with the Active Directory configuration
|
||||
|
||||
> [!div class="step-by-step"]
|
||||
[Configure Active Directory >](hello-hybrid-cert-whfb-settings-ad.md)
|
||||
|
||||
<br><br>
|
||||
|
||||
<hr>
|
||||
|
||||
## Follow the Windows Hello for Business hybrid certificate trust deployment guide
|
||||
1. [Overview](hello-hybrid-cert-trust.md)
|
||||
2. [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
3. [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
4. [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
5. Configure Windows Hello for Business settings (*You are here*)
|
||||
6. [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
@ -10,7 +10,7 @@ ms.pagetype: security, mobile
|
||||
author: DaniHalfin
|
||||
ms.localizationpriority: high
|
||||
ms.author: daniha
|
||||
ms.date: 07/07/2017
|
||||
ms.date: 09/08/2017
|
||||
---
|
||||
# Windows Hello for Business
|
||||
|
||||
@ -78,7 +78,7 @@ There are many deployment options from which to choose. Some of those options re
|
||||
Windows Hello for Business is two-factor authentication based the observed authentication factors of: something you have, something you know, and something part of you. Windows Hello for Business incorporates two of these factors: something you have (the user's private key protected by the device's security module) and something you know (your PIN). With the proper hardware, you can enhance the user experience by introducing biometrics. Using biometrics, you can replace the "something you know" authentication factor with the "something that is part of you" factor, with the assurances that users can fall back to the "something you know factor".
|
||||
|
||||
### Can I use PIN and biometrics to unlock my device?
|
||||
No. Windows Hello for Business provides two-factor authentication. However, we are investigating the ability to unlock the device with multiple factors.
|
||||
No. Windows Hello for Business provides two-factor authentication. However, we are investigating the ability to unlock the desktop with additional factors.
|
||||
|
||||
### What is the difference between Windows Hello and Windows Hello for Business
|
||||
Windows Hello represents the biometric framework provided in Windows 10. Windows Hello enables users to use biometrics to sign into their devices by securely storing their username and password and releasing it for authentication when the user successfully identifies themselves using biometrics. Windows Hello for Business uses asymmetric keys protected by the device's security module that requires a user gesture (PIN or biometrics) to authenticate.
|
||||
@ -86,6 +86,28 @@ Windows Hello represents the biometric framework provided in Windows 10. Window
|
||||
### I have extended Active Directory to Azure Active Directory. Can I use the on-prem deployment model?
|
||||
No. If your organization is federated or using online services, such as Office 365 or OneDrive, then you must use a hybrid deployment model. On-premises deployments are exclusive to organization who need more time before moving to the cloud and exclusively use Active Directory.
|
||||
|
||||
### Does Windows Hello for Business prevent the use of simple PINs?
|
||||
Yes. Our simple PIN algorithm looks for and disallows any PIN that has a constant delta from one digit to the next. This prevents repeating numbers, sequential numbers and simple patterns.
|
||||
So, for example:
|
||||
* 1111 has a constant delta of 0, so it is not allowed
|
||||
* 1234 has a constant delta of 1, so it is not allowed
|
||||
* 1357 has a constant delta of 2, so it is not allowed
|
||||
* 9630 has a constant delta of -3, so it is not allowed
|
||||
* 1231 does not have a constant delta, so it is okay
|
||||
* 1593 does not have a constant delta, so it is okay
|
||||
|
||||
This algorithm does not apply to alphanumeric PINs.
|
||||
|
||||
### How does PIN caching work with Windows Hello for Business?
|
||||
Windows Hello for Business provides a PIN caching user experience using a ticketing system. Rather than caching a PIN, processes cache a ticket they can use to request private key operations. Azure AD and Active Directory sign-in keys are cached under lock. This means the keys remain available for use without prompting as long as the user is interactively signed-in. Microsoft Account sign-in keys are considered transactional keys, which means the user is always prompted when accessing the key.
|
||||
|
||||
Beginning with Windows 10, Fall Creators Update, Windows Hello for Business used as a smart card (smart card emulation that is enabled by default) provides the same user experience of default smart card PIN caching. Each process requesting a private key operation will prompt the user for the PIN on first use. Subsequent private key operations will not prompt the user for the PIN.
|
||||
|
||||
The smart card emulation feature of Windows Hello for Business verifies the PIN and then discards the PIN in exchange for a ticket. The process does not receive the PIN, but rather the ticket that grants them private key operations. Windows 10 does not provide any Group Policy settings to adjust this caching.
|
||||
|
||||
### Can I disable the PIN while using Windows Hello for Business?
|
||||
No. The movement away from passwords is accomplished by gradually reducing the use of the password. In the occurence where you cannot authenticate with biometrics, you need a fall back mechansim that is not a password. The PIN is the fall back mechansim. Disabling or hiding the PIN credential provider disabled the use of biometrics.
|
||||
|
||||
### Does Windows Hello for Business work with third party federation servers?
|
||||
Windows Hello for Business can work with any third-party federation servers that support the protocols used during provisioning experience. Interested third-parties can inquiry at [whfbfeedback@microsoft.com](mailto:whfbfeedback@microsoft.com?subject=collaboration)
|
||||
|
||||
@ -98,3 +120,4 @@ Windows Hello for Business can work with any third-party federation servers that
|
||||
|
||||
### Does Windows Hello for Business work with Mac and Linux clients?
|
||||
Windows Hello for Business is a feature of Windows 10. At this time, Microsoft is not developing clients for other platforms. However, Microsoft is open to third parties who are interested in moving these platforms away from passwords. Interested third parties can inqury at [whfbfeedback@microsoft.com](mailto:whfbfeedback@microsoft.com?subject=collaboration)
|
||||
|
||||
|
@ -25,7 +25,7 @@ You can create a Group Policy or mobile device management (MDM) policy that will
|
||||
>
|
||||
>Beginning in version 1607, Windows Hello as a convenience PIN is disabled by default on all domain-joined computers. To enable a convenience PIN for Windows 10, version 1607, enable the Group Policy setting **Turn on convenience PIN sign-in**.
|
||||
>
|
||||
>Use **Windows Hello for Business** policy settings to manage PINs for Windows Hello for Business.
|
||||
>Use **PIN Complexity** policy settings to manage PINs for Windows Hello for Business.
|
||||
|
||||
## Group Policy settings for Windows Hello for Business
|
||||
|
||||
@ -292,71 +292,6 @@ The following table lists the MDM policy settings that you can configure for Win
|
||||
>[!NOTE]
|
||||
> If policy is not configured to explicitly require letters or special characters, users will be restricted to creating a numeric PIN.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
To deploy Windows Hello for Business, in some modes you must add Windows Server 2016 domain controllers to your Active Directory environment, but you don’t have to replace or remove your existing Active Directory servers — the servers required for Windows Hello for Business build on and add capability to your existing infrastructure. You don’t have to change the domain or forest functional level, and you can either add on-premises servers or use Azure Active Directory to deploy Windows Hello for Business in your network.
|
||||
|
||||
You’ll need this software to set Windows Hello for Business policies in your enterprise.
