diff --git a/.openpublishing.publish.config.json b/.openpublishing.publish.config.json
index 266cc6561d..f9d982e542 100644
--- a/.openpublishing.publish.config.json
+++ b/.openpublishing.publish.config.json
@@ -142,7 +142,7 @@
"locale": "en-us",
"monikers": [],
"moniker_ranges": [],
- "open_to_public_contributors": false,
+ "open_to_public_contributors": true,
"type_mapping": {
"Conceptual": "Content",
"ManagedReference": "Content",
diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json
index d2662faa3b..8dada868e0 100644
--- a/.openpublishing.redirection.json
+++ b/.openpublishing.redirection.json
@@ -5182,7 +5182,7 @@
},
{
"source_path": "education/windows/switch-to-pro-education.md",
-"redirect_url": "/education/windows/s-mode-switch-to-edu",
+"redirect_url": "/education/windows/change-to-pro-education",
"redirect_document_id": true
},
{
@@ -6406,6 +6406,11 @@
"redirect_document_id": true
},
{
+"source_path": "windows/configuration/configure-devices-without-mdm.md",
+"redirect_url": "/windows/configuration/provisioning-packages/provisioning-packages",
+"redirect_document_id": true
+},
+{
"source_path": "windows/configure/configure-mobile.md",
"redirect_url": "/windows/configuration/mobile-devices/configure-mobile",
"redirect_document_id": true
@@ -13619,5 +13624,62 @@
"source_path": "windows/security/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md",
"redirect_url": "/windows/security/threat-protection/windows-defender-atp/time-settings-windows-defender-advanced-threat-protection",
"redirect_document_id": true
-}]
+},
+{
+"source_path": "windows/configuration/basic-level-windows-diagnostic-events-and-fields-1703.md",
+"redirect_url": "/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/basic-level-windows-diagnostic-events-and-fields-1709.md",
+"redirect_url": "/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/basic-level-windows-diagnostic-events-and-fields.md",
+"redirect_url": "/windows/privacy/basic-level-windows-diagnostic-events-and-fields",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/configure-windows-diagnostic-data-in-your-organization.md",
+"redirect_url": "/windows/privacy/configure-windows-diagnostic-data-in-your-organization",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/diagnostic-data-viewer-overview.md",
+"redirect_url": "/windows/privacy/diagnostic-data-viewer-overview",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/enhanced-diagnostic-data-windows-analytics-events-and-fields.md",
+"redirect_url": "/windows/privacy/enhanced-diagnostic-data-windows-analytics-events-and-fields",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/gdpr-win10-whitepaper.md",
+"redirect_url": "/windows/privacy/gdpr-win10-whitepaper",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/manage-connections-from-windows-operating-system-components-to-microsoft-services.md",
+"redirect_url": "/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/manage-windows-endpoints-version-1709.md",
+"redirect_url": "/windows/privacy/manage-windows-endpoints",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/windows-diagnostic-data-1703.md",
+"redirect_url": "/windows/privacy/windows-diagnostic-data-1703",
+"redirect_document_id": true
+},
+{
+"source_path": "windows/configuration/windows-diagnostic-data.md",
+"redirect_url": "/windows/privacy/windows-diagnostic-data",
+"redirect_document_id": true
+},
+
+]
}
diff --git a/browsers/edge/available-policies.md b/browsers/edge/available-policies.md
index 8cc05b0bf9..4994e63ed6 100644
--- a/browsers/edge/available-policies.md
+++ b/browsers/edge/available-policies.md
@@ -14,14 +14,14 @@ ms.date: 4/30/2018
# Group Policy and Mobile Device Management (MDM) settings for Microsoft Edge
-> Applies to: Windows 10, Windows 10 Mobile
+> Applies to: Windows 10, Windows 10 Mobile
Microsoft Edge works with Group Policy and Microsoft Intune to help you manage your organization's computer settings. Group Policy objects (GPOs) can include registry-based Administrative Template policy settings, security settings, software deployment information, scripts, folder redirection, and preferences.
By using Group Policy and Intune, you can set up a policy setting once, and then copy that setting onto many computers. For example, you can set up multiple security settings in a GPO that is linked to a domain, and then apply all of those settings to every computer in the domain.
> [!NOTE]
-> For more info about the tools you can use to change your Group Policy objects, see the Internet Explorer 11 topics, [Group Policy and the Group Policy Management Console (GPMC)](https://go.microsoft.com/fwlink/p/?LinkId=617921), [Group Policy and the Local Group Policy Editor](https://go.microsoft.com/fwlink/p/?LinkId=617922), [Group Policy and the Advanced Group Policy Management (AGPM)](https://go.microsoft.com/fwlink/p/?LinkId=617923), and [Group Policy and Windows PowerShell](https://go.microsoft.com/fwlink/p/?LinkId=617924).
+> For more info about the tools you can use to change your Group Policy objects, see the Internet Explorer 11 topics, [Group Policy and the Group Policy Management Console (GPMC)](https://go.microsoft.com/fwlink/p/?LinkId=617921), [Group Policy and the Local Group Policy Editor](https://go.microsoft.com/fwlink/p/?LinkId=617922), [Group Policy and the Advanced Group Policy Management (AGPM)](https://go.microsoft.com/fwlink/p/?LinkId=617923), and [Group Policy and Windows PowerShell](https://go.microsoft.com/fwlink/p/?LinkId=617924).
Microsoft Edge works with the following Group Policy settings to help you manage your company's web browser configurations. The Group Policy settings are found in the Group Policy Editor in the following location:
@@ -36,7 +36,7 @@ You can configure Microsoft Edge to use a shared folder to store books from the
If enabled, a shared books folder is allowed.
-If disabled, a shared books folder not allowed.
+If disabled, a shared books folder not allowed.
**MDM settings in Microsoft Intune**
| | |
@@ -82,7 +82,7 @@ Adobe Flash is integrated with Microsoft Edge and is updated via Windows Update.
## Allow clearing browsing data on exit
>*Supported versions: Windows 10, version 1703*
-Your browsing data is the information that Microsoft Edge remembers and stores as you browse websites. Browsing data includes information you entered into forms, passwords, and the websites you visited. By default, this policy is disabled or not configured, the browsing data is not cleared when exiting. When this policy is disabled or not configured, you can turn on and configure the Clear browsing data option under Settings.
+Your browsing data is the information that Microsoft Edge remembers and stores as you browse websites. Browsing data includes information you entered forms, passwords, and the websites you visited. By default, this policy is disabled or not configured, the browsing data is not cleared when exiting. When this policy is disabled or not configured, you can turn on and configure the Clear browsing data option under Settings.
**Microsoft Intune to manage your MDM settings**
@@ -115,7 +115,7 @@ not configured. If disabled, Microsoft Edge does not retrieve the Books configur
## Allow Cortana
>*Supported versions: Windows 10, version 1607 or later*
-Cortana is integrated with Microsoft Edge, and when enabled, Cortana allows you use the voice assistant on your device. If disabled, Cortana is not available for use, but you can search to find items on your device.
+Cortana is integrated with Microsoft Edge, and when enabled, Cortana allows you to use the voice assistant on your device. If disabled, Cortana is not available for use, but you can search to find items on your device.
**Microsoft Intune to manage your MDM settings**
| | |
@@ -130,7 +130,7 @@ Cortana is integrated with Microsoft Edge, and when enabled, Cortana allows you
## Allow Developer Tools
>*Supported versions: Windows 10, version 1511 or later*
-F12 developer tools is a suite of tools to help you build and debug your webpage. By default, this policy is enabled making the F12 Developer Tools availabe to use.
+F12 developer tools is a suite of tools to help you build and debug your webpage. By default, this policy is enabled making the F12 Developer Tools available to use.
**Microsoft Intune to manage your MDM settings**
| | |
@@ -205,7 +205,7 @@ Microsoft Edge uses the compatibility list that helps websites with known compat
## Allow search engine customization
>*Supported versions: Windows 10, version 1703 or later*
-This policy setting allows search engine customization for domain-joined or MDM-enrolled devices only. For example, you can change the default search engine or add a new search engine. By default, this setting is enabled allowing you to add new search engines and change the default under Settings. If disabled, you cannot add search enginess or change the default.
+This policy setting allows search engine customization for domain-joined or MDM-enrolled devices only. For example, you can change the default search engine or add a new search engine. By default, this setting is enabled allowing you to add new search engines and change the default under Settings. If disabled, you cannot add search engines or change the default.
For more information, see [Microsoft browser extension policy](https://docs.microsoft.com/en-us/legal/windows/agreements/microsoft-browser-extension-policy).
@@ -216,7 +216,7 @@ For more information, see [Microsoft browser extension policy](https://docs.micr
|Supported devices |Desktop Mobile |
|URI full path |./Vendor/MSFT/Policy/Config/Browser/AllowSearchEngineCustomization |
|Data type | Integer |
-|Allowed values |
**0** - Additional search engines are not allowed and the default cannot be changed in the Address bar.
**1 (default)** - Additional search engines are allowed and the default can be changed in the Address bar.
|
+|Allowed values |
**0** - Additional search engines are not allowed, and the default cannot be changed in the Address bar.
**1 (default)** - Additional search engines are allowed, and the default can be changed in the Address bar.
|
## Allow web content on New Tab page
>*Supported versions: Windows 10*
@@ -230,7 +230,7 @@ If you disable this setting, Microsoft Edge opens a new tab with a blank page. I
If you don't configure this setting, employees can choose how new tabs appears.
-## Always Enable book library
+## Always show the Books Library in Microsoft Edge
>*Supported versions: Windows 10, version 1709 or later*
This policy settings specifies whether to always show the Books Library in Microsoft Edge. By default, this setting is disabled, which means the library is only visible in countries or regions where available. if enabled, the Books Library is always shown regardless of countries or region of activation.
@@ -249,7 +249,7 @@ This policy settings specifies whether to always show the Books Library in Micro
This policy setting, when enabled, lets you add up to five additional search engines. Employees cannot remove these search engines, but they can set any one as the default. By default, this setting is not configured and does not allow additional search engines to be added. If disabled, the search engines added are deleted.
-For each additional search engine you add, specify a link to the OpenSearch XML file that contains, at a minimum, the short name and the URL template (HTTPS) of the search engine. For more information about creating the OpenSearch XML file, see [Search provider discovery](https://developer.microsoft.com/en-us/microsoft-edge/platform/documentation/dev-guide/browser/search-provider-discovery/).
+For each additional search engine, you add, specify a link to the OpenSearch XML file that contains, at a minimum, the short name and the URL template (HTTPS) of the search engine. For more information about creating the OpenSearch XML file, see [Search provider discovery](https://developer.microsoft.com/en-us/microsoft-edge/platform/documentation/dev-guide/browser/search-provider-discovery/).
This setting does not set the default search engine. For that, you must use the "Set default search engine" setting.
@@ -293,7 +293,7 @@ This policy setting specifies whether cookies are allowed. By default, this sett
## Configure Do Not Track
>*Supported versions: Windows 10*
-This policy setting specifies whether Do Not Track requests to websites is allowed. By default, this setting is not configured allowing you to choose whether or not to send tracking information. If enabled, Do Not Track requests are always sent to websites asking for tracking information. If disabled, Do Not Track requests are never sent.
+This policy setting specifies whether Do Not Track requests to websites is allowed. By default, this setting is not configured allowing you to choose if to send tracking information. If enabled, Do Not Track requests are always sent to websites asking for tracking information. If disabled, Do Not Track requests are never sent.
**Microsoft Intune to manage your MDM settings**
| | |
@@ -317,7 +317,7 @@ If you disable or don't configure this setting, employees will see the Favorites
## Configure Password Manager
>*Supported versions: Windows 10*
-This policy setting specifies whether saving and managing passwords locally on the device is allowed. By default, this setting is enabled allowing you to save their passwords locally. If not configured, you can choose whether or not to save and manage passwords locally. If disabled, saving and managing passwords locally is turned off.
+This policy setting specifies whether saving and managing passwords locally on the device is allowed. By default, this setting is enabled allowing you to save their passwords locally. If not configured, you can choose if to save and manage passwords locally. If disabled, saving and managing passwords locally is turned off.
**Microsoft Intune to manage your MDM settings**
| | |
@@ -373,7 +373,7 @@ This policy setting specifies your Start pages for domain-joined or MDM-enrolled
## Configure the Adobe Flash Click-to-Run setting
>*Supported versions: Windows 10, version 1703 or later*
-This policy setting specifies whether you must take action, such as clicking the content or a Click-to-Run button, before seeing content in Adobe Flash. By default, this setting is enabled. when the setting is enabled, you must click the content, Click-to-Run button, or have the site appear on an auto-allow list before before the Adobe Flash content loads. If disabled, Adobe Flash loads and runs automatically.
+This policy setting specifies whether you must take action, such as clicking the content or a Click-to-Run button, before seeing content in Adobe Flash. By default, this setting is enabled. When the setting is enabled, you must click the content, Click-to-Run button, or have the site appear on an auto-allow list before the Adobe Flash content loads. If disabled, Adobe Flash loads and runs automatically.
**Microsoft Intune to manage your MDM settings**
| | |
@@ -405,7 +405,7 @@ This policy setting lets you configure whether to use Enterprise Mode and the En
## Configure Windows Defender SmartScreen
>*Supported versions: Windows 10*
-This policy setting specifies whether Windows Defender SmartScreen is allowed. By default, this setting is enabled or turned on and you cannot turn it off. If disabled, Windows Defender SmartScreen is turned off and you cannot turn it on. If not configured, you can choose whether to use Windows Defender SmartScreen.
+This policy setting specifies whether Windows Defender SmartScreen is allowed. By default, this setting is enabled or turned on, and you cannot turn it off. If disabled, Windows Defender SmartScreen is turned off, and you cannot turn it on. If not configured, you can choose whether to use Windows Defender SmartScreen.
**Microsoft Intune to manage your MDM settings**
| | |
@@ -434,7 +434,7 @@ This policy setting specifies whether the lockdown on the Start pages is disable
## Do not sync
>*Supported versions: Windows 10*
-This policy setting specifies whether you can use the Sync your Settings option to sync their settings to and from their device. By default, this setting is disabled or not configured, which means the Sync your Settings options are turned on, letting you pick what can sync on their device. If enabled, the Sync your Settings options are turned off and none of the Sync your Setting groups are synced on the device. You can use the Allow users to turn syncing on option to turn the feature off by default, but to let the employee change this setting. For information about what settings are sync'ed, see [About sync setting on Windows 10 devices](http://windows.microsoft.com/windows-10/about-sync-settings-on-windows-10-devices).
+This policy setting specifies whether you can use the Sync your Settings option to sync their settings to and from their device. By default, this setting is disabled or not configured, which means the Sync your Settings options are turned on, letting you pick what can sync on their device. If enabled, the Sync your Settings options are turned off and none of the Sync your Setting groups are synced on the device. You can use the Allow users to turn syncing on the option to turn the feature off by default, but to let the employee change this setting. For information about what settings are synced, see [About sync setting on Windows 10 devices](http://windows.microsoft.com/windows-10/about-sync-settings-on-windows-10-devices).
**Microsoft Intune to manage your MDM settings**
| | |
@@ -557,7 +557,7 @@ This policy setting specifies whether to enable or disable the First Run webpage
>*Supported versions: Windows 10, version 1511 or later*
-This policy setting specifies whether localhost IP address are visible or hiddle while making phone calls to the WebRTC protocol. By default, this setting is disabled or not configured (turned off), which means the localhost IP address are visible. If enabled (turned on), localhost IP addresses are hidden.
+This policy setting specifies whether localhost IP address is visible or hidden while making phone calls to the WebRTC protocol. By default, this setting is disabled or not configured (turned off), which means the localhost IP address is visible. If enabled (turned on), localhost IP addresses are hidden.
**Microsoft Intune to manage your MDM settings**
| | |
@@ -632,7 +632,7 @@ To set the default search engine, you must specify a link to the OpenSearch XML
>*Supported versions: Windows 10, version 1607 and later*
-This policy setting specifies whether you see an additional page in Microsoft Edge when opening sites that are configured to open in Internet Explorer using the Enterprise Site List. By default, this policy is disabled, which means no additional pages display. If enabled, you see an additional page.
+This policy setting specifies whether you see an additional page in Microsoft Edge when opening sites that are configured to open in Internet Explorer using the Enterprise Site List. By default, this policy is disabled, which means no additional page’s display. If enabled, you see an additional page.
**Microsoft Intune to manage your MDM settings**
| | |
diff --git a/browsers/edge/change-history-for-microsoft-edge.md b/browsers/edge/change-history-for-microsoft-edge.md
index 1958fa170c..219f27ed38 100644
--- a/browsers/edge/change-history-for-microsoft-edge.md
+++ b/browsers/edge/change-history-for-microsoft-edge.md
@@ -5,7 +5,9 @@ ms.prod: edge
ms.mktglfcycl: explore
ms.sitesec: library
ms.localizationpriority: high
-ms.date: 09/19/2017
+ms.date: ''
+ms.author: pashort
+author: shortpatti
---
# Change history for Microsoft Edge
diff --git a/browsers/edge/img-microsoft-edge-infographic-lg.md b/browsers/edge/img-microsoft-edge-infographic-lg.md
index e9d8b67cc2..cb3a42f1b9 100644
--- a/browsers/edge/img-microsoft-edge-infographic-lg.md
+++ b/browsers/edge/img-microsoft-edge-infographic-lg.md
@@ -2,6 +2,8 @@
description: A full-sized view of the Microsoft Edge infographic.
title: Full-sized view of the Microsoft Edge infographic
ms.date: 11/10/2016
+ms.author: pashort
+author: shortpatti
---
Return to: [Browser: Microsoft Edge and Internet Explorer 11](enterprise-guidance-using-microsoft-edge-and-ie11.md)
diff --git a/browsers/edge/security-enhancements-microsoft-edge.md b/browsers/edge/security-enhancements-microsoft-edge.md
index 40952d55dc..2d9f3ad066 100644
--- a/browsers/edge/security-enhancements-microsoft-edge.md
+++ b/browsers/edge/security-enhancements-microsoft-edge.md
@@ -7,6 +7,8 @@ ms.pagetype: security
title: Security enhancements for Microsoft Edge (Microsoft Edge for IT Pros)
ms.localizationpriority: high
ms.date: 10/16/2017
+ms.author: pashort
+author: shortpatti
---
# Security enhancements for Microsoft Edge
diff --git a/browsers/internet-explorer/TOC.md b/browsers/internet-explorer/TOC.md
index 5991583d77..229def58e0 100644
--- a/browsers/internet-explorer/TOC.md
+++ b/browsers/internet-explorer/TOC.md
@@ -1,7 +1,11 @@
#[IE11 Deployment Guide for IT Pros](ie11-deploy-guide/index.md)
+
##[Change history for the Internet Explorer 11 (IE11) Deployment Guide](ie11-deploy-guide/change-history-for-internet-explorer-11.md)
+
##[System requirements and language support for Internet Explorer 11](ie11-deploy-guide/system-requirements-and-language-support-for-ie11.md)
+
##[List of updated features and tools - Internet Explorer 11 (IE11)](ie11-deploy-guide/updated-features-and-tools-with-ie11.md)
+
##[Install and Deploy Internet Explorer 11 (IE11)](ie11-deploy-guide/install-and-deploy-ie11.md)
###[Customize Internet Explorer 11 installation packages](ie11-deploy-guide/customize-ie11-install-packages.md)
####[Using IEAK 11 to create packages](ie11-deploy-guide/using-ieak11-to-create-install-packages.md)
@@ -18,8 +22,11 @@
####[Deploy Internet Explorer 11 using Automatic Version Synchronization (AVS)](ie11-deploy-guide/deploy-ie11-using-automatic-version-synchronization-avs.md)
####[Deploy Internet Explorer 11 using software distribution tools](ie11-deploy-guide/deploy-ie11-using-software-distribution-tools.md)
###[Virtualization and compatibility with Internet Explorer 11](ie11-deploy-guide/virtualization-and-compatibility-with-ie11.md)
+
##[Collect data using Enterprise Site Discovery](ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md)
+
##[Enterprise Mode for Internet Explorer 11 (IE11)](ie11-deploy-guide/enterprise-mode-overview-for-ie11.md)
+###[Tips and tricks to manage Internet Explorer compatibility](ie11-deploy-guide/tips-and-tricks-to-manage-ie-compatibility.md)
###[Enterprise Mode and the Enterprise Mode Site List](ie11-deploy-guide/what-is-enterprise-mode.md)
###[Set up Enterprise Mode logging and data collection](ie11-deploy-guide/set-up-enterprise-mode-logging-and-data-collection.md)
###[Turn on Enterprise Mode and use a site list](ie11-deploy-guide/turn-on-enterprise-mode-and-use-a-site-list.md)
@@ -57,6 +64,8 @@
###[Remove sites from a local Enterprise Mode site list](ie11-deploy-guide/remove-sites-from-a-local-enterprise-mode-site-list.md)
###[Remove sites from a local compatibility view list](ie11-deploy-guide/remove-sites-from-a-local-compatibililty-view-list.md)
###[Turn off Enterprise Mode](ie11-deploy-guide/turn-off-enterprise-mode.md)
+
+
##[Group Policy and Internet Explorer 11 (IE11)](ie11-deploy-guide/group-policy-and-ie11.md)
###[Group Policy management tools](ie11-deploy-guide/group-policy-objects-and-ie11.md)
####[Group Policy and the Group Policy Management Console (GPMC)](ie11-deploy-guide/group-policy-and-group-policy-mgmt-console-ie11.md)
@@ -71,10 +80,12 @@
###[Group policy preferences and Internet Explorer 11](ie11-deploy-guide/group-policy-preferences-and-ie11.md)
###[Administrative templates and Internet Explorer 11](ie11-deploy-guide/administrative-templates-and-ie11.md)
###[Enable and disable add-ons using administrative templates and group policy](ie11-deploy-guide/enable-and-disable-add-ons-using-administrative-templates-and-group-policy.md)
+
##[Manage Internet Explorer 11](ie11-deploy-guide/manage-ie11-overview.md)
###[Auto detect settings Internet Explorer 11](ie11-deploy-guide/auto-detect-settings-for-ie11.md)
###[Auto configuration settings for Internet Explorer 11](ie11-deploy-guide/auto-configuration-settings-for-ie11.md)
###[Auto proxy configuration settings for Internet Explorer 11](ie11-deploy-guide/auto-proxy-configuration-settings-for-ie11.md)
+
##[Troubleshoot Internet Explorer 11 (IE11)](ie11-deploy-guide/troubleshoot-ie11.md)
###[Setup problems with Internet Explorer 11](ie11-deploy-guide/setup-problems-with-ie11.md)
###[Install problems with Internet Explorer 11](ie11-deploy-guide/install-problems-with-ie11.md)
@@ -87,14 +98,27 @@
###[Fix font rendering problems by turning off natural metrics](ie11-deploy-guide/turn-off-natural-metrics.md)
###[Intranet problems with Internet Explorer 11](ie11-deploy-guide/intranet-problems-and-ie11.md)
###[Browser cache changes and roaming profiles](ie11-deploy-guide/browser-cache-changes-and-roaming-profiles.md)
+
##[Out-of-date ActiveX control blocking](ie11-deploy-guide/out-of-date-activex-control-blocking.md)
+###[Blocked out-of-date ActiveX controls](ie11-deploy-guide/blocked-out-of-date-activex-controls.md)
+
##[Deprecated document modes and Internet Explorer 11](ie11-deploy-guide/deprecated-document-modes.md)
+
##[What is the Internet Explorer 11 Blocker Toolkit?](ie11-deploy-guide/what-is-the-internet-explorer-11-blocker-toolkit.md)
+###[Internet Explorer 11 delivery through automatic updates](ie11-deploy-guide/ie11-delivery-through-automatic-updates.md)
+###[Internet Explorer 11 Blocker Toolkit FAQ](ie11-faq/faq-ie11-blocker-toolkit.md)
+
##[Missing Internet Explorer Maintenance settings for Internet Explorer 11](ie11-deploy-guide/missing-internet-explorer-maintenance-settings-for-ie11.md)
+
##[Missing the Compatibility View Button](ie11-deploy-guide/missing-the-compatibility-view-button.md)
+
##[Deploy pinned websites using Microsoft Deployment Toolkit (MDT) 2013](ie11-deploy-guide/deploy-pinned-sites-using-mdt-2013.md)
+
#[IE11 Frequently Asked Questions (FAQ) Guide for IT Pros](ie11-faq/faq-for-it-pros-ie11.md)
+
#[Internet Explorer Administration Kit 11 (IEAK 11) - Administration Guide for IT Pros](ie11-ieak/index.md)
+##[What IEAK can do for you](ie11-ieak/what-ieak-can-do-for-you.md)
+##[Internet Explorer Administration Kit (IEAK) information and downloads](ie11-ieak/ieak-information-and-downloads.md)
##[Before you start using IEAK 11](ie11-ieak/before-you-create-custom-pkgs-ieak11.md)
###[Hardware and software requirements for IEAK 11](ie11-ieak/hardware-and-software-reqs-ieak11.md)
###[Determine the licensing version and features to use in IEAK 11](ie11-ieak/licensing-version-and-features-ieak11.md)
@@ -112,7 +136,9 @@
###[Create multiple versions of your custom package using IEAK 11](ie11-ieak/create-multiple-browser-packages-ieak11.md)
###[Before you install your package over your network using IEAK 11](ie11-ieak/prep-network-install-with-ieak11.md)
###[Use the RSoP snap-in to review policy settings](ie11-ieak/rsop-snapin-for-policy-settings-ieak11.md)
+###[IEAK 11 - Frequently Asked Questions](ie11-faq/faq-ieak11.md)
###[Troubleshoot custom package and IEAK 11 problems](ie11-ieak/troubleshooting-custom-browser-pkg-ieak11.md)
+
##[Internet Explorer Administration Kit 11 (IEAK 11) Customization Wizard options](ie11-ieak/ieak11-wizard-custom-options.md)
###[Use the File Locations page in the IEAK 11 Wizard](ie11-ieak/file-locations-ieak11-wizard.md)
###[Use the Platform Selection page in the IEAK 11 Wizard](ie11-ieak/platform-selection-ieak11-wizard.md)
@@ -140,6 +166,7 @@
###[Use the Programs page in the IEAK 11 Wizard](ie11-ieak/programs-ieak11-wizard.md)
###[Use the Additional Settings page in the IEAK 11 Wizard](ie11-ieak/additional-settings-ieak11-wizard.md)
###[Use the Wizard Complete - Next Steps page in the IEAK 11 Wizard](ie11-ieak/wizard-complete-ieak11-wizard.md)
+
##[Using Internet Settings (.INS) files with IEAK 11](ie11-ieak/using-internet-settings-ins-files.md)
###[Use the Branding .INS file to create custom branding and setup info](ie11-ieak/branding-ins-file-setting.md)
###[Use the BrowserToolbars .INS file to customize the Internet Explorer toolbar](ie11-ieak/browsertoolbars-ins-file-setting.md)
@@ -154,6 +181,7 @@
###[Use the Proxy .INS file to specify a proxy server](ie11-ieak/proxy-ins-file-setting.md)
###[Use the Security Imports .INS file to import security info](ie11-ieak/security-imports-ins-file-setting.md)
###[Use the URL .INS file to use an auto-configured proxy server](ie11-ieak/url-ins-file-setting.md)
+
##[IExpress Wizard for Windows Server 2008 R2 with SP1](ie11-ieak/iexpress-wizard-for-win-server.md)
###[IExpress Wizard command-line options](ie11-ieak/iexpress-command-line-options.md)
###[Internet Explorer Setup command-line options and return codes](ie11-ieak/ie-setup-command-line-options-and-return-codes.md)
diff --git a/browsers/internet-explorer/ie11-deploy-guide/blocked-out-of-date-activex-controls.md b/browsers/internet-explorer/ie11-deploy-guide/blocked-out-of-date-activex-controls.md
new file mode 100644
index 0000000000..2b02482254
--- /dev/null
+++ b/browsers/internet-explorer/ie11-deploy-guide/blocked-out-of-date-activex-controls.md
@@ -0,0 +1,40 @@
+---
+title: Blocked out-of-date ActiveX controls
+description: This page is periodically updated with new ActiveX controls blocked by this feature.
+author: shortpatti
+ms.author: pashort
+manager: elizapo
+ms.date: 05/10/2018
+ms.topic: article
+ms.prod: ie11
+ms.localizationpriority: low
+ms.mktglfcycl: deploy
+ms.pagetype: security
+ms.assetid: ''
+ms.sitesec: library
+---
+
+# Blocked out-of-date ActiveX controls
+
+ActiveX controls are small apps that let websites provide content, like videos and games, and let you interact with content, like toolbars. Unfortunately, because many ActiveX controls aren't automatically updated, they can become outdated as new versions are released. It's very important that you keep your ActiveX controls up to date because malicious software (or malware) can target security flaws in outdated controls, damaging your computer by collecting info from it, installing unwanted software, or by letting someone else control it remotely. To help avoid this situation, Internet Explorer includes a security feature called _out-of-date ActiveX control blocking_.
+
+We'll periodically update this page with new ActiveX controls blocked by this feature. We'll typically provide one month's advance notice before adding new controls to the list.
+
+You will receive a notification if a webpage tries to load one of the following of ActiveX control versions:
+
+**Java**
+
+| Java 2 Platform, Standard Edition (J2SE) 1.4, everything below (but not including) update 43 |
+|----------------------------------------------------------------------------------------------|
+| J2SE 5.0, everything below (but not including) update 99 |
+| Java SE 6, everything below (but not including) update 181 |
+| Java SE 7, everything below (but not including) update 171 |
+| Java SE 8, everything below (but not including) update 161 |
+| Java SE 9, everything below (but not including) update 4 |
+
+**Silverlight**
+
+| Everything below (but not including) Silverlight 5.1.50907.0 |
+|--------------------------------------------------------------|
+
+For more information, see [Out-of-date ActiveX control blocking](out-of-date-activex-control-blocking.md) and [Internet Explorer begins blocking out-of-date ActiveX controls](http://blogs.msdn.com/b/ie/archive/2014/08/06/internet-explorer-begins-blocking-out-of-date-activex-controls.aspx). You can also view Microsoft's complete list of out-of-date ActiveX controls in the XML-based [version list](http://go.microsoft.com/fwlink/?LinkId=403864).
\ No newline at end of file
diff --git a/browsers/internet-explorer/ie11-deploy-guide/ie11-delivery-through-automatic-updates.md b/browsers/internet-explorer/ie11-deploy-guide/ie11-delivery-through-automatic-updates.md
new file mode 100644
index 0000000000..559b4b45ed
--- /dev/null
+++ b/browsers/internet-explorer/ie11-deploy-guide/ie11-delivery-through-automatic-updates.md
@@ -0,0 +1,137 @@
+---
+ms.localizationpriority: low
+ms.mktglfcycl: support
+ms.pagetype: security
+description:
+author: shortpatti
+ms.author: pashort
+ms.manager: elizapo
+ms.prod: ie11
+ms.assetid:
+title: Internet Explorer 11 delivery through automatic updates
+ms.sitesec: library
+ms.date: 05/10/2018
+---
+
+# Internet Explorer 11 delivery through automatic updates
+Internet Explorer 11 makes browsing the web faster, easier, safer, and more reliable than ever. To help customers become more secure and up-to-date, Microsoft will distribute Internet Explorer 11 through Automatic Updates and the Windows Update and Microsoft Update sites. Internet Explorer 11 will be available for users of the 32-bit and 64-bit versions of Windows 7 Service Pack 1 (SP1), and 64-bit version of Windows Server 2008 R2 SP1. This article provides an overview of the delivery process and options available for IT administrators to control how and when Internet Explorer 11 is deployed to their organization through Automatic Updates.
+
+- [Automatic updates delivery process](#automatic-updates-delivery-process)
+- [Internet Explorer 11 automatic upgrades](#internet-explorer-11-automatic-upgrades)
+- [Options for blocking automatic delivery](#options-for-blocking-automatic-delivery)
+- [Availability of Internet Explorer 11](#availability-of-internet-explorer 11)
+- [Prevent automatic installation of Internet Explorer 11 with WSUS](#prevent-automatic-installation-of-internet-explorer-11-with-wsus)
+
+
+## Automatic updates delivery process
+
+Internet Explorer 11 only downloads and installs if it’s available for delivery through Automatic Updates; and Automatic Updates only offer Internet Explorer 11
+to users with local administrator accounts. User’s without local administrator accounts won’t be prompted to install the update and will continue using their
+current version of Internet Explorer.
+
+Internet Explorer 11 replaces Internet Explorer 8, Internet Explorer 9, or Internet Explorer 10. If you decide you don’t want Internet Explorer 11, and you’re running Windows 7 SP1 or Windows Server 2008 R2 with SP1, you can uninstall it from the **View installed updates** section of the **Uninstall an update** page of the Control Panel.
+
+>[!Note]
+>If a user installs Internet Explorer 11 and then removes it, it won’t be re-offered to that computer through Automatic Updates. Instead, the user will have to manually re-install the app.
+
+## Internet Explorer 11 automatic upgrades
+
+Internet Explorer 11 is offered through Automatic Updates and Windows Update as an Important update. Users running Windows 7 SP1, who have chosen to download and install updates automatically through Windows Update, are automatically upgraded to Internet Explorer 11.
+
+Users who were automatically upgraded to Internet Explorer 11 can decide to uninstall Internet Explorer 11. However, Internet Explorer 11 will still appear as an optional update through Windows Update.
+
+## Options for blocking automatic delivery
+
+If you use Automatic Updates in your company, but want to stop your users from automatically getting Internet Explorer 11, do one of the following:
+
+- **Download and use the Internet Explorer 11 Blocker Toolkit.** Includes a Group Policy template and a script that permanently blocks Internet Explorer 11 from being offered by Windows Update or Microsoft Update as a high-priority update. You can download this kit from the [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=40722).
+
+ >[!Note]
+ >The toolkit won't stop users with local administrator accounts from manually installing Internet Explorer 11. Using this toolkit also prevents your users from receiving automatic upgrades from Internet Explorer 8, Internet Explorer 9, or Internet Explorer 10 to Internet Explorer 11. For more information, see the [Internet Explorer 11 Blocker Toolkit frequently asked questions](../ie11-faq/faq-ie11-blocker-toolkit.md).
+
+- **Use an update management solution to control update deployment.**
+ If you already use an update management solution, like [Windows Server Update Services (WSUS)](https://docs.microsoft.com/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus) or the more advanced [System Center 2012 Configuration Manager](http://go.microsoft.com/fwlink/?LinkID=276664), you should use that instead of the Internet Explorer Blocker Toolkit.
+
+ >[!Note]
+ >If you use WSUS to manage updates, and Update Rollups are configured for automatic installation, Internet Explorer will automatically install throughout your company. This scenario is discussed in detail in the Knowledge Base article [here](http://support.microsoft.com/kb/946202).
+
+Additional information on Internet Explorer 11, including a Readiness Toolkit, technical overview, in-depth feature summary, and Internet Explorer 11 download is available on the [Internet Explorer 11 page of the Microsoft Edge IT Center](https://technet.microsoft.com/microsoft-edge/dn262703.aspx).
+
+## Availability of Internet Explorer 11
+
+Automatic Updates will start to distribute Internet Explorer 11 shortly after the final release of the product and will distribute it through the System Center Configuration Manager, Microsoft Systems Management Server, and WSUS.
+
+## Prevent automatic installation of Internet Explorer 11 with WSUS
+
+Internet Explorer 11 will be released to WSUS as an Update Rollup package. Therefore, if you’ve configured WSUS to “auto-approve” Update Rollup packages, it’ll be automatically approved and installed. To stop Internet Explorer 11 from being automatically approved for installation, you need to:
+
+1. Click **Start**, click **Administrative Tools**, and then click **Microsoft
+ Windows Server Update Services 3.0**.
+
+2. Expand *ComputerName*, and then click **Options**.
+
+3. Click **Automatic Approvals**.
+
+4. Click the rule that automatically approves an update that is classified as
+ Update Rollup, and then click **Edit.**
+
+ >[!Note]
+ >If you don’t see a rule like this, you most likely haven’t configured WSUS to automatically approve Update Rollups for installation. In this situation, you don’t have to do anything else.
+
+5. Click the **Update Rollups** property under the **Step 2: Edit the properties (click an underlined value)** section.
+
+ >[!Note]
+ >The properties for this rule will resemble the following:
When an update is in Update Rollups
Approve the update for all computers
+
+6. Clear the **Update Rollup** check box, and then click **OK**.
+
+7. Click **OK** to close the **Automatic Approvals** dialog box.
After the new Internet Explorer 11 package is available for download, you should manually synchronize the new package to your WSUS server, so that when you re-enable auto-approval it won’t be automatically installed.
+
+8. Click **Start**, click **Administrative Tools**, and then click **Microsoft Windows Server Update Services 3.0**.
+
+9. Expand *ComputerName*, and then click **Synchronizations**.
+
+10. Click **Synchronize Now**.
+
+11. Expand *ComputerName*, expand **Updates**, and then click **All Updates**.
+
+12. Choose **Unapproved** in the **Approval**drop down box.
+
+13. Check to make sure that Microsoft Internet Explorer 11 is listed as an unapproved update.
+
+ >[!Note]
+ >There may be multiple updates, depending on the imported language and operating system updates.
+
+**Optional**
+
+If you need to reset your Update Rollups packages to auto-approve, do this:
+
+1. Click **Start**, click **Administrative Tools**, and then click **Microsoft Windows Server Update Services 3.0**.
+
+2. Expand *ComputerName*, and then click **Options**.
+
+3. Click **Automatic Approvals**.
+
+4. Click the rule that automatically approves updates of different classifications, and then click **Edit**.
+
+5. Click the **Update Rollups** property under the **Step 2: Edit the properties (click an underlined value)** section.
+
+6. Check the **Update Rollups** check box, and then click **OK**.
+
+7. Click **OK** to close the **Automatic Approvals** dialog box.