|
||||
<table>
|
||||
<colgroup>
|
||||
<col width="25%" />
|
||||
<col width="25%" />
|
||||
<col width="25%" />
|
||||
<col width="25%" />
|
||||
</colgroup>
|
||||
<thead>
|
||||
<tr class="header">
|
||||
<th align="left">Windows Hello for Business mode</th>
|
||||
<th align="left">Azure AD</th>
|
||||
<th align="left">Active Directory (AD) on-premises (only supported with Windows 10, version 1703 clients)</th>
|
||||
<th align="left">Azure AD/AD hybrid (available with production release of Windows Server 2016)</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr class="odd">
|
||||
<td align="left">Key-based authentication</td>
|
||||
<td align="left">Azure AD subscription</td>
|
||||
<td align="left"><ul>
|
||||
<li>Active Directory Federation Service (AD FS) (Windows Server 2016)</li>
|
||||
<li>A few Windows Server 2016 domain controllers on-site</li>
|
||||
</ul></td>
|
||||
<td align="left"><ul>
|
||||
<li>Azure AD subscription</li>
|
||||
<li>[Azure AD Connect](https://go.microsoft.com/fwlink/p/?LinkId=616792)</li>
|
||||
<li>A few Windows Server 2016 domain controllers on-site</li>
|
||||
<li>A management solution, such as Configuration Manager, Group Policy, or MDM</li>
|
||||
<li>Active Directory Certificate Services (AD CS) without Network Device Enrollment Service (NDES)</li>
|
||||
</ul></td>
|
||||
</tr>
|
||||
<tr class="even">
|
||||
<td align="left">Certificate-based authentication</td>
|
||||
<td align="left"><ul>
|
||||
<li>Azure AD subscription</li>
|
||||
<li>Intune or non-Microsoft mobile device management (MDM) solution</li>
|
||||
<li>PKI infrastructure</li>
|
||||
</ul></td>
|
||||
<td align="left"><ul>
|
||||
<li>ADFS (Windows Server 2016)</li>
|
||||
<li>Active Directory Domain Services (AD DS) Windows Server 2016 schema</li>
|
||||
<li>PKI infrastructure</li>
|
||||
</ul></td>
|
||||
<td align="left"><ul>
|
||||
<li>Azure AD subscription</li>
|
||||
<li>[Azure AD Connect](https://go.microsoft.com/fwlink/p/?LinkId=616792)</li>
|
||||
<li>AD CS with NDES</li>
|
||||
<li>Configuration Manager for domain-joined certificate enrollment, or InTune for non-domain-joined devices, or a non-Microsoft MDM service that supports Windows Hello for Business</li>
|
||||
</ul></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
Configuration Manager and MDM provide the ability to manage Windows Hello for Business policy and to deploy and manage certificates protected by Windows Hello for Business.
|
||||
|
||||
Azure AD provides the ability to register devices with your enterprise and to provision Windows Hello for Business for organization accounts.
|
||||
|
||||
>[!IMPORTANT]
|
||||
>Active Directory on-premises deployment **is not currently available** and will become available with a future update of ADFS on Windows Server 2016. The requirements listed in the above table will apply when this deployment type becomes available.
|
||||
|
||||
|
||||
## How to use Windows Hello for Business with Azure Active Directory
|
||||
|
||||
@ -380,3 +315,5 @@ If you want to use Windows Hello for Business with certificates, you’ll need a
|
||||
- [Windows Hello errors during PIN creation](hello-errors-during-pin-creation.md)
|
||||
- [Event ID 300 - Windows Hello successfully created](hello-event-300.md)
|
||||
- [Windows Hello biometrics in the enterprise](hello-biometrics-in-enterprise.md)
|
||||
|
||||
Not finding content you need? Windows 10 users, tell us what you want on [Feedback Hub](feedback-hub:?tabid=2&contextid=897).
|
@ -88,7 +88,7 @@ The goal of Windows Hello for Business is to move organizations away from passwo
|
||||
|
||||
Cloud only and hybrid deployments provide many choices for multifactor authentication. On-premises deployments must use a multifactor authentication that provides an AD FS multifactor adapter to be used in conjunction with the on-premises Windows Server 2016 AD FS server role. Organizations can use from the on-premises Azure Multifactor Authentication server, or choose from several third parties (Read [Microsoft and third-party additional authentication methods](https://docs.microsoft.com/windows-server/identity/ad-fs/operations/configure-additional-authentication-methods-for-ad-fs#microsoft-and-third-party-additional-authentication-methods) for more information).
|
||||
>[!NOTE]
|
||||
> Azure Multi-Factor Authentication is available through a:
|
||||
> Azure Multi-Factor Authentication is available through:
|
||||
>* Microsoft Enterprise Agreement
|
||||
>* Open Volume License Program
|
||||
>* Cloud Solution Providers program
|
||||
@ -160,6 +160,10 @@ If your organization does not have cloud resources, write **On-Premises** in box
|
||||
|
||||
Choose a trust type that is best suited for your organizations. Remember, the trust type determines two things. Whether you issue authentication certificates to your users and if your deployment needs Windows Server 2016 domain controllers.
|
||||
|
||||
One trust model is not more secure than the other. The major difference is based on the organization comfort with deploying Windows Server 2016 domain controllers and not enrolling users with end entity certificates (key-trust) against using existing domain controllers (Windows Server 2008R2 or later) and needing to enroll certificates for all their users (certificate trust).
|
||||
|
||||
Because the certificate trust types issues certificates, there is more configuration and infrastructure needed to accomodate user certificate enrollment, which could also be a factor to consider in your decision. Additional infrastructure needed for certificate-trust deployements includes a certificate registration authority. Hybrid Azure AD joined devices managed by Group Policy need the Windows Server 2016 AD FS role to issue certificates. Hybrid Azure AD joined devices and Azure AD joined devices managed by Intune or a compatible MDM need the Windows Server NDES server role to issue certificates.
|
||||
|
||||
If your organization wants to use the key trust type, write **key trust** in box **1b** on your planning worksheet. Write **Windows Server 2016** in box **4d**. Write **N/A** in box **5b**.
|
||||
|
||||
If your organization wants to use the certificate trust type, write **certificate trust** in box **1b** on your planning worksheet. Write **Windows Server 2008 R2 or later** in box **4d**. In box **5c**, write **smart card logon** under the **Template Name** column and write **users** under the **Issued To** column on your planning worksheet.
|
||||
@ -208,7 +212,7 @@ If your Azure AD Connect is configured to synchronize identities (usernames only
|
||||
|
||||
You can configure your on-premises Windows Server 2016 AD FS role to use the Azure MFA service adapter. In this configuration, users are redirected to the on premises AD FS server (synchronizing identities only). The AD FS server uses the MFA adapter to communicate to the Azure MFA service to perform the second factor of authentication. If you choose to use AD FS with the Azure MFA cloud service adapter, write **AD FS with Azure MFA cloud adapter** in box **1f** on your planning worksheet.
|
||||
|
||||
Alternatively, you can use AD FS with an on-premises Azure MFA server adapter. Rather than AD FS communicating directly with the Azure MFA cloud service, it communicates with an on-premises AD FS server that synchronizes user information with the on-premises Active Directory. The Azure MFA server communicates with Azure MFA cloud services to perform the second factor of authentication. If you choose to use AD FS with the Azure MFA server adapter, write **AD FS with Azure MFA server adapter** in box **1f** on your planning worksheet.
|
||||
Alternatively, you can use AD FS with an on-premises Azure MFA server adapter. Rather than AD FS communicating directly with the Azure MFA cloud service, it communicates with an on-premises Azure MFA server that synchronizes user information with the on-premises Active Directory. The Azure MFA server communicates with Azure MFA cloud services to perform the second factor of authentication. If you choose to use AD FS with the Azure MFA server adapter, write **AD FS with Azure MFA server adapter** in box **1f** on your planning worksheet.
|
||||
|
||||
The last option is for you to use AD FS with a third-party adapter as the second factor of authentication. If you choose to use AD FS with a third-party MFA adapter, write **AD FS with third party** in box **1f** on your planning worksheet.
|
||||
|
||||
@ -267,9 +271,9 @@ If box **1a** on your planning worksheet reads **cloud only**, ignore the public
|
||||
|
||||
If box **1b** on your planning worksheet reads **key trust**, write **N/A** in box **5b** on your planning worksheet.
|
||||
|
||||
The registration authority only relates to certificate trust deployments and the management used for domain and non-domain joined devices.
|
||||
The registration authority only relates to certificate trust deployments and the management used for domain and non-domain joined devices. Hybrid Azure AD joined devices managed by Group Policy need the Windows Server 2016 AD FS role to issue certificates. Hybrid Azure AD joined devices and Azure AD joined devices managed by Intune or a compatible MDM need the Windows Server NDES server role to issue certificates.
|
||||
|
||||
If box **3a** reads **GP** and box **3b** reads **modern management**, write **AD FS RA and NDES** in box **5b** on your planning worksheet. In box **5c**, write the following certificate templates names and issuances:
|
||||
If box **2a** reads **GP** and box **2b** reads **modern management**, write **AD FS RA and NDES** in box **5b** on your planning worksheet. In box **5c**, write the following certificate templates names and issuances:
|
||||
|
||||
| Certificate Template Name | Issued To |
|
||||
| --- | --- |
|
||||
@ -279,14 +283,14 @@ If box **3a** reads **GP** and box **3b** reads **modern management**, write **A
|
||||
| Web Server | NDES |
|
||||
| CEP Encryption | NDES |
|
||||
|
||||
If box **3a** reads **GP** and box **3b** reads **N/A**, write **AD FA RA** in box **5b** and write the following certificate template names and issuances in box **5c** on your planning worksheet.
|
||||
If box **2a** reads **GP** and box **2b** reads **N/A**, write **AD FA RA** in box **5b** and write the following certificate template names and issuances in box **5c** on your planning worksheet.
|
||||
|
||||
| Certificate Template Name | Issued To |
|
||||
| --- | --- |
|
||||
| Exchange Enrollment Agent | AD FS RA |
|
||||
| Web Server | AD FS RA |
|
||||
|
||||
If box **3a** or **3b** reads modern management, write **NDES** in box **5b** and write the following certificate template names and issuances in box 5c on your planning worksheet.
|
||||
If box **2a** or **2b** reads modern management, write **NDES** in box **5b** and write the following certificate template names and issuances in box 5c on your planning worksheet.
|
||||
|
||||
| Certificate Template Name | Issued To |
|
||||
| --- | --- |
|
||||
|
@ -108,3 +108,5 @@ If you only had a biometric sign-in configured and, for any reason, were unable
|
||||
- [Windows Hello errors during PIN creation](hello-errors-during-pin-creation.md)
|
||||
- [Event ID 300 - Windows Hello successfully created](hello-event-300.md)
|
||||
- [Windows Hello biometrics in the enterprise](hello-biometrics-in-enterprise.md)
|
||||
|
||||
Not finding content you need? Windows 10 users, tell us what you want on [Feedback Hub](feedback-hub:?tabid=2&contextid=897).
|
After Width: | Height: | Size: 52 KiB |
BIN
windows/access-protection/hello-for-business/images/dsregcmd.png
Normal file
After Width: | Height: | Size: 81 KiB |
BIN
windows/access-protection/hello-for-business/images/event358.png
Normal file
After Width: | Height: | Size: 80 KiB |
After Width: | Height: | Size: 87 KiB |
After Width: | Height: | Size: 177 KiB |
After Width: | Height: | Size: 49 KiB |
After Width: | Height: | Size: 28 KiB |
After Width: | Height: | Size: 8.8 KiB |
After Width: | Height: | Size: 55 KiB |
After Width: | Height: | Size: 79 KiB |
After Width: | Height: | Size: 350 KiB |
BIN
windows/access-protection/hello-for-business/images/mfa.png
Normal file
After Width: | Height: | Size: 106 KiB |
@ -1,4 +1,4 @@
|
||||
# [Windows Hello for Business](hello-identity-verification.md)
|
||||
# [Windows Hello for Business](hello-identity-verification.md)
|
||||
|
||||
## [Windows Hello for Business Overview](hello-overview.md)
|
||||
## [How Windows Hello for Business works](hello-how-it-works.md)
|
||||
@ -13,6 +13,12 @@
|
||||
## [Planning a Windows Hello for Business Deployment](hello-planning-guide.md)
|
||||
|
||||
## [Windows Hello for Business Deployment Guide](hello-deployment-guide.md)
|
||||
### [Hybrid Azure AD Joined Certificate Trust Deployment](hello-hybrid-cert-trust.md)
|
||||
#### [Prerequistes](hello-hybrid-cert-trust-prereqs.md)
|
||||
#### [New Installation Baseline](hello-hybrid-cert-new-install.md)
|
||||
#### [Configure Azure Device Registration](hello-hybrid-cert-trust-devreg.md)
|
||||
#### [Configure Windows Hello for Business policy settings](hello-hybrid-cert-whfb-settings.md)
|
||||
#### [Sign-in and Provision](hello-hybrid-cert-whfb-provision.md)
|
||||
|
||||
### [On Premises Certificate Trust Deployment](hello-deployment-cert-trust.md)
|
||||
#### [Validate Active Directory prerequisites](hello-cert-trust-validate-ad-prereq.md)
|
||||
|
After Width: | Height: | Size: 15 KiB |
After Width: | Height: | Size: 26 KiB |
@ -13,62 +13,108 @@ author: brianlic-msft
|
||||
- Windows 10
|
||||
- Windows Server 2016
|
||||
|
||||
Introduced in Windows 10, version 1607, Windows Defender Remote Credential Guard helps you protect your credentials over a Remote Desktop connection by redirecting the Kerberos requests back to the device that's requesting the connection. It also provides single sign on experiences for Remote Desktop sessions. If the target device is compromised, your credentials are not exposed because both credential and credential derivatives are never sent to the target device.
|
||||
Introduced in Windows 10, version 1607, Windows Defender Remote Credential Guard helps you protect your credentials over a Remote Desktop connection by redirecting Kerberos requests back to the device that's requesting the connection. It also provides single sign-on experiences for Remote Desktop sessions.
|
||||
|
||||
You can use Remote Credential Guard in the following ways:
|
||||
Administrator credentials are highly privileged and must be protected. By using Windows Defender Remote Credential Guard to connect during Remote Desktop sessions, if the target device is compromised, your credentials are not exposed because both credential and credential derivatives are never passed over the network to the target device.
|
||||
|
||||
- Administrator credentials are highly privileged and must be protected. By using Remote Credential Guard to connect, you can be assured that your credentials are not passed over the network to the target device.