+
+>[!Note]
+>Because auto-approval rules are only evaluated when an update is first imported into WSUS, turning this rule back on after the Internet Explorer 11 update has been imported and synchronized to the server won’t cause this update to be auto-approved.
+
+
+## Additional resources
+
+- [Automatic delivery process](what-is-the-internet-explorer-11-blocker-toolkit.md#automatic-delivery-process)
+
+- [Internet Explorer 11 Blocker Toolkit download](https://www.microsoft.com/download/details.aspx?id=40722)
+
+- [Internet Explorer 11 FAQ for IT pros](https://docs.microsoft.com/internet-explorer/ie11-faq/faq-for-it-pros-ie11)
+
+- [Internet Explorer 11 delivery through automatic updates](https://technet.microsoft.com/microsoft-edge/dn449235)
+
+- [Internet Explorer 11 deployment guide](https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/index)
diff --git a/browsers/internet-explorer/ie11-deploy-guide/images/img-enterprise-mode-site-list-xml.jpg b/browsers/internet-explorer/ie11-deploy-guide/images/img-enterprise-mode-site-list-xml.jpg
new file mode 100644
index 0000000000..0bcfd3b650
Binary files /dev/null and b/browsers/internet-explorer/ie11-deploy-guide/images/img-enterprise-mode-site-list-xml.jpg differ
diff --git a/browsers/internet-explorer/ie11-deploy-guide/images/img-f12-developer-tools-emulation.jpg b/browsers/internet-explorer/ie11-deploy-guide/images/img-f12-developer-tools-emulation.jpg
new file mode 100644
index 0000000000..48ed75b701
Binary files /dev/null and b/browsers/internet-explorer/ie11-deploy-guide/images/img-f12-developer-tools-emulation.jpg differ
diff --git a/browsers/internet-explorer/ie11-deploy-guide/out-of-date-activex-control-blocking.md b/browsers/internet-explorer/ie11-deploy-guide/out-of-date-activex-control-blocking.md
index 9bcd6e6ec8..8b6848b28d 100644
--- a/browsers/internet-explorer/ie11-deploy-guide/out-of-date-activex-control-blocking.md
+++ b/browsers/internet-explorer/ie11-deploy-guide/out-of-date-activex-control-blocking.md
@@ -3,12 +3,13 @@ ms.localizationpriority: low
ms.mktglfcycl: deploy
ms.pagetype: security
description: Use out-of-date ActiveX control blocking to help you know when IE prevents a webpage from loading outdated ActiveX controls and to update the outdated control, so that it’s safer to use.
-author: eross-msft
+author: shortpatti
+ms.author: pashort
ms.prod: ie11
ms.assetid: e61866bb-1ff1-4a8d-96f2-61d3534e8199
title: Out-of-date ActiveX control blocking (Internet Explorer 11 for IT Pros)
ms.sitesec: library
-ms.date: 07/27/2017
+ms.date: 05/10/2018
---
@@ -47,7 +48,8 @@ It also works with these operating system and IE combinations:
|Windows Server 2008 SP2 |Windows Internet Explorer 9 only |
|Windows Vista SP2 |Windows Internet Explorer 9 only |
-For more info about this new feature, see the [Internet Explorer begins blocking out-of-date ActiveX controls](https://go.microsoft.com/fwlink/p/?LinkId=507691) blog. To see the complete list of out-of-date Active controls blocked by this feature, see [Blocked out-of-date ActiveX controls](https://go.microsoft.com/fwlink/p/?LinkId=517023).
+For more info about this new feature, see the [Internet Explorer begins blocking out-of-date ActiveX controls](https://go.microsoft.com/fwlink/p/?LinkId=507691) blog. To see the complete list of out-of-date Active controls blocked by this feature, see [Blocked out-of-date ActiveX controls](blocked-out-of-date-activex-controls.md).
+
## What does the out-of-date ActiveX control blocking notification look like?
When IE blocks an outdated ActiveX control, you’ll see a notification bar similar to this, depending on your version of IE:
diff --git a/browsers/internet-explorer/ie11-deploy-guide/tips-and-tricks-to-manage-ie-compatibility.md b/browsers/internet-explorer/ie11-deploy-guide/tips-and-tricks-to-manage-ie-compatibility.md
new file mode 100644
index 0000000000..378bcf0af5
--- /dev/null
+++ b/browsers/internet-explorer/ie11-deploy-guide/tips-and-tricks-to-manage-ie-compatibility.md
@@ -0,0 +1,133 @@
+---
+ms.localizationpriority: low
+ms.mktglfcycl: deploy
+ms.pagetype: appcompat
+description: Find out how to achieve better backward compatibility for your legacy web applications with the Enterprise Mode Site List.
+author: shortpatti
+ms.author: pashort
+ms.prod: ie11
+ms.assetid:
+title: Tips and tricks to manage Internet Explorer compatibility
+ms.sitesec: library
+ms.date: 05/10/2018
+---
+
+# Tips and tricks to manage Internet Explorer compatibility
+
+Find out how to achieve better backward compatibility for your legacy web applications with the Enterprise Mode Site List.
+
+Jump to:
+- [Tips for IT professionals](#tips-for-it-professionals)
+- [Tips for web developers](#tips-for-web-developers)
+
+[Enterprise Mode for Internet Explorer 11](enterprise-mode-overview-for-ie11.md) can be very effective in providing backward compatibility for older web apps. The Enterprise Mode Site List includes the ability to put any web app in any document mode, include IE8 and IE7 Enterprise Modes, without changing a single line of code on the website.
+
+
+
+Sites in the \ section can be rendered in any document mode, as shown in blue above. Some sites designed for older versions of Internet Explorer may require better backward compatibility, and these can leverage the \ section of the Enterprise Mode Site List. IE8 Enterprise Mode provides higher-fidelity emulation for Internet Explorer 8 by using, among other improvements, the original Internet Explorer 8 user agent string. IE7 Enterprise Mode further improves emulation by adding Compatibility View.
+
+Compatibility View, first introduced with Internet Explorer 8, is basically a switch. If a webpage has no DOCTYPE, that page will be rendered in Internet Explorer 5 mode. If there is a DOCTYPE, the page will be rendered in Internet Explorer 7 mode. You can effectively get Compatibility View by specifying Internet Explorer 7 in the \ section, as this falls back to Internet Explorer 5 automatically if there's no DOCTYPE, or you can use IE7 Enterprise Mode for even better emulation.
+
+## Tips for IT professionals
+
+### Inventory your sites
+
+Upgrading to a new browser can be a time-consuming and potentially costly venture. To help reduce these costs, you can download the [Enterprise Site Discovery Toolkit](https://www.microsoft.com/download/details.aspx?id=44570), which can help you prioritize which sites you should be testing based on their usage in your enterprise. For example, if the data shows that no one is visiting a particular legacy web app, you may not need to test or fix it. The toolkit is supported on Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11. The toolkit also gives you information about which document mode a page runs in your current browser so you can better understand how to fix that site if it breaks in a newer version of the browser.
+
+Once you know which sites to test and fix, the following remediation methods may help fix your compatibility issues in Internet Explorer 11 and Windows 10.
+
+### If you're on Internet Explorer 8 and upgrading to Internet Explorer 11:
+
+Use the Enterprise Mode Site List to add sites to the Internet Explorer 5, Internet Explorer 7, and Internet Explorer 8 documents modes, as well as IE8 Enterprise Mode and IE7 Enterprise Mode.
+
+- Sites with the *x-ua-compatible* meta tag or HTTP header set to "IE=edge" may break in Internet Explorer 11 and need to be set to Internet Explorer 8 mode. This is because "edge" in Internet Explorer 8 meant Internet Explorer 8 mode, but "edge" in Internet Explorer 11 means Internet Explorer 11 mode.
+
+- Sites without a DOCTYPE in zones other than Intranet will default to QME (or "interoperable quirks") rather than Internet Explorer 5 Quirks and may need to be set to Internet Explorer 5 mode.
+
+- Some sites may need to be added to both Enterprise Mode and Compatibility View to work. You can do this by adding the site to IE7 Enterprise Mode.
+
+### If you're on Internet Explorer 9 and upgrading to Internet Explorer 11:
+
+Use the Enterprise Mode Site List to add sites to the Internet Explorer 5, Internet Explorer 7, and Internet Explorer 9 document modes.
+
+- Sites with the *x-ua-compatible* meta tag or HTTP header set to "IE=edge" may break in Internet Explorer 11 and need to be set to Internet Explorer 9 mode. This is because "edge" in Internet Explorer 9 meant Internet Explorer 9 mode, but "edge" in Internet Explorer 11 means Internet Explorer 11 mode.
+
+- Sites without a DOCTYPE in zones other than Intranet will default to Interoperable Quirks rather than Internet Explorer 5 Quirks and may need to be set to Internet Explorer 5 mode.
+
+- If your sites worked in Internet Explorer 9, you won't need IE8 Enterprise Mode or IE7 Enterprise Mode.
+
+### If you're on Internet Explorer 10 and upgrading to Internet Explorer 11:
+
+Use the Enterprise Mode Site List to add sites to the Internet Explorer 5, Internet Explorer 7, and Internet Explorer 10 modes.
+
+- Sites with the *x-ua-compatible* meta tag or HTTP header set to "IE=edge" may break in Internet Explorer 11 and need to be set to Internet Explorer 10 mode. This is because "edge" in Internet Explorer 10 meant Internet Explorer 10 mode, but "edge" in Internet Explorer 11 means Internet Explorer 11 mode.
+
+- If your sites worked in Internet Explorer 10, you won't need IE8 Enterprise Mode or IE7 Enterprise Mode.
+
+### If you're on Internet Explorer 11 and upgrading to Windows 10:
+
+You're all set! You shouldn’t need to make any changes.
+
+## Tips for web developers
+
+If your website worked in an older version of Internet Explorer, but no longer works in Internet Explorer 11, you may need to update the site. Here are the set of steps you should take to find the appropriate remediation strategy.
+
+### Try document modes
+
+To see if the site works in the Internet Explorer 5, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, or Internet Explorer 11 document modes:
+
+- Open the site in Internet Explorer 11, load the F12 tools by pressing the **F12** key or by selecting **F12 Developer Tools** from the **Tools** menu, and select the **Emulation** tab.
+
+ 
+
+- Run the site in each document mode until you find the mode in which the site works.
+
+ >[!NOTE]
+ >You will need to make sure the User agent string dropdown matches the same browser version as the Document mode dropdown. For example, if you were testing to see if the site works in Internet Explorer 10, you should update the Document mode dropdown to 10 and the User agent string dropdown to Internet Explorer 10.
+
+- If you find a mode in which your site works, you will need to add the site domain, sub-domain, or URL to the Enterprise Mode Site List for the document mode in which the site works, or ask the IT administrator to do so. You can add the *x-ua-compatible* meta tag or HTTP header as well.
+
+### Try IE8 Enterprise Mode
+
+If a document mode didn't fix your site, try IE8 Enterprise Mode, which benefits sites written for Internet Explorer 5, Internet Explorer 7, and Internet Explorer 8 document modes.
+
+- Enable the **Let users turn on and use Enterprise Mode from the Tools menu** policy locally on your machine. To do this:
+
+ - Search for and run **gpedit.msc**
+
+ - Navigate to **Computer Configuration** \> **Administrative Template** \> **Windows Components** \> **Internet Explorer**.
+
+ - Enable the **Let users turn on and use Enterprise Mode from the Tools menu** Group Policy setting.
+
+ After making this change, run **gpupdate.exe /force** to make sure the setting is applied locally. You should also make sure to disable this setting once you're done testing. Alternately, you can use a regkey; see [Turn on local control and logging for Enterprise Mode](turn-on-local-control-and-logging-for-enterprise-mode.md) for more information.
+
+- Restart Internet Explorer 11 and open the site you're testing, then go to **Emulation** tab in the **F12 Developer Tools** and select **Enterprise** from the **Browser profile** dropdown. If the site works, inform the IT administrator that the site needs to be added to the IE8 Enterprise Mode section.
+
+### Try IE7 Enterprise Mode
+
+If IE8 Enterprise Mode doesn't work, IE7 Enterprise Mode will give you the Compatibility View behavior that shipped with Internet Explorer 8 with Enterprise Mode. To try this approach:
+
+- Go to the **Tools** menu, select **Compatibility View Settings**, and add the site to the list.
+
+- Go to **Emulation** tab in the **F12 Developer Tools** and select **Enterprise** from the **Browser profile** dropdown.
+
+If the site works, inform the IT administrator that the site needs to be added to the IE7 Enterprise Mode section.\
+
+>[!NOTE]
+>Adding the same Web path to the Enterprise Mode and sections of the Enterprise Mode Site List will not work, but we will address this in a future update.
+
+### Update the site for modern web standards
+
+We recommend that enterprise customers focus their new development on established, modern web standards for better performance and interoperability across devices, and avoid developing sites in older Internet Explorer document modes. We often hear that, due to fact that the Intranet zone defaults to Compatibility View, web developers inadvertently create new sites in the Internet Explorer 7 or Internet Explorer 5 modes in the Intranet zone, depending on whether or not they used a DOCTYPE. As you move your web apps to modern standards, you can enable the **Turn on Internet Explorer Standards Mode for local intranet** Group Policy setting and add those sites that need Internet Explorer 5 or Internet Explorer 7 modes to the Site List. Of course, it is always a good idea to test the app to ensure that these settings work for your environment.
+
+## Related resources
+
+- [Document modes](https://msdn.microsoft.com/library/dn384051(v=vs.85).aspx)
+- [What is Enterprise Mode?](what-is-enterprise-mode.md)
+- [Turn on Enterprise Mode and use a site list](turn-on-enterprise-mode-and-use-a-site-list.md)
+- [Enterprise Site Discovery Toolkit](https://www.microsoft.com/en-us/download/details.aspx?id=44570)
+- [Collect data using Enterprise Site Discovery](collect-data-using-enterprise-site-discovery.md)
+- [Download the Enterprise Mode Site List Manager (schema v.2)](https://go.microsoft.com/fwlink/p/?LinkId=716853)
+- [Download the Enterprise Mode Site List Manager (schema v.1)](https://go.microsoft.com/fwlink/p/?LinkID=394378)
+- [Add multiple sites to the Enterprise Mode site list using a file and the Enterprise Mode Site List Manager (schema v.1)](add-multiple-sites-to-enterprise-mode-site-list-using-the-version-1-schema-and-enterprise-mode-tool.md)
+- [Add multiple sites to the Enterprise Mode site list using a file and the Enterprise Mode Site List Manager (schema v.2)](add-multiple-sites-to-enterprise-mode-site-list-using-the-version-2-schema-and-enterprise-mode-tool.md)
\ No newline at end of file
diff --git a/browsers/internet-explorer/ie11-deploy-guide/what-is-the-internet-explorer-11-blocker-toolkit.md b/browsers/internet-explorer/ie11-deploy-guide/what-is-the-internet-explorer-11-blocker-toolkit.md
index 7cedb8e908..d69d91584e 100644
--- a/browsers/internet-explorer/ie11-deploy-guide/what-is-the-internet-explorer-11-blocker-toolkit.md
+++ b/browsers/internet-explorer/ie11-deploy-guide/what-is-the-internet-explorer-11-blocker-toolkit.md
@@ -10,7 +10,7 @@ ms.prod: ie11
ms.assetid: fafeaaee-171c-4450-99f7-5cc7f8d7ba91
title: What is the Internet Explorer 11 Blocker Toolkit? (Internet Explorer 11 for IT Pros)
ms.sitesec: library
-ms.date: 04/24/2018
+ms.date: 05/10/2018
---
@@ -135,79 +135,16 @@ After the new Internet Explorer 11 package is available for download, you should
>[!NOTE]
>Because auto-approval rules are only evaluated when an update is first imported into WSUS, turning this rule back on after the Internet Explorer 11 update has been imported and synchronized to the server won’t cause this update to be auto-approved.
-## Frequently Asked Questions
-Get answers to commonly asked questions about the Internet Explorer 11 Blocker Toolkit.
-
-### Automatic updates delivery process
-**Q. What tools can I use to manage Windows Updates and Microsoft Updates in my company?**
-A. We encourage anyone who wants full control over their company’s deployment of Windows Updates and Microsoft Updates, to use [Windows Server Update Services (WSUS)](https://docs.microsoft.com/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus), a free tool for users of Windows Server. You can also use the more advanced configuration management tool, [System Center 2012 Configuration Manager](https://technet.microsoft.com/library/gg682041.aspx).
-
-**Q. How long does the blocker mechanism work?**
-A. The Internet Explorer 11 Blocker Toolkit uses a registry key value to permanently turn off the automatic delivery of Internet Explorer 11. This behavior lasts as long as the registry key value isn’t removed or changed.
-
-**Q. Why should I use the Internet Explorer 11 Blocker Toolkit to stop delivery of Internet Explorer 11? Why can’t I just disable all of utomatic Updates?**
-A. Automatic Updates provide you with ongoing critical security and reliability updates. Turning this feature off can leave your computers more vulnerable. Instead, we suggest that you use an update management solution, such as WSUS, to fully control your environment while leaving this feature running, managing how and when the updates get to your user’s computers.
-
-The Internet Explorer 11 Blocker Toolkit safely allows Internet Explorer 11 to download and install in companies that can’t use WSUS, Configuration Manager, or other update management solution.
-
-**Q. Why don’t we just block URL access to Windows Update or Microsoft Update?**
-A. Blocking the Windows Update or Microsoft Update URLs also stops delivery of critical security and reliability updates for all of the supported versions of the Windows operating system; leaving your computers more vulnerable.
-
-### How the Internet Explorer 11 Blocker Toolkit works
-
-**Q. How should I test the Internet Explorer 11 Blocker Toolkit in my company?**
-A. Because the toolkit only sets a registry key to turn on and off the delivery of Internet Explorer 11, there should be no additional impact or side effects to your environment. No additional testing should be necessary.
-
-**Q. What’s the registry key used to block delivery of Internet Explorer 11?**
-A. HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Setup\\11.0
-
-**Q. What’s the registry key name and values?**
-The registry key name is **DoNotAllowIE11**, where:
-
-- A value of **1** turns off the automatic delivery of Internet Explorer 11
- using Automatic Updates and turns off the Express install option.
-
-- Not providing a registry key, or using a value of anything other than **1**,
- lets the user install Internet Explorer 11 through Automatic Updates or a
- manual update.
-
-**Q. Does the Internet Explorer 11 Blocker Toolkit stop users from manually installing Internet Explorer 11?**
-A. No. The Internet Explorer 11 Blocker Toolkit only stops computers from automatically installing Internet Explorer 11 through Automatic Updates. Users can still download and install Internet Explorer 11 from the Microsoft Download Center or from external media.
-
-**Q. Does the Internet Explorer 11 Blocker Toolkit stop users from automatically upgrading to Internet Explorer 11?**
-A. Yes. The Internet Explorer 11 Blocker Toolkit also prevents Automatic Updates from automatically upgrading a computer from Internet Explorer 8, Internet Explorer 9, or Internet Explorer 10 to Internet Explorer 11.
-
-**Q. How does the provided script work?**
-A. The script accepts one of two command line options:
-
-- **Block:** Creates the registry key that stops Internet Explorer 11 from installing through Automatic Updates.
-
-- **Unblock:** Removes the registry key that stops Internet Explorer 11 from installing through Automatic Updates.
-
-**Q. What’s the ADM template file used for?**
-A. The Administrative Template (.adm file) lets you import the new Group Policy environment and use Group Policy Objects to centrally manage all of the computers in your company.
-
-**Q. Is the tool localized?**
-A. No. The tool isn’t localized, it’s only available in English (en-us). However, it does work, without any modifications, on any language edition of the supported operating systems.
-
-### Internet Explorer 11 Blocker Toolkit and other update services
-
-**Q. Does the Internet Explorer 11 blocking mechanism also block delivery of Internet Explorer 11 through update management solutions, like SUS?**
-A. No. You can still deploy Internet Explorer 11 using one of the upgrade management solutions, even if the blocking mechanism is activated. The Internet Explorer 11 Blocker Toolkit is only intended for companies that don’t use upgrade management solutions.
-
-**Q. If WSUS is set to 'auto-approve' Update Rollup packages (this is not the default configuration), how do I stop Internet Explorer 11 from automatically installing throughout my company?**
-A. You only need to change your settings if:
-
-- You use WSUS to manage updates and allow auto-approvals for Update Rollup installation.
-
- -and-
-
-- You have computers running either Windows 7 SP1 or Windows Server 2008 R2 (SP1) with Internet Explorer 8, Internet Explorer 9, or Internet Explorer 10 installed.
-
- -and-
-
-- You don’t want to upgrade your older versions of Internet Explorer to Internet Explorer 11 right now.
-
-If these scenarios apply to your company, see [Internet Explorer 11 delivery through automatic updates](https://technet.microsoft.com/microsoft-edge/dn449235) for more information on how to prevent automatic installation.
+## Additional resources
+
+- [Internet Explorer 11 Blocker Toolkit download](https://www.microsoft.com/download/details.aspx?id=40722)
+
+- [Internet Explorer 11 Blocker Toolkit - Frequently Asked Questions](../ie11-faq/faq-ie11-blocker-toolkit.md)
+
+- [Internet Explorer 11 FAQ for IT pros](https://docs.microsoft.com/internet-explorer/ie11-faq/faq-for-it-pros-ie11)
+
+- [Internet Explorer 11 delivery through automatic updates](ie11-delivery-through-automatic-updates.md)
+
+- [Internet Explorer 11 deployment guide](https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/index)
diff --git a/browsers/internet-explorer/ie11-faq/faq-for-it-pros-ie11.md b/browsers/internet-explorer/ie11-faq/faq-for-it-pros-ie11.md
index d9b27be715..8722543ac2 100644
--- a/browsers/internet-explorer/ie11-faq/faq-for-it-pros-ie11.md
+++ b/browsers/internet-explorer/ie11-faq/faq-for-it-pros-ie11.md
@@ -114,18 +114,11 @@ IE11 includes all of the previous Group Policy settings you've used to manage an
For more information, see [New group policy settings for IE11](../ie11-deploy-guide/new-group-policy-settings-for-ie11.md).
-**Q: Is there a version of the Internet Explorer Administration Kit (IEAK) supporting IE11?**
-Yes. The Internet Explorer Administration Kit 11 (IEAK 11) is available for download. IEAK 11 lets you create custom versions of IE11 for use in your organization. For more information, see the following resources:
-
-- [Internet Explorer Administration Kit Information and Downloads](https://go.microsoft.com/fwlink/p/?LinkId=214250) on the Internet Explorer TechCenter.
-
-- [Internet Explorer Administration Kit 11 (IEAK 11) - Administrator's Guide](../ie11-ieak/index.md)
**Q: Where can I get more information about IE11 for IT pros?**
Visit the [Springboard Series for Microsoft Browsers](https://go.microsoft.com/fwlink/p/?LinkId=313191) webpage on TechNet.
-**Q: Is there a version of the Internet Explorer Blocker Toolkit that will prevent automatic installation of IE11?**
-Yes. The IE11 Blocker Toolkit is available for download. For more information, see [Toolkit to Disable Automatic Delivery of IE11](https://go.microsoft.com/fwlink/p/?LinkId=328195) on the Microsoft Download Center.
+
**Q: Can I customize settings for IE on Windows 8.1?**
Settings can be customized in the following ways:
@@ -146,7 +139,6 @@ Group Policy settings can be set to open either IE or Internet Explorer for the
|Always in Internet Explorer for the desktop |Links always open in Internet Explorer for the desktop. |
-
**Q. Can IEAK 11 build custom Internet Explorer 11 packages in languages other than the language of the in-use IEAK 11 version?**
Yes. You can use IEAK 11 to build custom Internet Explorer 11 packages in any of the supported 24 languages. You'll select the language for the custom package on the Language Selection page of the customization wizard.
@@ -164,6 +156,7 @@ IEAK 11 is available in 24 languages but can build customized Internet Explorer
+
**Q. What are the different modes available for the Internet Explorer Customization Wizard?**
The IEAK Customization Wizard displays pages based on your licensing mode selection, either **Internal** or **External**. For more information on IEAK Customization Wizard modes, see [Determine the licensing version and features to use in IEAK 11](../ie11-ieak/licensing-version-and-features-ieak11.md).
diff --git a/browsers/internet-explorer/ie11-faq/faq-ie11-blocker-toolkit.md b/browsers/internet-explorer/ie11-faq/faq-ie11-blocker-toolkit.md
new file mode 100644
index 0000000000..5aa814af97
--- /dev/null
+++ b/browsers/internet-explorer/ie11-faq/faq-ie11-blocker-toolkit.md
@@ -0,0 +1,118 @@
+---
+ms.localizationpriority: low
+ms.mktglfcycl: explore
+description: Get answers to commonly asked questions about the Internet Explorer 11 Blocker Toolkit.
+author: shortpatti
+ms.author: pashort
+ms.prod: ie11
+ms.assetid:
+title: Internet Explorer 11 Blocker Toolkit - Frequently Asked Questions
+ms.sitesec: library
+ms.date: 05/10/2018
+---
+
+# Internet Explorer 11 Blocker Toolkit - Frequently Asked Questions
+
+Get answers to commonly asked questions about the Internet Explorer 11 Blocker Toolkit.
+
+>[!Important]
+>If you administer your company’s environment using an update management solution, such as Windows Server Update Services (WSUS) or System Center 2012 Configuration Manager, you don’t need to use the Internet Explorer 11 Blocker Toolkit. Update management solutions let you completely manage your Windows Updates and Microsoft Updates, including your Internet Explorer 11 deployment.
+
+- [Automatic updates delivery process]()
+
+- [How the Internet Explorer 11 Blocker Toolkit works]()
+
+- [Internet Explorer 11 Blocker Toolkit and other update services]()
+
+## Automatic Updates delivery process
+
+
+**Q. Which users will receive Internet Explorer 11 as an important update?**
+A. Users running either Windows 7 with Service Pack 1 (SP1) or the 64-bit version of Windows Server 2008 R2 with Service Pack 1 (SP1) will receive Internet Explorer 11 as an important update, if Automatic Updates are turned on. Windows Update is manually run. Automatic Updates will automatically download and install the Internet Explorer 11 files if it’s turned on. For more information about how Internet Explorer works with Automatic Updates and information about other deployment blocking options, see [Internet Explorer 11 Delivery through automatic updates](../ie11-deploy-guide/ie11-delivery-through-automatic-updates.md).
+
+**Q. When is the Blocker Toolkit available?**
+A. The Blocker Toolkit is currently available from the [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=40722).
+
+**Q. What tools can I use to manage Windows Updates and Microsoft Updates in my company?**
+A. We encourage anyone who wants full control over their company’s deployment of Windows Updates and Microsoft Updates, to use [Windows Server Update Services (WSUS)](https://docs.microsoft.com/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus), a free tool for users of Windows Server. You can also use the more advanced configuration management tool, [System Center 2012 Configuration Manager](https://technet.microsoft.com/library/gg682041.aspx).
+
+**Q. How long does the blocker mechanism work?**
+A. The Internet Explorer 11 Blocker Toolkit uses a registry key value to permanently turn off the automatic delivery of Internet Explorer 11. This behavior lasts as long as the registry key value isn’t removed or changed.
+
+**Q. Why should I use the Internet Explorer 11 Blocker Toolkit to stop delivery of Internet Explorer 11? Why can’t I just disable all of Automatic Updates?**
+A. Automatic Updates provide you with ongoing critical security and reliability updates. Turning this feature off can leave your computers more vulnerable. Instead, we suggest that you use an update management solution, such as WSUS, to fully control your environment while leaving this feature running, managing how and when the updates get to your user’s computers.
+
+The Internet Explorer 11 Blocker Toolkit safely allows Internet Explorer 11 to download and install in companies that can’t use WSUS, Configuration Manager, or
+other update management solution.
+
+**Q. Why don’t we just block URL access to Windows Update or Microsoft Update?**
+A. Blocking the Windows Update or Microsoft Update URLs also stops delivery of critical security and reliability updates for all of the supported versions of the Windows operating system; leaving your computers more vulnerable.
+
+How the Internet Explorer 11 Blocker Toolkit works
+
+**Q. How should I test the Internet Explorer 11 Blocker Toolkit in my company?**
+A. Because the toolkit only sets a registry key to turn on and off the delivery of Internet Explorer 11, there should be no additional impact or side effects to your environment. No additional testing should be necessary.
+
+**Q. What’s the registry key used to block delivery of Internet Explorer 11?**
+A. HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Setup\\11.0
+
+**Q. What’s the registry key name and values?**
+The registry key name is **DoNotAllowIE11**, where:
+
+- A value of **1** turns off the automatic delivery of Internet Explorer 11 using Automatic Updates and turns off the Express install option.
+
+- Not providing a registry key, or using a value of anything other than **1**, lets the user install Internet Explorer 11 through Automatic Updates or a
+ manual update.
+
+**Q. Does the Internet Explorer 11 Blocker Toolkit stop users from manually installing Internet Explorer 11?**
+A. No. The Internet Explorer 11 Blocker Toolkit only stops computers from automatically installing Internet Explorer 11 through Automatic Updates. Users can still download and install Internet Explorer 11 from the Microsoft Download Center or from external media.
+
+**Q. Does the Internet Explorer 11 Blocker Toolkit stop users from automatically upgrading to Internet Explorer 11?**
+A. Yes. The Internet Explorer 11 Blocker Toolkit also prevents Automatic Updates from automatically upgrading a computer from Internet Explorer 8, Internet Explorer 9, or Internet Explorer 10 to Internet Explorer 11.
+
+**Q. How does the provided script work?**
+A. The script accepts one of two command line options:
+
+- **Block:** Creates the registry key that stops Internet Explorer 11 from installing through Automatic Updates.
+
+- **Unblock:** Removes the registry key that stops Internet Explorer 11 from installing through Automatic Updates.
+
+**Q. What’s the ADM template file used for?**
+A. The Administrative Template (.adm file) lets you import the new Group Policy environment and use Group Policy Objects to centrally manage all of the computers in your company.
+
+**Q. Is the tool localized?**
+A. No. The tool isn’t localized, it’s only available in English (en-us). However, it does work, without any modifications, on any language edition of the supported operating systems.
+
+## Internet Explorer 11 Blocker Toolkit and other update services
+
+**Q: Is there a version of the Internet Explorer Blocker Toolkit that will prevent automatic installation of IE11?**
+Yes. The IE11 Blocker Toolkit is available for download. For more information, see [Toolkit to Disable Automatic Delivery of IE11](https://go.microsoft.com/fwlink/p/?LinkId=328195) on the Microsoft Download Center.
+
+**Q. Does the Internet Explorer 11 blocking mechanism also block delivery of Internet Explorer 11 through update management solutions, like WSUS?**
+A. No. You can still deploy Internet Explorer 11 using one of the upgrade management solutions, even if the blocking mechanism is activated. The Internet Explorer 11 Blocker Toolkit is only intended for companies that don’t use upgrade management solutions.
+
+**Q. If WSUS is set to 'auto-approve' Update Rollup packages (this is not the default configuration), how do I stop Internet Explorer 11 from automatically installing throughout my company?**
+A. You only need to change your settings if:
+
+- You use WSUS to manage updates and allow auto-approvals for Update Rollup installation.
+
+ -and-
+
+- You have computers running either Windows 7 SP1 or Windows Server 2008 R2 (SP1) with Internet Explorer 8, Internet Explorer 9, or Internet Explorer 10 installed.
+
+ -and-
+
+- You don’t want to upgrade your older versions of Internet Explorer to Internet Explorer 11 right now.
+
+If these scenarios apply to your company, see [Internet Explorer 11 delivery through automatic updates](../ie11-deploy-guide/ie11-delivery-through-automatic-updates.md) for more information on how to prevent automatic installation.
+
+
+## Additional resources
+
+- [Internet Explorer 11 Blocker Toolkit download](https://www.microsoft.com/download/details.aspx?id=40722)
+
+- [Internet Explorer 11 FAQ for IT pros](https://docs.microsoft.com/internet-explorer/ie11-faq/faq-for-it-pros-ie11)
+
+- [Internet Explorer 11 delivery through automatic updates](../ie11-deploy-guide/ie11-delivery-through-automatic-updates.md)
+
+- [Internet Explorer 11 deployment guide](https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/index)
diff --git a/browsers/internet-explorer/ie11-faq/faq-ieak11.md b/browsers/internet-explorer/ie11-faq/faq-ieak11.md
new file mode 100644
index 0000000000..092cf003e6
--- /dev/null
+++ b/browsers/internet-explorer/ie11-faq/faq-ieak11.md
@@ -0,0 +1,117 @@
+---
+ms.localizationpriority: low
+ms.mktglfcycl: support
+ms.pagetype: security
+description: Internet Explorer Administration Kit (IEAK) helps corporations, Internet service providers (ISPs), Internet content providers (ICPs), and independent software vendors (ISVs) to deploy and manage web-based solutions.
+author: shortpatti
+ms.author: pashort
+ms.manager: elizapo
+ms.prod: ie11
+ms.assetid:
+title: IEAK 11 - Frequently Asked Questions
+ms.sitesec: library
+ms.date: 05/10/2018
+---
+
+# IEAK 11 - Frequently Asked Questions
+
+Get answers to commonly asked questions about the Internet Explorer Administration Kit 11 (IEAK 11), and find links to additional material you might find helpful.
+
+**What is IEAK 11?**
+
+IEAK 11 enables you to customize, brand, and distribute customized Internet Explorer 11 browser packages across an organization. Download the kit from the [Internet Explorer Administration Kit (IEAK) information and downloads](../ie11-ieak/ieak-information-and-downloads.md).
+
+**What are the supported operating systems?**
+
+You can customize and install IEAK 11 on the following supported operating systems:
+
+- Windows 8
+
+- Windows Server 2012
+
+- Windows 7 Service Pack 1 (SP1)
+
+- Windows Server 2008 R2 Service Pack 1 (SP1)
+
+>[!Note]
+>IEAK 11 does not support building custom packages for Windows RT.
+
+
+**What can I customize with IEAK 11?**
+
+The IEAK 11 enables you to customize branding and settings for Internet Explorer 11. For PCs running Windows 7, the custom package also includes the Internet Explorer executable.
+
+>[!Note]
+>Internet Explorer 11 is preinstalled on PCs running Windows 8. Therefore, the executable is not included in the customized package.
+
+**Can IEAK 11 build custom Internet Explorer 11 packages in languages other than the language of the in-use IEAK 11 version?**
+Yes. You can use IEAK 11 to build custom Internet Explorer 11 packages in any of the supported 24 languages. You'll select the language for the custom package on the Language Selection page of the customization wizard.
+
+>[!Note]
+>IEAK 11 is available in 24 languages but can build customized Internet Explorer 11 packages in all languages of the supported operating systems. To download IEAK 11, see [Internet Explorer Administration Kit (IEAK) information and downloads](../ie11-ieak/ieak-information-and-downloads.md).
+
+**Q: Is there a version of the Internet Explorer Administration Kit (IEAK) supporting IE11?**
+Yes. The Internet Explorer Administration Kit 11 (IEAK 11) is available for download. IEAK 11 lets you create custom versions of IE11 for use in your organization. For more information, see the following resources:
+
+- [Internet Explorer Administration Kit Information and Downloads](https://go.microsoft.com/fwlink/p/?LinkId=214250) on the Internet Explorer TechCenter.
+
+- [Internet Explorer Administration Kit 11 (IEAK 11) - Administrator's Guide](../ie11-ieak/index.md)
+
+**What are the different modes available for the Internet Explorer Customization Wizard?**
+The IEAK Customization Wizard displays pages based on your licensing mode selection, either **Internal** or **External**. For more information on IEAK Customization Wizard modes, see [What IEAK can do for you](../ie11-ieak/what-ieak-can-do-for-you.md).
+
+The following table displays which pages are available in IEAK 11, based on the licensing mode:
+
+| **Wizard Pages** | **External** | **Internal** |
+|-------------------------------------------|--------------|--------------|
+| Welcome to the IEAK | Yes | Yes |
+| File Locations | Yes | Yes |
+| Platform Selection | Yes | Yes |
+| Language Selection | Yes | Yes |
+| Package Type Selection | Yes | Yes |
+| Feature Selection | Yes | Yes |
+| Automatic Version Synchronization | Yes | Yes |
+| Custom Components | Yes | Yes |
+| Corporate Install | No | Yes |
+| User Experience | No | Yes |
+| Browser User Interface | Yes | Yes |
+| Search Providers | Yes | Yes |
+| Important URLs - Home page and Support | Yes | Yes |
+| Accelerators | Yes | Yes |
+| Favorites, Favorites Bar, and Feeds | Yes | Yes |
+| Browsing Options | No | Yes |
+| First Run Wizard and Welcome Page Options | Yes | Yes |
+| Compatibility View | Yes | Yes |
+| Connection Manager | Yes | Yes |
+| Connection Settings | Yes | Yes |
+| Automatic Configuration | No | Yes |
+| Proxy Settings | Yes | Yes |
+| Security and Privacy Settings | No | Yes |
+| Add a Root Certificate | Yes | No |
+| Programs | Yes | Yes |
+| Additional Settings | No | Yes |
+| Wizard Complete | Yes | Yes |
+
+
+**Q. Can IEAK 11 build custom Internet Explorer 11 packages in languages other than the language of the in-use IEAK 11 version?**
+Yes. You can use IEAK 11 to build custom Internet Explorer 11 packages in any of the supported 24 languages. You'll select the language for the custom package on the Language Selection page of the customization wizard.