|
||||
> [!IMPORTANT]
|
||||
> For information on Remote Desktop connection scenarios involving helpdesk support, see [Remote Desktop connections and helpdesk support scenarios](#helpdesk) in this article.
|
||||
|
||||
- Helpdesk employees in your organization must connect to domain-joined devices that could be compromised. With Windows Defender Remote Credential Guard, the helpdesk employee can use RDP to connect to the target device without compromising their credentials to malware.
|
||||
|
||||
## Comparing Windows Defender Remote Credential Guard with a server protected with Credential Guard
|
||||
|
||||
Use the following diagrams to help understand how Windows Defender Remote Credential Guard works, what it helps protect against, and how it compares with using a server protected with Credential Guard. As the diagram shows, Windows Defender Remote Credential Guard blocks NTLM (allowing only Kerberos), prevents Pass the Hash, and prevents usage of a credential after disconnection.
|
||||
|
||||

|
||||
<a id="comparing-remote-credential-guard-with-other-remote-desktop-connection-options"></a>
|
||||
|
||||
## Comparing Windows Defender Remote Credential Guard with other Remote Desktop connection options
|
||||
|
||||
Use the following table to compare different security options for Remote Desktop connections.
|
||||
The following diagram helps you to understand how a standard Remote Desktop session to a server without Windows Defender Remote Credential Guard works:
|
||||
|
||||
> [!NOTE]
|
||||
> This table compares different options than are shown in the previous diagram.
|
||||

|
||||
|
||||
| Remote Desktop | Windows Defender Remote Credential Guard | Restricted Admin mode |
|
||||
|---|---|---|
|
||||
| Protection: Provides **less protection** than other modes in this table. | Protection: Provides **moderate protection**, compared to other modes in this table. | Protection: Provides **the most protection** of the modes in this table. However, it also requires you to be in the local “Administrators” group on the remote computer. |
|
||||
| Version support: The remote computer can be running **any operating system that supports credential delegation**, which was introduced in Windows Vista. | Version support: The remote computer must be running **at least Windows 10, version 1607, or Windows Server 2016**. | Version support: The remote computer must be running **at least patched Windows 7 or patched Windows Server 2008 R2**.<br><br>For more information about patches (software updates) related to Restricted Admin mode, see [Microsoft Security Advisory 2871997](https://technet.microsoft.com/library/security/2871997.aspx). |
|
||||
| NA | Helps prevent:<br><br>- **Pass the Hash**<br>- Usage of a **credential after disconnection** | Prevents:<br><br>- **Pass the Hash**<br>- Usage of **domain identity during connection** |
|
||||
| Credentials supported from the remote desktop client device:<br><br>- **Signed on** credentials<br>- **Supplied** credentials<br>- **Saved** credentials | Credentials supported from the remote desktop client device:<br><br>- **Signed on** credentials only | Credentials supported from the remote desktop client device:<br><br>- **Signed on** credentials<br>- **Supplied** credentials<br>- **Saved** credentials |
|
||||
| Access: **Users allowed**, that is, members of remote desktop users group of remote host. | Access: **Users allowed**, that is, members of remote desktop users group of remote host. | Access: **Administrators only**, that is, only members in administrators group of remote host. |
|
||||
| Network identity: Remote desktop session **connects to other resources as signed on user**. | Network identity: Remote desktop session **connects to other resources as signed on user**. | Network identity: Remote desktop session **connects to other resources as remote host’s identity**. |
|
||||
| Multi-hop: From the remote desktop, you **can connect through Remote Desktop to another computer**. | Multi-hop: From the remote desktop, you **can connect through Remote Desktop to another computer**. | No multi-hop: From the remote desktop, you **cannot connect through Remote Desktop to another computer**. |
|
||||
| Supported authentication protocol: **Any negotiable protocol**. | Supported authentication protocol: **Kerberos only**. | Supported authentication protocol: **Any negotiable protocol**. |
|
||||
<br />
|
||||
|
||||
## Hardware and software requirements
|
||||
The following diagram helps you to understand how Windows Defender Remote Credential Guard works, what it helps to protect against, and compares it with the [Restricted Admin mode](http://social.technet.microsoft.com/wiki/contents/articles/32905.how-to-enable-restricted-admin-mode-for-remote-desktop.aspx) option:
|
||||
|
||||
To use Windows Defender Remote Credential Guard, the Remote Desktop client and server must meet the following requirements:
|
||||

|
||||
|
||||
- In order to connect using credentials other than signed-in credentials, the Remote Desktop client device must be running at least Windows 10, version 1703.
|
||||
<br />
|
||||
As illustrated, Windows Defender Remote Credential Guard blocks NTLM (allowing only Kerberos), prevents Pass-the-Hash (PtH) attacks, and also prevents use of credentials after disconnection.
|
||||
|
||||
<br />
|
||||
<br />
|
||||
Use the following table to compare different Remote Desktop connection security options:
|
||||
|
||||
<br />
|
||||
<br />
|
||||
|
||||
|**Feature** | **Remote Desktop** | **Windows Defender Remote Credential Guard** | **Restricted Admin mode** |
|
||||
|---|---|---|---|
|
||||
| **Protection benefits** | Credentials on the server are not protected from Pass-the-Hash attacks. |User credentials remain on the client. An attacker can act on behalf of the user *only* when the session is ongoing | User logs on to the server as local administrator, so an attacker cannot act on behalf of the “domain user”. Any attack is local to the server|
|
||||
| **Version support** | The remote computer can run any Windows operating system|Both the client and the remote computer must be running **at least Windows 10, version 1607, or Windows Server 2016**.|The remote computer must be running **at least patched Windows 7 or patched Windows Server 2008 R2**. <br /><br />For more information about patches (software updates) related to Restricted Admin mode, see [Microsoft Security Advisory 2871997](https://technet.microsoft.com/library/security/2871997.aspx).
|
||||
|**Helps prevent** | N/A |<ul><li> Pass-the-Hash</li> <li>Use of a credential after disconnection </li></ul>|<ul><li> Pass-the-Hash</li> <li>Use of domain identity during connection </li></ul>|
|
||||
|**Credentials supported from the remote desktop client device**|<ul><li>**Signed on** credentials <li> **Supplied** credentials<li> **Saved** credentials </ul>|<ul><li> **Signed on** credentials only | <ul><li>**Signed on** credentials<li>**Supplied** credentials<li>**Saved** credentials</ul>
|
||||
|**Access**|**Users allowed**, that is, members of Remote Desktop Users group of remote host.|**Users allowed**, that is, members of Remote Desktop Users of remote host.|**Administrators only**, that is, only members of Administrators group of remote host.