+
+IEAK 11 is available in 24 languages but can build customized Internet Explorer 11 packages in all languages of the supported operating systems. Select a language below and download IEAK 11 from the download center:
+| | | |
+|---------|---------|---------|
+|[English](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/en-us/ieak.msi) |[French](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/fr-fr/ieak.msi) |[Norwegian (Bokmål)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/nb-no/ieak.msi) |
+|[Arabic](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/ar-sa/ieak.msi) |[Chinese (Simplified)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/zh-cn/ieak.msi) |[Chinese(Traditional)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/zh-tw/ieak.msi) |
+|[Czech](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/cs-cz/ieak.msi) |[Danish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/da-dk/ieak.msi) |[Dutch](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/nl-nl/ieak.msi) |
+|[Finnish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/fi-fi/ieak.msi) |[German](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/de-de/ieak.msi) |[Greek](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/el-gr/ieak.msi) |
+|[Hebrew](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/he-il/ieak.msi) |[Hungarian](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/hu-hu/ieak.msi) |[Italian](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/it-it/ieak.msi) |
+|[Japanese](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/ja-jp/ieak.msi) |[Korean](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/ko-kr/ieak.msi) |[Polish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/pl-pl/ieak.msi) |
+|[Portuguese (Brazil)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/pt-br/ieak.msi) |[Portuguese (Portugal)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/pt-pt/ieak.msi) |[Russian](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/ru-ru/ieak.msi) |
+|[Spanish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/es-es/ieak.msi) |[Swedish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/sv-se/ieak.msi) |[Turkish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/tr-tr/ieak.msi) |
+
+
+## Additional resources
+
+[Download IEAK 11](https://technet.microsoft.com/microsoft-edge/bb219517)
+[IEAK 11 overview](https://technet.microsoft.com/microsoft-edge/dn532244)
+[IEAK 11 product documentation](https://docs.microsoft.com/internet-explorer/ie11-ieak/index)
+[IEAK 11 licensing guidelines](../ie11-ieak/licensing-version-and-features-ieak11.md)
diff --git a/browsers/internet-explorer/ie11-ieak/ieak-information-and-downloads.md b/browsers/internet-explorer/ie11-ieak/ieak-information-and-downloads.md
new file mode 100644
index 0000000000..ad6689257a
--- /dev/null
+++ b/browsers/internet-explorer/ie11-ieak/ieak-information-and-downloads.md
@@ -0,0 +1,46 @@
+---
+ms.localizationpriority: low
+ms.mktglfcycl: support
+ms.pagetype: security
+description: The Internet Explorer Administration Kit (IEAK) simplifies the creation, deployment, and management of customized Internet Explorer packages. You can use the IEAK to configure the out-of-box Internet Explorer experience or to manage user settings after Internet Explorer deployment.
+author: shortpatti
+ms.author: pashort
+ms.manager: elizapo
+ms.prod: ie11
+ms.assetid:
+title: Internet Explorer Administration Kit (IEAK) information and downloads
+ms.sitesec: library
+ms.date: 05/10/2018
+---
+
+# Internet Explorer Administration Kit (IEAK) information and downloads
+
+The Internet Explorer Administration Kit (IEAK) simplifies the creation, deployment, and management of customized Internet Explorer packages. You can use the IEAK to configure the out-of-box Internet Explorer experience or to manage user settings after Internet Explorer deployment. To find more information on the IEAK, see [What IEAK can do for you](what-ieak-can-do-for-you.md).
+
+## Internet Explorer Administration Kit 11 (IEAK 11)
+
+[IEAK 11 documentation](index.md)
+
+[IEAK 11 licensing guidelines](licensing-version-and-features-ieak11.md)
+
+[IEAK 11 - Frequently Asked Questions](../ie11-faq/faq-ieak11.md)
+
+[Internet Explorer Administration Kit 11 (IEAK 11) - Administrator's Guide](before-you-create-custom-pkgs-ieak11.md)
+
+## Download IEAK
+
+To download, choose to **Open** the download or **Save** it to your hard drive first.
+
+
+| | | |
+|---------|---------|---------|
+|[English](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/en-us/ieak.msi) |[French](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/fr-fr/ieak.msi) |[Norwegian (Bokmål)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/nb-no/ieak.msi) |
+|[Arabic](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/ar-sa/ieak.msi) |[German](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/de-de/ieak.msi) |[Polish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/pl-pl/ieak.msi) |
+|[Chinese (Simplified)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/zh-cn/ieak.msi) |[Greek](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/el-gr/ieak.msi) |[Portuguese (Brazil)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/pt-br/ieak.msi) |
+|[Chinese (Traditional)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/zh-tw/ieak.msi) |[Hebrew](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/he-il/ieak.msi) |[Portuguese (Portugal)](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/pt-pt/ieak.msi) |
+|[Czech](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/cs-cz/ieak.msi) |[Hungarian](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/hu-hu/ieak.msi) |[Russian](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/ru-ru/ieak.msi) |
+|[Danish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/da-dk/ieak.msi) |[Italian](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/it-it/ieak.msi) |[Spanish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/es-es/ieak.msi) |
+|[Dutch](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/nl-nl/ieak.msi) |[Japanese](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/ja-jp/ieak.msi) |[Swedish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/sv-se/ieak.msi) |
+|[Finnish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/fi-fi/ieak.msi) |[Korean](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/ko-kr/ieak.msi) |[Turkish](http://download.microsoft.com/download/A/B/1/AB1954BF-8B20-4F01-808A-FE5EE5269F08/MSI/tr-tr/ieak.msi) |
+
+
diff --git a/browsers/internet-explorer/ie11-ieak/index.md b/browsers/internet-explorer/ie11-ieak/index.md
index b0edeae7c4..998e7264d7 100644
--- a/browsers/internet-explorer/ie11-ieak/index.md
+++ b/browsers/internet-explorer/ie11-ieak/index.md
@@ -17,38 +17,9 @@ The Internet Explorer Administration Kit (IEAK) simplifies the creation, deploym
Use this guide to learn about the several options and processes you'll need to consider while you're using the Internet Explorer Administration Kit 11 (IEAK 11) to customize, deploy, and manage Internet Explorer 11 for your employee's devices.
->[!IMPORTANT}
+>[!IMPORTANT]
>Because this content isn't intended to be a step-by-step guide, not all of the steps are necessary.
-## IEAK 11 users
-Internet Explorer Administration Kit (IEAK) helps corporations, Internet service providers (ISPs), Internet content providers (ICPs), and independent software vendors (ISVs) to deploy and manage web-based solutions.
-
-IEAK 10 and newer includes the ability to install using one of the following installation modes:
-- Internal
-- External
-
->[!NOTE]
->IEAK 11 works in network environments, with or without Microsoft Active Directory service.
-
-### Corporations
-IEAK helps corporate administrators establish version control, centrally distribute and manage browser installation, configure automatic connection profiles, and customize large portions of Internet Explorer, including features, security, communications settings, and other important functionality.
-
-Corporate administrators install IEAK using Internal mode (for Internet Explorer 10 or newer) or Corporate mode (for Internet Explorer 9 or older).
-
-### Internet service providers
-IEAK helps ISPs customize, deploy and distribute, add third-party add-ons, search providers, and custom components, as well as include web slices and accelerators all as part of a custom Internet Explorer installation package.
-
-ISPs install IEAK using External mode (for Internet Explorer 10 or newer) or Internet Service Provider (ISP) mode (for Internet Explorer 9 or older).
-
-### Internet content providers
-IEAK helps ICPs customize the appearance of Internet Explorer and its Setup program, including letting you add your company name or specific wording to the Title bar, set up a customer support webpage, set up the user home page and search providers, add links to the Favorites and the Explorer bars, add optional components, web slices and accelerators, and determine which compatibility mode Internet Explorer should use.
-
-ICPs install IEAK using External mode (for Internet Explorer 10 or newer) or Internet Content Provider (ICP) mode (for Internet Explorer 9 or older)
-
-### Independent software vendors
-IEAK helps ISVs distribute (and redistribute) a custom version of Internet Explorer that can include custom components, programs, and controls (like the web browser control) that you create for your users. ISVs can also determine home pages, search providers, and add websites to the Favorites bar.
-
-ISVs install IEAK using External mode (for Internet Explorer 10 or newer) or Internet Content Provider (ICP) mode (for Internet Explorer 9 or older).
## Included technology
IEAK 11 includes the following technology:
@@ -68,7 +39,10 @@ IE11 and IEAK 11 offers differing experiences between Windows 7 and Windows 8.1
|Internet Explorer Customization Wizard 11 |Step-by-step wizard screens that help you create custom IE11 installation packages. |
## Related topics
+- [IEAK 11 - Frequently Asked Questions](../ie11-faq/faq-ieak11.md)
+- [Download IEAK 11](ieak-information-and-downloads.md)
+- [IEAK 11 administrators guide](https://docs.microsoft.com/internet-explorer/ie11-ieak/index)
+- [IEAK 11 licensing guidelines](licensing-version-and-features-ieak11.md)
- [Internet Explorer 11 - FAQ for IT Pros](../ie11-faq/faq-for-it-pros-ie11.md)
- [Internet Explorer 11 (IE11) - Deployment Guide for IT Pros](../ie11-deploy-guide/index.md)
-- [Microsoft Edge - Deployment Guide for IT Pros](https://go.microsoft.com/fwlink/p/?LinkId=760643)
-
+- [Microsoft Edge - Deployment Guide for IT Pros](https://go.microsoft.com/fwlink/p/?LinkId=760643)
\ No newline at end of file
diff --git a/browsers/internet-explorer/ie11-ieak/what-ieak-can-do-for-you.md b/browsers/internet-explorer/ie11-ieak/what-ieak-can-do-for-you.md
new file mode 100644
index 0000000000..afa8430977
--- /dev/null
+++ b/browsers/internet-explorer/ie11-ieak/what-ieak-can-do-for-you.md
@@ -0,0 +1,66 @@
+---
+ms.localizationpriority: low
+ms.mktglfcycl: support
+ms.pagetype: security
+description: Internet Explorer Administration Kit (IEAK) helps corporations, Internet service providers (ISPs), Internet content providers (ICPs), and independent software vendors (ISVs) to deploy and manage web-based solutions.
+author: shortpatti
+ms.author: pashort
+ms.manager: elizapo
+ms.prod: ie11
+ms.assetid:
+title: What IEAK can do for you
+ms.sitesec: library
+ms.date: 05/10/2018
+---
+
+# What IEAK can do for you
+
+Internet Explorer Administration Kit (IEAK) helps corporations, Internet service providers (ISPs), Internet content providers (ICPs), and independent software vendors (ISVs) to deploy and manage web-based solutions.
+
+IEAK 10 and newer includes the ability to install using one of the following installation modes:
+
+- Internal
+
+- External
+
+## IEAK 11 users
+Internet Explorer Administration Kit (IEAK) helps corporations, Internet service providers (ISPs), Internet content providers (ICPs), and independent software vendors (ISVs) to deploy and manage web-based solutions.
+
+IEAK 10 and newer includes the ability to install using one of the following installation modes:
+- Internal
+- External
+
+>[!NOTE]
+>IEAK 11 works in network environments, with or without Microsoft Active Directory service.
+
+
+### Corporations
+IEAK helps corporate administrators establish version control, centrally distribute and manage browser installation, configure automatic connection profiles, and customize large portions of Internet Explorer, including features, security, communications settings, and other important functionality.
+
+Corporate administrators install IEAK using Internal mode (for Internet Explorer 10 or newer) or Corporate mode (for Internet Explorer 9 or older).
+
+### Internet service providers
+IEAK helps ISPs customize, deploy and distribute, add third-party add-ons, search providers, and custom components, as well as include web slices and accelerators all as part of a custom Internet Explorer installation package.
+
+ISPs install IEAK using External mode (for Internet Explorer 10 or newer) or Internet Service Provider (ISP) mode (for Internet Explorer 9 or older).
+
+### Internet content providers
+IEAK helps ICPs customize the appearance of Internet Explorer and its Setup program, including letting you add your company name or specific wording to the Title bar, set up a customer support webpage, set up the user home page and search providers, add links to the Favorites and the Explorer bars, add optional components, web slices and accelerators, and determine which compatibility mode Internet Explorer should use.
+
+ICPs install IEAK using External mode (for Internet Explorer 10 or newer) or Internet Content Provider (ICP) mode (for Internet Explorer 9 or older)
+
+### Independent software vendors
+IEAK helps ISVs distribute (and redistribute) a custom version of Internet Explorer that can include custom components, programs, and controls (like the web browser control) that you create for your users. ISVs can also determine home pages, search providers, and add websites to the Favorites bar.
+
+ISVs install IEAK using External mode (for Internet Explorer 10 or newer) or Internet Content Provider (ICP) mode (for Internet Explorer 9 or older).
+
+## Additional resources
+
+- [IEAK 11 - Frequently Asked Questions](../ie11-faq/faq-ieak11.md)
+- [Download IEAK 11](ieak-information-and-downloads.md)
+- [IEAK 11 overview](index.md)
+- [IEAK 11 administrators guide](https://docs.microsoft.com/internet-explorer/ie11-ieak/index)
+- [IEAK 11 licensing guidelines](licensing-version-and-features-ieak11.md)
+- [Internet Explorer 11 - FAQ for IT Pros](../ie11-faq/faq-for-it-pros-ie11.md)
+- [Internet Explorer 11 (IE11) - Deployment Guide for IT Pros](../ie11-deploy-guide/index.md)
+- [Microsoft Edge - Deployment Guide for IT Pros](https://go.microsoft.com/fwlink/p/?LinkId=760643)
\ No newline at end of file
diff --git a/devices/hololens/TOC.md b/devices/hololens/TOC.md
index b262c23f1c..49d9417151 100644
--- a/devices/hololens/TOC.md
+++ b/devices/hololens/TOC.md
@@ -9,6 +9,8 @@
## [Share HoloLens with multiple people](hololens-multiple-users.md)
## [Configure HoloLens using a provisioning package](hololens-provisioning.md)
## [Install apps on HoloLens](hololens-install-apps.md)
-## [Get ready to preview new mixed reality apps for HoloLens](hololens-public-preview-apps.md)
+## [Preview new mixed reality apps for HoloLens](hololens-public-preview-apps.md)
+### [Microsoft Remote Assist app](hololens-microsoft-remote-assist-app.md)
+### [Microsoft Layout app](hololens-microsoft-layout-app.md)
## [Enable Bitlocker device encryption for HoloLens](hololens-encryption.md)
## [Change history for Microsoft HoloLens documentation](change-history-hololens.md)
\ No newline at end of file
diff --git a/devices/hololens/change-history-hololens.md b/devices/hololens/change-history-hololens.md
index 6b277cfa47..9a7f96a9d6 100644
--- a/devices/hololens/change-history-hololens.md
+++ b/devices/hololens/change-history-hololens.md
@@ -7,14 +7,24 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
-ms.date: 04/30/2018
+ms.date: 05/21/2018
---
# Change history for Microsoft HoloLens documentation
This topic lists new and updated topics in the [Microsoft HoloLens documentation](index.md).
+## May 2018
+
+New or changed topic | Description
+--- | ---
+[Preview new mixed reality apps for HoloLens](hololens-public-preview-apps.md) | New
+[Microsoft Remote Assist app](hololens-microsoft-remote-assist-app.md) | New
+[Microsoft Layout app](hololens-microsoft-layout-app.md) | New
+
## Windows 10 Holographic for Business, version 1803
The topics in this library have been updated for Windows 10 Holographic for Business, version 1803. The following new topics have been added:
diff --git a/devices/hololens/hololens-encryption.md b/devices/hololens/hololens-encryption.md
index a673506578..c600771609 100644
--- a/devices/hololens/hololens-encryption.md
+++ b/devices/hololens/hololens-encryption.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 12/20/2017
---
diff --git a/devices/hololens/hololens-enroll-mdm.md b/devices/hololens/hololens-enroll-mdm.md
index db28187680..fde1f15636 100644
--- a/devices/hololens/hololens-enroll-mdm.md
+++ b/devices/hololens/hololens-enroll-mdm.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/devices/hololens/hololens-install-apps.md b/devices/hololens/hololens-install-apps.md
index badec3873c..d33b78b2a9 100644
--- a/devices/hololens/hololens-install-apps.md
+++ b/devices/hololens/hololens-install-apps.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 12/20/2017
---
diff --git a/devices/hololens/hololens-kiosk.md b/devices/hololens/hololens-kiosk.md
index d17932da87..e2d13d4a96 100644
--- a/devices/hololens/hololens-kiosk.md
+++ b/devices/hololens/hololens-kiosk.md
@@ -6,14 +6,15 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 04/30/2018
---
# Set up HoloLens in kiosk mode
->[!WARNING]
->Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
+
In Windows 10, version 1803, you can configure your HoloLens devices to run as multi-app or single-app kiosks.
diff --git a/devices/hololens/hololens-microsoft-layout-app.md b/devices/hololens/hololens-microsoft-layout-app.md
new file mode 100644
index 0000000000..6e782af99f
--- /dev/null
+++ b/devices/hololens/hololens-microsoft-layout-app.md
@@ -0,0 +1,75 @@
+---
+title: Microsoft Layout
+description: How to get and deploy the Microsoft Layout app throughout your organization
+ms.prod: w10
+ms.mktglfcycl: manage
+ms.pagetype: hololens, devices
+ms.sitesec: library
+author: alhopper-msft
+ms.author: alhopper
+ms.topic: article
+ms.localizationpriority: medium
+ms.date: 05/21/2018
+---
+# Microsoft Layout
+
+Bring designs from concept to completion with confidence and speed. Import 3D models to easily create room layouts in real-world scale. Experience designs as high-quality holograms in physical space or virtual reality and edit with stakeholders in real time. With Microsoft Layout, see ideas in context, saving valuable time and money.
+
+## Device options and technical requirements
+
+Below are the device options, and technical requirements, to use and deploy Microsoft Layout throughout your organization.
+
+### Device options
+
+Microsoft Layout works with a HoloLens, or with a Windows Mixed Reality headset with motion controllers.
+
+#### HoloLens requirements
+
+| OS requirements | Details |
+|:----------------------------------|:-----------------------------------------------------------|
+| Build 10.0.17134.77 or above | See [Manage updates to HoloLens](hololens-updates.md) for instructions on upgrading to this build. |
+
+#### Windows Mixed Reality headset requirements
+
+| Requirements | Details |
+|:----------------------------------------------|:-----------------------------------------------------------|
+| Windows 10 PC with build 16299.0 or higher | The Windows 10 PC hardware must be able to support the headset. See [Windows Mixed Reality PC hardware guidelines](https://support.microsoft.com/en-us/help/4039260/windows-10-mixed-reality-pc-hardware-guidelines) for specific hardware requirements. We recommend following the **Windows Mixed Reality Ultra** hardware guidelines. |
+| Motion controllers | Motion controllers are hardware accessories that allow users to take action in mixed reality. See [Motion controllers](https://docs.microsoft.com/en-us/windows/mixed-reality/motion-controllers) to learn more. |
+
+### Technical requirements
+
+Have the following technical requirements in place to start using Microsoft Layout.
+
+| Requirement | Details | Learn more |
+|:----------------------------------|:------------------|:------------------|
+| Azure Active Directory (Azure AD) | Required for app distribution through the [Microsoft Store for Business](https://docs.microsoft.com/en-us/microsoft-store/sign-up-microsoft-store-for-business). If you choose not to distribute the app through the Microsoft Store for Business, users can also install Layout on a HoloLens or PC from the [Microsoft Store](https://www.microsoft.com/en-us/store/apps). | [Get started with Azure AD](https://docs.microsoft.com/en-us/azure/active-directory/get-started-azure-ad) |
+| Network connectivity | Internet access is required to download the app, and utilize all of its features. There are no bandwidth requirements. | |
+| Apps for sharing | Video calling or screen sharing requires a separate app, such as Microsoft Remote Assist on HoloLens, or Skype or Skype for Business on Windows Mixed Reality headsets.
A Windows 10 PC that meets the Windows Mixed Reality Ultra specifications is also required for video calling or screen sharing when using Layout with a Windows Mixed Reality headset. | [Remote Assist](hololens-microsoft-remote-assist-app.md)
[Windows Mixed Reality PC hardware guidelines](https://support.microsoft.com/en-us/help/4039260/windows-10-mixed-reality-pc-hardware-guidelines) |
+| Import Tool for Microsoft Layout | The Import Tool for Microsoft Layout is a companion app for Layout that makes model optimization and management easy. The Import Tool runs on Windows 10 PCs, and is required to transfer existing 3D models from your PC to Microsoft Layout, so they can be viewed and edited from the HoloLens or mixed reality headset. The Import Tool is also required to transfer Visio space dimensions to the HoloLens or Windows Mixed Reality headset. | [Import Tool for Microsoft Layout](#get-and-deploy-the-import-tool-for-microsoft-layout) |
+
+## Get and deploy Microsoft Layout
+
+Microsoft Layout is available from the Microsoft Store for Business for free for a limited time:
+
+1. Go to the [Microsoft Layout](https://businessstore.microsoft.com/en-us/store/details/app/9NSJN53K3GFJ) app in the Microsoft Store for Business.
+1. Click **Get the app**. Microsoft Layout is added to the **Products and Services** tab for your private store.
+1. Users can open the **Products and Services** tab to install the app to their device, or you can deploy the app throughout your organization using MDM. See [Install apps on HoloLens](hololens-install-apps.md) for further instructions on deploying apps.
+
+For a limited time, users can also [Get Microsoft Layout from the Microsoft Store](https://www.microsoft.com/store/productId/9NSJN53K3GFJ) for free.
+
+### Get and deploy the Import Tool for Microsoft Layout
+
+The **Import Tool for Microsoft Layout** is a companion app for Layout that makes model optimization and management easy. The Import Tool runs on Windows 10 PCs, and is required to transfer existing 3D models from your PC to Microsoft Layout, for viewing and editing on Microsoft HoloLens or a Windows Mixed Reality headset.
+
+The companion app is available in both the Microsoft Store for Business, and the Microsoft Store, for free for a limited time:
+
+* [Get the Microsoft Layout Import Tool](https://businessstore.microsoft.com/en-us/store/details/app/9N88Q3RXPLP0) from the Microsoft Store for Business. See [Distribute apps to your employees from Microsoft Store for Business](https://docs.microsoft.com/en-us/microsoft-store/distribute-apps-to-your-employees-microsoft-store-for-business) for instructions on using the Microsoft Store for Business, and/or MDM, to deploy Windows 10 apps throughout your organization.
+* Alternately, have your users [Get the Microsoft Layout Import Tool](https://www.microsoft.com/store/productId/9N88Q3RXPLP0) from the Microsoft Store to install the app on their Windows 10 PC.
+
+## Use Microsoft Layout
+
+For guidance on using the features of the Microsoft Layout app, please see [Set up and use Microsoft Layout](https://support.microsoft.com/help/4294437).
+
+## Questions and support
+
+You can ask questions and engage with our team in the [Mixed Reality Tech Community](https://techcommunity.microsoft.com/t5/Mixed-Reality/ct-p/MixedReality).
\ No newline at end of file
diff --git a/devices/hololens/hololens-microsoft-remote-assist-app.md b/devices/hololens/hololens-microsoft-remote-assist-app.md
new file mode 100644
index 0000000000..c0338f0e8d
--- /dev/null
+++ b/devices/hololens/hololens-microsoft-remote-assist-app.md
@@ -0,0 +1,67 @@
+---
+title: Microsoft Remote Assist
+description: How to get and deploy the Microsoft Remote Assist app throughout your organization
+ms.prod: w10
+ms.mktglfcycl: manage
+ms.pagetype: hololens, devices
+ms.sitesec: library
+author: alhopper-msft
+ms.author: alhopper
+ms.topic: article
+ms.localizationpriority: medium
+ms.date: 05/21/2018
+---
+# Microsoft Remote Assist
+
+Collaborate remotely with heads-up, hands-free video calling, image sharing, and mixed reality annotations. Firstline workers can share what they see with any expert on Microsoft Teams, while staying hands on to solve problems and complete tasks together, faster. Backed by enterprise-level security, Microsoft Remote Assist enables communication with peace of mind.
+
+## Technical requirements
+
+Below are the technical requirements to deploy and use Microsoft Remote Assist throughout your organization.
+
+### Device requirements
+
+| Device | OS requirements | Details |
+|:---------------------------|:----------------------------------|:-----------------------------------------------------------|
+| HoloLens | Build 10.0.14393.0 or above | See [Manage updates to HoloLens](https://docs.microsoft.com/en-us/HoloLens/hololens-updates) for instructions on using Windows Update for Business, MDM, and Windows Server Update Service (WSUS) to deploy updates to HoloLens. |
+| Windows 10 PC (optional) | Any Windows 10 build | A Windows 10 PC can collaborate with the HoloLens using Microsoft Teams. |
+| Mobile device (optional) | Android or iOS | A mobile device can collaborate with the HoloLens using Microsoft Teams. Inking, annotations, and image insertion are not currently available on mobile. |
+
+> [!Note]
+> HoloLens build 10.0.14393.0 is the minimum that supports Remote Assist. We recommend updating the HoloLens to newer versions when they are available.
+
+### Licensing & product requirements
+
+| Product required | Details | Learn more |
+|:----------------------------------|:------------------|:------------------|
+| Azure Active Directory (Azure AD) | Required to log users into the Remote Assist app through Microsoft Teams. Also required for app distribution through the [Microsoft Store for Business](https://docs.microsoft.com/en-us/microsoft-store/sign-up-microsoft-store-for-business). If you choose not to distribute the app through the Microsoft Store for Business, users can alternately install Remote Assist on a HoloLens or PC from the [Microsoft Store](https://www.microsoft.com/en-us/store/apps). | [Get started with Azure AD](https://docs.microsoft.com/en-us/azure/active-directory/get-started-azure-ad) |
+| Microsoft Teams | Microsoft Teams facilitates communication in Remote Assist. Microsoft Teams must be installed on any device that will make calls to the HoloLens. | [Overview of Microsoft Teams](https://docs.microsoft.com/en-us/MicrosoftTeams/teams-overview) |
+| Microsoft Office 365 | Because Microsoft Teams is part of Office 365, each user who will make calls from their PC/phone to the HoloLens will need an Office 365 license. | [Office 365 licensing for Microsoft Teams](https://docs.microsoft.com/en-us/MicrosoftTeams/office-365-licensing) |
+
+### Network requirements
+
+1.5 MB/s is the recommended bandwidth for optimal performance of Microsoft Remote Assist. Though audio/video calls may be possible in environments with reduced bandwidth, you may experience HoloLens feature degradation, limiting the user experience. To test your company’s network bandwidth, follow these steps:
+
+ 1. Have a mobile Teams user (iOS or Android) video call a desktop Teams user.
+ 2. Add another separate video call between a 3rd and 4th user, and another for a 5th and 6th user.
+ 3. Continue adding video callers to stress test your network bandwidth until confident that multiple users can successfully connect on video calls at the same time.
+
+See [Preparing your organization's network for Microsoft Teams](https://docs.microsoft.com/en-us/MicrosoftTeams/prepare-network) to learn more.
+
+## Get and deploy Microsoft Remote Assist
+
+Microsoft Remote Assist is available from the Microsoft Store for Business for free for a limited time:
+
+1. Go to the [Microsoft Remote Assist](https://businessstore.microsoft.com/en-us/store/details/app/9PPJSDMD680S) app in the Microsoft Store for Business.
+1. Click **Get the app**. Microsoft Remote Assist is added to the **Products and Services** tab for your private store.
+1. Users can open the **Products and Services** tab to install the app to their device, or you can deploy the app throughout your organization using MDM. See [Install apps on HoloLens](hololens-install-apps.md) for further instructions on deploying apps.
+
+For a limited time, users can also [Get Microsoft Remote Assist from the Microsoft Store](https://www.microsoft.com/store/productId/9PPJSDMD680S) for free.
+
+## Use Microsoft Remote Assist
+
+For guidance on using the features of the Microsoft Remote Assist app, please see [Set up and use Microsoft Remote Assist](https://support.microsoft.com/en-us/help/4294812).
+
+## Questions and support
+
+You can ask questions and engage with our team in the [Mixed Reality Tech Community](https://techcommunity.microsoft.com/t5/Mixed-Reality/ct-p/MixedReality).
diff --git a/devices/hololens/hololens-multiple-users.md b/devices/hololens/hololens-multiple-users.md
index b4ed3c8b1c..2f75216d91 100644
--- a/devices/hololens/hololens-multiple-users.md
+++ b/devices/hololens/hololens-multiple-users.md
@@ -6,14 +6,14 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 04/30/2018
---
# Share HoloLens with multiple people
->[!WARNING]
->Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
A HoloLens device can be shared by multiple Azure Active Directory (Azure AD) accounts, each with their own user settings and user data on the device.
@@ -21,7 +21,7 @@ A HoloLens device can be shared by multiple Azure Active Directory (Azure AD) ac
During setup, you must select **My work or school owns it** and sign in with an Azure AD account. After setup, ensure that **Other People** appears in **Settings** > **Accounts**.
-Other people can use the HoloLens device by signing in with their Azure AD account credentials. To switch users, press the power button once to go to standby and then press the power button again to return to the lock screen, or select the user tile on the upper right of th epins panel to sign out the current user.
+Other people can use the HoloLens device by signing in with their Azure AD account credentials. To switch users, press the power button once to go to standby and then press the power button again to return to the lock screen, or select the user tile on the upper right of the pins panel to sign out the current user.
>[!NOTE]
>Each subsequent user will need to perform [Calibration](https://developer.microsoft.com/windows/mixed-reality/calibration) in order to set their correct interpupillary distance (PD) for the device while signed in.
diff --git a/devices/hololens/hololens-provisioning.md b/devices/hololens/hololens-provisioning.md
index 8054d4f82d..3db745d872 100644
--- a/devices/hololens/hololens-provisioning.md
+++ b/devices/hololens/hololens-provisioning.md
@@ -6,14 +6,15 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 04/30/2018
---
# Configure HoloLens using a provisioning package
->[!WARNING]
->Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
+
[Windows provisioning](https://docs.microsoft.com/windows/configuration/provisioning-packages/provisioning-packages) makes it easy for IT administrators to configure end-user devices without imaging. Windows Configuration Designer is a tool for configuring images and runtime settings which are then built into provisioning packages.
diff --git a/devices/hololens/hololens-public-preview-apps.md b/devices/hololens/hololens-public-preview-apps.md
index 9d4a7d277a..dc61a8e6e2 100644
--- a/devices/hololens/hololens-public-preview-apps.md
+++ b/devices/hololens/hololens-public-preview-apps.md
@@ -1,96 +1,32 @@
---
-title: Get early access to preview new mixed reality apps for HoloLens
-description: Here's what you need to know to prepare for the public preview of new mixed reality apps for HoloLens
+title: Preview new mixed reality apps for HoloLens
+description: Here's how to download and distribute new mixed reality apps for HoloLens, free for a limited time during public preview
ms.prod: w10
ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: alhopper
+ms.author: alhopper
+ms.topic: article
ms.localizationpriority: medium
-ms.date: 05/07/2018
+ms.date: 05/21/2018
---
-# Get ready to preview new mixed reality apps for HoloLens
+# Preview new mixed reality apps for HoloLens
Microsoft has just announced two new mixed reality apps coming to HoloLens: Microsoft Remote Assist and Microsoft Layout.
-On May 22, 2018, these apps will be available to download for free for a limited time from the [Microsoft Store](https://www.microsoft.com/en-us/store/apps) and [Microsoft Store for Business](https://businessstore.microsoft.com/en-us/store). At that time you'll be able to distribute the apps across your organization as part of a public preview. In the meantime, here's what you need to know to prepare for the public preview of each app, to make sure your roll-out is smooth and seamless.
+The gap between the real and digital world limits our ability to take advantage of new technologies and transform how we work, learn, create, communicate, and live. **Mixed reality is here to close that gap**.
-## Microsoft Remote Assist
+Mixed reality has the potential to help customers and businesses across the globe do things that until now, have never been possible. Mixed reality helps businesses and employees complete crucial tasks faster, safer, more efficiently, and create new ways to connect to customers and partners.
-Microsoft Remote Assist enables collaboration in mixed reality to solve problems faster. Firstline workers can collaborate remotely with heads-up, hands-free video calling, image sharing, and mixed reality annotations. They can share what they see with an expert on Microsoft Teams, while staying hands-on to solve problems and complete tasks together, faster.
+Ready to get started? Check out the links below to learn more about how you can download and deploy Microsoft's new commercial-focused mixed reality apps.
-Below, you'll find the technical requirements you'll need to meet in order to distribute Microsoft Remote Assist throughout your organization when it's available from the [Microsoft Store](https://www.microsoft.com/en-us/store/apps) and [Microsoft Store for Business](https://businessstore.microsoft.com/en-us/store) on May 22, 2018.
+## In this section
-### Device requirements
-
-| Device | OS requirements | Details |
-|:---------------------------|:----------------------------------|:-----------------------------------------------------------|
-| HoloLens | RS1, build 10.0.14393.0 | See [Manage updates to HoloLens](https://docs.microsoft.com/en-us/HoloLens/hololens-updates) for instructions on using Windows Update for Business, MDM, and Windows Server Update Service (WSUS) to deploy updates to HoloLens. |
-| Windows 10 PC (optional) | Any Windows 10 build | You can use a Windows 10 PC to collaborate with the HoloLens. |
-| Mobile device (optional) | Android or iOS | You can use a mobile device to collaborate with the HoloLens. Inking, annotations, and image insertion are not currently available on mobile. |
-
-> [!Note]
-> RS1 OS build 10.0.14393.0 is the minimum HoloLens build that supports Remote Assist. We recommend updating the HoloLens to newer versions when they are available.
-
-### Licensing & product requirements
-
-| Product required | Details | Learn more |
-|:----------------------------------|:------------------|:------------------|
-| Azure Active Directory (Azure AD) | Required to log users into the Remote Assist app through Microsoft Teams. Also required for app distribution through the [Microsoft Store for Business](https://docs.microsoft.com/en-us/microsoft-store/sign-up-microsoft-store-for-business). If you choose not to distribute the app through the Microsoft Store for Business, users can also install Remote Assist on a HoloLens or PC from the [Microsoft store](https://www.microsoft.com/en-us/store/apps) using their Microsoft Account credentials (MSA). | [Get started with Azure AD](https://docs.microsoft.com/en-us/azure/active-directory/get-started-azure-ad) |
-| Microsoft Teams | Microsoft Teams is the backbone that facilitates communication in Remote Assist. All devices that will make calls to the HoloLens will need to have Microsoft Teams installed. | [Overview of Microsoft Teams](https://docs.microsoft.com/en-us/MicrosoftTeams/teams-overview) |
-| Microsoft Office 365 | Because Microsoft Teams is part of Office 365, all users who will make calls from their PC/phone to the HoloLens will need an Office 365 license. | [Office 365 licensing for Microsoft Teams](https://docs.microsoft.com/en-us/MicrosoftTeams/office-365-licensing) |
-
-### Network requirements
-
-1.5 MB/s is the recommended bandwidth for optimal performance of Microsoft Remote Assist. Though audio/video calls may be possible in environments with reduced bandwidth, you may experience HoloLens feature degradation, limiting the user experience. To test your company’s network bandwidth, we suggest following the steps outlined below:
-
- 1. Have a mobile Teams user (iOS or Android) video call a desktop Teams user.
- 2. Once the video call has been successfully connected between user 1 and 2, add another separate video call between a 3rd and 4th user, and another for a 5th and 6th user.
- 3. Continue adding video callers to stress test your network bandwidth until confident that multiple users can successfully connect on video calls at the same time.
-
-See [Preparing your organization's network for Microsoft Teams](https://docs.microsoft.com/en-us/MicrosoftTeams/prepare-network) to learn more.
-
-## Microsoft Layout
-
-Bring designs from concept to completion with confidence and speed using Microsoft Layout. Import 3D models to easily create room layouts in real-world scale. Experience designs as high-quality holograms in physical or virtual space and edit in real time. With Microsoft Layout, see ideas in context, saving valuable time and money.
-
-Below, you'll find the device options, and technical requirements, you'll need to consider in order to distribute Layout throughout your organization when it's available from the [Microsoft Store](https://www.microsoft.com/en-us/store/apps) and [Microsoft Store for Business](https://businessstore.microsoft.com/en-us/store) on May 22, 2018.
-
-### Device options
-
-You can use Microsoft Layout with a HoloLens, or with a Windows Mixed Reality immersive headset with motion controllers.
-
-#### HoloLens requirements
-
-| OS requirements | Details |
-|:----------------------------------|:-----------------------------------------------------------|
-| HoloLens, with RS4 build | This build will be available as a HoloLens update on May 22, to align with the app release. Instructions for upgrading to the RS4 OS build are forthcoming. |
-
-Alternately, you can get started testing out the RS4 build in advance of May 22. See [HoloLens RS4 Preview](https://docs.microsoft.com/en-us/windows/mixed-reality/hololens-rs4-preview) for instructions on flashing the RS4 build to your device. Be advised that doing so will erase all content on the device, and will put the device on track to receive future pre-released versions of the OS which may exhibit bugs and issues. We recommend using preview builds for testing only.
-
-#### Windows Mixed Reality immersive headset requirements
-
-| OS requirements | Details |
-|:----------------------------------------------|:-----------------------------------------------------------|
-| Windows 10 PC with build 16299.0 or higher | The Windows 10 PC hardware must be able to support the headset. See [Windows Mixed Reality PC hardware guidelines](https://support.microsoft.com/en-us/help/4039260/windows-10-mixed-reality-pc-hardware-guidelines) for specific hardware requirements. We recommend following the **Windows Mixed Reality Ultra** hardware guidelines. |
-| Motion controllers | Motion controllers are hardware accessories that allow users to take action in mixed reality. See [Motion controllers](https://docs.microsoft.com/en-us/windows/mixed-reality/motion-controllers) to learn more. |
-
-### Technical requirements
-
-Have the following technical requirements in place to start using Microsoft Layout as soon as it's available:
-
-| Requirement | Details | Learn more |
-|:----------------------------------|:------------------|:------------------|
-| Azure Active Directory (Azure AD) | Required for app distribution through the [Microsoft Store for Business](https://docs.microsoft.com/en-us/microsoft-store/sign-up-microsoft-store-for-business). If you choose not to distribute the app through the Microsoft Store for Business, users can also install Layout on a HoloLens or PC from the [Microsoft Store](https://www.microsoft.com/en-us/store/apps) using their Microsoft Account credentials (MSA). | [Get started with Azure AD](https://docs.microsoft.com/en-us/azure/active-directory/get-started-azure-ad) |
-| Network connectivity | Internet access is required to download the app, and utilize all of its features. There are no bandwidth requirements. | |
-| Apps for sharing | Video calling or screen sharing requires a separate app, such as Microsoft Remote Assist on HoloLens, or Skype or Skype for Business on Windows Mixed Reality headsets.