|
||||
|**Network identity**|Remote Desktop session **connects to other resources as signed-in user**. | Remote Desktop session **connects to other resources as signed-in user**. |Remote Desktop session **connects to other resources as remote host’s identity**.|
|
||||
|**Multi-hop**|From the remote desktop, **you can connect through Remote Desktop to another computer** | From the remote desktop, you **can connect through Remote Desktop to another computer**.|Not allowed for user as the session is running as a local host account|
|
||||
|**Supported authentication** |Any negotiable protocol.| Kerberos only.|Any negotiable protocol|
|
||||
<br />
|
||||
|
||||
For further technical information, see [Remote Desktop Protocol](https://msdn.microsoft.com/library/aa383015(v=vs.85).aspx)
|
||||
and [How Kerberos works](https://technet.microsoft.com/en-us/library/cc961963.aspx(d=robot))
|
||||
|
||||
<br />
|
||||
|
||||
<a id="helpdesk"></a>
|
||||
|
||||
## Remote Desktop connections and helpdesk support scenarios
|
||||
|
||||
For helpdesk support scenarios in which personnel require administrative access to provide remote assistance to computer users via Remote Desktop sessions, Microsoft recommends that Windows Defender Remote Credential Guard should not be used in that context. This is because if an RDP session is initiated to a compromised client that an attacker already controls, the attacker could use that open channel to create sessions on the user's behalf (without compromising credentials) to access any of the user’s resources for a limited time (a few hours) after the session disconnects.
|
||||
|
||||
Therefore, we recommend instead that you use the Restricted Admin mode option. For helpdesk support scenarios, RDP connections should only be initiated using the /RestrictedAdmin switch. This helps ensure that credentials and other user resources are not exposed to compromised remote hosts. For more information, see [Mitigating Pass-the-Hash and Other Credential Theft v2](http://download.microsoft.com/download/7/7/A/77ABC5BD-8320-41AF-863C-6ECFB10CB4B9/Mitigating-Pass-the-Hash-Attacks-and-Other-Credential-Theft-Version-2.pdf).
|
||||
|
||||
To further harden security, we also recommend that you implement Local Administrator Password Solution (LAPS), a Group Policy client-side extension (CSE) introduced in Windows 8.1 that automates local administrator password management. LAPS mitigates the risk of lateral escalation and other cyberattacks facilitated when customers use the same administrative local account and password combination on all their computers. You can download and install LAPS [here](https://www.microsoft.com/en-us/download/details.aspx?id=46899).
|
||||
|
||||
For further information on LAPS, see [Microsoft Security Advisory 3062591](https://technet.microsoft.com/en-us/library/security/3062591.aspx).
|
||||
|
||||
|
||||
<a id="reqs"></a>
|
||||
|
||||
## Remote Credential Guard requirements
|
||||
|
||||
To use Windows Defender Remote Credential Guard, the Remote Desktop client and remote host must meet the following requirements:
|
||||
|
||||
The Remote Desktop client device:
|
||||
|
||||
- Must be running at least Windows 10, version 1703 to be able to supply credentials.
|
||||
- Must be running at least Windows 10, version 1607 or Windows Server 2016 to use the user’s signed-in credentials. This requires the user’s account be able to sign in to both the client device and the remote host.
|
||||
- Must be running the Remote Desktop Classic Windows application. The Remote Desktop Universal Windows Platform application doesn't support Windows Defender Remote Credential Guard.
|
||||
- Must use Kerberos authentication to connect to the remote host. If the client cannot connect to a domain controller, then RDP attempts to fall back to NTLM. Windows Defender Remote Credential Guard does not allow NTLM fallback because this would expose credentials to risk.
|
||||
|
||||
The Remote Desktop remote host:
|
||||
|
||||
- Must be running at least Windows 10, version 1607 or Windows Server 2016.
|
||||
- Must allow Restricted Admin connections.
|
||||
- Must allow the client’s domain user to access Remote Desktop connections.
|
||||
- Must allow delegation of non-exportable credentials.
|
||||
|
||||
There are no hardware requirements for Windows Defender Remote Credential Guard.
|
||||
|
||||
> [!NOTE]
|
||||
> Remote Desktop client devices running earlier versions, at minimum Windows 10 version 1607, only support signed-in credentials, so the client device must also be joined to an Active Directory domain. Both Remote Desktop client and server must either be joined to the same domain, or the Remote Desktop server can be joined to a domain that has a trust relationship to the client device's domain.
|
||||
|
||||
- For Windows Defender Remote Credential Guard to be supported, the user must authenticate to the remote host using Kerberos authentication
|
||||
- For Windows Defender Remote Credential Guard to be supported, the user must authenticate to the remote host using Kerberos authentication.
|
||||
- The remote host must be running at least Windows 10 version 1607, or Windows Server 2016.
|
||||
- The Remote Desktop classic Windows app is required. The Remote Desktop Universal Windows Platform app doesn't support Windows Defender Remote Credential Guard.
|
||||
|
||||
## Enable Windows Defender Remote Credential Guard
|
||||
|
||||
You must enable Windows Defender Remote Credential Guard on the target device by using the registry.
|
||||
You must enable Restricted Admin or Windows Defender Remote Credential Guard on the remote host by using the Registry.
|
||||
|
||||
1. Open Registry Editor.
|
||||
2. Enable Windows Defender Remote Credential Guard:
|
||||
1. Open Registry Editor on the remote host.
|
||||
2. Enable Restricted Admin and Windows Defender Remote Credential Guard:
|
||||
- Go to HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa.
|
||||
- Add a new DWORD value named **DisableRestrictedAdmin**. Set the value of this registry setting to 0 to turn on Windows Defender Remote Credential Guard.
|
||||
- Add a new DWORD value named **DisableRestrictedAdmin**.
|
||||
- To turn on Restricted Admin and Windows Defender Remote Credential Guard, set the value of this registry setting to 0 to turn on Windows Defender Remote Credential Guard.
|
||||
3. Close Registry Editor.
|
||||
|
||||
You can add this by running the following from an elevated command prompt:
|
||||
You can add this by running the following command from an elevated command prompt:
|
||||
|
||||
```
|
||||
reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /d 0 /t REG_DWORD
|
||||
@ -76,7 +122,7 @@ reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /d 0
|
||||
|
||||
## Using Windows Defender Remote Credential Guard
|
||||
|
||||
You can use Windows Defender Remote Credential Guard on the client device by setting a Group Policy or by using a parameter with Remote Desktop Connection.
|
||||
Beginning with Windows 10 version 1703, you can enable Windows Defender Remote Credential Guard on the client device either by using Group Policy or by using a parameter with the Remote Desktop Connection.
|
||||
|
||||
### Turn on Windows Defender Remote Credential Guard by using Group Policy
|
||||
|
||||
@ -91,9 +137,9 @@ You can use Windows Defender Remote Credential Guard on the client device by set
|
||||
|
||||
> **Note:** Neither Windows Defender Remote Credential Guard nor Restricted Admin mode will send credentials in clear text to the Remote Desktop server.
|
||||
|
||||
- If you want to require Windows Defender Remote Credential Guard, choose **Require Windows Defender Remote Credential Guard**. With this setting, a Remote Desktop connection will succeed only if the remote computer meets the [Hardware and software requirements](#hardware-and-software-requirements) listed earlier in this topic.
|
||||
- If you want to require Windows Defender Remote Credential Guard, choose **Require Windows Defender Remote Credential Guard**. With this setting, a Remote Desktop connection will succeed only if the remote computer meets the [requirements](#reqs) listed earlier in this topic.
|
||||
|
||||
- If you want to require Restricted Admin mode, choose **Require Restricted Admin**. For information about Restricted Admin mode, see the table in [Comparing Windows Defender Remote Credential Guard with other options for Remote Desktop connections](#comparing-remote-credential-guard-with-other-options-for-remote-desktop-connections), earlier in this topic.
|
||||
- If you want to require Restricted Admin mode, choose **Require Restricted Admin**. For information about Restricted Admin mode, see the table in [Comparing Windows Defender Remote Credential Guard with other Remote Desktop connection options](#comparing-remote-credential-guard-with-other-remote-desktop-connection-options), earlier in this topic.
|
||||
|
||||
4. Click **OK**.
|
||||
|
||||
@ -104,7 +150,7 @@ You can use Windows Defender Remote Credential Guard on the client device by set
|
||||
|
||||
### Use Windows Defender Remote Credential Guard with a parameter to Remote Desktop Connection
|
||||
|
||||
If you don't use Group Policy in your organization, you can add the remoteGuard parameter when you start Remote Desktop Connection to turn on Windows Defender Remote Credential Guard for that connection.
|
||||
If you don't use Group Policy in your organization, or if not all your remote hosts support Remote Credential Guard, you can add the remoteGuard parameter when you start Remote Desktop Connection to turn on Windows Defender Remote Credential Guard for that connection.
|
||||
|
||||
```
|
||||
mstsc.exe /remoteGuard
|
||||
@ -113,18 +159,12 @@ mstsc.exe /remoteGuard
|
||||
|
||||
## Considerations when using Windows Defender Remote Credential Guard
|
||||
|
||||
- Windows Defender Remote Credential Guard does not include device claims. For example, if you’re trying to access a file server from the remote and the file server requires device claim, access will be denied.
|
||||
- Windows Defender Remote Credential Guard does not support compound authentication. For example, if you’re trying to access a file server from a remote host that requires a device claim, access will be denied.
|
||||
|
||||
- Windows Defender Remote Credential Guard cannot be used to connect to a device that is joined to Azure Active Directory.
|
||||
- Windows Defender Remote Credential Guard cannot be used to connect to a device that is not domain-joined to Active Directory, for example, remote hosts joined to Azure Active Directory.
|
||||
|
||||
- Remote Desktop Credential Guard only works with the RDP protocol.
|
||||
|
||||
- No credentials are sent to the target device, but the target device still acquires the Kerberos Service Tickets on its own.
|
||||
|
||||
- Remote Desktop Gateway is not compatible with Windows Defender Remote Credential Guard.
|
||||
|
||||
- You cannot use saved credentials or credentials that are different than yours. You must use the credentials of the user who is logged into the device.
|
||||
|
||||
- Both the client and the server must be joined to the same domain or the domains must have a trust relationship.
|
||||
- No credentials are sent to the target device, but the target device still acquires Kerberos Service Tickets on its own.
|
||||
|
||||
- The server and client must authenticate using Kerberos.
|
@ -1,7 +1,6 @@
|
||||
---
|
||||
title: Windows Defender Firewall with Advanced Security Design Guide (Windows 10)
|
||||
description: Windows Defender Firewall with Advanced Security
|
||||
Design Guide
|
||||
description: Windows Defender Firewall with Advanced Security Design Guide
|
||||
ms.assetid: 5c631389-f232-4b95-9e48-ec02b8677d51
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
|
@ -1,5 +1,6 @@
|
||||
# [Manage applications in Windows 10](index.md)
|
||||
## [Sideload apps](sideload-apps-in-windows-10.md)
|
||||
## [Remove background task resource restrictions](enterprise-background-activity-controls.md)
|
||||
## [Application Virtualization (App-V) for Windows](app-v/appv-for-windows.md)
|
||||
### [Getting Started with App-V](app-v/appv-getting-started.md)
|
||||
#### [What's new in App-V for Windows 10, version 1703 and earlier](app-v/appv-about-appv.md)
|
||||
@ -100,5 +101,8 @@
|
||||
#### [Viewing App-V Server Publishing Metadata](app-v/appv-viewing-appv-server-publishing-metadata.md)
|
||||
#### [Running a Locally Installed Application Inside a Virtual Environment with Virtualized Applications](app-v/appv-running-locally-installed-applications-inside-a-virtual-environment.md)
|
||||
## [Service Host process refactoring](svchost-service-refactoring.md)
|
||||
## [Per-user services in Windows](per-user-services-in-windows.md)
|
||||
## [Disabling System Services in Windows Server](https://docs.microsoft.com/windows-server/security/windows-services/security-guidelines-for-disabling-system-services-in-windows-server)
|
||||
## [Understand apps in Windows 10](apps-in-windows-10.md)
|
||||
## [Deploy app upgrades on Windows 10 Mobile](deploy-app-upgrades-windows-10-mobile.md)
|
||||
## [Change history for Application management](change-history-for-application-management.md)
|
||||
|
153
windows/application-management/apps-in-windows-10.md
Normal file
@ -0,0 +1,153 @@
|
||||
---
|
||||
title: Windows 10 - Apps
|
||||
description: What are Windows, UWP, and Win32 apps
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: mobile
|
||||
ms.author: elizapo
|
||||
author: lizap
|
||||
ms.localizationpriority: low
|
||||
ms.date: 09/15/2017
|
||||
---
|
||||
# Understand the different apps included in Windows 10
|
||||
|
||||
The following types of apps run on Windows 10:
|
||||
- Windows apps - introduced in Windows 8, primarily installed from the Store app.
|
||||
- Universal Windows Platform (UWP) apps - designed to work across platforms, can be installed on multiple platforms including Windows client, Windows Phone, and Xbox. All UWP apps are also Windows apps, but not all Windows apps are UWP apps.
|
||||
- "Win32" apps - traditional Windows applications, built for 32-bit systems.
|
||||
|
||||
Digging into the Windows apps, there are two categories:
|
||||
- System apps - Apps that are installed in the c:\Windows\* directory. These apps are integral to the OS.
|
||||
- Apps - All other apps, installed in c:\Program Files\WindowsApps. There are two classes of apps:
|
||||
- Provisioned: Installed the first time you sign into Windows. You'll see a tile or Start menu item for these apps, but they aren't installed until the first sign-in.
|
||||
- Installed: Installed as part of the OS.
|
||||
|
||||
The following tables list the system apps, installed Windows apps, and provisioned Windows apps in a standard Windows 10 Enterprise installation. (If you have a custom image, your specific apps might differ.) The tables list the app, the full name, show the app's status in Windows 10 version 1511, 1607, and 1703, and indicate whether an app can be uninstalled through the UI.
|
||||
|
||||
Some of the apps show up in multiple tables - that's because their status changed between versions. Make sure to check the version column for the version you are currently running.
|
||||
|
||||
> [!TIP]
|
||||
> Want to see a list of the apps installed on your specific image? You can run the following PowerShell cmdlet:
|
||||
> ```powershell
|
||||
> Get-AppxPackage |Select Name,PackageFamilyName
|
||||
> Get-AppsProvisionedPackage -Online | select DisplayName,PackageName
|
||||
> ```
|
||||
|
||||
|
||||
## System apps
|
||||
System apps are integral to the operating system. Here are the typical system apps in Windows 10 versions 1511, 1607, and 1703.