A Windows 10 PC that meets the Windows Mixed Reality Ultra specifications is also required for video calling or screen sharing when using Layout with a Windows Mixed Reality headset. | [Remote Assist](#remote-assist)
[Windows Mixed Reality PC hardware guidelines](https://support.microsoft.com/en-us/help/4039260/windows-10-mixed-reality-pc-hardware-guidelines) |
-| Import Tool for Microsoft Layout | The Import Tool for Microsoft Layout is a companion app for Layout that makes model optimization and management easy. The Import Tool is required to transfer existing 3D models from your PC to Microsoft Layout, for viewing and editing on HoloLens or a Windows Mixed Reality headset. To import 3D models, users must download and launch the Import Tool for Microsoft Layout on their PC, available for free from the [Microsoft Store](https://www.microsoft.com/en-us/store/apps) and [Microsoft Store for Business](https://businessstore.microsoft.com/en-us/store) starting May 22nd. The Import Tool is also required to transfer Visio space dimensions to the HoloLens or Windows Mixed Reality headset. | |
-
-### Visio Add-in for Microsoft Layout
-
-The free Visio Add-in for Microsoft Layout enables you to import space dimensions from Visio to view and edit on HoloLens or in Windows Mixed Reality. The Import Tool for Microsoft Layout is also required.
-
-Be sure to grab the Import Tool and Visio Add-in for Microsoft Layout from the [Microsoft Store](https://www.microsoft.com/en-us/store/apps) or [Microsoft Store for Business](https://businessstore.microsoft.com/en-us/store) on May 22 if you'd like to import, view, and edit space dimensions from Visio.
+| Topic | Description |
+| --- | --- |
+| [Microsoft Remote Assist](hololens-microsoft-remote-assist-app.md) | Microsoft Remote Assist enables collaboration in mixed reality to solve problems faster. Firstline workers can collaborate remotely with heads-up, hands-free video calling, image sharing, and mixed reality annotations. They can share what they see with an expert on Microsoft Teams, while staying hands-on to solve problems and complete tasks together, faster. |
+| [Microsoft Layout](hololens-microsoft-layout-app.md ) | Bring designs from concept to completion with confidence and speed using Microsoft Layout. Import 3D models to easily create room layouts in real-world scale. Experience designs as high-quality holograms in physical or virtual space and edit in real time. With Microsoft Layout, you can see ideas in context, saving valuable time and money. |
## Questions and support
diff --git a/devices/hololens/hololens-requirements.md b/devices/hololens/hololens-requirements.md
index c6061e863f..d9d44b45ba 100644
--- a/devices/hololens/hololens-requirements.md
+++ b/devices/hololens/hololens-requirements.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/devices/hololens/hololens-setup.md b/devices/hololens/hololens-setup.md
index 3fa1130923..513cc01e01 100644
--- a/devices/hololens/hololens-setup.md
+++ b/devices/hololens/hololens-setup.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/devices/hololens/hololens-updates.md b/devices/hololens/hololens-updates.md
index e7e0c89ac7..db02ac16fe 100644
--- a/devices/hololens/hololens-updates.md
+++ b/devices/hololens/hololens-updates.md
@@ -6,14 +6,15 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 04/30/2018
---
# Manage updates to HoloLens
->[!WARNING]
->Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
+
Windows 10, version 1803, is the first feature update to Windows Holographic for Business since its release in Windows 10, version 1607. As with desktop devices, administrators can manage updates to the HoloLens operating system using [Windows Update for Business](https://docs.microsoft.com/windows/deployment/update/waas-manage-updates-wufb).
diff --git a/devices/hololens/hololens-upgrade-enterprise.md b/devices/hololens/hololens-upgrade-enterprise.md
index 3beed8592e..8af44caabc 100644
--- a/devices/hololens/hololens-upgrade-enterprise.md
+++ b/devices/hololens/hololens-upgrade-enterprise.md
@@ -6,14 +6,15 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 04/30/2018
---
# Unlock Windows Holographic for Business features
->[!WARNING]
->Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
+
Microsoft HoloLens is available in the *Development Edition*, which runs Windows Holographic (an edition of Windows 10 designed for HoloLens), and in the [Commercial Suite](https://docs.microsoft.com/windows/mixed-reality/commercial-features), which provides extra features designed for business.
diff --git a/devices/hololens/hololens-whats-new.md b/devices/hololens/hololens-whats-new.md
index 00e18e5b12..9fd9e4d5de 100644
--- a/devices/hololens/hololens-whats-new.md
+++ b/devices/hololens/hololens-whats-new.md
@@ -6,14 +6,15 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 04/30/2018
---
# What's new in Microsoft HoloLens
->[!WARNING]
->Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
+
Windows 10, version 1803, is the first feature update to Windows Holographic for Business since its release in Windows 10, version 1607. This update introduces the following changes:
diff --git a/devices/hololens/index.md b/devices/hololens/index.md
index e362576abb..1cc40ecf7a 100644
--- a/devices/hololens/index.md
+++ b/devices/hololens/index.md
@@ -6,8 +6,10 @@ ms.mktglfcycl: manage
ms.pagetype: hololens, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
-ms.date: 05/07/2018
+ms.date: 05/22/2018
---
# Microsoft HoloLens
@@ -31,7 +33,7 @@ ms.date: 05/07/2018
[Share HoloLens with multiple people](hololens-multiple-users.md) | Multiple users can shared a HoloLens device by using their Azure Active Directory accounts. |
| [Configure HoloLens using a provisioning package](hololens-provisioning.md) | Provisioning packages make it easy for IT administrators to configure HoloLens devices without imaging |
| [Install apps on HoloLens](hololens-install-apps.md) | Use Microsoft Store for Business, mobile device management (MDM), or the Windows Device Portal to install apps on HoloLens |
-| [Get ready to preview new mixed reality apps for HoloLens](hololens-public-preview-apps.md) | Get ready to distribute and use new mixed reality apps for HoloLens during private preview |
+| [Preview new mixed reality apps for HoloLens](hololens-public-preview-apps.md) | Download and deploy new mixed reality apps for HoloLens, free for a limited time during public preview |
| [Enable Bitlocker device encryption for HoloLens](hololens-encryption.md) | Learn how to use Bitlocker device encryption to protect files and information stored on the HoloLens |
| [Change history for Microsoft HoloLens documentation](change-history-hololens.md) | See new and updated topics in the HoloLens documentation library. |
diff --git a/devices/surface-hub/accessibility-surface-hub.md b/devices/surface-hub/accessibility-surface-hub.md
index 0e4f926262..3fbf1e269e 100644
--- a/devices/surface-hub/accessibility-surface-hub.md
+++ b/devices/surface-hub/accessibility-surface-hub.md
@@ -9,6 +9,7 @@ ms.pagetype: surfacehub
ms.sitesec: library
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 08/16/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/admin-group-management-for-surface-hub.md b/devices/surface-hub/admin-group-management-for-surface-hub.md
index cd6644429f..2803f47304 100644
--- a/devices/surface-hub/admin-group-management-for-surface-hub.md
+++ b/devices/surface-hub/admin-group-management-for-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub, security
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/appendix-a-powershell-scripts-for-surface-hub.md b/devices/surface-hub/appendix-a-powershell-scripts-for-surface-hub.md
index 4f299c72fd..36df6680a5 100644
--- a/devices/surface-hub/appendix-a-powershell-scripts-for-surface-hub.md
+++ b/devices/surface-hub/appendix-a-powershell-scripts-for-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 01/10/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/apply-activesync-policies-for-surface-hub-device-accounts.md b/devices/surface-hub/apply-activesync-policies-for-surface-hub-device-accounts.md
index 3ea97cffed..cd10c695db 100644
--- a/devices/surface-hub/apply-activesync-policies-for-surface-hub-device-accounts.md
+++ b/devices/surface-hub/apply-activesync-policies-for-surface-hub-device-accounts.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/change-history-surface-hub.md b/devices/surface-hub/change-history-surface-hub.md
index c3ab437724..65ebd4f756 100644
--- a/devices/surface-hub/change-history-surface-hub.md
+++ b/devices/surface-hub/change-history-surface-hub.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 03/06/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/change-surface-hub-device-account.md b/devices/surface-hub/change-surface-hub-device-account.md
index 5b3d1e35db..9e7f3c004d 100644
--- a/devices/surface-hub/change-surface-hub-device-account.md
+++ b/devices/surface-hub/change-surface-hub-device-account.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/connect-and-display-with-surface-hub.md b/devices/surface-hub/connect-and-display-with-surface-hub.md
index dd8d127472..225d3e235a 100644
--- a/devices/surface-hub/connect-and-display-with-surface-hub.md
+++ b/devices/surface-hub/connect-and-display-with-surface-hub.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/create-a-device-account-using-office-365.md b/devices/surface-hub/create-a-device-account-using-office-365.md
index 5fc4dd60a1..cc1d0ec9cd 100644
--- a/devices/surface-hub/create-a-device-account-using-office-365.md
+++ b/devices/surface-hub/create-a-device-account-using-office-365.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 05/04/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/create-and-test-a-device-account-surface-hub.md b/devices/surface-hub/create-and-test-a-device-account-surface-hub.md
index cc5d233b08..cc60ff723c 100644
--- a/devices/surface-hub/create-and-test-a-device-account-surface-hub.md
+++ b/devices/surface-hub/create-and-test-a-device-account-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 03/06/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/device-reset-surface-hub.md b/devices/surface-hub/device-reset-surface-hub.md
index a595ea198c..bf70666e38 100644
--- a/devices/surface-hub/device-reset-surface-hub.md
+++ b/devices/surface-hub/device-reset-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/differences-between-surface-hub-and-windows-10-enterprise.md b/devices/surface-hub/differences-between-surface-hub-and-windows-10-enterprise.md
index 61120d6a25..40c7b012de 100644
--- a/devices/surface-hub/differences-between-surface-hub-and-windows-10-enterprise.md
+++ b/devices/surface-hub/differences-between-surface-hub-and-windows-10-enterprise.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: isaiahng
ms.author: jdecker
+ms.topic: article
ms.date: 11/01/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/enable-8021x-wired-authentication.md b/devices/surface-hub/enable-8021x-wired-authentication.md
index e23860d5ba..ff69e90418 100644
--- a/devices/surface-hub/enable-8021x-wired-authentication.md
+++ b/devices/surface-hub/enable-8021x-wired-authentication.md
@@ -7,6 +7,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 11/15/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/exchange-properties-for-surface-hub-device-accounts.md b/devices/surface-hub/exchange-properties-for-surface-hub-device-accounts.md
index 1c936f687a..40f93af750 100644
--- a/devices/surface-hub/exchange-properties-for-surface-hub-device-accounts.md
+++ b/devices/surface-hub/exchange-properties-for-surface-hub-device-accounts.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/finishing-your-surface-hub-meeting.md b/devices/surface-hub/finishing-your-surface-hub-meeting.md
index 7ef7ca904e..bfc104fa22 100644
--- a/devices/surface-hub/finishing-your-surface-hub-meeting.md
+++ b/devices/surface-hub/finishing-your-surface-hub-meeting.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/first-run-program-surface-hub.md b/devices/surface-hub/first-run-program-surface-hub.md
index b0d0d183ef..d488122210 100644
--- a/devices/surface-hub/first-run-program-surface-hub.md
+++ b/devices/surface-hub/first-run-program-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/hybrid-deployment-surface-hub-device-accounts.md b/devices/surface-hub/hybrid-deployment-surface-hub-device-accounts.md
index b464e456dc..eabfb6c6cd 100644
--- a/devices/surface-hub/hybrid-deployment-surface-hub-device-accounts.md
+++ b/devices/surface-hub/hybrid-deployment-surface-hub-device-accounts.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 04/12/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/index.md b/devices/surface-hub/index.md
index 06c8519cfc..e966b4a42f 100644
--- a/devices/surface-hub/index.md
+++ b/devices/surface-hub/index.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 09/07/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/install-apps-on-surface-hub.md b/devices/surface-hub/install-apps-on-surface-hub.md
index b0737d1f6b..69f12c9881 100644
--- a/devices/surface-hub/install-apps-on-surface-hub.md
+++ b/devices/surface-hub/install-apps-on-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub, store
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 10/20/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/local-management-surface-hub-settings.md b/devices/surface-hub/local-management-surface-hub-settings.md
index c59fd9ac8a..9bff610bcf 100644
--- a/devices/surface-hub/local-management-surface-hub-settings.md
+++ b/devices/surface-hub/local-management-surface-hub-settings.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/manage-settings-with-mdm-for-surface-hub.md b/devices/surface-hub/manage-settings-with-mdm-for-surface-hub.md
index d81d9cfc72..a21025c060 100644
--- a/devices/surface-hub/manage-settings-with-mdm-for-surface-hub.md
+++ b/devices/surface-hub/manage-settings-with-mdm-for-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub, mobility
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 03/07/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/manage-surface-hub-settings.md b/devices/surface-hub/manage-surface-hub-settings.md
index c79f175559..a4a53440fb 100644
--- a/devices/surface-hub/manage-surface-hub-settings.md
+++ b/devices/surface-hub/manage-surface-hub-settings.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/manage-surface-hub.md b/devices/surface-hub/manage-surface-hub.md
index 612bdeb704..6f90968880 100644
--- a/devices/surface-hub/manage-surface-hub.md
+++ b/devices/surface-hub/manage-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 01/17/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/manage-windows-updates-for-surface-hub.md b/devices/surface-hub/manage-windows-updates-for-surface-hub.md
index 0de4ed8d77..d3e78f1ff7 100644
--- a/devices/surface-hub/manage-windows-updates-for-surface-hub.md
+++ b/devices/surface-hub/manage-windows-updates-for-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 11/03/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/miracast-over-infrastructure.md b/devices/surface-hub/miracast-over-infrastructure.md
index 341ce3a1d0..a6a44e2d03 100644
--- a/devices/surface-hub/miracast-over-infrastructure.md
+++ b/devices/surface-hub/miracast-over-infrastructure.md
@@ -7,6 +7,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 08/03/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/miracast-troubleshooting.md b/devices/surface-hub/miracast-troubleshooting.md
index f8843ffe57..3c6c085881 100644
--- a/devices/surface-hub/miracast-troubleshooting.md
+++ b/devices/surface-hub/miracast-troubleshooting.md
@@ -7,6 +7,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/monitor-surface-hub.md b/devices/surface-hub/monitor-surface-hub.md
index 7fe0d6aeff..6b10bdc4c5 100644
--- a/devices/surface-hub/monitor-surface-hub.md
+++ b/devices/surface-hub/monitor-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/on-premises-deployment-surface-hub-device-accounts.md b/devices/surface-hub/on-premises-deployment-surface-hub-device-accounts.md
index 7c6a90015d..6b3031daf5 100644
--- a/devices/surface-hub/on-premises-deployment-surface-hub-device-accounts.md
+++ b/devices/surface-hub/on-premises-deployment-surface-hub-device-accounts.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 04/13/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/on-premises-deployment-surface-hub-multi-forest.md b/devices/surface-hub/on-premises-deployment-surface-hub-multi-forest.md
index 9456eb9891..dd4e285e06 100644
--- a/devices/surface-hub/on-premises-deployment-surface-hub-multi-forest.md
+++ b/devices/surface-hub/on-premises-deployment-surface-hub-multi-forest.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/online-deployment-surface-hub-device-accounts.md b/devices/surface-hub/online-deployment-surface-hub-device-accounts.md
index 6a314c317a..c253d82d11 100644
--- a/devices/surface-hub/online-deployment-surface-hub-device-accounts.md
+++ b/devices/surface-hub/online-deployment-surface-hub-device-accounts.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 02/21/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/password-management-for-surface-hub-device-accounts.md b/devices/surface-hub/password-management-for-surface-hub-device-accounts.md
index 859034da95..c17507564e 100644
--- a/devices/surface-hub/password-management-for-surface-hub-device-accounts.md
+++ b/devices/surface-hub/password-management-for-surface-hub-device-accounts.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub, security
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/physically-install-your-surface-hub-device.md b/devices/surface-hub/physically-install-your-surface-hub-device.md
index dc9cdf25ad..fb4c19723b 100644
--- a/devices/surface-hub/physically-install-your-surface-hub-device.md
+++ b/devices/surface-hub/physically-install-your-surface-hub-device.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub, readiness
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/prepare-your-environment-for-surface-hub.md b/devices/surface-hub/prepare-your-environment-for-surface-hub.md
index cef7042de1..5ac57b764e 100644
--- a/devices/surface-hub/prepare-your-environment-for-surface-hub.md
+++ b/devices/surface-hub/prepare-your-environment-for-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 12/04/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/provisioning-packages-for-surface-hub.md b/devices/surface-hub/provisioning-packages-for-surface-hub.md
index b357f97f9c..8646da068a 100644
--- a/devices/surface-hub/provisioning-packages-for-surface-hub.md
+++ b/devices/surface-hub/provisioning-packages-for-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/remote-surface-hub-management.md b/devices/surface-hub/remote-surface-hub-management.md
index e57046e72c..d4b921b254 100644
--- a/devices/surface-hub/remote-surface-hub-management.md
+++ b/devices/surface-hub/remote-surface-hub-management.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/save-bitlocker-key-surface-hub.md b/devices/surface-hub/save-bitlocker-key-surface-hub.md
index a872c380d5..5fedc2bf80 100644
--- a/devices/surface-hub/save-bitlocker-key-surface-hub.md
+++ b/devices/surface-hub/save-bitlocker-key-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub, security
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/set-up-your-surface-hub.md b/devices/surface-hub/set-up-your-surface-hub.md
index 4a88209a97..876fd56138 100644
--- a/devices/surface-hub/set-up-your-surface-hub.md
+++ b/devices/surface-hub/set-up-your-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/setup-worksheet-surface-hub.md b/devices/surface-hub/setup-worksheet-surface-hub.md
index 06234fe14a..f74f466fe8 100644
--- a/devices/surface-hub/setup-worksheet-surface-hub.md
+++ b/devices/surface-hub/setup-worksheet-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/skype-hybrid-voice.md b/devices/surface-hub/skype-hybrid-voice.md
index 4f3303c2c2..8ad23c643f 100644
--- a/devices/surface-hub/skype-hybrid-voice.md
+++ b/devices/surface-hub/skype-hybrid-voice.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/support-solutions-surface-hub.md b/devices/surface-hub/support-solutions-surface-hub.md
index 6b03449a2e..b40eaef7de 100644
--- a/devices/surface-hub/support-solutions-surface-hub.md
+++ b/devices/surface-hub/support-solutions-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: kaushika-msft
ms.author: jdecker
+ms.topic: article
ms.date: 10/24/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/surface-hub-authenticator-app.md b/devices/surface-hub/surface-hub-authenticator-app.md
index 4e76e525e0..b4bbecf00d 100644
--- a/devices/surface-hub/surface-hub-authenticator-app.md
+++ b/devices/surface-hub/surface-hub-authenticator-app.md
@@ -7,6 +7,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 08/28/2017
localizationpriority: medium
---
diff --git a/devices/surface-hub/surface-hub-downloads.md b/devices/surface-hub/surface-hub-downloads.md
index 71706b04fe..0f35d022a9 100644
--- a/devices/surface-hub/surface-hub-downloads.md
+++ b/devices/surface-hub/surface-hub-downloads.md
@@ -7,6 +7,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 08/22/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/surface-hub-start-menu.md b/devices/surface-hub/surface-hub-start-menu.md
index 07671c8e12..1be0ee8978 100644
--- a/devices/surface-hub/surface-hub-start-menu.md
+++ b/devices/surface-hub/surface-hub-start-menu.md
@@ -7,6 +7,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 01/17/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/surface-hub-wifi-direct.md b/devices/surface-hub/surface-hub-wifi-direct.md
index 87de677e90..3f933415fc 100644
--- a/devices/surface-hub/surface-hub-wifi-direct.md
+++ b/devices/surface-hub/surface-hub-wifi-direct.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/surfacehub-whats-new-1703.md b/devices/surface-hub/surfacehub-whats-new-1703.md
index 59ced8ff5d..5c18d5d2d8 100644
--- a/devices/surface-hub/surfacehub-whats-new-1703.md
+++ b/devices/surface-hub/surfacehub-whats-new-1703.md
@@ -7,6 +7,7 @@ ms.pagetype: devices
ms.sitesec: library
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 01/18/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/troubleshoot-surface-hub.md b/devices/surface-hub/troubleshoot-surface-hub.md
index 1056ed9472..d33bb2ca55 100644
--- a/devices/surface-hub/troubleshoot-surface-hub.md
+++ b/devices/surface-hub/troubleshoot-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 03/16/2018
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/use-fully-qualified-domain-name-surface-hub.md b/devices/surface-hub/use-fully-qualified-domain-name-surface-hub.md
index b108f07936..8ae6d82f72 100644
--- a/devices/surface-hub/use-fully-qualified-domain-name-surface-hub.md
+++ b/devices/surface-hub/use-fully-qualified-domain-name-surface-hub.md
@@ -4,6 +4,7 @@ description: Troubleshoot common problems, including setup issues, Exchange Acti
keywords: ["Troubleshoot common problems", "setup issues", "Exchange ActiveSync errors"]
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
ms.prod: w10
diff --git a/devices/surface-hub/use-room-control-system-with-surface-hub.md b/devices/surface-hub/use-room-control-system-with-surface-hub.md
index 2ab4e26c88..8bcdde0580 100644
--- a/devices/surface-hub/use-room-control-system-with-surface-hub.md
+++ b/devices/surface-hub/use-room-control-system-with-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/whiteboard-collaboration.md b/devices/surface-hub/whiteboard-collaboration.md
index 7ad560c77e..dd9606c9c3 100644
--- a/devices/surface-hub/whiteboard-collaboration.md
+++ b/devices/surface-hub/whiteboard-collaboration.md
@@ -7,6 +7,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 10/20/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface-hub/wireless-network-management-for-surface-hub.md b/devices/surface-hub/wireless-network-management-for-surface-hub.md
index b9348bc48d..c7aac74ce4 100644
--- a/devices/surface-hub/wireless-network-management-for-surface-hub.md
+++ b/devices/surface-hub/wireless-network-management-for-surface-hub.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub, networking
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface/advanced-uefi-security-features-for-surface-pro-3.md b/devices/surface/advanced-uefi-security-features-for-surface-pro-3.md
index 4e5dde8200..0ee3c45774 100644
--- a/devices/surface/advanced-uefi-security-features-for-surface-pro-3.md
+++ b/devices/surface/advanced-uefi-security-features-for-surface-pro-3.md
@@ -9,6 +9,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices, security
ms.sitesec: library
author: miladCA
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/devices/surface/change-history-for-surface.md b/devices/surface/change-history-for-surface.md
index 443f787ea4..7b010ca138 100644
--- a/devices/surface/change-history-for-surface.md
+++ b/devices/surface/change-history-for-surface.md
@@ -5,13 +5,22 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
-ms.date: 02/12/2018
+ms.author: jdecker
+ms.topic: article
+ms.date: 05/15/2018
---
# Change history for Surface documentation
This topic lists new and updated topics in the Surface documentation library.
+## May 2018
+
+|New or changed topic | Description |
+| --- | --- |
+|[Microsoft Surface Data Eraser](microsoft-surface-data-eraser.md) | Added version 3.2.58.0 information |
+|[Surface device compatibility with Windows 10 Long-Term Servicing Channel (LTSC)](surface-device-compatibility-with-windows-10-ltsc.md) | Removed note box around content |
+
## February 2018
|New or changed topic | Description |
diff --git a/devices/surface/considerations-for-surface-and-system-center-configuration-manager.md b/devices/surface/considerations-for-surface-and-system-center-configuration-manager.md
index 7f1ca137fd..1160b8cacc 100644
--- a/devices/surface/considerations-for-surface-and-system-center-configuration-manager.md
+++ b/devices/surface/considerations-for-surface-and-system-center-configuration-manager.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface, devices
ms.sitesec: library
author: Scottmca
+ms.author: jdecker
+ms.topic: article
ms.date: 10/16/2017
---
diff --git a/devices/surface/customize-the-oobe-for-surface-deployments.md b/devices/surface/customize-the-oobe-for-surface-deployments.md
index b05c06e3ef..1f60319e04 100644
--- a/devices/surface/customize-the-oobe-for-surface-deployments.md
+++ b/devices/surface/customize-the-oobe-for-surface-deployments.md
@@ -9,6 +9,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface, devices
ms.sitesec: library
author: jobotto
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/devices/surface/deploy-surface-app-with-windows-store-for-business.md b/devices/surface/deploy-surface-app-with-windows-store-for-business.md
index 00d28623aa..491ca43c11 100644
--- a/devices/surface/deploy-surface-app-with-windows-store-for-business.md
+++ b/devices/surface/deploy-surface-app-with-windows-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface, store
ms.sitesec: library
author: miladCA
+ms.author: jdecker
+ms.topic: article
ms.date: 09/21/2017
---
diff --git a/devices/surface/deploy-the-latest-firmware-and-drivers-for-surface-devices.md b/devices/surface/deploy-the-latest-firmware-and-drivers-for-surface-devices.md
index 0759f97b9a..288ad5d68c 100644
--- a/devices/surface/deploy-the-latest-firmware-and-drivers-for-surface-devices.md
+++ b/devices/surface/deploy-the-latest-firmware-and-drivers-for-surface-devices.md
@@ -11,6 +11,7 @@ ms.sitesec: library
author: brecords
ms.date: 12/07/2017
ms.author: jdecker
+ms.topic: article
---
# Download the latest firmware and drivers for Surface devices
diff --git a/devices/surface/deploy-windows-10-to-surface-devices-with-mdt.md b/devices/surface/deploy-windows-10-to-surface-devices-with-mdt.md
index d0ec9f01fe..1f84f574f3 100644
--- a/devices/surface/deploy-windows-10-to-surface-devices-with-mdt.md
+++ b/devices/surface/deploy-windows-10-to-surface-devices-with-mdt.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface
ms.sitesec: library
author: Scottmca
+ms.author: jdecker
+ms.topic: article
ms.date: 10/16/2017
---
diff --git a/devices/surface/deploy.md b/devices/surface/deploy.md
index 70879513fa..00e7dc22e0 100644
--- a/devices/surface/deploy.md
+++ b/devices/surface/deploy.md
@@ -8,6 +8,7 @@ ms.sitesec: library
author: brecords
ms.date: 01/29/2018
ms.author: jdecker
+ms.topic: article
---
# Deploy Surface devices
diff --git a/devices/surface/enable-peap-eap-fast-and-cisco-leap-on-surface-devices.md b/devices/surface/enable-peap-eap-fast-and-cisco-leap-on-surface-devices.md
index e5e7084262..34439da53f 100644
--- a/devices/surface/enable-peap-eap-fast-and-cisco-leap-on-surface-devices.md
+++ b/devices/surface/enable-peap-eap-fast-and-cisco-leap-on-surface-devices.md
@@ -9,6 +9,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface, devices
ms.sitesec: library
author: miladCA
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/devices/surface/enroll-and-configure-surface-devices-with-semm.md b/devices/surface/enroll-and-configure-surface-devices-with-semm.md
index 1b21185ebd..086d18eead 100644
--- a/devices/surface/enroll-and-configure-surface-devices-with-semm.md
+++ b/devices/surface/enroll-and-configure-surface-devices-with-semm.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices, security
ms.sitesec: library
author: jobotto
+ms.author: jdecker
+ms.topic: article
ms.date: 01/06/2017
---
diff --git a/devices/surface/ethernet-adapters-and-surface-device-deployment.md b/devices/surface/ethernet-adapters-and-surface-device-deployment.md
index 70a83684af..835ce1fdb0 100644
--- a/devices/surface/ethernet-adapters-and-surface-device-deployment.md
+++ b/devices/surface/ethernet-adapters-and-surface-device-deployment.md
@@ -9,6 +9,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface, devices
ms.sitesec: library
author: jobotto
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/devices/surface/index.md b/devices/surface/index.md
index e9007ff9b0..477f6aaedf 100644
--- a/devices/surface/index.md
+++ b/devices/surface/index.md
@@ -8,6 +8,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices
ms.sitesec: library
author: heatherpoulsen
+ms.author: jdecker
+ms.topic: article
ms.date: 10/16/2017
---
diff --git a/devices/surface/ltsb-for-surface.md b/devices/surface/ltsb-for-surface.md
index a4c9d85f83..8c54cb0ffd 100644
--- a/devices/surface/ltsb-for-surface.md
+++ b/devices/surface/ltsb-for-surface.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.date: 04/25/2017
---
diff --git a/devices/surface/manage-surface-dock-firmware-updates.md b/devices/surface/manage-surface-dock-firmware-updates.md
index e25ba31621..b68eb061ba 100644
--- a/devices/surface/manage-surface-dock-firmware-updates.md
+++ b/devices/surface/manage-surface-dock-firmware-updates.md
@@ -9,6 +9,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices
ms.sitesec: library
author: jobotto
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/devices/surface/manage-surface-pro-3-firmware-updates.md b/devices/surface/manage-surface-pro-3-firmware-updates.md
index 69e97eaf87..35087de606 100644
--- a/devices/surface/manage-surface-pro-3-firmware-updates.md
+++ b/devices/surface/manage-surface-pro-3-firmware-updates.md
@@ -9,6 +9,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices
ms.sitesec: library
author: jobotto
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/devices/surface/manage-surface-uefi-settings.md b/devices/surface/manage-surface-uefi-settings.md
index 4b154c0a9a..bb2c6d516d 100644
--- a/devices/surface/manage-surface-uefi-settings.md
+++ b/devices/surface/manage-surface-uefi-settings.md
@@ -8,6 +8,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: devices, surface
author: miladCA
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/devices/surface/microsoft-surface-data-eraser.md b/devices/surface/microsoft-surface-data-eraser.md
index b1f7c26052..ad9c11f469 100644
--- a/devices/surface/microsoft-surface-data-eraser.md
+++ b/devices/surface/microsoft-surface-data-eraser.md
@@ -10,7 +10,8 @@ ms.pagetype: surface, devices, security
ms.sitesec: library
author: brecords
ms.author: jdecker
-ms.date: 02/12/2018
+ms.topic: article
+ms.date: 05/15/2018
---
# Microsoft Surface Data Eraser
@@ -146,6 +147,12 @@ After you create a Microsoft Surface Data Eraser USB stick, you can boot a suppo
Microsoft Surface Data Eraser is periodically updated by Microsoft. For information about the changes provided in each new version, see the following:
+### Version 3.2.58.0
+This version of Microsoft Surface Data Eraser adds support for the following:
+
+- • Additional storage devices (drives) for Surface Pro and Surface Laptop devices
+
+
### Version 3.2.46.0
This version of Microsoft Surface Data Eraser adds support for the following:
diff --git a/devices/surface/microsoft-surface-deployment-accelerator.md b/devices/surface/microsoft-surface-deployment-accelerator.md
index 631198f085..095c142f16 100644
--- a/devices/surface/microsoft-surface-deployment-accelerator.md
+++ b/devices/surface/microsoft-surface-deployment-accelerator.md
@@ -10,6 +10,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface, devices
ms.sitesec: library
author: miladCA
+ms.author: jdecker
+ms.topic: article
---
# Microsoft Surface Deployment Accelerator
diff --git a/devices/surface/step-by-step-surface-deployment-accelerator.md b/devices/surface/step-by-step-surface-deployment-accelerator.md
index 33683b5d6c..38f84d491f 100644
--- a/devices/surface/step-by-step-surface-deployment-accelerator.md
+++ b/devices/surface/step-by-step-surface-deployment-accelerator.md
@@ -9,6 +9,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface, devices
ms.sitesec: library
author: miladCA
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/devices/surface/support-solutions-surface.md b/devices/surface/support-solutions-surface.md
index 3525ce34a9..2ee030e7da 100644
--- a/devices/surface/support-solutions-surface.md
+++ b/devices/surface/support-solutions-surface.md
@@ -9,6 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: kaushika-msft
ms.author: jdecker
+ms.topic: article
ms.date: 09/08/2017
ms.localizationpriority: medium
---
diff --git a/devices/surface/surface-device-compatibility-with-windows-10-ltsc.md b/devices/surface/surface-device-compatibility-with-windows-10-ltsc.md
index 0d4409c657..52bef60ccd 100644
--- a/devices/surface/surface-device-compatibility-with-windows-10-ltsc.md
+++ b/devices/surface/surface-device-compatibility-with-windows-10-ltsc.md
@@ -8,6 +8,7 @@ ms.pagetype: surface, devices
ms.sitesec: library
author: brecords
ms.author: jdecker
+ms.topic: article
ms.date: 01/03/2018
---
@@ -35,8 +36,7 @@ The LTSC servicing option is designed for device types and scenarios where the k
>[!NOTE]
>For general information about Windows servicing branches, including LTSC, see [Overview of Windows as a service](https://technet.microsoft.com/itpro/windows/update/waas-overview#long-term-servicing-branch).