|
||||
|
||||
| Name | Full name | 1511 | 1607 | 1703 | Uninstall through UI? |
|
||||
|------------------|-------------------------------------------|------|------|------|--------------------------------------------------------|
|
||||
| Cortana UI | CortanaListenUIApp | | | x | No |
|
||||
| | Desktop Learning | | | x | No |
|
||||
| | DesktopView | | | x | No |
|
||||
| | EnvironmentsApp | | | x | No |
|
||||
| Mixed Reality + | HoloCamera | | | x | No |
|
||||
| Mixed Reality + | HoloItemPlayerApp | | | x | No |
|
||||
| Mixed Reality + | HoloShell | | | x | No |
|
||||
| | Microsoft.AAD.Broker.Plugin | x | x | x | No |
|
||||
| | Microsoft.AccountsControl | x | x | x | No |
|
||||
| Hello setup UI | Microsoft.BioEnrollment | x | x | x | No |
|
||||
| | Microsoft.CredDialogHost | | | x | No |
|
||||
| | Microsoft.LockApp | x | x | x | No |
|
||||
| Microsoft Edge | Microsoft.Microsoft.Edge | x | x | x | No |
|
||||
| | Microsoft.PPIProjection | | x | x | No |
|
||||
| | Microsoft.Windows. Apprep.ChxApp | | x | x | No |
|
||||
| | Microsoft.Windows. AssignedAccessLockApp | x | x | x | No |
|
||||
| | Microsoft.Windows. CloudExperienceHost | x | x | x | No |
|
||||
| | Microsoft.Windows. ContentDeliveryManager | x | x | x | No |
|
||||
| Cortana | Microsoft.Windows.Cortana | x | x | x | No |
|
||||
| | Microsoft.Windows. Holographic.FirstRun | | | x | No |
|
||||
| | Microsoft.Windows. ModalSharePickerHost | | | x | No |
|
||||
| | Microsoft.Windows. OOBENetworkCaptivePort | | | x | No |
|
||||
| | Microsoft.Windows. OOBENetworkConnection | | | x | No |
|
||||
| | Microsoft.Windows. ParentalControls | x | x | x | No |
|
||||
| | Microsoft.Windows. SecHealthUI | | | x | No |
|
||||
| | Microsoft.Windows. SecondaryTileExperience | x | x | x | No |
|
||||
| | Microsoft.Windows. SecureAssessmentBrowser | | x | x | No |
|
||||
| Start | Microsoft.Windows. ShellExperienceHost | x | x | x | No |
|
||||
| Windows Feedback | Microsoft.WindowsFeedback | x | * | * | No |
|
||||
| | Microsoft.XboxGameCallableUI | x | x | x | No |
|
||||
| Xbox logon UI | Microsoft.XboxIdentityProvider | x | | | No |
|
||||
| Contact Support | Windows.ContactSupport | x | x* | x* | In 1511, no.* |
|
||||
| | Windows.Devicesflow | x | | | No |
|
||||
| Settings | Windows.ImmersiveControlPanel | x | x | x | No |
|
||||
| Connect | Windows.MiracastView | x | x | x | No |
|
||||
| Print UI | Windows.PrintDialog | x | x | x | No |
|
||||
| Purchase UI | Windows.PurchaseDialog | x | | | No |
|
||||
|
||||
> [!NOTE]
|
||||
> - The Windows Feedback app changed to the Windows Feedback Hub in version 1607. It's listed in the installed apps table below.
|
||||
> - As of Windows 10 version 1607, you can use the Optional Features app to uninstall the Contact Support app.
|
||||
|
||||
## Installed Windows apps
|
||||
Here are the typical installed Windows apps in Windows 10 versions 1511, 1607, and 1703.
|
||||
|
||||
| Name | Full name | 1511 | 1607 | 1703 | Uninstall through UI? |
|
||||
|--------------------|-----------------------------------------|------|------|------|---------------------------|
|
||||
| Remote Desktop | Microsoft.RemoteDesktop | | x | x | Yes |
|
||||
| PowerBI | Microsoft.Microsoft PowerBIforWindows | | x | x | Yes |
|
||||
| Candy Crush | king.com.CandyCrushSodaSaga | x | | | Yes |
|
||||
| Code Writer | ActiproSoftwareLLC.562882FEEB491 | | x | x | Yes |
|
||||
| Eclipse Manager | 46928bounde.EclipseManager | | x | x | Yes |
|
||||
| Pandora | PandoraMediaInc.29680B314EFC2 | | x | x | Yes |
|
||||
| Photoshop Express | AdobeSystemIncorporated. AdobePhotoshop | | x | x | Yes |
|
||||
| Duolingo | D5EA27B7.Duolingo- LearnLanguagesforFree | | | x | Yes |
|
||||
| Network Speed Test | Microsoft.NetworkSpeedTest | | x | x | Yes |
|
||||
| Paid Wi-FI | | x | | | Yes |
|
||||
| Skype Video | | x | | | Yes |
|
||||
| Twitter | | x | | | Yes |
|
||||
| PicArts | | x | | | Yes |
|
||||
| Minecraft | | x | | | Yes |
|
||||
| Flipboard | | x | | | Yes |
|
||||
|
||||
## Provisioned Windows apps
|
||||
Here are the typical provisioned Windows apps in Windows 10 versions 1511, 1607, and 1703.
|
||||
|
||||
| Name | Full name | 1511 | 1607 | 1703 | Uninstall through UI? |
|
||||
|---------------------------------|----------------------------------------|------|------|------|---------------------------|
|
||||
| 3D Builder | Microsoft.3DBuilder | x | | x | Yes |
|
||||
| App Connector | Microsoft.Appconnector | x | | | Yes, through Settings app |
|
||||
| Money | Microsoft.BingFinance | x | | | Yes |
|
||||
| News | Microsoft.BingNews | x | * | * | Yes |
|
||||
| Sports | Microsoft.BingSports | x | | | Yes |
|
||||
| Weather | Microsoft.BingWeather | x | x | x | No |
|
||||
| Phone Companion | Microsoft.CommsPhone | x | | | Yes |
|
||||
| | Microsoft.ConnectivityStore | x | | | No |
|
||||
| | Microsoft.DesktopAppInstaller | | x | x | Yes, through Settings app |
|
||||
| Get Started/Tips | Microsoft.Getstarted | x | x | x | Yes |
|
||||
| Messaging | Microsoft.Messaging | x | x | x | No |
|
||||
| Microsoft 3D Viewer | Microsoft.Microsoft3DViewer | | | x | No |
|
||||
| Get Office | Microsoft.MicrosoftOfficeHub | x | x | x | Yes |
|
||||
| Solitaire | Microsoft.Microsoft SolitaireCollection | x | x | x | Yes |
|
||||
| Sticky Notes | Microsoft.MicrosoftStickyNotes | | x | x | No |
|
||||
| OneNote | Microsoft.Office.OneNote | x | x | x | No |
|
||||
| Sway | Microsoft.Office.Sway | x | * | * | Yes |
|
||||
| | Microsoft.OneConnect | | x | x | No |
|
||||
| Paint 3D | Microsoft.MSPaint | | | x | No |
|
||||
| People | Microsoft.People | x | x | x | No |
|
||||
| Get Skype/Skype (preview)/Skype | Microsoft.SkypeApp | x | x | x | Yes |
|
||||
| | Microsoft.StorePurchaseApp | | x | x | No |
|
||||
| | Microsoft.Wallet | | | x | No |
|
||||
| Photos | Microsoft.Windows.Photos | x | x | x | No |
|
||||
| Alarms & Clock | Microsoft.WindowsAlarms | x | x | x | No |
|
||||
| Calculator | Microsoft.WindowsCalculator | x | x | x | No |
|
||||
| Camera | Microsoft.WindowsCamera | x | x | x | No |
|
||||
| Mail and Calendar | Microsoft.windows communicationsapps | x | x | x | No |
|
||||
| Feedback Hub | Microsoft.WindowsFeedbackHub | * | x | x | Yes |
|
||||
| Maps | Microsoft.WindowsMaps | x | x | x | No |
|
||||
| Phone | Microsoft.WindowsPhone | x | | | No |
|
||||
| Voice Recorder | Microsoft.SoundRecorder | x | x | x | No |
|
||||
| Store | Microsoft.WindowsStore | x | x | x | No |
|
||||
| Xbox | Microsoft.XboxApp | x | x | x | No |
|
||||
| | Microsoft.XboxGameOverlay | | | x | No |
|
||||
| | Microsoft.XboxIdentityProvider | * | x | x | No |
|
||||
| Groove | Microsoft.ZuneMusic | x | x | x | No |
|
||||
| Movies & TV | Microsoft.ZuneVideo | x | x | x | No |
|
||||
| | Microsoft.XboxSpeech ToTextOverlay | | | x | No |
|
||||
|
||||
> [!NOTE]
|
||||
> - As of Windows 10, version 1607, News and Sway are installed apps.
|
||||
> - Both Feedback Hub and Microsoft.XboxIdentityProvider were installed apps in version 1511 and provisioned apps in versions 1607 and later.
|
@ -8,12 +8,20 @@ ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: high
|
||||
author: jdeckerms
|
||||
ms.date: 09/15/2017
|
||||
---
|
||||
|
||||
# Change history for Configure Windows 10
|
||||
|
||||
This topic lists new and updated topics in the [Configure Windows 10](index.md) documentation for Windows 10 and Windows 10 Mobile.
|
||||
|
||||
## September 2017
|
||||
| New or changed topic | Description |
|
||||
| --- | --- |
|
||||
| [Per-user services in Windows 10](per-user-services-in-windows.md) | New |
|
||||
| [Remove background task resource restrictions](enterprise-background-activity-controls.md) | New |
|
||||
| [Understand the different apps included in Windows 10](apps-in-windows-10.md) | New |
|
||||
|
||||
## July 2017
|
||||
| New or changed topic | Description |
|
||||
| --- | --- |
|
||||
|
@ -0,0 +1,63 @@
|
||||
---
|
||||
author: TylerMSFT
|
||||
title: Remove background task resource restrictions
|
||||
description: Allow enterprise background tasks unrestricted access to computer resources.
|
||||
ms.author: twhitney
|
||||
ms.date: 09/26/2017
|
||||
ms.topic: article
|
||||
ms.prod: windows
|
||||
ms.technology: uwp
|
||||
keywords: windows 10, uwp, enterprise, background task, resources
|
||||
---
|
||||
|
||||
# Remove background task resource restrictions
|
||||
|
||||
To provide the best experience for consumers, Windows provides controls that give users the choice of which experiences may run in the background.
|
||||
|
||||
By default, resource limits are imposed on applications. Foreground apps are given the most memory and execution time; background apps get less. Users are thus protected from poor foreground app performance and heavy battery drain.
|
||||
|
||||
Enterprise users want the same ability to enable or limit background activity. In Windows 10, version 1703 (also known as the Creators Update), enterprises can now configure settings via policy and provisioning that control background activity.
|
||||
|
||||
## Background activity controls
|
||||
|
||||
Users have the ability to control background activity for their device through two interfaces in the **Settings** app: the **Background apps** page and the **Battery usage by app** page. The **Background apps** page has a master switch to turn background activity on or off for all apps, and provides individual switches to control each app's ability to run in the background.
|
||||
|
||||

|
||||
|
||||
The **Battery usage by app** page allows fine-grained tuning of background activity. Users have the ability to set background activity to by **Managed By Windows**, as well as turning it on or off for each app. Only devices with a battery have this page available in the **Settings** app. Here is the set of available controls on desktop:
|
||||
|
||||

|
||||
|
||||
Here is the set of available controls for mobile devices:
|
||||
|
||||

|
||||
|
||||
Although the user interface differs across editions of the operating system, the policy and developer interface is consistent across Windows 10. For more information about these controls, see [Optimize background activity](https://docs.microsoft.com/windows/uwp/debug-test-perf/optimize-background-activity).
|
||||
|
||||
## Enterprise background activity controls
|
||||
|
||||
Starting with Windows 10, version 1703, enterprises can control background activity through mobile device management (MDM) or Group Policy. The user controls discussed above can be controlled with the following policies:
|
||||
|
||||
`./Vendor/Microsoft/Policy/Config/Privacy/LetAppsRunInBackground`
|
||||
`./Vendor/Microsoft/Policy/Config/Privacy/LetAppsRunInBackground_ForceAllowTheseApps`
|
||||
`./Vendor/Microsoft/Policy/Config/Privacy/LetAppsRunInBackground_ForceDenyTheseApps`
|
||||
`./Vendor/Microsoft/Policy/Config/Privacy/LetAppsRunInBackground_UserInControlOfTheseApps`
|
||||
|
||||
These policies control the background activity battery settings for Universal Windows Platform (UWP) apps. They enable apps to not be managed by the Windows system policies and not be restricted when battery saver is active. Applying these policies to a device will disable the user controls for the applications specified in the policies in the **Settings** app. See [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsruninbackground) for more information about these policies.
|
||||
|
||||
An app can determine which settings are in place for itself by using [BackgroundExecutionManager.RequestAccessAsync](https://docs.microsoft.com/uwp/api/Windows.ApplicationModel.Background.BackgroundAccessStatus) before any background activity is attempted, and then examining the returned [BackgroundAccessStatus](https://docs.microsoft.com/uwp/api/windows.applicationmodel.background.backgroundaccessstatus) enumeration. The values of this enumeration correspond to settings in the **battery usage by App** settings page:
|
||||
|
||||
- **AlwaysAllowed**: Corresponds to **Always Allowed in Background** and **Managed By User**. This enables apps to run as much as possible in the background, including while the device is in battery saver mode.
|
||||
|
||||
- **AllowedSubjectToSystemPolicy**: This is the default value. It corresponds to **Managed by Windows**. This enables apps to run in the background as determined by Windows. If the device is currently in the battery saver state then background activities do not run.
|
||||
|
||||
- **DeniedDueToSystemPolicy**: Corresponds to **Managed by Windows** and indicates that the system has determined that the app cannot currently run in the background.
|
||||
|
||||
- **DeniedByUser**: Corresponds to **Never Allowed in the Background**. The app cannot run in the background. Either the configuration in the settings app, or enterprise policy, has defined that this app is not allowed to run in the background.
|
||||
|
||||
The Universal Windows Platform ensures that consumers will have great battery life and that foreground apps will perform well. Enterprises have the ability to change settings to enable scenarios specific to their business needs. Administrators can use the **Background apps** policies to enable or disable whether a UWP app can run in the background.
|
||||
|
||||
## See also
|
||||
|
||||
[Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsruninbackground)
|
||||
[Optimize background activity](https://docs.microsoft.com/windows/uwp/debug-test-perf/optimize-background-activity)
|