->[!NOTE]
->As a general guideline, devices that fulfill the following criteria are considered general-purpose devices and should be paired with Windows 10 Pro or Windows 10 Enterprise using the Semi-Annual Channel servicing option:
+As a general guideline, devices that fulfill the following criteria are considered general-purpose devices and should be paired with Windows 10 Pro or Windows 10 Enterprise using the Semi-Annual Channel servicing option:
* Devices that run productivity software such as Microsoft Office
diff --git a/devices/surface/surface-dock-updater.md b/devices/surface/surface-dock-updater.md
index 55d7b233dc..977bbaebc7 100644
--- a/devices/surface/surface-dock-updater.md
+++ b/devices/surface/surface-dock-updater.md
@@ -11,6 +11,7 @@ ms.sitesec: library
author: brecords
ms.date: 02/23/2018
ms.author: jdecker
+ms.topic: article
---
# Microsoft Surface Dock Updater
diff --git a/devices/surface/surface-enterprise-management-mode.md b/devices/surface/surface-enterprise-management-mode.md
index bcf6b4b60c..42df3fd641 100644
--- a/devices/surface/surface-enterprise-management-mode.md
+++ b/devices/surface/surface-enterprise-management-mode.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices, security
ms.sitesec: library
author: jobotto
+ms.author: jdecker
+ms.topic: article
ms.date: 01/06/2017
---
diff --git a/devices/surface/unenroll-surface-devices-from-semm.md b/devices/surface/unenroll-surface-devices-from-semm.md
index 4e8cb226f3..323624a34f 100644
--- a/devices/surface/unenroll-surface-devices-from-semm.md
+++ b/devices/surface/unenroll-surface-devices-from-semm.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices, security
ms.sitesec: library
author: jobotto
+ms.author: jdecker
+ms.topic: article
ms.date: 01/06/2017
---
diff --git a/devices/surface/update.md b/devices/surface/update.md
index 7c1b86fbb8..29e0b9517b 100644
--- a/devices/surface/update.md
+++ b/devices/surface/update.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices
ms.sitesec: library
author: heatherpoulsen
+ms.author: jdecker
+ms.topic: article
ms.date: 12/01/2016
---
diff --git a/devices/surface/upgrade-surface-devices-to-windows-10-with-mdt.md b/devices/surface/upgrade-surface-devices-to-windows-10-with-mdt.md
index 20b66668b4..4e13cfd089 100644
--- a/devices/surface/upgrade-surface-devices-to-windows-10-with-mdt.md
+++ b/devices/surface/upgrade-surface-devices-to-windows-10-with-mdt.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface
ms.sitesec: library
author: Scottmca
+ms.author: jdecker
+ms.topic: article
ms.date: 10/16/2017
---
diff --git a/devices/surface/use-system-center-configuration-manager-to-manage-devices-with-semm.md b/devices/surface/use-system-center-configuration-manager-to-manage-devices-with-semm.md
index 9234eb04c3..c5de082d9e 100644
--- a/devices/surface/use-system-center-configuration-manager-to-manage-devices-with-semm.md
+++ b/devices/surface/use-system-center-configuration-manager-to-manage-devices-with-semm.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.pagetype: surface, devices
ms.sitesec: library
author: KiranDavane
+ms.author: jdecker
+ms.topic: article
ms.date: 02/01/2017
---
diff --git a/devices/surface/using-the-sda-deployment-share.md b/devices/surface/using-the-sda-deployment-share.md
index b65fc91fb5..75bb5c6f65 100644
--- a/devices/surface/using-the-sda-deployment-share.md
+++ b/devices/surface/using-the-sda-deployment-share.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: deploy
ms.pagetype: surface, devices
ms.sitesec: library
author: Scottmca
+ms.author: jdecker
+ms.topic: article
ms.date: 10/16/2017
---
diff --git a/devices/surface/wake-on-lan-for-surface-devices.md b/devices/surface/wake-on-lan-for-surface-devices.md
index b9d7b5d2e3..c584cc40bb 100644
--- a/devices/surface/wake-on-lan-for-surface-devices.md
+++ b/devices/surface/wake-on-lan-for-surface-devices.md
@@ -8,6 +8,7 @@ ms.pagetype: surface, devices
ms.sitesec: library
author: brecords
ms.author: jdecker
+ms.topic: article
ms.date: 01/03/2018
---
diff --git a/devices/surface/windows-autopilot-and-surface-devices.md b/devices/surface/windows-autopilot-and-surface-devices.md
index bc678a28bd..3550f35fd6 100644
--- a/devices/surface/windows-autopilot-and-surface-devices.md
+++ b/devices/surface/windows-autopilot-and-surface-devices.md
@@ -9,6 +9,7 @@ ms.sitesec: library
author: brecords
ms.date: 01/31/2018
ms.author: jdecker
+ms.topic: article
---
# Windows Autopilot and Surface devices
diff --git a/education/get-started/change-history-ms-edu-get-started.md b/education/get-started/change-history-ms-edu-get-started.md
index 0110254868..97ddde85fb 100644
--- a/education/get-started/change-history-ms-edu-get-started.md
+++ b/education/get-started/change-history-ms-edu-get-started.md
@@ -2,7 +2,8 @@
title: Change history for Microsoft Education Get Started
description: New and changed topics in the Microsoft Education get started guide.
keywords: Microsoft Education get started guide, IT admin, IT pro, school, education, change history
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/get-started/configure-microsoft-store-for-education.md b/education/get-started/configure-microsoft-store-for-education.md
index ec173a261d..021052c85b 100644
--- a/education/get-started/configure-microsoft-store-for-education.md
+++ b/education/get-started/configure-microsoft-store-for-education.md
@@ -2,7 +2,8 @@
title: Configure Microsoft Store for Education
description: Learn how to use the new Microsoft Education system to set up a cloud infrastructure for your school, acquire devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, School Data Sync, Microsoft Teams, Microsoft Store for Education, Azure AD, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: get-started
diff --git a/education/get-started/enable-microsoft-teams.md b/education/get-started/enable-microsoft-teams.md
index 6c74c506b0..bc2a138036 100644
--- a/education/get-started/enable-microsoft-teams.md
+++ b/education/get-started/enable-microsoft-teams.md
@@ -2,7 +2,8 @@
title: Enable Microsoft Teams for your school
description: Learn how to use the new Microsoft Education system to set up a cloud infrastructure for your school, acquire devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, School Data Sync, Microsoft Teams, Microsoft Store for Education, Azure AD, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: get-started
diff --git a/education/get-started/finish-setup-and-other-tasks.md b/education/get-started/finish-setup-and-other-tasks.md
index 55a52faa11..8b1e03783b 100644
--- a/education/get-started/finish-setup-and-other-tasks.md
+++ b/education/get-started/finish-setup-and-other-tasks.md
@@ -2,7 +2,8 @@
title: Finish Windows 10 device setup and other tasks
description: Learn how to use the new Microsoft Education system to set up a cloud infrastructure for your school, acquire devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, School Data Sync, Microsoft Teams, Microsoft Store for Education, Azure AD, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: get-started
diff --git a/education/get-started/get-started-with-microsoft-education.md b/education/get-started/get-started-with-microsoft-education.md
index 4746bcc249..136ad9ac13 100644
--- a/education/get-started/get-started-with-microsoft-education.md
+++ b/education/get-started/get-started-with-microsoft-education.md
@@ -2,7 +2,8 @@
title: Deploy and manage a full cloud IT solution with Microsoft Education
description: Learn how to use the new Microsoft Education system to set up a cloud infrastructure for your school, acquire devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, School Data Sync, Microsoft Teams, Microsoft Store for Education, Azure AD, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: hero-article
diff --git a/education/get-started/set-up-office365-edu-tenant.md b/education/get-started/set-up-office365-edu-tenant.md
index 59d939c2eb..71ea282542 100644
--- a/education/get-started/set-up-office365-edu-tenant.md
+++ b/education/get-started/set-up-office365-edu-tenant.md
@@ -2,7 +2,8 @@
title: Set up an Office 365 Education tenant
description: Learn how to use the new Microsoft Education system to set up a cloud infrastructure for your school, acquire devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, School Data Sync, Microsoft Teams, Microsoft Store for Education, Azure AD, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: get-started
diff --git a/education/get-started/set-up-windows-10-education-devices.md b/education/get-started/set-up-windows-10-education-devices.md
index ac9f52c84f..4fdd5ca5a5 100644
--- a/education/get-started/set-up-windows-10-education-devices.md
+++ b/education/get-started/set-up-windows-10-education-devices.md
@@ -2,7 +2,8 @@
title: Set up Windows 10 education devices
description: Learn how to use the new Microsoft Education system to set up a cloud infrastructure for your school, acquire devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, School Data Sync, Microsoft Teams, Microsoft Store for Education, Azure AD, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: get-started
diff --git a/education/get-started/set-up-windows-education-devices.md b/education/get-started/set-up-windows-education-devices.md
index edb76d6448..e1c82b393d 100644
--- a/education/get-started/set-up-windows-education-devices.md
+++ b/education/get-started/set-up-windows-education-devices.md
@@ -2,7 +2,8 @@
title: Set up Windows 10 devices using Windows OOBE
description: Learn how to use the new Microsoft Education system to set up a cloud infrastructure for your school, acquire devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, School Data Sync, Microsoft Teams, Microsoft Store for Education, Azure AD, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: get-started
diff --git a/education/get-started/use-intune-for-education.md b/education/get-started/use-intune-for-education.md
index 646d7b8e16..e33b8f69c3 100644
--- a/education/get-started/use-intune-for-education.md
+++ b/education/get-started/use-intune-for-education.md
@@ -2,7 +2,8 @@
title: Use Intune for Education to manage groups, apps, and settings
description: Learn how to use the new Microsoft Education system to set up a cloud infrastructure for your school, acquire devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, School Data Sync, Microsoft Teams, Microsoft Store for Education, Azure AD, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: get-started
diff --git a/education/get-started/use-school-data-sync.md b/education/get-started/use-school-data-sync.md
index c5392b41b9..24fe1b1421 100644
--- a/education/get-started/use-school-data-sync.md
+++ b/education/get-started/use-school-data-sync.md
@@ -2,7 +2,8 @@
title: Use School Data Sync to import student data
description: Learn how to use the new Microsoft Education system to set up a cloud infrastructure for your school, acquire devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, School Data Sync, Microsoft Teams, Microsoft Store for Education, Azure AD, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: get-started
diff --git a/education/trial-in-a-box/educator-tib-get-started.md b/education/trial-in-a-box/educator-tib-get-started.md
index 1995443537..1a1f2a36e8 100644
--- a/education/trial-in-a-box/educator-tib-get-started.md
+++ b/education/trial-in-a-box/educator-tib-get-started.md
@@ -3,6 +3,7 @@ title: Educator Trial in a Box Guide
description: Need help or have a question about using Microsoft Education? Start here.
keywords: support, troubleshooting, education, Microsoft Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, Microsoft Store for Education, Set up School PCs
ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: article
@@ -26,7 +27,8 @@ ms.date: 03/18/2018
| [](#edu-task2) | **Interested in significantly improving your students' reading speed and comprehension?[1](#footnote1)** Try the [Learning Tools Immersive Reader](#edu-task2) to see how kids can learn to read faster, using text read aloud, and highlighting words for syntax. |
| [](#edu-task3) | **Looking to foster collaboration, communication, and critical thinking in the classroom?** Launch [Microsoft Teams](#edu-task3) and learn how to set up digital classroom discussions, respond to student questions, and organize class content. |
| [](#edu-task4) | **Trying to expand classroom creativity and interaction between students?** Open [OneNote](#edu-task4) and create an example group project for your class. |
-| [](#edu-task5) | **Want to teach kids to further collaborate and problem solve?** Play with [Minecraft: Education Edition](#edu-task5) to see how it can be used as a collaborative and versatile platform across subjects to encourage 21st century skills. |
+| [](#edu-task5) | **Curious about telling stories through video?** Try the [Photos app](#edu-task5) to make your own example video. |
+| [](#edu-task6) | **Want to teach kids to further collaborate and problem solve?** Play with [Minecraft: Education Edition](#edu-task6) to see how it can be used as a collaborative and versatile platform across subjects to encourage 21st century skills. |
| | |
@@ -42,8 +44,8 @@ ms.date: 03/18/2018
To try out the educator tasks, start by logging in as a teacher.
1. Turn on **Device A** and ensure you plug in the PC to an electrical outlet.
-2. Connect to your school's Wi-Fi network or connect with a local Ethernet connection.
- >**Note**: If your Wi-Fi network requires a web browser login page to connect to the Internet you should connect using the Ethernet port. If your Wi-Fi network has additional restrictions that will prevent the device from connecting to the internet without registration you should consider using Device A from a different network.
+2. Connect **Device A** to your school's Wi-Fi network or connect with a local Ethernet connection using the Ethernet adapter included in this kit.
+ >**Note**: If your Wi-Fi network requires a web browser login page to connect to the Internet, connect using the Ethernet port. If your Wi-Fi network has additional restrictions that will prevent the device from connecting to the internet without registration, consider connecting **Device A** to a different network.
3. Log in to **Device A** using the **Teacher Username** and **Teacher Password** included in the **Credentials Sheet** located in your kit.
@@ -67,13 +69,17 @@ Learning Tools and the Immersive Reader can be used in the Microsoft Edge browse
**Try this!**
1. On the **Start** menu, click the Word document titled **Design Think**.
+
2. Click **Edit Document** and select **Edit in Browser**.
+
3. Select the **View** menu.
+
4. Select the **Immersive Reader** button.

5. Press the **Play** button to hear text read aloud.
+
6. Select these various settings to see different ways to configure Immersive Reader for your students.
| Text to Speech | Text Preferences | Grammar Options | Line Focus |
@@ -100,6 +106,7 @@ Take a guided tour of Microsoft Teams and test drive this digital hub.
**Try this!**
1. Take a guided tour of Microsoft Teams and test drive some teaching tasks. Open the Microsoft Edge browser and navigate to https://msteamsdemo.azurewebsites.net.
+
2. Use your school credentials provided in the **Credentials Sheet**.
@@ -120,7 +127,9 @@ See how a group project comes together with opportunities to interact with other
When you're not using the pen, just use the magnet to stick it to the left side of the screen until you need it again.
1. On the **Start** menu, click the OneNote shortcut named **Imagine Giza** to open the **Reimagine the Great Pyramid of Giza project**.
+
2. Take the digital pen out of the box and make notes or draw.
+
3. Follow the instructions for the project. Look for the **Try this!** callouts to experiment with these engaging activities.
- Discover the power of digital ink by selecting the Draw tab. Choose your pen and get scribbling.
@@ -138,10 +147,11 @@ When you're not using the pen, just use the magnet to stick it to the left side
-
+

-## 5. Get kids to further collaborate and problem solve
+## 6. Get kids to further collaborate and problem solve
> [!VIDEO https://www.youtube.com/embed/QI_bRNUugog]
@@ -197,24 +219,31 @@ Minecraft: Education Edition provides an immersive environment to develop creati
Today, we'll explore a Minecraft world through the eyes of a student.
1. Connect the included mouse to your computer for optimal interaction.
+
2. Open Microsoft Edge and visit https://aka.ms/lessonhub.
+
3. Scroll down to the **Details** section and select **Download World**.

4. When prompted, save the world.
+
5. Enter your same teacher username and password and click **Accept**.
+
6. Click **OK** on the **Minecraft: Education Edition Free Trial** box.
+
7. Click **Play**.
+
8. Click **Lesson Hub Vol 1** to enter the downloaded world.
+
9. Explore the world by using the keys on your keyboard.
* **W** moves forward.
* **A** moves left.
* **S** moves right.
* **D** moves backward.
-
10. Use your mouse as your "eyes". Just move it to look around.
+
11. For a bird's eye view, double-tap the SPACE BAR. Now press the SPACE BAR to fly higher. And then hold the SHIFT key to safely land.
To try more advanced movements or building within Minecraft, use the Minecraft Controls Diagram.
@@ -232,6 +261,45 @@ Today, we'll explore a Minecraft world through the eyes of a student.

+
+
+
+
**Watch what Educators say about Microsoft Education delivering better learning outcomes**
Bring out the best in students by providing a platform for collaborating, exploring, personalized learning, and getting things done across all devices.
diff --git a/education/trial-in-a-box/images/Math1.png b/education/trial-in-a-box/images/Math1.png
new file mode 100644
index 0000000000..70891c9c29
Binary files /dev/null and b/education/trial-in-a-box/images/Math1.png differ
diff --git a/education/trial-in-a-box/images/Math2.png b/education/trial-in-a-box/images/Math2.png
new file mode 100644
index 0000000000..9ffd2638ac
Binary files /dev/null and b/education/trial-in-a-box/images/Math2.png differ
diff --git a/education/trial-in-a-box/images/edu-tib-setp-6-v4.png b/education/trial-in-a-box/images/edu-tib-setp-6-v4.png
index c46d7861af..72393bc1ea 100644
Binary files a/education/trial-in-a-box/images/edu-tib-setp-6-v4.png and b/education/trial-in-a-box/images/edu-tib-setp-6-v4.png differ
diff --git a/education/trial-in-a-box/images/edu-tib-setp-7-jump.png b/education/trial-in-a-box/images/edu-tib-setp-7-jump.png
new file mode 100644
index 0000000000..1287f292b8
Binary files /dev/null and b/education/trial-in-a-box/images/edu-tib-setp-7-jump.png differ
diff --git a/education/trial-in-a-box/images/edu-tib-setp-7-v1.png b/education/trial-in-a-box/images/edu-tib-setp-7-v1.png
new file mode 100644
index 0000000000..2d113beeaa
Binary files /dev/null and b/education/trial-in-a-box/images/edu-tib-setp-7-v1.png differ
diff --git a/education/trial-in-a-box/index.md b/education/trial-in-a-box/index.md
index 486c9358c7..c44eeb37fb 100644
--- a/education/trial-in-a-box/index.md
+++ b/education/trial-in-a-box/index.md
@@ -2,7 +2,8 @@
title: Microsoft Education Trial in a Box
description: For IT admins, educators, and students, discover what you can do with Microsoft 365 Education. Try it out with our Trial in a Box program.
keywords: education, Microsoft 365 Education, trial, full cloud IT solution, school, deploy, setup, IT admin, educator, student, explore, Trial in a Box
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: article
diff --git a/education/trial-in-a-box/itadmin-tib-get-started.md b/education/trial-in-a-box/itadmin-tib-get-started.md
index d450bc8dea..9381310f46 100644
--- a/education/trial-in-a-box/itadmin-tib-get-started.md
+++ b/education/trial-in-a-box/itadmin-tib-get-started.md
@@ -3,6 +3,7 @@ title: IT Admin Trial in a Box Guide
description: Try out Microsoft 365 Education to implement a full cloud infrastructure for your school, manage devices and apps, and configure and deploy policies to your Windows 10 devices.
keywords: education, Microsoft 365 Education, trial, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, Microsoft Store for Education
ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: get-started
@@ -44,12 +45,13 @@ If you run into any problems while following the steps in this guide, or you hav
## 1. Log in to Device A with your IT Admin credentials and connect to the school network
To try out the IT admin tasks, start by logging in as an IT admin.
-1. Turn on **Device A** and ensure you plug in the PC to an electrical outlet.
-2. Connect to your school's Wi-Fi network or connect with a local Ethernet connection.
- >**Note**: If your Wi-Fi network requires a web browser login page to connect to the Internet you should connect using the Ethernet port. If your Wi-Fi network has additional restrictions that will prevent the device from connecting to the internet without registration you should consider using Device A from a different network.
+1. Set up **Device A** first, then set up **Device B**.
+2. Turn on **Device A** and ensure you plug in the PC to an electrical outlet.
+3. Connect **Device A** to your school's Wi-Fi network or connect with a local Ethernet connection using the Ethernet adapter included in this kit.
+ >**Note**: If your Wi-Fi network requires a web browser login page to connect to the Internet, connect using the Ethernet port. If your Wi-Fi network has additional restrictions that will prevent the device from connecting to the internet without registration, consider connecting **Device A** to a different network.
-3. Log in to **Device A** using the **Administrator Username** and **Administrator Password** included in the **Credentials Sheet** located in your kit.
-4. Note the serial numbers on the Trial in a Box devices and register both devices with the hardware manufacturer to activate the manufacturer's warranty.
+4. Log in to **Device A** using the **Administrator Username** and **Administrator Password** included in the **Credentials Sheet** located in your kit.
+5. Note the serial numbers on the Trial in a Box devices and register both devices with the hardware manufacturer to activate the manufacturer's warranty.
diff --git a/education/trial-in-a-box/support-options.md b/education/trial-in-a-box/support-options.md
index 9df3ab2015..bc8718b81a 100644
--- a/education/trial-in-a-box/support-options.md
+++ b/education/trial-in-a-box/support-options.md
@@ -2,7 +2,8 @@
title: Microsoft Education Trial in a Box Support
description: Need help or have a question about using Microsoft Education Trial in a Box? Start here.
keywords: support, troubleshooting, education, Microsoft 365 Education, full cloud IT solution, school, deploy, setup, manage, Windows 10, Intune for Education, Office 365 for Education, Microsoft Store for Education, Set up School PCs
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.topic: article
diff --git a/education/windows/autopilot-reset.md b/education/windows/autopilot-reset.md
index caf4a7f2c0..f5acaf2f91 100644
--- a/education/windows/autopilot-reset.md
+++ b/education/windows/autopilot-reset.md
@@ -2,7 +2,8 @@
title: Reset devices with Autopilot Reset
description: Gives an overview of Autopilot Reset and how you can enable and use it in your schools.
keywords: Autopilot Reset, Windows 10, education
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/change-history-edu.md b/education/windows/change-history-edu.md
index 2c31544cc6..b65a448e31 100644
--- a/education/windows/change-history-edu.md
+++ b/education/windows/change-history-edu.md
@@ -2,7 +2,8 @@
title: Change history for Windows 10 for Education (Windows 10)
description: New and changed topics in Windows 10 for Education
keywords: Windows 10 education documentation, change history
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/change-to-pro-education.md b/education/windows/change-to-pro-education.md
index 190b45e980..1508eb05f4 100644
--- a/education/windows/change-to-pro-education.md
+++ b/education/windows/change-to-pro-education.md
@@ -3,6 +3,7 @@ title: Change to Windows 10 Education from Windows 10 Pro
description: Learn how IT Pros can opt into changing to Windows 10 Pro Education from Windows 10 Pro.
keywords: change, free change, Windows 10 Pro to Windows 10 Pro Education, Windows 10 Pro to Windows 10 Pro Education, education customers, Windows 10 Pro Education, Windows 10 Pro
ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: edu
@@ -12,12 +13,11 @@ ms.author: MikeBlodge
ms.date: 04/30/2018
---
-# Change to Windows 10 Education from Windows 10 Pro
+# Change to Windows 10 Pro Education from Windows 10 Pro
Windows 10 Pro Education is a new offering in Windows 10, version 1607. This edition builds on the commercial version of Windows 10 Pro and provides important management controls needed in schools by providing education-specific default settings.
If you have an education tenant and use devices with Windows 10 Pro, global administrators can opt-in to a free change to Windows 10 Pro Education depending on your scenario.
-- [Switch from Windows 10 Pro in S mode to Windows 10 Pro Education in S mode](https://www.microsoft.com/en-us/education/windows/s-mode-change-to-edu)
-- [Switch from Windows 10 Pro to Windows 10 Pro Education](#switch-from-windows-10-pro-to-windows-10-pro-education)
+- [Switch to Windows 10 Pro Education in S mode from Windows 10 Pro in S mode](https://docs.microsoft.com/en-us/education/windows/s-mode-switch-to-edu)
To take advantage of this offering, make sure you meet the [requirements for changing](#requirements-for-changing). For academic customers who are eligible to change to Windows 10 Pro Education, but are unable to use the above methods, contact Microsoft Support for assistance.
@@ -90,7 +90,7 @@ You can use Windows Configuration Designer to create a provisioning package that
## Education customers with Azure AD joined devices
-Academic institutions can easily move from Windows 10 Pro to Windows 10 Pro Education without using activation keys or reboots. When one of your users enters their Azure AD credentials associated with a Windows 10 Pro Education license, the operating system changees to Windows 10 Pro Education and all the appropriate Windows 10 Pro Education features are unlocked. Previously, only schools or organizations purchasing devices as part of the Shape the Future K-12 program or with a Microsoft Volume Licensing Agreement could deploy Windows 10 Pro Education to their users. Now, if you have an Azure AD for your organization, you can take advantage of the Windows 10 Pro Education features.
+Academic institutions can easily move from Windows 10 Pro to Windows 10 Pro Education without using activation keys or reboots. When one of your users enters their Azure AD credentials associated with a Windows 10 Pro Education license, the operating system changes to Windows 10 Pro Education and all the appropriate Windows 10 Pro Education features are unlocked. Previously, only schools or organizations purchasing devices as part of the Shape the Future K-12 program or with a Microsoft Volume Licensing Agreement could deploy Windows 10 Pro Education to their users. Now, if you have an Azure AD for your organization, you can take advantage of the Windows 10 Pro Education features.
When you change to Windows 10 Pro Education, you get the following benefits:
@@ -284,10 +284,10 @@ Once the automatic change to Windows 10 Pro Education is turned off, the change

-4. You will be asked if you're sure that you want to turn off automatic changees to Windows 10 Pro Education. Click **Yes**.
+4. You will be asked if you're sure that you want to turn off automatic changes to Windows 10 Pro Education. Click **Yes**.
5. Click **Close** in the **Success** page.
- All global admins get a confirmation email that a request was made to roll back your organization to Windows 10 Pro. If you, or another global admin, decide later that you want to turn on automatic changees again, you can do this by selecting **change to Windows 10 Pro Education for free** from the **Manage > Benefits** in the Microsoft Store for Education.
+ All global admins get a confirmation email that a request was made to roll back your organization to Windows 10 Pro. If you, or another global admin, decide later that you want to turn on automatic changes again, you can do this by selecting **change to Windows 10 Pro Education for free** from the **Manage > Benefits** in the Microsoft Store for Education.
## Preparing for deployment of Windows 10 Pro Education licenses
diff --git a/education/windows/chromebook-migration-guide.md b/education/windows/chromebook-migration-guide.md
index bdc7935944..0b6473c667 100644
--- a/education/windows/chromebook-migration-guide.md
+++ b/education/windows/chromebook-migration-guide.md
@@ -4,6 +4,7 @@ description: In this guide you will learn how to migrate a Google Chromebook-bas
ms.assetid: 7A1FA48A-C44A-4F59-B895-86D4D77F8BEA
keywords: migrate, automate, device, Chromebook migration
ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.pagetype: edu, devices
diff --git a/education/windows/configure-windows-for-education.md b/education/windows/configure-windows-for-education.md
index 2c12c48915..e3d0114db7 100644
--- a/education/windows/configure-windows-for-education.md
+++ b/education/windows/configure-windows-for-education.md
@@ -4,7 +4,8 @@ description: Provides guidance on ways to configure the OS diagnostic data, cons
keywords: Windows 10 deployment, recommendations, privacy settings, school, education, configurations, accessibility, assistive technology
ms.mktglfcycl: plan
ms.sitesec: library
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.pagetype: edu
ms.localizationpriority: high
author: CelesteDG
diff --git a/education/windows/create-tests-using-microsoft-forms.md b/education/windows/create-tests-using-microsoft-forms.md
index a5fdfd4970..3b0c7b4e62 100644
--- a/education/windows/create-tests-using-microsoft-forms.md
+++ b/education/windows/create-tests-using-microsoft-forms.md
@@ -2,7 +2,8 @@
title: Create tests using Microsoft Forms
description: Learn how to use Microsoft Forms with the Take a Test app to prevent access to other computers or online resources while completing a test.
keywords: school, Take a Test, Microsoft Forms
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/deploy-windows-10-in-a-school-district.md b/education/windows/deploy-windows-10-in-a-school-district.md
index af5f429e0c..ab3bedaa0b 100644
--- a/education/windows/deploy-windows-10-in-a-school-district.md
+++ b/education/windows/deploy-windows-10-in-a-school-district.md
@@ -3,6 +3,7 @@ title: Deploy Windows 10 in a school district (Windows 10)
description: Learn how to deploy Windows 10 in a school district. Integrate the school environment with Office 365, Active Directory Domain Services (AD DS), and Microsoft Azure Active Directory (Azure AD), use System Center Configuration Manager, Intune, and Group Policy to manage devices.
keywords: configure, tools, device, school district, deploy Windows 10
ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.pagetype: edu
ms.sitesec: library
diff --git a/education/windows/deploy-windows-10-in-a-school.md b/education/windows/deploy-windows-10-in-a-school.md
index 996d28b59a..20552e300d 100644
--- a/education/windows/deploy-windows-10-in-a-school.md
+++ b/education/windows/deploy-windows-10-in-a-school.md
@@ -3,6 +3,7 @@ title: Deploy Windows 10 in a school (Windows 10)
description: Learn how to integrate your school environment with Microsoft Office 365, Active Directory Domain Services (AD DS), and Microsoft Azure Active Directory (Azure AD). Deploy Windows 10 and apps to new devices or upgrade existing devices to Windows 10. Manage faculty, students, and devices by using Microsoft Intune and Group Policy.
keywords: configure, tools, device, school, deploy Windows 10
ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.pagetype: edu
ms.sitesec: library
diff --git a/education/windows/edu-deployment-recommendations.md b/education/windows/edu-deployment-recommendations.md
index 707c3f7956..b65f7776f4 100644
--- a/education/windows/edu-deployment-recommendations.md
+++ b/education/windows/edu-deployment-recommendations.md
@@ -9,6 +9,7 @@ author: CelesteDG
ms.author: celested
ms.date: 10/13/2017
ms.prod: W10
+ms.technology: Windows
---
# Deployment recommendations for school IT administrators
diff --git a/education/windows/education-scenarios-store-for-business.md b/education/windows/education-scenarios-store-for-business.md
index fad685b3d2..7818bc8ecf 100644
--- a/education/windows/education-scenarios-store-for-business.md
+++ b/education/windows/education-scenarios-store-for-business.md
@@ -11,6 +11,7 @@ searchScope:
author: trudyha
ms.author: trudyha
ms.date: 3/30/2018
+ms.technology: Windows
---
# Working with Microsoft Store for Education
diff --git a/education/windows/get-minecraft-device-promotion.md b/education/windows/get-minecraft-device-promotion.md
index 5250c1f8df..45c3a1d2d0 100644
--- a/education/windows/get-minecraft-device-promotion.md
+++ b/education/windows/get-minecraft-device-promotion.md
@@ -11,6 +11,7 @@ searchScope:
- Store
ms.author: trudyha
ms.date: 07/27/2017
+ms.technology: Windows
---
# Get Minecraft: Education Edition with Windows 10 device promotion
diff --git a/education/windows/get-minecraft-for-education.md b/education/windows/get-minecraft-for-education.md
index 1abe2df826..2354f8351b 100644
--- a/education/windows/get-minecraft-for-education.md
+++ b/education/windows/get-minecraft-for-education.md
@@ -11,6 +11,8 @@ searchScope:
- Store
ms.author: trudyha
ms.date: 07/27/2017
+ms.technology: Windows
+ms.topic: conceptual
---
# Get Minecraft: Education Edition
diff --git a/education/windows/index.md b/education/windows/index.md
index d579704f5f..3c74f8e5ab 100644
--- a/education/windows/index.md
+++ b/education/windows/index.md
@@ -2,7 +2,8 @@
title: Windows 10 for Education (Windows 10)
description: Learn how to use Windows 10 in schools.
keywords: Windows 10, education
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/s-mode-switch-to-edu.md b/education/windows/s-mode-switch-to-edu.md
index 4fc7cd0c9e..9e17d2476b 100644
--- a/education/windows/s-mode-switch-to-edu.md
+++ b/education/windows/s-mode-switch-to-edu.md
@@ -5,13 +5,14 @@ keywords: Windows 10 Pro Education in S mode, S mode, system requirements, Overv
ms.mktglfcycl: deploy
ms.localizationpriority: high
ms.prod: w10
+ms.technology: Windows
ms.sitesec: library
ms.pagetype: edu
ms.date: 04/30/2018
author: Mikeblodge
---
-# Windows 10 Pro in S mode for Education
+# Switch to Windows 10 Pro Education in S mode from Windows 10 Pro in S mode
S mode is an enhanced security mode of Windows 10 – streamlined for security and superior performance. With Windows 10 in S mode, everyone can download and install Microsoft-verified apps from the Microsoft Store for Education – this keep devices running fast and secure day in and day out.
@@ -39,10 +40,7 @@ S mode is an enhanced security mode of Windows 10 – streamlined for security a
|Device Guard | | | | X |
### Windows 10 in S mode is safe, secure, and fast.
-However, in some limited scenarios, you might need to switch to Windows 10 Education. You can switch devices running Windows 10, version 1709 or later. Use the following information to switch to Windows 10 Pro through the Microsoft Store.
-
-> [!IMPORTANT]
-> While it’s free to switch to Windows 10 Pro, it’s not reversible. The only way to rollback this kind of switch is through a BMR factory reset.
+However, in some limited scenarios, you might need to switch to Windows 10 Education. You can switch devices running Windows 10, version 1709 or later. Use the following information to switch to Windows 10 Pro through the Microsoft Store.
## How to switch
@@ -54,8 +52,10 @@ There are two switch options available using the Microsoft Store for Education:
Tenant-wide Windows 10 Pro in S mode > Pro Education in S mode
Tenant-wide Windows 10 Pro > Pro Education
-> [!NOTE]
-> To rollback to Windows 10 Pro in S mode, a BMR factory reset must be performed.
+> [!IMPORTANT]
+> While it’s free to switch to Windows 10 Pro, it’s not reversible. The only way to rollback this kind of switch is through a BMR factory reset..
+
+[Recovery media (bare metal recovery)](https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/create-media-to-run-push-button-reset-features-s14) helps restore a Windows device to the factory state, even if the user needs to replace the hard drive or completely wipe the drive clean. If a device is switched out of S mode via the Microsoft Store, it will remain out of S mode even after the device is reset.
### Devices running Windows 10, version 1709
diff --git a/education/windows/school-get-minecraft.md b/education/windows/school-get-minecraft.md
index f0c3df0aea..8b1cd7033a 100644
--- a/education/windows/school-get-minecraft.md
+++ b/education/windows/school-get-minecraft.md
@@ -11,6 +11,8 @@ searchScope:
- Store
ms.author: trudyha
ms.date: 1/5/2018
+ms.technology: Windows
+ms.topic: conceptual
---
# For IT administrators - get Minecraft: Education Edition
diff --git a/education/windows/set-up-school-pcs-technical.md b/education/windows/set-up-school-pcs-technical.md
index 8164b32aca..4494eb052d 100644
--- a/education/windows/set-up-school-pcs-technical.md
+++ b/education/windows/set-up-school-pcs-technical.md
@@ -3,6 +3,7 @@ title: Set up School PCs app technical reference
description: Describes the changes that the Set up School PCs app makes to a PC.
keywords: shared cart, shared PC, school, set up school pcs
ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/set-up-students-pcs-to-join-domain.md b/education/windows/set-up-students-pcs-to-join-domain.md
index 76079be7ff..92ad941be7 100644
--- a/education/windows/set-up-students-pcs-to-join-domain.md
+++ b/education/windows/set-up-students-pcs-to-join-domain.md
@@ -3,6 +3,7 @@ title: Set up student PCs to join domain
description: Learn how to use Configuration Designer to easily provision student devices to join Active Directory.
keywords: school, student PC setup, Windows Configuration Designer
ms.prod: W10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.localizationpriority: high
diff --git a/education/windows/set-up-students-pcs-with-apps.md b/education/windows/set-up-students-pcs-with-apps.md
index 80bc4c8bfe..cd215a1424 100644
--- a/education/windows/set-up-students-pcs-with-apps.md
+++ b/education/windows/set-up-students-pcs-with-apps.md
@@ -2,7 +2,8 @@
title: Provision student PCs with apps
description: Learn how to use Configuration Designer to easily provision student devices to join Active Directory.
keywords: shared cart, shared PC, school, provision PCs with apps, Windows Configuration Designer
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.pagetype: edu
ms.mktglfcycl: plan
ms.sitesec: library
diff --git a/education/windows/set-up-windows-10.md b/education/windows/set-up-windows-10.md
index 6c68f0eee5..4ffaef6cf5 100644
--- a/education/windows/set-up-windows-10.md
+++ b/education/windows/set-up-windows-10.md
@@ -2,7 +2,8 @@
title: Set up Windows devices for education
description: Decide which option for setting up Windows 10 is right for you.
keywords: school, Windows device setup, education device setup
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/take-a-test-app-technical.md b/education/windows/take-a-test-app-technical.md
index 937dfe5d9d..ab9a8051ac 100644
--- a/education/windows/take-a-test-app-technical.md
+++ b/education/windows/take-a-test-app-technical.md
@@ -2,7 +2,8 @@
title: Take a Test app technical reference
description: The policies and settings applied by the Take a Test app.
keywords: take a test, test taking, school, policies
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/take-a-test-multiple-pcs.md b/education/windows/take-a-test-multiple-pcs.md
index f83c1e7773..1e0d000611 100644
--- a/education/windows/take-a-test-multiple-pcs.md
+++ b/education/windows/take-a-test-multiple-pcs.md
@@ -3,6 +3,7 @@ title: Set up Take a Test on multiple PCs
description: Learn how to set up and use the Take a Test app on multiple PCs.
keywords: take a test, test taking, school, set up on multiple PCs
ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/take-a-test-single-pc.md b/education/windows/take-a-test-single-pc.md
index 630e913e2d..f9565e53d3 100644
--- a/education/windows/take-a-test-single-pc.md
+++ b/education/windows/take-a-test-single-pc.md
@@ -2,7 +2,8 @@
title: Set up Take a Test on a single PC
description: Learn how to set up and use the Take a Test app on a single PC.
keywords: take a test, test taking, school, set up on single PC
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/take-tests-in-windows-10.md b/education/windows/take-tests-in-windows-10.md
index f41a994602..74b379ba75 100644
--- a/education/windows/take-tests-in-windows-10.md
+++ b/education/windows/take-tests-in-windows-10.md
@@ -2,7 +2,8 @@
title: Take tests in Windows 10
description: Learn how to set up and use the Take a Test app.
keywords: take a test, test taking, school, how to, use Take a Test
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/teacher-get-minecraft.md b/education/windows/teacher-get-minecraft.md
index 14bbe54561..eb7e30081b 100644
--- a/education/windows/teacher-get-minecraft.md
+++ b/education/windows/teacher-get-minecraft.md
@@ -3,6 +3,7 @@ title: For teachers get Minecraft Education Edition
description: Learn how teachers can get and distribute Minecraft.
keywords: school, Minecraft, Education Edition, educators, teachers, acquire, distribute
ms.prod: W10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.localizationpriority: high
@@ -11,6 +12,8 @@ searchScope:
- Store
ms.author: trudyha
ms.date: 1/5/2018
+ms.topic: conceptual
+---
# For teachers - get Minecraft: Education Edition
diff --git a/education/windows/test-windows10s-for-edu.md b/education/windows/test-windows10s-for-edu.md
index 8361320231..306c4127ed 100644
--- a/education/windows/test-windows10s-for-edu.md
+++ b/education/windows/test-windows10s-for-edu.md
@@ -3,7 +3,8 @@ title: Test Windows 10 in S mode on existing Windows 10 education devices
description: Provides guidance on downloading and testing Windows 10 in S mode for existing Windows 10 education devices.
keywords: Windows 10 in S mode, try, download, school, education, Windows 10 in S mode installer, existing Windows 10 education devices
ms.mktglfcycl: deploy
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.pagetype: edu
ms.sitesec: library
ms.localizationpriority: high
diff --git a/education/windows/use-set-up-school-pcs-app.md b/education/windows/use-set-up-school-pcs-app.md
index 2c8ac8ab6f..24bde1c0c2 100644
--- a/education/windows/use-set-up-school-pcs-app.md
+++ b/education/windows/use-set-up-school-pcs-app.md
@@ -2,7 +2,8 @@
title: Use Set up School PCs app
description: Learn how the Set up School PCs app works and how to use it.
keywords: shared cart, shared PC, school, Set up School PCs, overview, how to use
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: edu
diff --git a/education/windows/windows-editions-for-education-customers.md b/education/windows/windows-editions-for-education-customers.md
index 8ceb104dc8..48fe5c1cf7 100644
--- a/education/windows/windows-editions-for-education-customers.md
+++ b/education/windows/windows-editions-for-education-customers.md
@@ -2,7 +2,8 @@
title: Windows 10 editions for education customers
description: Provides an overview of the two Windows 10 editions that are designed for the needs of K-12 institutions.
keywords: Windows 10 Pro Education, Windows 10 Education, Windows 10 editions, education customers
-ms.prod: w10
+ms.prod: w10
+ms.technology: Windows
ms.mktglfcycl: plan
ms.sitesec: library
ms.pagetype: edu
diff --git a/mdop/agpm/use-a-test-environment.md b/mdop/agpm/use-a-test-environment.md
index c9543a0a0c..a7ebad6170 100644
--- a/mdop/agpm/use-a-test-environment.md
+++ b/mdop/agpm/use-a-test-environment.md
@@ -20,7 +20,7 @@ If you use a testing organizational unit (OU) to test Group Policy objects (GPOs
1. While you have the GPO checked out for editing, in the **Group Policy Management Console**, click **Group Policy Objects** in the forest and domain in which you are managing GPOs.
-2. Click the checked out copy of the GPO to be tested. The name will be preceded with **\[Checked Out\]**. (If it is not listed, click **Action**, then **Refresh**. Sort the names alphabetically, and **\[Checked Out\]** GPOs will typically appear at the top of the list.)
+2. Click the checked out copy of the GPO to be tested. The name will be preceded with **\[AGPM\]**. (If it is not listed, click **Action**, then **Refresh**. Sort the names alphabetically, and **\[AGPM\]** GPOs will typically appear at the top of the list.)
3. Drag and drop the GPO to the test OU.
diff --git a/mdop/mbam-v25/mbam-25-supported-configurations.md b/mdop/mbam-v25/mbam-25-supported-configurations.md
index 1c9cdc239c..8c4076c276 100644
--- a/mdop/mbam-v25/mbam-25-supported-configurations.md
+++ b/mdop/mbam-v25/mbam-25-supported-configurations.md
@@ -339,7 +339,7 @@ You must install SQL Server with the **SQL\_Latin1\_General\_CP1\_CI\_AS** coll
@@ -359,6 +359,8 @@ You must install SQL Server with the **SQL\_Latin1\_General\_CP1\_CI\_AS** coll
+**Note**
+In order to support SQL 2016 you must install the March 2017 Servicing Release for MDOP https://www.microsoft.com/en-us/download/details.aspx?id=54967 . In general stay current by always using the most recent servicing update as it also includes all bugfixes and new features.
### SQL Server processor, RAM, and disk space requirements – Stand-alone topology
diff --git a/store-for-business/acquire-apps-microsoft-store-for-business.md b/store-for-business/acquire-apps-microsoft-store-for-business.md
index 3c59ec92f0..c33748b67a 100644
--- a/store-for-business/acquire-apps-microsoft-store-for-business.md
+++ b/store-for-business/acquire-apps-microsoft-store-for-business.md
@@ -6,7 +6,9 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
ms.date: 11/01/2017
+ms.topic: conceptual
ms.localizationpriority: high
---
diff --git a/store-for-business/add-profile-to-devices.md b/store-for-business/add-profile-to-devices.md
index 411a0ae2cd..7dbd97369e 100644
--- a/store-for-business/add-profile-to-devices.md
+++ b/store-for-business/add-profile-to-devices.md
@@ -8,6 +8,7 @@ ms.pagetype: store
author: TrudyHa
ms.author: TrudyHa
ms.date: 2/9/2018
+ms.topic: conceptual
ms.localizationpriority: high
---
diff --git a/store-for-business/add-unsigned-app-to-code-integrity-policy.md b/store-for-business/add-unsigned-app-to-code-integrity-policy.md
index 74835df001..b98108019e 100644
--- a/store-for-business/add-unsigned-app-to-code-integrity-policy.md
+++ b/store-for-business/add-unsigned-app-to-code-integrity-policy.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store, security
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/app-inventory-management-microsoft-store-for-business.md b/store-for-business/app-inventory-management-microsoft-store-for-business.md
index 2471527f23..378577a85c 100644
--- a/store-for-business/app-inventory-management-microsoft-store-for-business.md
+++ b/store-for-business/app-inventory-management-microsoft-store-for-business.md
@@ -8,6 +8,7 @@ ms.sitesec: library
ms.pagetype: store
author: TrudyHa
ms.author: TrudyHa
+ms.topic: conceptual
ms.date: 10/16/2017
---
diff --git a/store-for-business/apps-in-microsoft-store-for-business.md b/store-for-business/apps-in-microsoft-store-for-business.md
index c1dd888a79..ee7ce7e0b1 100644
--- a/store-for-business/apps-in-microsoft-store-for-business.md
+++ b/store-for-business/apps-in-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/assign-apps-to-employees.md b/store-for-business/assign-apps-to-employees.md
index 0b7230b467..3af69fb912 100644
--- a/store-for-business/assign-apps-to-employees.md
+++ b/store-for-business/assign-apps-to-employees.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/13/2017
---
diff --git a/store-for-business/configure-mdm-provider-microsoft-store-for-business.md b/store-for-business/configure-mdm-provider-microsoft-store-for-business.md
index 9cbc2e2676..65cc6bfbe9 100644
--- a/store-for-business/configure-mdm-provider-microsoft-store-for-business.md
+++ b/store-for-business/configure-mdm-provider-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 1/6/2018
---
diff --git a/store-for-business/device-guard-signing-portal.md b/store-for-business/device-guard-signing-portal.md
index 19d5c5bfa6..583e67fbd7 100644
--- a/store-for-business/device-guard-signing-portal.md
+++ b/store-for-business/device-guard-signing-portal.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store, security
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/distribute-apps-from-your-private-store.md b/store-for-business/distribute-apps-from-your-private-store.md
index 2228ac8f3e..468df4a05e 100644
--- a/store-for-business/distribute-apps-from-your-private-store.md
+++ b/store-for-business/distribute-apps-from-your-private-store.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 3/19/2018
---
diff --git a/store-for-business/distribute-apps-to-your-employees-microsoft-store-for-business.md b/store-for-business/distribute-apps-to-your-employees-microsoft-store-for-business.md
index cab6dfb6e3..c6426e7ed9 100644
--- a/store-for-business/distribute-apps-to-your-employees-microsoft-store-for-business.md
+++ b/store-for-business/distribute-apps-to-your-employees-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/13/2017
---
diff --git a/store-for-business/distribute-apps-with-management-tool.md b/store-for-business/distribute-apps-with-management-tool.md
index 34e541c6e4..59c3458632 100644
--- a/store-for-business/distribute-apps-with-management-tool.md
+++ b/store-for-business/distribute-apps-with-management-tool.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/distribute-offline-apps.md b/store-for-business/distribute-offline-apps.md
index 0aacda9288..8885087daa 100644
--- a/store-for-business/distribute-offline-apps.md
+++ b/store-for-business/distribute-offline-apps.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/find-and-acquire-apps-overview.md b/store-for-business/find-and-acquire-apps-overview.md
index 99e13fa7c0..cdfab14a7f 100644
--- a/store-for-business/find-and-acquire-apps-overview.md
+++ b/store-for-business/find-and-acquire-apps-overview.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/index.md b/store-for-business/index.md
index 5c2990c742..71a8c271d1 100644
--- a/store-for-business/index.md
+++ b/store-for-business/index.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/manage-access-to-private-store.md b/store-for-business/manage-access-to-private-store.md
index 9b10d08550..dcf2a8f992 100644
--- a/store-for-business/manage-access-to-private-store.md
+++ b/store-for-business/manage-access-to-private-store.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.date: 10/17/2017
---
@@ -30,7 +32,7 @@ Organizations can use either an MDM policy, or Group Policy to show only their p
## Show private store only using MDM policy
-Organizations using an MDM to manage apps can use a policy to show only the private store. When your MDM supports Microsoft Store for Business, the MDM can use the [Policy CSP](https://msdn.microsoft.com/en-us/library/windows/hardware/dn904962.aspx). More specifically, the [ApplicationManagement/RequirePrivateStoreOnly](https://msdn.microsoft.com/en-us/library/windows/hardware/dn904962.aspx#ApplicationManagement_RequirePrivateStoreOnly) policy.
+Organizations using an MDM to manage apps can use a policy to show only the private store. When your MDM supports Microsoft Store for Business, the MDM can use the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx). More specifically, the [ApplicationManagement/RequirePrivateStoreOnly](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx#ApplicationManagement_RequirePrivateStoreOnly) policy.
**ApplicationManagement/RequirePrivateStoreOnly** policy is supported on the following Windows 10 editions:
- Enterprise
diff --git a/store-for-business/manage-apps-microsoft-store-for-business-overview.md b/store-for-business/manage-apps-microsoft-store-for-business-overview.md
index 85fb5deed0..0659ad86dc 100644
--- a/store-for-business/manage-apps-microsoft-store-for-business-overview.md
+++ b/store-for-business/manage-apps-microsoft-store-for-business-overview.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/manage-mpsa-software-microsoft-store-for-business.md b/store-for-business/manage-mpsa-software-microsoft-store-for-business.md
index 970b3c783f..8f1ca2e3ce 100644
--- a/store-for-business/manage-mpsa-software-microsoft-store-for-business.md
+++ b/store-for-business/manage-mpsa-software-microsoft-store-for-business.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 3/20/2018
---
diff --git a/store-for-business/manage-orders-microsoft-store-for-business.md b/store-for-business/manage-orders-microsoft-store-for-business.md
index 2bc147f08b..f568a374eb 100644
--- a/store-for-business/manage-orders-microsoft-store-for-business.md
+++ b/store-for-business/manage-orders-microsoft-store-for-business.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 11/10/2017
---
diff --git a/store-for-business/manage-private-store-settings.md b/store-for-business/manage-private-store-settings.md
index e851331cdb..1ffbe49b5b 100644
--- a/store-for-business/manage-private-store-settings.md
+++ b/store-for-business/manage-private-store-settings.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.date: 3/29/2018
ms.localizationpriority: high
---
diff --git a/store-for-business/manage-settings-microsoft-store-for-business.md b/store-for-business/manage-settings-microsoft-store-for-business.md
index 7462859380..f3416cdec4 100644
--- a/store-for-business/manage-settings-microsoft-store-for-business.md
+++ b/store-for-business/manage-settings-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/manage-users-and-groups-microsoft-store-for-business.md b/store-for-business/manage-users-and-groups-microsoft-store-for-business.md
index 800ab20f14..d38bfadd62 100644
--- a/store-for-business/manage-users-and-groups-microsoft-store-for-business.md
+++ b/store-for-business/manage-users-and-groups-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
@@ -35,8 +37,8 @@ For more information on Azure AD, see [About Office 365 and Azure Active Directo
## Add user accounts to your Azure AD directory
If you created a new Azure AD directory when you signed up for Store for Business, you'll have a directory set up with one user account - the global administrator. That global administrator can add user accounts to your Azure AD directory. However, adding user accounts to your Azure AD directory will not give those employees access to Store for Business. You'll need to assign Store for Business roles to your employees. For more information, see [Roles and permissions in the Store for Business.](roles-and-permissions-microsoft-store-for-business.md)
-You can use the [Office 365 admin dashboard](https://go.microsoft.com/fwlink/p/?LinkId=708616) or [Azure management portal](https://go.microsoft.com/fwlink/p/?LinkId=691086) to add user accounts to your Azure AD directory. If you'll be using Azure management portal, you'll need an active subscription to [Azure management portal](https://go.microsoft.com/fwlink/p/?LinkId=708617).
+You can use the [Office 365 admin dashboard](https://portal.office.com/adminportal) or [Azure management portal](https://go.microsoft.com/fwlink/p/?LinkId=691086) to add user accounts to your Azure AD directory. If you'll be using Azure management portal, you'll need an active subscription to [Azure management portal](https://go.microsoft.com/fwlink/p/?LinkId=708617).
For more information, see:
-- [Add user accounts using Office 365 admin dashboard](https://go.microsoft.com/fwlink/p/?LinkId=708618)
-- [Add user accounts using Azure management portal](https://go.microsoft.com/fwlink/p/?LinkId=708619)
\ No newline at end of file
+- [Add user accounts using Office 365 admin dashboard](https://support.office.com/en-us/article/add-users-individually-or-in-bulk-to-office-365-admin-help-1970f7d6-03b5-442f-b385-5880b9c256ec)
+- [Add user accounts using Azure management portal](https://go.microsoft.com/fwlink/p/?LinkId=708619)
diff --git a/store-for-business/microsoft-store-for-business-education-powershell-module.md b/store-for-business/microsoft-store-for-business-education-powershell-module.md
index acc4768d86..294c61aa0a 100644
--- a/store-for-business/microsoft-store-for-business-education-powershell-module.md
+++ b/store-for-business/microsoft-store-for-business-education-powershell-module.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
localizationpriority: high
ms.author:
ms.date: 10/22/2017
diff --git a/store-for-business/microsoft-store-for-business-overview.md b/store-for-business/microsoft-store-for-business-overview.md
index 3dd01700a4..c9e7c8d541 100644
--- a/store-for-business/microsoft-store-for-business-overview.md
+++ b/store-for-business/microsoft-store-for-business-overview.md
@@ -7,6 +7,8 @@ ms.pagetype: store, mobile
ms.mktglfcycl: manage
ms.sitesec: library
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/notifications-microsoft-store-business.md b/store-for-business/notifications-microsoft-store-business.md
index 57ea2652f3..f48f641211 100644
--- a/store-for-business/notifications-microsoft-store-business.md
+++ b/store-for-business/notifications-microsoft-store-business.md
@@ -8,6 +8,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/store-for-business/prerequisites-microsoft-store-for-business.md b/store-for-business/prerequisites-microsoft-store-for-business.md
index 48adf681cf..f6c1d85c7c 100644
--- a/store-for-business/prerequisites-microsoft-store-for-business.md
+++ b/store-for-business/prerequisites-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/13/2017
---
diff --git a/store-for-business/release-history-microsoft-store-business-education.md b/store-for-business/release-history-microsoft-store-business-education.md
index bb8c98ae04..59e3fc2354 100644
--- a/store-for-business/release-history-microsoft-store-business-education.md
+++ b/store-for-business/release-history-microsoft-store-business-education.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.date: 4/26/2018
---
diff --git a/store-for-business/roles-and-permissions-microsoft-store-for-business.md b/store-for-business/roles-and-permissions-microsoft-store-for-business.md
index e5c032895c..c784530f81 100644
--- a/store-for-business/roles-and-permissions-microsoft-store-for-business.md
+++ b/store-for-business/roles-and-permissions-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 3/30/2018
---
diff --git a/store-for-business/settings-reference-microsoft-store-for-business.md b/store-for-business/settings-reference-microsoft-store-for-business.md
index 334a1f8ed5..2e66f7c1d2 100644
--- a/store-for-business/settings-reference-microsoft-store-for-business.md
+++ b/store-for-business/settings-reference-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 11/01/2017
---
diff --git a/store-for-business/sfb-change-history.md b/store-for-business/sfb-change-history.md
index 0d80d2e32a..61ba68f8b6 100644
--- a/store-for-business/sfb-change-history.md
+++ b/store-for-business/sfb-change-history.md
@@ -7,6 +7,7 @@ ms.sitesec: library
ms.pagetype: store
author: TrudyHa
ms.author: TrudyHa
+ms.topic: conceptual
ms.date: 4/26/2018
ms.localizationpriority: high
---
diff --git a/store-for-business/sign-code-integrity-policy-with-device-guard-signing.md b/store-for-business/sign-code-integrity-policy-with-device-guard-signing.md
index c042b9fa38..3401fb7506 100644
--- a/store-for-business/sign-code-integrity-policy-with-device-guard-signing.md
+++ b/store-for-business/sign-code-integrity-policy-with-device-guard-signing.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store, security
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/sign-up-microsoft-store-for-business-overview.md b/store-for-business/sign-up-microsoft-store-for-business-overview.md
index cf0109c335..322f58f498 100644
--- a/store-for-business/sign-up-microsoft-store-for-business-overview.md
+++ b/store-for-business/sign-up-microsoft-store-for-business-overview.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/13/2017
---
diff --git a/store-for-business/sign-up-microsoft-store-for-business.md b/store-for-business/sign-up-microsoft-store-for-business.md
index 2de6dc6f94..92588ae4b9 100644
--- a/store-for-business/sign-up-microsoft-store-for-business.md
+++ b/store-for-business/sign-up-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/troubleshoot-microsoft-store-for-business.md b/store-for-business/troubleshoot-microsoft-store-for-business.md
index cc5eefa7a5..85d37c28cb 100644
--- a/store-for-business/troubleshoot-microsoft-store-for-business.md
+++ b/store-for-business/troubleshoot-microsoft-store-for-business.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/13/2017
---
diff --git a/store-for-business/update-microsoft-store-for-business-account-settings.md b/store-for-business/update-microsoft-store-for-business-account-settings.md
index 26d293ea41..498e98ef45 100644
--- a/store-for-business/update-microsoft-store-for-business-account-settings.md
+++ b/store-for-business/update-microsoft-store-for-business-account-settings.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 10/17/2017
---
diff --git a/store-for-business/whats-new-microsoft-store-business-education.md b/store-for-business/whats-new-microsoft-store-business-education.md
index 92debb23e2..22f2d481f3 100644
--- a/store-for-business/whats-new-microsoft-store-business-education.md
+++ b/store-for-business/whats-new-microsoft-store-business-education.md
@@ -6,6 +6,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.date: 4/26/2018
---
diff --git a/store-for-business/working-with-line-of-business-apps.md b/store-for-business/working-with-line-of-business-apps.md
index 0c12c3b9f9..c4c5fb0ad1 100644
--- a/store-for-business/working-with-line-of-business-apps.md
+++ b/store-for-business/working-with-line-of-business-apps.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store
author: TrudyHa
+ms.author: TrudyHa
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 3/19/2018
---
diff --git a/windows/application-management/TOC.md b/windows/application-management/TOC.md
index 310d18137e..e726c4d38f 100644
--- a/windows/application-management/TOC.md
+++ b/windows/application-management/TOC.md
@@ -108,3 +108,4 @@
## [Disabling System Services in Windows Server](https://docs.microsoft.com/windows-server/security/windows-services/security-guidelines-for-disabling-system-services-in-windows-server)
## [Deploy app upgrades on Windows 10 Mobile](deploy-app-upgrades-windows-10-mobile.md)
## [Change history for Application management](change-history-for-application-management.md)
+## [How to keep apps removed from Windows 10 from returning during an update](remove-provisioned-apps-during-update.md)
\ No newline at end of file
diff --git a/windows/application-management/change-history-for-application-management.md b/windows/application-management/change-history-for-application-management.md
index 933bf0e0ab..580efc16c4 100644
--- a/windows/application-management/change-history-for-application-management.md
+++ b/windows/application-management/change-history-for-application-management.md
@@ -8,6 +8,8 @@ ms.sitesec: library
ms.pagetype: security
ms.localizationpriority: medium
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.date: 10/24/2017
---
diff --git a/windows/application-management/manage-windows-mixed-reality.md b/windows/application-management/manage-windows-mixed-reality.md
index d00670af75..f6af0d88a5 100644
--- a/windows/application-management/manage-windows-mixed-reality.md
+++ b/windows/application-management/manage-windows-mixed-reality.md
@@ -8,7 +8,8 @@ ms.sitesec: library
ms.localizationpriority: medium
author: jdeckerms
ms.author: jdecker
-ms.date: 04/30/2018
+ms.topic: article
+ms.date: 05/16/2018
---
# Enable or block Windows Mixed Reality apps in the enterprise
@@ -43,7 +44,7 @@ Organizations that use Windows Server Update Services (WSUS) must take action to
```
Add-Package
- Dism /Image:C:\test\offline /Add-Package /PackagePath:*path to the cab file*
+ Dism /Online /add-package /packagepath:(path)
```
c. In **Settings** > **Update & Security** > **Windows Update**, select **Check for updates**.
diff --git a/windows/application-management/remove-provisioned-apps-during-update.md b/windows/application-management/remove-provisioned-apps-during-update.md
new file mode 100644
index 0000000000..23057f6df2
--- /dev/null
+++ b/windows/application-management/remove-provisioned-apps-during-update.md
@@ -0,0 +1,127 @@
+---
+title: How to keep apps removed from Windows 10 from returning during an update
+description: How to keep provisioned apps that were removed from your machine from returning during an update.
+ms.prod: w10
+ms.mktglfcycl: deploy
+ms.sitesec: library
+ms.author: helohr
+author: HeidiLohr
+ms.date: 05/10/2018
+---
+# How to keep apps removed from Windows 10 from returning during an update
+
+>Applies to: Windows 10 (Semi-Annual Channel)
+
+When you update a computer running Windows 10, version 1703 or 1709, you might see provisioned apps that you previously removed return post-update. This can happen if the computer was offline when you removed the apps. This issue was fixed in Windows 10, version 1803.
+
+>[!NOTE]
+>* This issue only occurs after a feature update (from one version to the next), not monthly updates or security-related updates.
+>* This only applies to first-party apps that shipped with Windows 10. This doesn't apply to third-party apps, Microsoft Store apps, or LOB apps.
+
+To remove a provisioned app, you need to remove the provisioning package. The apps might reappear if you removed the packages in one of the following ways:
+
+* If you removed the packages while the wim file was mounted when the device was offline.
+* If you removed the packages by running a PowerShell cmdlet on the device while Windows was online. Although the apps won't appear for new users, you'll still see the apps for the user account you signed in as.
+
+When you remove a provisioned app, we create a registry key that tells Windows not to reinstall or update that app the next time Windows is updated. If the computer isn't online when you deprovision the app, then we don't create that registry key. (This behavior is fixed in Windows 10, version 1803. If you're running Windows 10, version 1709, apply the latest security update to fix it.)
+
+>[!NOTE]
+>If you remove a provisioned app while Windows is online, it's only removed for *new users*—the user that you signed in as will still have that provisioned app. That's because the registry key created when you deprovision the app only applies to new users created *after* the key is created. This doesn't happen if you remove the provisioned app while Windows is offline.
+
+To prevent these apps from reappearing at the next update, manually create a registry key for each app, then update the computer.
+
+## Create registry keys for deprovisioned apps
+
+Use the following steps to create a registry key:
+
+1. Identify any provisioned apps you want removed. Record the package name for each app.
+2. Create a .reg file to generate a registry key for each app. Use [this list of Windows 10, version 1709 registry keys](#registry-keys-for-provisioned-apps) as your starting point.
+ 1. Paste the list of registry keys into Notepad (or a text editor).
+ 2. Remove the registry keys belonging to the apps you want to keep. For example, if you want to keep the Bing Weather app, delete this registry key:
+ ```
+ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\A ppxAllUserStore\Deprovisioned\Microsoft.BingWeather_8wekyb3d8bbwe]
+ ```
+ 3. Save the file with a .txt extension, then right-click the file and change the extension to .reg.
+3. Double-click the .reg file to create the registry keys. You can see the new keys in HKLM\\path-to-reg-keys.
+
+You're now ready to update your computer. After the update, check the list of apps in the computer to confirm the removed apps are still gone.
+
+## Package names for apps provisioned in Windows 10, version 1709
+
+|Displayed app name|Package name|
+|---|---|
+|Microsoft.3DBuilder|Microsoft.3DBuilder_15.2.10821.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.BingWeather|Microsoft.BingWeather_4.23.10923.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.DesktopAppInstaller|Microsoft.DesktopAppInstaller_1.10.16004.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.GetHelp|Microsoft.GetHelp_10.1706.1811.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.Getstarted|Microsoft.Getstarted_5.12.2691.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.HEVCVideoExtension|Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe|
+|Microsoft.Messaging|Microsoft.Messaging_2018.124.707.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.Microsoft3DViewer|Microsoft.Microsoft3DViewer_3.1803.29012.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.MicrosoftOfficeHub|Microsoft.MicrosoftOfficeHub_2017.715.118.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.MicrosoftSolitaireCollection|Microsoft.MicrosoftSolitaireCollection_3.18.12091.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.MicrosoftStickyNotes|Microsoft.MicrosoftStickyNotes_2.1.18.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.MSPaint|Microsoft.MSPaint_4.1803.21027.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.Office.OneNote|Microsoft.Office.OneNote_2015.9126.21251.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.OneConnect|Microsoft.OneConnect_3.1708.2224.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.People|Microsoft.People_2017.1006.1846.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.Print3D|Microsoft.Print3D_1.0.2422.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.SkypeApp|Microsoft.SkypeApp_12.1811.248.1000_neutral_~_kzf8qxf38zg5c|
+|Microsoft.StorePurchaseApp|Microsoft.StorePurchaseApp_11802.1802.23014.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.Wallet|Microsoft.Wallet_1.0.16328.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.Windows.Photos|Microsoft.Windows.Photos_2018.18022.15810.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.WindowsAlarms|Microsoft.WindowsAlarms_2017.920.157.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.WindowsCalculator|Microsoft.WindowsCalculator_2017.928.0.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.WindowsCamera|Microsoft.WindowsCamera_2017.1117.10.1000_neutral_~_8wekyb3d8bbwe|
+|microsoft.windowscommunicationsapps|microsoft.windowscommunicationsapps_2015.9126.21425.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.WindowsFeedbackHub|Microsoft.WindowsFeedbackHub_2018.323.50.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.WindowsMaps|Microsoft.WindowsMaps_2017.1003.1829.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.WindowsSoundRecorder|Microsoft.WindowsSoundRecorder_2017.928.5.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.WindowsStore|Microsoft.WindowsStore_11803.1001.613.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.Xbox.TCUI|Microsoft.Xbox.TCUI_1.8.24001.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.XboxApp|Microsoft.XboxApp_39.39.21002.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.XboxGameOverlay|Microsoft.XboxGameOverlay_1.24.5001.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.XboxIdentityProvider|Microsoft.XboxIdentityProvider_2017.605.1240.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.XboxSpeechToTextOverlay|Microsoft.XboxSpeechToTextOverlay_1.21.13002.0_neutral_~_8wekyb3d8bbwe|
+|Microsoft.ZuneMusic|Microsoft.ZuneMusic_2019.18011.13411.1000_neutral_~_8wekyb3d8bbwe|
+|Microsoft.ZuneVideo|Microsoft.ZuneVideo_2019.17122.16211.1000_neutral_~_8wekyb3d8bbwe|
+
+## Registry keys for provisioned apps
+
+```syntax
+1709 Registry Keys
+Windows Registry Editor Version 5.00
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.BingWeather_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.GetHelp_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.Getstarted_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.MSPaint_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.Office.OneNote_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.OneConnect_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.People_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.Print3D_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.SkypeApp_kzf8qxf38zg5c]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.StorePurchaseApp_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.Wallet_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.Windows.Photos_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.WindowsAlarms_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.WindowsCalculator_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.WindowsCamera_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\microsoft.windowscommunicationsapps_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.WindowsMaps_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.WindowsStore_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.Xbox.TCUI_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.XboxApp_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.XboxGameOverlay_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.ZuneMusic_8wekyb3d8bbwe]
+[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deprovisioned\Microsoft.ZuneVideo_8wekyb3d8bbwe]
+```
diff --git a/windows/client-management/mdm/accountmanagement-csp.md b/windows/client-management/mdm/accountmanagement-csp.md
index 0575027aa8..866c9e3470 100644
--- a/windows/client-management/mdm/accountmanagement-csp.md
+++ b/windows/client-management/mdm/accountmanagement-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/23/2018
---
diff --git a/windows/client-management/mdm/accountmanagement-ddf.md b/windows/client-management/mdm/accountmanagement-ddf.md
index a7703a14e8..4e6eb780a7 100644
--- a/windows/client-management/mdm/accountmanagement-ddf.md
+++ b/windows/client-management/mdm/accountmanagement-ddf.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/23/2018
---
diff --git a/windows/client-management/mdm/accounts-csp.md b/windows/client-management/mdm/accounts-csp.md
index a5bb5e5ab5..08b59f469e 100644
--- a/windows/client-management/mdm/accounts-csp.md
+++ b/windows/client-management/mdm/accounts-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/17/2018
---
diff --git a/windows/client-management/mdm/accounts-ddf-file.md b/windows/client-management/mdm/accounts-ddf-file.md
index 0153899c28..a6e5b3ded3 100644
--- a/windows/client-management/mdm/accounts-ddf-file.md
+++ b/windows/client-management/mdm/accounts-ddf-file.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/17/2018
---
diff --git a/windows/client-management/mdm/activesync-csp.md b/windows/client-management/mdm/activesync-csp.md
index 80431db230..aed29f1f97 100644
--- a/windows/client-management/mdm/activesync-csp.md
+++ b/windows/client-management/mdm/activesync-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/activesync-ddf-file.md b/windows/client-management/mdm/activesync-ddf-file.md
index 51c1385789..a1c9d4cb8d 100644
--- a/windows/client-management/mdm/activesync-ddf-file.md
+++ b/windows/client-management/mdm/activesync-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/add-an-azure-ad-tenant-and-azure-ad-subscription.md b/windows/client-management/mdm/add-an-azure-ad-tenant-and-azure-ad-subscription.md
index 281dc44c70..5065235319 100644
--- a/windows/client-management/mdm/add-an-azure-ad-tenant-and-azure-ad-subscription.md
+++ b/windows/client-management/mdm/add-an-azure-ad-tenant-and-azure-ad-subscription.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/alljoynmanagement-csp.md b/windows/client-management/mdm/alljoynmanagement-csp.md
index c8e1153a75..8745e5a972 100644
--- a/windows/client-management/mdm/alljoynmanagement-csp.md
+++ b/windows/client-management/mdm/alljoynmanagement-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/alljoynmanagement-ddf.md b/windows/client-management/mdm/alljoynmanagement-ddf.md
index 2356c2dd90..c9da82f50a 100644
--- a/windows/client-management/mdm/alljoynmanagement-ddf.md
+++ b/windows/client-management/mdm/alljoynmanagement-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/application-csp.md b/windows/client-management/mdm/application-csp.md
index a8eaca5a12..2f3b7f1d06 100644
--- a/windows/client-management/mdm/application-csp.md
+++ b/windows/client-management/mdm/application-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/applicationrestrictions-xsd.md b/windows/client-management/mdm/applicationrestrictions-xsd.md
index 54e3d3c6b5..1a54b6702f 100644
--- a/windows/client-management/mdm/applicationrestrictions-xsd.md
+++ b/windows/client-management/mdm/applicationrestrictions-xsd.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/applocker-csp.md b/windows/client-management/mdm/applocker-csp.md
index e380c4b6bf..f1f1e0aaaa 100644
--- a/windows/client-management/mdm/applocker-csp.md
+++ b/windows/client-management/mdm/applocker-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/30/2018
---
diff --git a/windows/client-management/mdm/applocker-ddf-file.md b/windows/client-management/mdm/applocker-ddf-file.md
index fe6e6c167c..b61780ae9e 100644
--- a/windows/client-management/mdm/applocker-ddf-file.md
+++ b/windows/client-management/mdm/applocker-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/applocker-xsd.md b/windows/client-management/mdm/applocker-xsd.md
index ecce16aabf..ea7901dc45 100644
--- a/windows/client-management/mdm/applocker-xsd.md
+++ b/windows/client-management/mdm/applocker-xsd.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/appv-deploy-and-config.md b/windows/client-management/mdm/appv-deploy-and-config.md
index 1a3dce230a..5b7d449cb7 100644
--- a/windows/client-management/mdm/appv-deploy-and-config.md
+++ b/windows/client-management/mdm/appv-deploy-and-config.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/assign-seats.md b/windows/client-management/mdm/assign-seats.md
index dfe0baab52..1033a9f800 100644
--- a/windows/client-management/mdm/assign-seats.md
+++ b/windows/client-management/mdm/assign-seats.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/assignedaccess-csp.md b/windows/client-management/mdm/assignedaccess-csp.md
index 7287b515ba..9ee6c9171a 100644
--- a/windows/client-management/mdm/assignedaccess-csp.md
+++ b/windows/client-management/mdm/assignedaccess-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/25/2018
---
diff --git a/windows/client-management/mdm/assignedaccess-ddf.md b/windows/client-management/mdm/assignedaccess-ddf.md
index f57c98d76e..a76545fe53 100644
--- a/windows/client-management/mdm/assignedaccess-ddf.md
+++ b/windows/client-management/mdm/assignedaccess-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 02/22/2018
---
diff --git a/windows/client-management/mdm/azure-active-directory-integration-with-mdm.md b/windows/client-management/mdm/azure-active-directory-integration-with-mdm.md
index 87f7c33162..e4e4f8910a 100644
--- a/windows/client-management/mdm/azure-active-directory-integration-with-mdm.md
+++ b/windows/client-management/mdm/azure-active-directory-integration-with-mdm.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/05/2017
---
diff --git a/windows/client-management/mdm/azure-ad-and-microsoft-intune-automatic-mdm-enrollment-in-the-new-portal.md b/windows/client-management/mdm/azure-ad-and-microsoft-intune-automatic-mdm-enrollment-in-the-new-portal.md
index f93d78ce36..c0a57334bc 100644
--- a/windows/client-management/mdm/azure-ad-and-microsoft-intune-automatic-mdm-enrollment-in-the-new-portal.md
+++ b/windows/client-management/mdm/azure-ad-and-microsoft-intune-automatic-mdm-enrollment-in-the-new-portal.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 01/17/2018
---
diff --git a/windows/client-management/mdm/bitlocker-csp.md b/windows/client-management/mdm/bitlocker-csp.md
index ce295ef0c7..a1a2dd3a81 100644
--- a/windows/client-management/mdm/bitlocker-csp.md
+++ b/windows/client-management/mdm/bitlocker-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 01/04/2018
---
diff --git a/windows/client-management/mdm/bitlocker-ddf-file.md b/windows/client-management/mdm/bitlocker-ddf-file.md
index 2e799e20dd..b3df788f7c 100644
--- a/windows/client-management/mdm/bitlocker-ddf-file.md
+++ b/windows/client-management/mdm/bitlocker-ddf-file.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/bootstrap-csp.md b/windows/client-management/mdm/bootstrap-csp.md
index 91c374f17b..e59f02fc74 100644
--- a/windows/client-management/mdm/bootstrap-csp.md
+++ b/windows/client-management/mdm/bootstrap-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/browserfavorite-csp.md b/windows/client-management/mdm/browserfavorite-csp.md
index 5dc4046e6f..de3a4c2736 100644
--- a/windows/client-management/mdm/browserfavorite-csp.md
+++ b/windows/client-management/mdm/browserfavorite-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/bulk-assign-and-reclaim-seats-from-user.md b/windows/client-management/mdm/bulk-assign-and-reclaim-seats-from-user.md
index 1bf6f155f5..953ec2e528 100644
--- a/windows/client-management/mdm/bulk-assign-and-reclaim-seats-from-user.md
+++ b/windows/client-management/mdm/bulk-assign-and-reclaim-seats-from-user.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md b/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
index ea6b39ee4f..63c22e0fb2 100644
--- a/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
+++ b/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/cellularsettings-csp.md b/windows/client-management/mdm/cellularsettings-csp.md
index 21a3bbbdc4..19669fb1b1 100644
--- a/windows/client-management/mdm/cellularsettings-csp.md
+++ b/windows/client-management/mdm/cellularsettings-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/certificate-authentication-device-enrollment.md b/windows/client-management/mdm/certificate-authentication-device-enrollment.md
index a7b94f6b27..6562fc73d0 100644
--- a/windows/client-management/mdm/certificate-authentication-device-enrollment.md
+++ b/windows/client-management/mdm/certificate-authentication-device-enrollment.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/certificate-renewal-windows-mdm.md b/windows/client-management/mdm/certificate-renewal-windows-mdm.md
index b2241c0952..a857467f1a 100644
--- a/windows/client-management/mdm/certificate-renewal-windows-mdm.md
+++ b/windows/client-management/mdm/certificate-renewal-windows-mdm.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/certificatestore-csp.md b/windows/client-management/mdm/certificatestore-csp.md
index 21a4fb28c2..cde5940e24 100644
--- a/windows/client-management/mdm/certificatestore-csp.md
+++ b/windows/client-management/mdm/certificatestore-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/certificatestore-ddf-file.md b/windows/client-management/mdm/certificatestore-ddf-file.md
index ab234ad8a1..820779ea14 100644
--- a/windows/client-management/mdm/certificatestore-ddf-file.md
+++ b/windows/client-management/mdm/certificatestore-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/cleanpc-csp.md b/windows/client-management/mdm/cleanpc-csp.md
index 78bcc6d494..4ce39d12fb 100644
--- a/windows/client-management/mdm/cleanpc-csp.md
+++ b/windows/client-management/mdm/cleanpc-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/cleanpc-ddf.md b/windows/client-management/mdm/cleanpc-ddf.md
index af04d6e6d4..1c1c3ded0a 100644
--- a/windows/client-management/mdm/cleanpc-ddf.md
+++ b/windows/client-management/mdm/cleanpc-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/clientcertificateinstall-csp.md b/windows/client-management/mdm/clientcertificateinstall-csp.md
index 1183e5b3d6..bf01d38374 100644
--- a/windows/client-management/mdm/clientcertificateinstall-csp.md
+++ b/windows/client-management/mdm/clientcertificateinstall-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 11/03/2017
---
diff --git a/windows/client-management/mdm/clientcertificateinstall-ddf-file.md b/windows/client-management/mdm/clientcertificateinstall-ddf-file.md
index 10617e23a2..977dd79898 100644
--- a/windows/client-management/mdm/clientcertificateinstall-ddf-file.md
+++ b/windows/client-management/mdm/clientcertificateinstall-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/cm-cellularentries-csp.md b/windows/client-management/mdm/cm-cellularentries-csp.md
index 22bb311265..adffb8bef0 100644
--- a/windows/client-management/mdm/cm-cellularentries-csp.md
+++ b/windows/client-management/mdm/cm-cellularentries-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 08/02/2017
---
diff --git a/windows/client-management/mdm/cm-proxyentries-csp.md b/windows/client-management/mdm/cm-proxyentries-csp.md
index 59956b5db5..50b393f039 100644
--- a/windows/client-management/mdm/cm-proxyentries-csp.md
+++ b/windows/client-management/mdm/cm-proxyentries-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/cmpolicy-csp.md b/windows/client-management/mdm/cmpolicy-csp.md
index 1eeee323ba..6b1ae02496 100644
--- a/windows/client-management/mdm/cmpolicy-csp.md
+++ b/windows/client-management/mdm/cmpolicy-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/cmpolicyenterprise-csp.md b/windows/client-management/mdm/cmpolicyenterprise-csp.md
index 75a6658d5e..46f6724edb 100644
--- a/windows/client-management/mdm/cmpolicyenterprise-csp.md
+++ b/windows/client-management/mdm/cmpolicyenterprise-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/cmpolicyenterprise-ddf-file.md b/windows/client-management/mdm/cmpolicyenterprise-ddf-file.md
index 17d660ee81..8082e19a7b 100644
--- a/windows/client-management/mdm/cmpolicyenterprise-ddf-file.md
+++ b/windows/client-management/mdm/cmpolicyenterprise-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/configuration-service-provider-reference.md b/windows/client-management/mdm/configuration-service-provider-reference.md
index dbd55b06f3..1bc5f854f8 100644
--- a/windows/client-management/mdm/configuration-service-provider-reference.md
+++ b/windows/client-management/mdm/configuration-service-provider-reference.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/24/2018
---
diff --git a/windows/client-management/mdm/create-a-custom-configuration-service-provider.md b/windows/client-management/mdm/create-a-custom-configuration-service-provider.md
index 97eba5a985..e9e64f8c54 100644
--- a/windows/client-management/mdm/create-a-custom-configuration-service-provider.md
+++ b/windows/client-management/mdm/create-a-custom-configuration-service-provider.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/customdeviceui-csp.md b/windows/client-management/mdm/customdeviceui-csp.md
index b813a4a4d1..06c4308457 100644
--- a/windows/client-management/mdm/customdeviceui-csp.md
+++ b/windows/client-management/mdm/customdeviceui-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/customdeviceui-ddf.md b/windows/client-management/mdm/customdeviceui-ddf.md
index 265fa33a9b..d862212b6c 100644
--- a/windows/client-management/mdm/customdeviceui-ddf.md
+++ b/windows/client-management/mdm/customdeviceui-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/data-structures-windows-store-for-business.md b/windows/client-management/mdm/data-structures-windows-store-for-business.md
index 4f63cd3e06..3b6a66593b 100644
--- a/windows/client-management/mdm/data-structures-windows-store-for-business.md
+++ b/windows/client-management/mdm/data-structures-windows-store-for-business.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/defender-csp.md b/windows/client-management/mdm/defender-csp.md
index 3abe24d7f7..3e9c038842 100644
--- a/windows/client-management/mdm/defender-csp.md
+++ b/windows/client-management/mdm/defender-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 01/29/2018
---
diff --git a/windows/client-management/mdm/defender-ddf.md b/windows/client-management/mdm/defender-ddf.md
index 1a0438dc8e..c0f90952b5 100644
--- a/windows/client-management/mdm/defender-ddf.md
+++ b/windows/client-management/mdm/defender-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 01/29/20178
---
diff --git a/windows/client-management/mdm/design-a-custom-windows-csp.md b/windows/client-management/mdm/design-a-custom-windows-csp.md
index de5fb5efed..66df907c0c 100644
--- a/windows/client-management/mdm/design-a-custom-windows-csp.md
+++ b/windows/client-management/mdm/design-a-custom-windows-csp.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/devdetail-csp.md b/windows/client-management/mdm/devdetail-csp.md
index 786d02beff..4537f2c630 100644
--- a/windows/client-management/mdm/devdetail-csp.md
+++ b/windows/client-management/mdm/devdetail-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 08/25/2017
---
diff --git a/windows/client-management/mdm/devdetail-ddf-file.md b/windows/client-management/mdm/devdetail-ddf-file.md
index 9ae9264eea..7a3c0a14cc 100644
--- a/windows/client-management/mdm/devdetail-ddf-file.md
+++ b/windows/client-management/mdm/devdetail-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/developersetup-csp.md b/windows/client-management/mdm/developersetup-csp.md
index de3145a84f..6562f29006 100644
--- a/windows/client-management/mdm/developersetup-csp.md
+++ b/windows/client-management/mdm/developersetup-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/developersetup-ddf.md b/windows/client-management/mdm/developersetup-ddf.md
index 6560f47d5a..6ca207820f 100644
--- a/windows/client-management/mdm/developersetup-ddf.md
+++ b/windows/client-management/mdm/developersetup-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/device-update-management.md b/windows/client-management/mdm/device-update-management.md
index d00d0a4d57..f20da5c4c5 100644
--- a/windows/client-management/mdm/device-update-management.md
+++ b/windows/client-management/mdm/device-update-management.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 11/15/2017
---
diff --git a/windows/client-management/mdm/deviceinstanceservice-csp.md b/windows/client-management/mdm/deviceinstanceservice-csp.md
index daa68b5f98..9c8435dbaa 100644
--- a/windows/client-management/mdm/deviceinstanceservice-csp.md
+++ b/windows/client-management/mdm/deviceinstanceservice-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/devicelock-csp.md b/windows/client-management/mdm/devicelock-csp.md
index d70696fa67..8d44aca043 100644
--- a/windows/client-management/mdm/devicelock-csp.md
+++ b/windows/client-management/mdm/devicelock-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/devicelock-ddf-file.md b/windows/client-management/mdm/devicelock-ddf-file.md
index b28ed962ce..11ec6e0bf0 100644
--- a/windows/client-management/mdm/devicelock-ddf-file.md
+++ b/windows/client-management/mdm/devicelock-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/devicemanageability-csp.md b/windows/client-management/mdm/devicemanageability-csp.md
index 3ddbb3dcaa..fb86e76896 100644
--- a/windows/client-management/mdm/devicemanageability-csp.md
+++ b/windows/client-management/mdm/devicemanageability-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 11/01/2017
---
diff --git a/windows/client-management/mdm/devicemanageability-ddf.md b/windows/client-management/mdm/devicemanageability-ddf.md
index ebb83615c2..44440337e3 100644
--- a/windows/client-management/mdm/devicemanageability-ddf.md
+++ b/windows/client-management/mdm/devicemanageability-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/devicestatus-csp.md b/windows/client-management/mdm/devicestatus-csp.md
index 25e45dfb80..89a798ab13 100644
--- a/windows/client-management/mdm/devicestatus-csp.md
+++ b/windows/client-management/mdm/devicestatus-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/12/2018
---
diff --git a/windows/client-management/mdm/devicestatus-ddf.md b/windows/client-management/mdm/devicestatus-ddf.md
index 7e4a7a5933..8f0e5a3364 100644
--- a/windows/client-management/mdm/devicestatus-ddf.md
+++ b/windows/client-management/mdm/devicestatus-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/12/2018
---
diff --git a/windows/client-management/mdm/devinfo-csp.md b/windows/client-management/mdm/devinfo-csp.md
index b7a165df3b..bbff58b76c 100644
--- a/windows/client-management/mdm/devinfo-csp.md
+++ b/windows/client-management/mdm/devinfo-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/devinfo-ddf-file.md b/windows/client-management/mdm/devinfo-ddf-file.md
index 114a481554..8b88fb1918 100644
--- a/windows/client-management/mdm/devinfo-ddf-file.md
+++ b/windows/client-management/mdm/devinfo-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/diagnose-mdm-failures-in-windows-10.md b/windows/client-management/mdm/diagnose-mdm-failures-in-windows-10.md
index 8301049541..9fc4d5138f 100644
--- a/windows/client-management/mdm/diagnose-mdm-failures-in-windows-10.md
+++ b/windows/client-management/mdm/diagnose-mdm-failures-in-windows-10.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/diagnosticlog-csp.md b/windows/client-management/mdm/diagnosticlog-csp.md
index 106105c026..4b9157ad49 100644
--- a/windows/client-management/mdm/diagnosticlog-csp.md
+++ b/windows/client-management/mdm/diagnosticlog-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/diagnosticlog-ddf.md b/windows/client-management/mdm/diagnosticlog-ddf.md
index 31cee8e1de..4fb7edff7c 100644
--- a/windows/client-management/mdm/diagnosticlog-ddf.md
+++ b/windows/client-management/mdm/diagnosticlog-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/disconnecting-from-mdm-unenrollment.md b/windows/client-management/mdm/disconnecting-from-mdm-unenrollment.md
index 03e23b59f5..13878c6f74 100644
--- a/windows/client-management/mdm/disconnecting-from-mdm-unenrollment.md
+++ b/windows/client-management/mdm/disconnecting-from-mdm-unenrollment.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/dmacc-csp.md b/windows/client-management/mdm/dmacc-csp.md
index e0a6c7450e..8db057501d 100644
--- a/windows/client-management/mdm/dmacc-csp.md
+++ b/windows/client-management/mdm/dmacc-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/dmacc-ddf-file.md b/windows/client-management/mdm/dmacc-ddf-file.md
index 31b0c6a655..93a041f3d1 100644
--- a/windows/client-management/mdm/dmacc-ddf-file.md
+++ b/windows/client-management/mdm/dmacc-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/dmclient-csp.md b/windows/client-management/mdm/dmclient-csp.md
index 6adcc5b415..bde1f8c70d 100644
--- a/windows/client-management/mdm/dmclient-csp.md
+++ b/windows/client-management/mdm/dmclient-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 11/01/2017
---
diff --git a/windows/client-management/mdm/dmclient-ddf-file.md b/windows/client-management/mdm/dmclient-ddf-file.md
index e4a11620fa..1c171bbb0f 100644
--- a/windows/client-management/mdm/dmclient-ddf-file.md
+++ b/windows/client-management/mdm/dmclient-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/dmprocessconfigxmlfiltered.md b/windows/client-management/mdm/dmprocessconfigxmlfiltered.md
index 880ca3e6ec..f035ff93d4 100644
--- a/windows/client-management/mdm/dmprocessconfigxmlfiltered.md
+++ b/windows/client-management/mdm/dmprocessconfigxmlfiltered.md
@@ -16,7 +16,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/dmsessionactions-csp.md b/windows/client-management/mdm/dmsessionactions-csp.md
index 6b098de192..6e8aa70785 100644
--- a/windows/client-management/mdm/dmsessionactions-csp.md
+++ b/windows/client-management/mdm/dmsessionactions-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/dmsessionactions-ddf.md b/windows/client-management/mdm/dmsessionactions-ddf.md
index d04dff87aa..e587b4c69f 100644
--- a/windows/client-management/mdm/dmsessionactions-ddf.md
+++ b/windows/client-management/mdm/dmsessionactions-ddf.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/dynamicmanagement-csp.md b/windows/client-management/mdm/dynamicmanagement-csp.md
index cbe6465b8c..4d50badd48 100644
--- a/windows/client-management/mdm/dynamicmanagement-csp.md
+++ b/windows/client-management/mdm/dynamicmanagement-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/dynamicmanagement-ddf.md b/windows/client-management/mdm/dynamicmanagement-ddf.md
index 91f179d6ce..0ca27a4ec0 100644
--- a/windows/client-management/mdm/dynamicmanagement-ddf.md
+++ b/windows/client-management/mdm/dynamicmanagement-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/eap-configuration.md b/windows/client-management/mdm/eap-configuration.md
index 87bea65441..4c66aef7db 100644
--- a/windows/client-management/mdm/eap-configuration.md
+++ b/windows/client-management/mdm/eap-configuration.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/email2-csp.md b/windows/client-management/mdm/email2-csp.md
index 60e492ca69..dce5177a0f 100644
--- a/windows/client-management/mdm/email2-csp.md
+++ b/windows/client-management/mdm/email2-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/email2-ddf-file.md b/windows/client-management/mdm/email2-ddf-file.md
index f550a0c9c7..cad330322f 100644
--- a/windows/client-management/mdm/email2-ddf-file.md
+++ b/windows/client-management/mdm/email2-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/enable-admx-backed-policies-in-mdm.md b/windows/client-management/mdm/enable-admx-backed-policies-in-mdm.md
index 3cbe681524..acb4952dea 100644
--- a/windows/client-management/mdm/enable-admx-backed-policies-in-mdm.md
+++ b/windows/client-management/mdm/enable-admx-backed-policies-in-mdm.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 11/01/2017
---
diff --git a/windows/client-management/mdm/enable-offline-updates-for-windows-embedded-8-1-handheld-devices-to-windows-10.md b/windows/client-management/mdm/enable-offline-updates-for-windows-embedded-8-1-handheld-devices-to-windows-10.md
index d5799f4611..4c21520591 100644
--- a/windows/client-management/mdm/enable-offline-updates-for-windows-embedded-8-1-handheld-devices-to-windows-10.md
+++ b/windows/client-management/mdm/enable-offline-updates-for-windows-embedded-8-1-handheld-devices-to-windows-10.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy.md b/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy.md
index 86fa8a02b9..5e60eb85a2 100644
--- a/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy.md
+++ b/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 10/04/2017
---
diff --git a/windows/client-management/mdm/enterprise-app-management.md b/windows/client-management/mdm/enterprise-app-management.md
index 8aaf17e2a9..755b31d58e 100644
--- a/windows/client-management/mdm/enterprise-app-management.md
+++ b/windows/client-management/mdm/enterprise-app-management.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/22/2017
---
diff --git a/windows/client-management/mdm/enterpriseapn-csp.md b/windows/client-management/mdm/enterpriseapn-csp.md
index 9795891e62..ecf0ae28ec 100644
--- a/windows/client-management/mdm/enterpriseapn-csp.md
+++ b/windows/client-management/mdm/enterpriseapn-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/22/2017
---
diff --git a/windows/client-management/mdm/enterpriseapn-ddf.md b/windows/client-management/mdm/enterpriseapn-ddf.md
index 99d327d3d4..ebd171a390 100644
--- a/windows/client-management/mdm/enterpriseapn-ddf.md
+++ b/windows/client-management/mdm/enterpriseapn-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/enterpriseappmanagement-csp.md b/windows/client-management/mdm/enterpriseappmanagement-csp.md
index 64e6e98dcb..a17fca7628 100644
--- a/windows/client-management/mdm/enterpriseappmanagement-csp.md
+++ b/windows/client-management/mdm/enterpriseappmanagement-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/enterpriseappvmanagement-csp.md b/windows/client-management/mdm/enterpriseappvmanagement-csp.md
index 9b0c5cf24b..006a9353a2 100644
--- a/windows/client-management/mdm/enterpriseappvmanagement-csp.md
+++ b/windows/client-management/mdm/enterpriseappvmanagement-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/enterpriseappvmanagement-ddf.md b/windows/client-management/mdm/enterpriseappvmanagement-ddf.md
index 1946bb8358..bc28fee863 100644
--- a/windows/client-management/mdm/enterpriseappvmanagement-ddf.md
+++ b/windows/client-management/mdm/enterpriseappvmanagement-ddf.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/enterpriseassignedaccess-csp.md b/windows/client-management/mdm/enterpriseassignedaccess-csp.md
index 222f582e36..e5f202eacb 100644
--- a/windows/client-management/mdm/enterpriseassignedaccess-csp.md
+++ b/windows/client-management/mdm/enterpriseassignedaccess-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 07/12/2017
---
diff --git a/windows/client-management/mdm/enterpriseassignedaccess-ddf.md b/windows/client-management/mdm/enterpriseassignedaccess-ddf.md
index 58a3bf5f04..890112e13c 100644
--- a/windows/client-management/mdm/enterpriseassignedaccess-ddf.md
+++ b/windows/client-management/mdm/enterpriseassignedaccess-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/enterpriseassignedaccess-xsd.md b/windows/client-management/mdm/enterpriseassignedaccess-xsd.md
index a95eed6af8..cb651d8548 100644
--- a/windows/client-management/mdm/enterpriseassignedaccess-xsd.md
+++ b/windows/client-management/mdm/enterpriseassignedaccess-xsd.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/enterprisedataprotection-csp.md b/windows/client-management/mdm/enterprisedataprotection-csp.md
index c79f4f55e9..f76ebb330b 100644
--- a/windows/client-management/mdm/enterprisedataprotection-csp.md
+++ b/windows/client-management/mdm/enterprisedataprotection-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 08/09/2017
---
diff --git a/windows/client-management/mdm/enterprisedataprotection-ddf-file.md b/windows/client-management/mdm/enterprisedataprotection-ddf-file.md
index eb9a7eb29d..15c68b54d0 100644
--- a/windows/client-management/mdm/enterprisedataprotection-ddf-file.md
+++ b/windows/client-management/mdm/enterprisedataprotection-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/enterprisedesktopappmanagement-csp.md b/windows/client-management/mdm/enterprisedesktopappmanagement-csp.md
index 89037bff06..2c036e00e7 100644
--- a/windows/client-management/mdm/enterprisedesktopappmanagement-csp.md
+++ b/windows/client-management/mdm/enterprisedesktopappmanagement-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 07/11/2017
---
diff --git a/windows/client-management/mdm/enterprisedesktopappmanagement-ddf-file.md b/windows/client-management/mdm/enterprisedesktopappmanagement-ddf-file.md
index 9b847cedfb..26ff1f5785 100644
--- a/windows/client-management/mdm/enterprisedesktopappmanagement-ddf-file.md
+++ b/windows/client-management/mdm/enterprisedesktopappmanagement-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/enterprisedesktopappmanagement2-xsd.md b/windows/client-management/mdm/enterprisedesktopappmanagement2-xsd.md
index 82d8fb2f13..79f6ff63e1 100644
--- a/windows/client-management/mdm/enterprisedesktopappmanagement2-xsd.md
+++ b/windows/client-management/mdm/enterprisedesktopappmanagement2-xsd.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/enterpriseext-csp.md b/windows/client-management/mdm/enterpriseext-csp.md
index 376700561f..fe887a54e4 100644
--- a/windows/client-management/mdm/enterpriseext-csp.md
+++ b/windows/client-management/mdm/enterpriseext-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/enterpriseext-ddf.md b/windows/client-management/mdm/enterpriseext-ddf.md
index 39bca734e1..72451bab66 100644
--- a/windows/client-management/mdm/enterpriseext-ddf.md
+++ b/windows/client-management/mdm/enterpriseext-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/enterpriseextfilessystem-csp.md b/windows/client-management/mdm/enterpriseextfilessystem-csp.md
index ead94360c1..b7afdf089e 100644
--- a/windows/client-management/mdm/enterpriseextfilessystem-csp.md
+++ b/windows/client-management/mdm/enterpriseextfilessystem-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/enterpriseextfilesystem-ddf.md b/windows/client-management/mdm/enterpriseextfilesystem-ddf.md
index b3bd10d28c..eafe9dc1ab 100644
--- a/windows/client-management/mdm/enterpriseextfilesystem-ddf.md
+++ b/windows/client-management/mdm/enterpriseextfilesystem-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/enterprisemodernappmanagement-csp.md b/windows/client-management/mdm/enterprisemodernappmanagement-csp.md
index 0921c036c4..b4f3ce2304 100644
--- a/windows/client-management/mdm/enterprisemodernappmanagement-csp.md
+++ b/windows/client-management/mdm/enterprisemodernappmanagement-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/01/2018
---
diff --git a/windows/client-management/mdm/enterprisemodernappmanagement-ddf.md b/windows/client-management/mdm/enterprisemodernappmanagement-ddf.md
index 12cb46b485..08075cd45e 100644
--- a/windows/client-management/mdm/enterprisemodernappmanagement-ddf.md
+++ b/windows/client-management/mdm/enterprisemodernappmanagement-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/01/2018
---
diff --git a/windows/client-management/mdm/enterprisemodernappmanagement-xsd.md b/windows/client-management/mdm/enterprisemodernappmanagement-xsd.md
index b962018dfd..3c81c009ea 100644
--- a/windows/client-management/mdm/enterprisemodernappmanagement-xsd.md
+++ b/windows/client-management/mdm/enterprisemodernappmanagement-xsd.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/euiccs-csp.md b/windows/client-management/mdm/euiccs-csp.md
index eb5f1186ce..8e493b7fa5 100644
--- a/windows/client-management/mdm/euiccs-csp.md
+++ b/windows/client-management/mdm/euiccs-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/02/2018
---
diff --git a/windows/client-management/mdm/euiccs-ddf-file.md b/windows/client-management/mdm/euiccs-ddf-file.md
index 06be1ba347..6649a7a42d 100644
--- a/windows/client-management/mdm/euiccs-ddf-file.md
+++ b/windows/client-management/mdm/euiccs-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/02/2018
---
diff --git a/windows/client-management/mdm/federated-authentication-device-enrollment.md b/windows/client-management/mdm/federated-authentication-device-enrollment.md
index 891a590e8b..22ee108fb4 100644
--- a/windows/client-management/mdm/federated-authentication-device-enrollment.md
+++ b/windows/client-management/mdm/federated-authentication-device-enrollment.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 07/28/2017
---
diff --git a/windows/client-management/mdm/filesystem-csp.md b/windows/client-management/mdm/filesystem-csp.md
index cf58cd9eec..5e2ce038a2 100644
--- a/windows/client-management/mdm/filesystem-csp.md
+++ b/windows/client-management/mdm/filesystem-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/firewall-csp.md b/windows/client-management/mdm/firewall-csp.md
index 8140375101..1a552c057a 100644
--- a/windows/client-management/mdm/firewall-csp.md
+++ b/windows/client-management/mdm/firewall-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 01/26/2018
---
diff --git a/windows/client-management/mdm/firewall-ddf-file.md b/windows/client-management/mdm/firewall-ddf-file.md
index 6dbc4367bb..f9a9e98d71 100644
--- a/windows/client-management/mdm/firewall-ddf-file.md
+++ b/windows/client-management/mdm/firewall-ddf-file.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/get-inventory.md b/windows/client-management/mdm/get-inventory.md
index 996288488b..b40c8c4274 100644
--- a/windows/client-management/mdm/get-inventory.md
+++ b/windows/client-management/mdm/get-inventory.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/get-localized-product-details.md b/windows/client-management/mdm/get-localized-product-details.md
index 9c23d4096b..990c816be4 100644
--- a/windows/client-management/mdm/get-localized-product-details.md
+++ b/windows/client-management/mdm/get-localized-product-details.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/get-offline-license.md b/windows/client-management/mdm/get-offline-license.md
index 44417ff92c..65ae6a7b6a 100644
--- a/windows/client-management/mdm/get-offline-license.md
+++ b/windows/client-management/mdm/get-offline-license.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/get-product-details.md b/windows/client-management/mdm/get-product-details.md
index c1d6da5658..30ec8b7d37 100644
--- a/windows/client-management/mdm/get-product-details.md
+++ b/windows/client-management/mdm/get-product-details.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/get-product-package.md b/windows/client-management/mdm/get-product-package.md
index f851fbc6e7..15dd879715 100644
--- a/windows/client-management/mdm/get-product-package.md
+++ b/windows/client-management/mdm/get-product-package.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/get-product-packages.md b/windows/client-management/mdm/get-product-packages.md
index 115cc191c9..cda326c9e5 100644
--- a/windows/client-management/mdm/get-product-packages.md
+++ b/windows/client-management/mdm/get-product-packages.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/get-seat.md b/windows/client-management/mdm/get-seat.md
index 0ac45f69ca..ae6f05d26d 100644
--- a/windows/client-management/mdm/get-seat.md
+++ b/windows/client-management/mdm/get-seat.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/get-seats-assigned-to-a-user.md b/windows/client-management/mdm/get-seats-assigned-to-a-user.md
index 4c1e6bb379..1209d5aa2a 100644
--- a/windows/client-management/mdm/get-seats-assigned-to-a-user.md
+++ b/windows/client-management/mdm/get-seats-assigned-to-a-user.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/get-seats.md b/windows/client-management/mdm/get-seats.md
index 029fc4f030..f65e6988e2 100644
--- a/windows/client-management/mdm/get-seats.md
+++ b/windows/client-management/mdm/get-seats.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/healthattestation-csp.md b/windows/client-management/mdm/healthattestation-csp.md
index dcb5b491fd..2ebb1b49fe 100644
--- a/windows/client-management/mdm/healthattestation-csp.md
+++ b/windows/client-management/mdm/healthattestation-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/healthattestation-ddf.md b/windows/client-management/mdm/healthattestation-ddf.md
index 5268078e48..8296982379 100644
--- a/windows/client-management/mdm/healthattestation-ddf.md
+++ b/windows/client-management/mdm/healthattestation-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/hotspot-csp.md b/windows/client-management/mdm/hotspot-csp.md
index 20ac4822c5..87aa4a054e 100644
--- a/windows/client-management/mdm/hotspot-csp.md
+++ b/windows/client-management/mdm/hotspot-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/iconfigserviceprovider2.md b/windows/client-management/mdm/iconfigserviceprovider2.md
index 6ddf6d6d93..fbdb51d309 100644
--- a/windows/client-management/mdm/iconfigserviceprovider2.md
+++ b/windows/client-management/mdm/iconfigserviceprovider2.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/iconfigserviceprovider2configmanagernotification.md b/windows/client-management/mdm/iconfigserviceprovider2configmanagernotification.md
index 74f076cc41..1ae5155478 100644
--- a/windows/client-management/mdm/iconfigserviceprovider2configmanagernotification.md
+++ b/windows/client-management/mdm/iconfigserviceprovider2configmanagernotification.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/iconfigserviceprovider2getnode.md b/windows/client-management/mdm/iconfigserviceprovider2getnode.md
index 4fd62bc432..df315b2ba4 100644
--- a/windows/client-management/mdm/iconfigserviceprovider2getnode.md
+++ b/windows/client-management/mdm/iconfigserviceprovider2getnode.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnode.md b/windows/client-management/mdm/icspnode.md
index 23e39b227c..dedf93e0b1 100644
--- a/windows/client-management/mdm/icspnode.md
+++ b/windows/client-management/mdm/icspnode.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodeadd.md b/windows/client-management/mdm/icspnodeadd.md
index 81fb9d967d..504d0751e1 100644
--- a/windows/client-management/mdm/icspnodeadd.md
+++ b/windows/client-management/mdm/icspnodeadd.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodeclear.md b/windows/client-management/mdm/icspnodeclear.md
index 355577e43e..2c0e45ea99 100644
--- a/windows/client-management/mdm/icspnodeclear.md
+++ b/windows/client-management/mdm/icspnodeclear.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodecopy.md b/windows/client-management/mdm/icspnodecopy.md
index b9822fc38b..1061d2b6b9 100644
--- a/windows/client-management/mdm/icspnodecopy.md
+++ b/windows/client-management/mdm/icspnodecopy.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodedeletechild.md b/windows/client-management/mdm/icspnodedeletechild.md
index 92497291bf..147c0f4af3 100644
--- a/windows/client-management/mdm/icspnodedeletechild.md
+++ b/windows/client-management/mdm/icspnodedeletechild.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodedeleteproperty.md b/windows/client-management/mdm/icspnodedeleteproperty.md
index 3b2c6743d4..b771500d38 100644
--- a/windows/client-management/mdm/icspnodedeleteproperty.md
+++ b/windows/client-management/mdm/icspnodedeleteproperty.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodeexecute.md b/windows/client-management/mdm/icspnodeexecute.md
index b1fba31565..12c428de69 100644
--- a/windows/client-management/mdm/icspnodeexecute.md
+++ b/windows/client-management/mdm/icspnodeexecute.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodegetchildnodenames.md b/windows/client-management/mdm/icspnodegetchildnodenames.md
index 3ea4793494..72d72c56ac 100644
--- a/windows/client-management/mdm/icspnodegetchildnodenames.md
+++ b/windows/client-management/mdm/icspnodegetchildnodenames.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodegetproperty.md b/windows/client-management/mdm/icspnodegetproperty.md
index daaffe8564..0778b71554 100644
--- a/windows/client-management/mdm/icspnodegetproperty.md
+++ b/windows/client-management/mdm/icspnodegetproperty.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodegetpropertyidentifiers.md b/windows/client-management/mdm/icspnodegetpropertyidentifiers.md
index 5ede9f4479..d0c557b04f 100644
--- a/windows/client-management/mdm/icspnodegetpropertyidentifiers.md
+++ b/windows/client-management/mdm/icspnodegetpropertyidentifiers.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodegetvalue.md b/windows/client-management/mdm/icspnodegetvalue.md
index 6446023340..6207cb507c 100644
--- a/windows/client-management/mdm/icspnodegetvalue.md
+++ b/windows/client-management/mdm/icspnodegetvalue.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodemove.md b/windows/client-management/mdm/icspnodemove.md
index 4f146bc36c..5540b3727d 100644
--- a/windows/client-management/mdm/icspnodemove.md
+++ b/windows/client-management/mdm/icspnodemove.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodesetproperty.md b/windows/client-management/mdm/icspnodesetproperty.md
index 2bbf25984e..6f455d56f5 100644
--- a/windows/client-management/mdm/icspnodesetproperty.md
+++ b/windows/client-management/mdm/icspnodesetproperty.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodesetvalue.md b/windows/client-management/mdm/icspnodesetvalue.md
index 87308b0f06..eff2b58e9e 100644
--- a/windows/client-management/mdm/icspnodesetvalue.md
+++ b/windows/client-management/mdm/icspnodesetvalue.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspnodetransactioning.md b/windows/client-management/mdm/icspnodetransactioning.md
index abb73632ec..4bb80100aa 100644
--- a/windows/client-management/mdm/icspnodetransactioning.md
+++ b/windows/client-management/mdm/icspnodetransactioning.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/icspvalidate.md b/windows/client-management/mdm/icspvalidate.md
index d981ff560b..f1c05d21fd 100644
--- a/windows/client-management/mdm/icspvalidate.md
+++ b/windows/client-management/mdm/icspvalidate.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/implement-server-side-mobile-application-management.md b/windows/client-management/mdm/implement-server-side-mobile-application-management.md
index 2c178ee251..3fe6fa5ee0 100644
--- a/windows/client-management/mdm/implement-server-side-mobile-application-management.md
+++ b/windows/client-management/mdm/implement-server-side-mobile-application-management.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/index.md b/windows/client-management/mdm/index.md
index 85f15ea285..350fa8e7f2 100644
--- a/windows/client-management/mdm/index.md
+++ b/windows/client-management/mdm/index.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/management-tool-for-windows-store-for-business.md b/windows/client-management/mdm/management-tool-for-windows-store-for-business.md
index 17a5ef28d6..933ae47c17 100644
--- a/windows/client-management/mdm/management-tool-for-windows-store-for-business.md
+++ b/windows/client-management/mdm/management-tool-for-windows-store-for-business.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 10/27/2017
---
diff --git a/windows/client-management/mdm/maps-csp.md b/windows/client-management/mdm/maps-csp.md
index 6c33cbb2b3..85296234bf 100644
--- a/windows/client-management/mdm/maps-csp.md
+++ b/windows/client-management/mdm/maps-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/maps-ddf-file.md b/windows/client-management/mdm/maps-ddf-file.md
index ac17e5b0f5..b0788414da 100644
--- a/windows/client-management/mdm/maps-ddf-file.md
+++ b/windows/client-management/mdm/maps-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/mdm-enrollment-of-windows-devices.md b/windows/client-management/mdm/mdm-enrollment-of-windows-devices.md
index 72566a2607..c841ddef41 100644
--- a/windows/client-management/mdm/mdm-enrollment-of-windows-devices.md
+++ b/windows/client-management/mdm/mdm-enrollment-of-windows-devices.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 11/15/2017
---
diff --git a/windows/client-management/mdm/messaging-csp.md b/windows/client-management/mdm/messaging-csp.md
index e9562286e3..a8b9de322a 100644
--- a/windows/client-management/mdm/messaging-csp.md
+++ b/windows/client-management/mdm/messaging-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/messaging-ddf.md b/windows/client-management/mdm/messaging-ddf.md
index f5d34d958c..67dc397e58 100644
--- a/windows/client-management/mdm/messaging-ddf.md
+++ b/windows/client-management/mdm/messaging-ddf.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/mobile-device-enrollment.md b/windows/client-management/mdm/mobile-device-enrollment.md
index 2fe9ccfab5..635e45fd2f 100644
--- a/windows/client-management/mdm/mobile-device-enrollment.md
+++ b/windows/client-management/mdm/mobile-device-enrollment.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 08/11/2017
---
diff --git a/windows/client-management/mdm/multisim-csp.md b/windows/client-management/mdm/multisim-csp.md
index 3b07d6a98c..1b3e56a680 100644
--- a/windows/client-management/mdm/multisim-csp.md
+++ b/windows/client-management/mdm/multisim-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/22/2018
---
diff --git a/windows/client-management/mdm/multisim-ddf.md b/windows/client-management/mdm/multisim-ddf.md
index b75b123630..54c76ae742 100644
--- a/windows/client-management/mdm/multisim-ddf.md
+++ b/windows/client-management/mdm/multisim-ddf.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 02/27/2018
---
diff --git a/windows/client-management/mdm/nap-csp.md b/windows/client-management/mdm/nap-csp.md
index 8543181e2c..ba2ef8f0b2 100644
--- a/windows/client-management/mdm/nap-csp.md
+++ b/windows/client-management/mdm/nap-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/napdef-csp.md b/windows/client-management/mdm/napdef-csp.md
index 0e8a673820..f94af70c0f 100644
--- a/windows/client-management/mdm/napdef-csp.md
+++ b/windows/client-management/mdm/napdef-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/networkproxy-csp.md b/windows/client-management/mdm/networkproxy-csp.md
index 6348228427..9b846e226a 100644
--- a/windows/client-management/mdm/networkproxy-csp.md
+++ b/windows/client-management/mdm/networkproxy-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/12/2018
---
diff --git a/windows/client-management/mdm/networkproxy-ddf.md b/windows/client-management/mdm/networkproxy-ddf.md
index 096ec6d25a..b8fbd90dbc 100644
--- a/windows/client-management/mdm/networkproxy-ddf.md
+++ b/windows/client-management/mdm/networkproxy-ddf.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/networkqospolicy-csp.md b/windows/client-management/mdm/networkqospolicy-csp.md
index c231223bc4..4ccc4536e2 100644
--- a/windows/client-management/mdm/networkqospolicy-csp.md
+++ b/windows/client-management/mdm/networkqospolicy-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/networkqospolicy-ddf.md b/windows/client-management/mdm/networkqospolicy-ddf.md
index fa7dc5e2fc..12c6572869 100644
--- a/windows/client-management/mdm/networkqospolicy-ddf.md
+++ b/windows/client-management/mdm/networkqospolicy-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md
index 132b7389b6..6098b4e8c7 100644
--- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md
+++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md
@@ -9,8 +9,8 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
-ms.date: 04/26/2018
+author: MariciaAlforque
+ms.date: 05/11/2018
---
# What's new in MDM enrollment and management
@@ -1626,6 +1626,31 @@ The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware
## Change history in MDM documentation
+### May 2018
+
+
+
+
+
+
+
+
+
New or updated topic
+
Description
+
+
+
+
+
[Policy DDF file](policy-ddf-file.md)
+
Updated the DDF files in the Windows 10 version 1703 and 1709.
+
+
[Download the Policy DDF file for Windows 10, version 1709](http://download.microsoft.com/download/8/C/4/8C43C116-62CB-470B-9B69-76A3E2BC32A8/PolicyDDF_all.xml)
+
[Download the Policy DDF file for Windows 10, version 1703](http://download.microsoft.com/download/7/2/C/72C36C37-20F9-41BF-8E23-721F6FFC253E/PolicyDDF_all.xml)
@@ -112,7 +113,7 @@ The following list shows the supported values:
-
+
@@ -166,7 +167,7 @@ The following list shows the supported values:
1
-
+
1
1
1
1
@@ -245,12 +246,6 @@ The following list shows the supported values:
- 1 - Allow. Allow users on these managed devices to use Quick Pair and other proximity based scenarios
-
-
-
-
-
-
@@ -272,7 +267,7 @@ The following list shows the supported values:
-
+
@@ -319,7 +314,7 @@ If this policy is not set or it is deleted, the default local radio name is used
-
+
diff --git a/windows/client-management/mdm/policy-csp-browser.md b/windows/client-management/mdm/policy-csp-browser.md
index ab3d44948e..8672f1e47e 100644
--- a/windows/client-management/mdm/policy-csp-browser.md
+++ b/windows/client-management/mdm/policy-csp-browser.md
@@ -5,13 +5,14 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
-ms.date: 04/16/2018
+author: MariciaAlforque
+ms.date: 05/14/2018
---
# Policy CSP - Browser
+
@@ -224,7 +225,7 @@ The following list shows the supported values:
-
+
@@ -294,7 +295,7 @@ To verify AllowAutofill is set to 0 (not allowed):
-
+
@@ -404,7 +405,7 @@ The following list shows the supported values:
-
+
@@ -477,7 +478,7 @@ To verify AllowCookies is set to 0 (not allowed):
-
+
@@ -542,7 +543,7 @@ The following list shows the supported values:
-
+
@@ -612,7 +613,7 @@ To verify AllowDoNotTrack is set to 0 (not allowed):
1
-
+
1
1
1
@@ -671,7 +672,7 @@ The following list shows the supported values:
-
+
@@ -730,7 +731,7 @@ The following list shows the supported values:
2
-
+
2
2
2
@@ -789,7 +790,7 @@ The following list shows the supported values:
-
+
@@ -914,7 +915,7 @@ The following list shows the supported values:
-
+
@@ -984,7 +985,7 @@ To verify AllowPasswordManager is set to 0 (not allowed):
-
+
@@ -1117,7 +1118,7 @@ The following list shows the supported values:
-
+
@@ -1178,7 +1179,7 @@ The following list shows the supported values:
-
+
@@ -1575,7 +1576,7 @@ The following list shows the supported values:
-
+
@@ -1639,7 +1640,7 @@ The following list shows the supported values:
-
+
@@ -1684,7 +1685,7 @@ The following list shows the supported values:
-
+
@@ -1736,7 +1737,7 @@ The default value is an empty string. Otherwise, the string should contain the U
-
+
@@ -1867,7 +1868,7 @@ The following list shows the supported values:
-
+
@@ -2048,7 +2049,7 @@ The following list shows the supported values:
-
+
@@ -2109,7 +2110,7 @@ The following list shows the supported values:
-
+
@@ -2227,7 +2228,7 @@ The following list shows the supported values:
-
+
@@ -2356,7 +2357,7 @@ ADMX Info:
-
+
@@ -2491,7 +2492,7 @@ The following list shows the supported values:
@@ -143,7 +144,7 @@ The following list shows the supported values:
-
+
@@ -194,7 +195,7 @@ The following list shows the supported values:
-
+
@@ -318,7 +319,7 @@ The following list shows the supported values:
-
+
@@ -411,17 +412,14 @@ This setting supports a range of values between 0 and 1.
- 0 - Do not link
- 1 (default) - Allow phone-PC linking
-
-
-
-
Validation:
If the Connectivity/AllowPhonePCLinking policy is configured to value 0, the add a phone button in the Phones section in settings will be greyed out and clicking it will not launch the window for a user to enter their phone number.
Device that has previously opt-in to MMX will also stop showing on the device list.
+
@@ -444,7 +442,7 @@ Device that has previously opt-in to MMX will also stop showing on the device li
-
+
@@ -502,7 +500,7 @@ The following list shows the supported values:
-
+
@@ -554,7 +552,7 @@ The following list shows the supported values:
@@ -338,7 +338,7 @@ Here are the steps to create canonical domain names:
-
+
@@ -390,7 +390,7 @@ ADMX Info:
-
+
@@ -441,7 +441,7 @@ ADMX Info:
-
+
diff --git a/windows/client-management/mdm/policy-csp-notifications.md b/windows/client-management/mdm/policy-csp-notifications.md
index 51caa36965..2d3a5e15e8 100644
--- a/windows/client-management/mdm/policy-csp-notifications.md
+++ b/windows/client-management/mdm/policy-csp-notifications.md
@@ -5,13 +5,14 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
-ms.date: 04/16/2018
+author: MariciaAlforque
+ms.date: 05/14/2018
---
# Policy CSP - Notifications
+
@@ -78,6 +79,9 @@ If you disable or do not configure this policy setting, the client computer will
No reboots or service restarts are required for this policy setting to take effect.
+> [!Warning]
+> This policy is designed for zero exhaust. This policy may cause some MDM processes to break because WNS notification is used by the MDM server to send real time tasks to the device, such as remote wipe, unenroll, remote find, and mandatory app installation. When this policy is set to disallow WNS, those real time processes will no longer work and some time-sensitive actions such as remote wipe when the device is stolen or unenrollment when the device is compromised will not work.
+
ADMX Info:
@@ -98,7 +102,6 @@ Validation:
3. Ensure that you can't receive a notification from Facebook app while FB app isn't running
-
@@ -120,7 +123,7 @@ Validation:
-
-
[Scope](./policy-configuration-service-provider.md#policy-scope):
@@ -134,9 +112,6 @@ ms.date: 04/16/2018
Added in Windows 10, version 1803. Placeholder only. Do not use in production environment.
-
-
-
@@ -158,7 +133,7 @@ Added in Windows 10, version 1803. Placeholder only. Do not use in production e
-
+
@@ -268,7 +243,7 @@ The following list shows the supported values:
-
+
@@ -324,7 +299,7 @@ The following list shows the supported values:
-
+
@@ -381,7 +356,7 @@ The following list shows the supported values:
-
+
@@ -437,7 +412,7 @@ The following list shows the supported values:
-
+
@@ -493,7 +468,7 @@ The following list shows the supported values:
-
+
@@ -623,7 +598,7 @@ This policy has been deprecated.
-
+
@@ -683,6 +658,7 @@ The following list shows the supported values:
+This policy setting controls the ability to send inking and typing data to Microsoft to improve the language recognition and suggestion capabilities of apps and services running on Windows.
@@ -774,7 +750,7 @@ The following list shows the supported values:
-
+
@@ -828,7 +804,7 @@ The following list shows the supported values:
-
+
@@ -882,7 +858,7 @@ The following list shows the supported values:
diff --git a/windows/client-management/mdm/policy-csp-windowspowershell.md b/windows/client-management/mdm/policy-csp-windowspowershell.md
index 3ca5b0ea63..9fc4dd7314 100644
--- a/windows/client-management/mdm/policy-csp-windowspowershell.md
+++ b/windows/client-management/mdm/policy-csp-windowspowershell.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/16/2018
---
diff --git a/windows/client-management/mdm/policy-csp-wirelessdisplay.md b/windows/client-management/mdm/policy-csp-wirelessdisplay.md
index cafb7be12e..6c1ca5bd2d 100644
--- a/windows/client-management/mdm/policy-csp-wirelessdisplay.md
+++ b/windows/client-management/mdm/policy-csp-wirelessdisplay.md
@@ -5,8 +5,8 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
-ms.date: 03/12/2018
+author: MariciaAlforque
+ms.date: 05/14/2018
---
# Policy CSP - WirelessDisplay
@@ -265,7 +265,7 @@ The following list shows the supported values:
1
-
+
1
1
1
@@ -404,7 +404,7 @@ The following list shows the supported values:
1
-
+
1
1
1
diff --git a/windows/client-management/mdm/policy-ddf-file.md b/windows/client-management/mdm/policy-ddf-file.md
index 89b18ee42a..7c5fa15587 100644
--- a/windows/client-management/mdm/policy-ddf-file.md
+++ b/windows/client-management/mdm/policy-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/26/2018
---
diff --git a/windows/client-management/mdm/policymanager-csp.md b/windows/client-management/mdm/policymanager-csp.md
index a888021e38..366179d7ac 100644
--- a/windows/client-management/mdm/policymanager-csp.md
+++ b/windows/client-management/mdm/policymanager-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/28/2017
---
diff --git a/windows/client-management/mdm/provisioning-csp.md b/windows/client-management/mdm/provisioning-csp.md
index f2b9958913..67afc6ae9d 100644
--- a/windows/client-management/mdm/provisioning-csp.md
+++ b/windows/client-management/mdm/provisioning-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/proxy-csp.md b/windows/client-management/mdm/proxy-csp.md
index 0df779416e..31a3e8994f 100644
--- a/windows/client-management/mdm/proxy-csp.md
+++ b/windows/client-management/mdm/proxy-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/push-notification-windows-mdm.md b/windows/client-management/mdm/push-notification-windows-mdm.md
index bfdd850a97..40aae74dbe 100644
--- a/windows/client-management/mdm/push-notification-windows-mdm.md
+++ b/windows/client-management/mdm/push-notification-windows-mdm.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/22/2017
---
diff --git a/windows/client-management/mdm/pxlogical-csp.md b/windows/client-management/mdm/pxlogical-csp.md
index a633f4a681..8a137d239f 100644
--- a/windows/client-management/mdm/pxlogical-csp.md
+++ b/windows/client-management/mdm/pxlogical-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/reboot-csp.md b/windows/client-management/mdm/reboot-csp.md
index dba00c6cd5..b5bccdbf85 100644
--- a/windows/client-management/mdm/reboot-csp.md
+++ b/windows/client-management/mdm/reboot-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/reboot-ddf-file.md b/windows/client-management/mdm/reboot-ddf-file.md
index 2ba444f6f8..36baf398e0 100644
--- a/windows/client-management/mdm/reboot-ddf-file.md
+++ b/windows/client-management/mdm/reboot-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/reclaim-seat-from-user.md b/windows/client-management/mdm/reclaim-seat-from-user.md
index 0f3aeb0558..e3351b8c80 100644
--- a/windows/client-management/mdm/reclaim-seat-from-user.md
+++ b/windows/client-management/mdm/reclaim-seat-from-user.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/register-your-free-azure-active-directory-subscription.md b/windows/client-management/mdm/register-your-free-azure-active-directory-subscription.md
index 6aef81069b..dd6f9467a1 100644
--- a/windows/client-management/mdm/register-your-free-azure-active-directory-subscription.md
+++ b/windows/client-management/mdm/register-your-free-azure-active-directory-subscription.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/registry-csp.md b/windows/client-management/mdm/registry-csp.md
index 66f0960d0a..fecf3f5a44 100644
--- a/windows/client-management/mdm/registry-csp.md
+++ b/windows/client-management/mdm/registry-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/registry-ddf-file.md b/windows/client-management/mdm/registry-ddf-file.md
index 77241d46ff..7477a7c981 100644
--- a/windows/client-management/mdm/registry-ddf-file.md
+++ b/windows/client-management/mdm/registry-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/remotefind-csp.md b/windows/client-management/mdm/remotefind-csp.md
index caec581c7d..d84582b492 100644
--- a/windows/client-management/mdm/remotefind-csp.md
+++ b/windows/client-management/mdm/remotefind-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/remotefind-ddf-file.md b/windows/client-management/mdm/remotefind-ddf-file.md
index 19cf44771f..814fadbb25 100644
--- a/windows/client-management/mdm/remotefind-ddf-file.md
+++ b/windows/client-management/mdm/remotefind-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/remotelock-csp.md b/windows/client-management/mdm/remotelock-csp.md
index 1daf39aa19..0511301b25 100644
--- a/windows/client-management/mdm/remotelock-csp.md
+++ b/windows/client-management/mdm/remotelock-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/remotelock-ddf-file.md b/windows/client-management/mdm/remotelock-ddf-file.md
index e41eeb9e38..99fa47713c 100644
--- a/windows/client-management/mdm/remotelock-ddf-file.md
+++ b/windows/client-management/mdm/remotelock-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/remotering-csp.md b/windows/client-management/mdm/remotering-csp.md
index 206e334ae8..0d72fa4640 100644
--- a/windows/client-management/mdm/remotering-csp.md
+++ b/windows/client-management/mdm/remotering-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/remotering-ddf-file.md b/windows/client-management/mdm/remotering-ddf-file.md
index 50d9bb92bb..01fe0aa96f 100644
--- a/windows/client-management/mdm/remotering-ddf-file.md
+++ b/windows/client-management/mdm/remotering-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/remotewipe-csp.md b/windows/client-management/mdm/remotewipe-csp.md
index fc9618891f..366bb79824 100644
--- a/windows/client-management/mdm/remotewipe-csp.md
+++ b/windows/client-management/mdm/remotewipe-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/23/2018
---
diff --git a/windows/client-management/mdm/remotewipe-ddf-file.md b/windows/client-management/mdm/remotewipe-ddf-file.md
index a9ec625e99..0f0de9b725 100644
--- a/windows/client-management/mdm/remotewipe-ddf-file.md
+++ b/windows/client-management/mdm/remotewipe-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/23/2018
---
diff --git a/windows/client-management/mdm/reporting-csp.md b/windows/client-management/mdm/reporting-csp.md
index 8833a9d134..924654540b 100644
--- a/windows/client-management/mdm/reporting-csp.md
+++ b/windows/client-management/mdm/reporting-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/reporting-ddf-file.md b/windows/client-management/mdm/reporting-ddf-file.md
index 616c065bdc..6387fc0b59 100644
--- a/windows/client-management/mdm/reporting-ddf-file.md
+++ b/windows/client-management/mdm/reporting-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/rest-api-reference-windows-store-for-business.md b/windows/client-management/mdm/rest-api-reference-windows-store-for-business.md
index 465bbd98f8..aae4546ae8 100644
--- a/windows/client-management/mdm/rest-api-reference-windows-store-for-business.md
+++ b/windows/client-management/mdm/rest-api-reference-windows-store-for-business.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 09/18/2017
---
diff --git a/windows/client-management/mdm/rootcacertificates-csp.md b/windows/client-management/mdm/rootcacertificates-csp.md
index 1f5811644c..4f6ec839e8 100644
--- a/windows/client-management/mdm/rootcacertificates-csp.md
+++ b/windows/client-management/mdm/rootcacertificates-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/06/2018
---
diff --git a/windows/client-management/mdm/rootcacertificates-ddf-file.md b/windows/client-management/mdm/rootcacertificates-ddf-file.md
index e7109c768a..587008f3f5 100644
--- a/windows/client-management/mdm/rootcacertificates-ddf-file.md
+++ b/windows/client-management/mdm/rootcacertificates-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/07/2018
---
diff --git a/windows/client-management/mdm/samples-for-writing-a-custom-configuration-service-provider.md b/windows/client-management/mdm/samples-for-writing-a-custom-configuration-service-provider.md
index a1d1af99a2..63260885d9 100644
--- a/windows/client-management/mdm/samples-for-writing-a-custom-configuration-service-provider.md
+++ b/windows/client-management/mdm/samples-for-writing-a-custom-configuration-service-provider.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/secureassessment-csp.md b/windows/client-management/mdm/secureassessment-csp.md
index 4357c5f176..a8ba842ba7 100644
--- a/windows/client-management/mdm/secureassessment-csp.md
+++ b/windows/client-management/mdm/secureassessment-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/secureassessment-ddf-file.md b/windows/client-management/mdm/secureassessment-ddf-file.md
index 598bdf0a98..a17b7547dd 100644
--- a/windows/client-management/mdm/secureassessment-ddf-file.md
+++ b/windows/client-management/mdm/secureassessment-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/securitypolicy-csp.md b/windows/client-management/mdm/securitypolicy-csp.md
index 60851d4e87..20ef07773e 100644
--- a/windows/client-management/mdm/securitypolicy-csp.md
+++ b/windows/client-management/mdm/securitypolicy-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/server-requirements-windows-mdm.md b/windows/client-management/mdm/server-requirements-windows-mdm.md
index 746e0a2ecc..cbbeeaeccb 100644
--- a/windows/client-management/mdm/server-requirements-windows-mdm.md
+++ b/windows/client-management/mdm/server-requirements-windows-mdm.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/sharedpc-csp.md b/windows/client-management/mdm/sharedpc-csp.md
index e55c31bcf5..ef19b3d790 100644
--- a/windows/client-management/mdm/sharedpc-csp.md
+++ b/windows/client-management/mdm/sharedpc-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/sharedpc-ddf-file.md b/windows/client-management/mdm/sharedpc-ddf-file.md
index bfa9d3d806..b17d1adabd 100644
--- a/windows/client-management/mdm/sharedpc-ddf-file.md
+++ b/windows/client-management/mdm/sharedpc-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/storage-csp.md b/windows/client-management/mdm/storage-csp.md
index 7f0638060a..26207420d9 100644
--- a/windows/client-management/mdm/storage-csp.md
+++ b/windows/client-management/mdm/storage-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/storage-ddf-file.md b/windows/client-management/mdm/storage-ddf-file.md
index fe440045c3..46d64527ac 100644
--- a/windows/client-management/mdm/storage-ddf-file.md
+++ b/windows/client-management/mdm/storage-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/structure-of-oma-dm-provisioning-files.md b/windows/client-management/mdm/structure-of-oma-dm-provisioning-files.md
index 66e387b2ee..dd67204515 100644
--- a/windows/client-management/mdm/structure-of-oma-dm-provisioning-files.md
+++ b/windows/client-management/mdm/structure-of-oma-dm-provisioning-files.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/supl-csp.md b/windows/client-management/mdm/supl-csp.md
index 0265da462a..d4fff403d1 100644
--- a/windows/client-management/mdm/supl-csp.md
+++ b/windows/client-management/mdm/supl-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/supl-ddf-file.md b/windows/client-management/mdm/supl-ddf-file.md
index 927923512b..e6ed98d713 100644
--- a/windows/client-management/mdm/supl-ddf-file.md
+++ b/windows/client-management/mdm/supl-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/surfacehub-csp.md b/windows/client-management/mdm/surfacehub-csp.md
index 3654fa873f..f6ec67db21 100644
--- a/windows/client-management/mdm/surfacehub-csp.md
+++ b/windows/client-management/mdm/surfacehub-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 07/28/2017
---
diff --git a/windows/client-management/mdm/surfacehub-ddf-file.md b/windows/client-management/mdm/surfacehub-ddf-file.md
index d465098263..c3b580b0e5 100644
--- a/windows/client-management/mdm/surfacehub-ddf-file.md
+++ b/windows/client-management/mdm/surfacehub-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/tpmpolicy-csp.md b/windows/client-management/mdm/tpmpolicy-csp.md
index 5fa0f29fa7..2a39e0fa82 100644
--- a/windows/client-management/mdm/tpmpolicy-csp.md
+++ b/windows/client-management/mdm/tpmpolicy-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 11/01/2017
---
diff --git a/windows/client-management/mdm/tpmpolicy-ddf-file.md b/windows/client-management/mdm/tpmpolicy-ddf-file.md
index 21c7534a21..e4f359684a 100644
--- a/windows/client-management/mdm/tpmpolicy-ddf-file.md
+++ b/windows/client-management/mdm/tpmpolicy-ddf-file.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/uefi-csp.md b/windows/client-management/mdm/uefi-csp.md
index 72f8871f90..ef549e1753 100644
--- a/windows/client-management/mdm/uefi-csp.md
+++ b/windows/client-management/mdm/uefi-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 02/01/2018
---
diff --git a/windows/client-management/mdm/uefi-ddf.md b/windows/client-management/mdm/uefi-ddf.md
index 8ea53d146e..de67ae71b4 100644
--- a/windows/client-management/mdm/uefi-ddf.md
+++ b/windows/client-management/mdm/uefi-ddf.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 02/01/2018
---
diff --git a/windows/client-management/mdm/understanding-admx-backed-policies.md b/windows/client-management/mdm/understanding-admx-backed-policies.md
index 16f22e3436..03b111b649 100644
--- a/windows/client-management/mdm/understanding-admx-backed-policies.md
+++ b/windows/client-management/mdm/understanding-admx-backed-policies.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/02/2018
---
diff --git a/windows/client-management/mdm/unifiedwritefilter-csp.md b/windows/client-management/mdm/unifiedwritefilter-csp.md
index 2436883665..ae18f01c72 100644
--- a/windows/client-management/mdm/unifiedwritefilter-csp.md
+++ b/windows/client-management/mdm/unifiedwritefilter-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/unifiedwritefilter-ddf.md b/windows/client-management/mdm/unifiedwritefilter-ddf.md
index 417cff25cf..b2757575a6 100644
--- a/windows/client-management/mdm/unifiedwritefilter-ddf.md
+++ b/windows/client-management/mdm/unifiedwritefilter-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/update-csp.md b/windows/client-management/mdm/update-csp.md
index 67de432346..837be49e57 100644
--- a/windows/client-management/mdm/update-csp.md
+++ b/windows/client-management/mdm/update-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 02/23/2018
---
diff --git a/windows/client-management/mdm/update-ddf-file.md b/windows/client-management/mdm/update-ddf-file.md
index b628189e10..c4858fe6d8 100644
--- a/windows/client-management/mdm/update-ddf-file.md
+++ b/windows/client-management/mdm/update-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 02/23/2018
---
diff --git a/windows/client-management/mdm/using-powershell-scripting-with-the-wmi-bridge-provider.md b/windows/client-management/mdm/using-powershell-scripting-with-the-wmi-bridge-provider.md
index 97a2c276e6..1db424cd03 100644
--- a/windows/client-management/mdm/using-powershell-scripting-with-the-wmi-bridge-provider.md
+++ b/windows/client-management/mdm/using-powershell-scripting-with-the-wmi-bridge-provider.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/vpn-csp.md b/windows/client-management/mdm/vpn-csp.md
index fdbdbaed7c..010d58563c 100644
--- a/windows/client-management/mdm/vpn-csp.md
+++ b/windows/client-management/mdm/vpn-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/02/2017
---
diff --git a/windows/client-management/mdm/vpn-ddf-file.md b/windows/client-management/mdm/vpn-ddf-file.md
index 5d2e590301..51a11541d3 100644
--- a/windows/client-management/mdm/vpn-ddf-file.md
+++ b/windows/client-management/mdm/vpn-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/vpnv2-csp.md b/windows/client-management/mdm/vpnv2-csp.md
index caa8e9ad15..e98cd44400 100644
--- a/windows/client-management/mdm/vpnv2-csp.md
+++ b/windows/client-management/mdm/vpnv2-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 11/01/2017
---
diff --git a/windows/client-management/mdm/vpnv2-ddf-file.md b/windows/client-management/mdm/vpnv2-ddf-file.md
index fa8d530b3d..ffaae7d39e 100644
--- a/windows/client-management/mdm/vpnv2-ddf-file.md
+++ b/windows/client-management/mdm/vpnv2-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/vpnv2-profile-xsd.md b/windows/client-management/mdm/vpnv2-profile-xsd.md
index 7f839bb83d..6c582f4933 100644
--- a/windows/client-management/mdm/vpnv2-profile-xsd.md
+++ b/windows/client-management/mdm/vpnv2-profile-xsd.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 02/05/2018
---
diff --git a/windows/client-management/mdm/w4-application-csp.md b/windows/client-management/mdm/w4-application-csp.md
index b554adc39f..03b49e0560 100644
--- a/windows/client-management/mdm/w4-application-csp.md
+++ b/windows/client-management/mdm/w4-application-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/w7-application-csp.md b/windows/client-management/mdm/w7-application-csp.md
index 95c20b9f6d..129f56db57 100644
--- a/windows/client-management/mdm/w7-application-csp.md
+++ b/windows/client-management/mdm/w7-application-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/wifi-csp.md b/windows/client-management/mdm/wifi-csp.md
index 65e4a03576..6e43514e39 100644
--- a/windows/client-management/mdm/wifi-csp.md
+++ b/windows/client-management/mdm/wifi-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 04/16/2018
---
diff --git a/windows/client-management/mdm/wifi-ddf-file.md b/windows/client-management/mdm/wifi-ddf-file.md
index a82d3b6fb2..b5bcd3d75e 100644
--- a/windows/client-management/mdm/wifi-ddf-file.md
+++ b/windows/client-management/mdm/wifi-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/win32-and-centennial-app-policy-configuration.md b/windows/client-management/mdm/win32-and-centennial-app-policy-configuration.md
index 7137215434..8c6f58a89e 100644
--- a/windows/client-management/mdm/win32-and-centennial-app-policy-configuration.md
+++ b/windows/client-management/mdm/win32-and-centennial-app-policy-configuration.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/win32appinventory-csp.md b/windows/client-management/mdm/win32appinventory-csp.md
index 83bd355acb..b7431d69f0 100644
--- a/windows/client-management/mdm/win32appinventory-csp.md
+++ b/windows/client-management/mdm/win32appinventory-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/win32appinventory-ddf-file.md b/windows/client-management/mdm/win32appinventory-ddf-file.md
index 51c5584c13..9521871934 100644
--- a/windows/client-management/mdm/win32appinventory-ddf-file.md
+++ b/windows/client-management/mdm/win32appinventory-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/windows-mdm-enterprise-settings.md b/windows/client-management/mdm/windows-mdm-enterprise-settings.md
index a2f41aef35..0035d1b6dc 100644
--- a/windows/client-management/mdm/windows-mdm-enterprise-settings.md
+++ b/windows/client-management/mdm/windows-mdm-enterprise-settings.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/windowsadvancedthreatprotection-csp.md b/windows/client-management/mdm/windowsadvancedthreatprotection-csp.md
index 4e19920eef..642dc9ac95 100644
--- a/windows/client-management/mdm/windowsadvancedthreatprotection-csp.md
+++ b/windows/client-management/mdm/windowsadvancedthreatprotection-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 11/01/2017
---
diff --git a/windows/client-management/mdm/windowsadvancedthreatprotection-ddf.md b/windows/client-management/mdm/windowsadvancedthreatprotection-ddf.md
index d475e14ee4..eee40a5341 100644
--- a/windows/client-management/mdm/windowsadvancedthreatprotection-ddf.md
+++ b/windows/client-management/mdm/windowsadvancedthreatprotection-ddf.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md b/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md
index 80bd272f42..de75c4898d 100644
--- a/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md
+++ b/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/22/2018
---
diff --git a/windows/client-management/mdm/windowsdefenderapplicationguard-ddf-file.md b/windows/client-management/mdm/windowsdefenderapplicationguard-ddf-file.md
index a5571745b5..33e53da2a3 100644
--- a/windows/client-management/mdm/windowsdefenderapplicationguard-ddf-file.md
+++ b/windows/client-management/mdm/windowsdefenderapplicationguard-ddf-file.md
@@ -5,7 +5,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 03/22/2018
---
diff --git a/windows/client-management/mdm/windowslicensing-csp.md b/windows/client-management/mdm/windowslicensing-csp.md
index 5c09c194ae..24786700eb 100644
--- a/windows/client-management/mdm/windowslicensing-csp.md
+++ b/windows/client-management/mdm/windowslicensing-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 10/09/2017
---
diff --git a/windows/client-management/mdm/windowslicensing-ddf-file.md b/windows/client-management/mdm/windowslicensing-ddf-file.md
index 227863bf2d..df272ec6f1 100644
--- a/windows/client-management/mdm/windowslicensing-ddf-file.md
+++ b/windows/client-management/mdm/windowslicensing-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/windowssecurityauditing-csp.md b/windows/client-management/mdm/windowssecurityauditing-csp.md
index 7bca9db9ee..c7ebdf2171 100644
--- a/windows/client-management/mdm/windowssecurityauditing-csp.md
+++ b/windows/client-management/mdm/windowssecurityauditing-csp.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/client-management/mdm/windowssecurityauditing-ddf-file.md b/windows/client-management/mdm/windowssecurityauditing-ddf-file.md
index 4deb322275..666177f587 100644
--- a/windows/client-management/mdm/windowssecurityauditing-ddf-file.md
+++ b/windows/client-management/mdm/windowssecurityauditing-ddf-file.md
@@ -6,7 +6,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 12/05/2017
---
diff --git a/windows/client-management/mdm/wmi-providers-supported-in-windows.md b/windows/client-management/mdm/wmi-providers-supported-in-windows.md
index 04bf8de073..05490b9d7c 100644
--- a/windows/client-management/mdm/wmi-providers-supported-in-windows.md
+++ b/windows/client-management/mdm/wmi-providers-supported-in-windows.md
@@ -9,7 +9,7 @@ ms.author: maricia
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: nickbrower
+author: MariciaAlforque
ms.date: 06/26/2017
---
diff --git a/windows/configuration/TOC.md b/windows/configuration/TOC.md
index 775abee2b1..8c39396225 100644
--- a/windows/configuration/TOC.md
+++ b/windows/configuration/TOC.md
@@ -1,15 +1,4 @@
# [Configure Windows 10](index.md)
-## [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md)
-## [Diagnostic Data Viewer Overview](diagnostic-data-viewer-overview.md)
-## [Windows 10, version 1803 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md)
-## [Windows 10, version 1709 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md)
-## [Windows 10, version 1703 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md)
-## [Windows 10, version 1709 enhanced diagnostic data events and fields used by Windows Analytics](enhanced-diagnostic-data-windows-analytics-events-and-fields.md)
-## [Windows 10, version 1709 and newer diagnostic data for the Full level](windows-diagnostic-data.md)
-## [Windows 10, version 1703 diagnostic data for the Full level](windows-diagnostic-data-1703.md)
-## [Beginning your General Data Protection Regulation (GDPR) journey for Windows 10](gdpr-win10-whitepaper.md)
-## [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md)
-## [Manage Windows 10 connection endpoints](manage-windows-endpoints-version-1709.md)
## [Manage Wi-Fi Sense in your company](manage-wifi-sense-in-enterprise.md)
## [Configure kiosk and shared devices running Windows 10 desktop editions](kiosk-shared-pc.md)
### [Set up a shared or guest PC with Windows 10](set-up-shared-or-guest-pc.md)
diff --git a/windows/configuration/change-history-for-configure-windows-10.md b/windows/configuration/change-history-for-configure-windows-10.md
index 135248c1d1..3b3edbc102 100644
--- a/windows/configuration/change-history-for-configure-windows-10.md
+++ b/windows/configuration/change-history-for-configure-windows-10.md
@@ -8,6 +8,8 @@ ms.sitesec: library
ms.pagetype: security
ms.localizationpriority: high
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
@@ -20,6 +22,7 @@ This topic lists new and updated topics in the [Configure Windows 10](index.md)
New or changed topic | Description
--- | ---
[Manage Wi-Fi Sense in your company](manage-wifi-sense-in-enterprise.md) | Added note that Wi-Fi Sense is no longer available.
+Topics about Windows 10 diagnostic data | Moved to [Windows Privacy](https://docs.microsoft.com/windows/privacy/).
## RELEASE: Windows 10, version 1803
@@ -28,6 +31,20 @@ The topics in this library have been updated for Windows 10, version 1803. The f
- Windows Configuration Designer setting: [AccountManagement](wcd/wcd-accountmanagement.md)
- Windows Configuration Designer setting: [RcsPresence](wcd/wcd-rcspresence.md)
+The following topics were moved into the [Privacy](/windows/privacy/index) library:
+
+- [Configure Windows diagnostic data in your organization](/windows/privacy/configure-windows-diagnostic-data-in-your-organization)
+- [Diagnostic Data Viewer Overview](/windows/privacy/diagnostic-data-viewer-overview)
+- [Windows 10, version 1803 basic level Windows diagnostic events and fields](/windows/privacy/basic-level-windows-diagnostic-events-and-fields)
+- [Windows 10, version 1709 basic level Windows diagnostic events and fields](/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709)
+- [Windows 10, version 1703 basic level Windows diagnostic events and fields](/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703)
+- [Windows 10, version 1709 enhanced diagnostic data events and fields used by Windows Analytics](/windows/privacy/enhanced-diagnostic-data-windows-analytics-events-and-fields)
+- [Windows 10, version 1709 diagnostic data for the Full level](/windows/privacy/windows-diagnostic-data)
+- [Windows 10, version 1703 diagnostic data for the Full level](/windows/privacy/windows-diagnostic-data-1703)
+- [Beginning your General Data Protection Regulation (GDPR) journey for Windows 10](/windows/privacy/gdpr-win10-whitepaper)
+- [Manage connections from Windows operating system components to Microsoft services](/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services)
+- [Manage Windows 10 connection endpoints](/windows/privacy/manage-windows-endpoints-version-1709)
+
## April 2018
New or changed topic | Description
diff --git a/windows/configuration/changes-to-start-policies-in-windows-10.md b/windows/configuration/changes-to-start-policies-in-windows-10.md
index 495f5b8cb3..73428d50b6 100644
--- a/windows/configuration/changes-to-start-policies-in-windows-10.md
+++ b/windows/configuration/changes-to-start-policies-in-windows-10.md
@@ -6,7 +6,9 @@ keywords: ["group policy", "start menu", "start screen"]
ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
-author: jdeckerms
+author: coreyp
+ms.author: coreyp
+ms.topic: article
ms.localizationpriority: high
ms.date: 11/28/2017
---
diff --git a/windows/configuration/configure-devices-without-mdm.md b/windows/configuration/configure-devices-without-mdm.md
deleted file mode 100644
index 6dbf9464c3..0000000000
--- a/windows/configuration/configure-devices-without-mdm.md
+++ /dev/null
@@ -1,203 +0,0 @@
----
-title: Configure devices without MDM (Windows 10)
-description: Create a runtime provisioning package to apply settings, profiles, and file assets to a device running Windows 10.
-keywords: runtime provisioning, provisioning package
-ms.prod: w10
-ms.mktglfcycl: manage
-ms.sitesec: library
-ms.pagetype: mobile, devices
-author: jdeckerms
-ms.localizationpriority: medium
-ms.date: 07/27/2017
----
-
-# Configure devices without MDM
-
-
-**Applies to**
-
-- Windows 10
-- Windows 10 Mobile
-
-Create a runtime provisioning package to apply settings, profiles, and file assets to a device running Windows 10 Pro, Windows 10 Enterprise, Windows 10 Education, Windows 10 Mobile, or Windows 10 Mobile Enterprise.
-
-Sometimes mobile device management (MDM) isn't available to you for setting up a device because the device isn't connected to your network, or because an employee is remote and needs a fast replacement for a work device. You might not use MDM in your organization at all, but would like an easy way to place a standard configuration on multiple devices.
-
-Rather than wiping a device and applying a new system image, in Windows 10 you can apply a provisioning package at any time. A provisioning package can include management instructions and policies, installation of specific apps, customization of network connections and policies, and more.
-
-You can provide provisioning packages on a network shared folder that employees can access to configure their devices. Or you can put a provisioning package on a USB flash drive or SD card to hand out.
-
-Provisioning packages are simple for employees to install. And when they remove a provisioning package, policies that the package applied to their device are removed.
-
-## Advantages
-
-
-- You can configure new devices without re-imaging.
-
-- Works on both mobile and desktop devices.
-
-- No network connectivity required.
-
-- Simple for people to apply.
-
-- Ensures compliance and security before a device is enrolled in MDM.
-
-## Typical use cases
-
-
-- **Set up a new off-the-shelf device for an employee**
-
- Package might include edition upgrade, device name, company root certificate, Wi-Fi profile, domain join with service account, or company application.
-
-- **Configure an off-the-shelf mobile device to be used as a point of sale or inventory terminal**
-
- Package might include edition upgrade, device name, company root certificate, Wi-Fi profile, security policies, company application, or assigned access (also known as [kiosk mode](set-up-a-device-for-anyone-to-use.md).
-
-- **Help employees set up personally-owned devices to use for work**
-
- Package might include company root certificate, Wi-Fi profiles, security policies, or company application.
-
- > [!NOTE]
- > Test to make sure that removing the provisioning package from a personal device removes everything that the package installed. Some settings are not reverted when a provisioning package is removed from the device.
-
-
-
-- **Repurpose devices by returning the device to a specific state between users**
-
- Package might include computer name, company root certificate, Wi-Fi profile, or company application.
-
- > [!NOTE]
- > To return the **Start** menu to a specific state, you must reset the device. When you reset the device, you can apply the provisioning package during the first-run experience.
-
-
-
-For details about the settings you can customize in provisioning packages, see [Windows Provisioning settings reference]( https://go.microsoft.com/fwlink/p/?LinkId=619012).
-
-## Create a provisioning package
-
-Use the Windows Imaging and Configuration Designer (ICD) tool included in the Windows Assessment and Deployment Kit (ADK) for Windows 10 to create a runtime provisioning package. [Install the ADK.](https://developer.microsoft.com/windows/hardware/windows-assessment-deployment-kit)
-
-When you run Windows ICD, you have several options for creating your package.
-
-.
-
-- Choose **Simple provisioning** to define a desired configuration in Windows ICD and then apply that configuration on target devices. The simple provisioning wizard makes the entire process quick and easy by guiding an IT administrator through common configuration settings in a step-by-step manner.
-- Choose **Provision school devices** to quickly create provisioning packages that configure settings and policies tailored for students. Learn more about using Windows ICD to provision student PCs (link tb added).
-- Choose **Advanced provisioning** to create provisioning packages in the advanced settings editor and include classic (Win32) and Universal Windows Platform (UWP) apps for deployment on end-user devices.
-
-> [!IMPORTANT]
-> When you build a provisioning package, you may include sensitive information in the project files and in the provisioning package (.ppkg) file. Although you have the option to encrypt the .ppkg file, project files are not encrypted. You should store the project files in a secure location and delete the project files when they are no longer needed.
-
-### Using Simple provisioning
-
-1. Open Windows ICD (by default, `%windir%\\Program Files (x86)\\Windows Kits\\10\\Assessment and Deployment Kit\\Imaging and Configuration Designer\\x86\\ICD.exe`).
-2. Click **Simple provisioning**.
-2. Name your project and click **Finish**.
-3. In the **Set up device** step, enter a unique 15-character name for the device. For help generating a unique name, you can use %SERIAL%, which includes a hardware-specific serial number, or you can use %RAND:x%, which generates random characters of x length.
-4. (Optional) You can upgrade the following editions of Windows 10 by providing a product key for the edition to upgrade to.
- - Home to Education
- - Pro to Education
- - Pro to Enterprise
- - Enterprise to Education
- - Mobile to Mobile Enterprise
-5. Click **Set up network**.
-6. Toggle **On** or **Off** for wireless network connectivity. If you select **On**, enter the SSID, type, and (if required) password for the wireless network.
-7. Click **Enroll into Active Directory**.
-8. Toggle **Yes** or **No** for Active Directory enrollment. If you select **Yes**, enter the credentials for an account with permissions to enroll the device. (Optional) Enter a user name and password to create a local administrator account.
-
- > [!WARNING]
- > If you don't create a local administrator account and the device fails to enroll in Active Directory for any reason, you will have to reimage the device and start over. As a best practice, we recommend:
- >
- >- Use a least-privileged domain account to join the device to the domain.
- >- Create a temporary administrator account to use for debugging or reprovisioning if the device fails to enroll successfully.
- >- [Use Group Policy to delete the temporary administrator account](https://blogs.technet.microsoft.com/canitpro/2014/12/10/group-policy-creating-a-standard-local-admin-account/) after the device is enrolled in Active Directory.
-
-9. Click **Finish**.
-10. Review your settings in the summary. You can return to previous pages to change your selections. Then, under **Protect your package**, toggle **Yes** or **No** to encrypt the provisioning package. If you select **Yes**, enter a password. This password must be entered to apply the encrypted provisioning package.
-11. Click **Create**.
-
-
-
-### Using Advanced provisioning
-
-
-
-1. Open Windows ICD (by default, %windir%\\Program Files (x86)\\Windows Kits\\10\\Assessment and Deployment Kit\\Imaging and Configuration Designer\\x86\\ICD.exe).
-2. Click **Advanced provisioning**.
-3. Choose **New provisioning package**.
-3. Name your project, and click **Next**.
-4. Choose **All Windows editions**, **All Windows desktop editions**, or **All Windows mobile editions**, depending on the devices you intend to provision, and click **Next**.
-5. On **New project**, click **Finish**. The workspace for your package opens.
-6. Configure settings. [Learn more about specific settings in provisioning packages.]( https://go.microsoft.com/fwlink/p/?LinkId=615916)
-7. On the **File** menu, select **Save.**
-8. On the **Export** menu, select **Provisioning package**.
-9. Change **Owner** to **IT Admin**, which will set the precedence of this provisioning package higher than provisioning packages applied to this device from other sources, and then select **Next.**
-10. Set a value for **Package Version**.
- > [!TIP]
- > You can make changes to existing packages and change the version number to update previously applied packages.
-
-11. Optional. In the **Provisioning package security** window, you can choose to encrypt the package and enable package signing.
- - **Enable package encryption** - If you select this option, an auto-generated password will be shown on the screen.
- - **Enable package signing** - If you select this option, you must select a valid certificate to use for signing the package. You can specify the certificate by clicking **Select...** and choosing the certificate you want to use to sign the package.
- > [!IMPORTANT]
- > We recommend that you include a trusted provisioning certificate in your provisioning package. When the package is applied to a device, the certificate is added to the system store and any package signed with that certificate thereafter can be applied silently.
-
-12. Click **Next** to specify the output location where you want the provisioning package to go once it's built. By default, Windows ICD uses the project folder as the output location.
- Optionally, you can click **Browse** to change the default output location.
-13. Click **Next**.
-14. Click **Build** to start building the package. The project information is displayed in the build page and the progress bar indicates the build status.
- If you need to cancel the build, click **Cancel**. This cancels the current build process, closes the wizard, and takes you back to the **Customizations Page**.
-15. If your build fails, an error message will show up that includes a link to the project folder. You can scan the logs to determine what caused the error. Once you fix the issue, try building the package again.
- If your build is successful, the name of the provisioning package, output directory, and project directory will be shown.
- - If you choose, you can build the provisioning package again and pick a different path for the output package. To do this, click **Back** to change the output package name and path, and then click **Next** to start another build.
- - If you are done, click **Finish** to close the wizard and go back to the **Customizations Page**.
-16. Select the **output location** link to go to the location of the package. You can provide that .ppkg to others through any of the following methods:
- - Shared network folder
- - SharePoint site
- - Removable media (USB/SD)
- - Email
- - USB tether (mobile only)
-
-Learn more: [Build and apply a provisioning package](https://go.microsoft.com/fwlink/p/?LinkID=629651)
-
-## Apply package
-
-
-On a desktop computer, the employee goes to **Settings** > **Accounts** > **Work access** > **Add or remove a management package** > **Add a package**, and selects the package to install. The user can also add a provisioning package simply by double-clicking the .ppkg file in local storage, on removable media, or at a URL.
-
-
-
-On a mobile device, the employee goes to **Settings** > **Accounts** > **Provisioning.** > **Add a package**, and selects the package on removable media to install.
-
-
-
-## Manage a package
-
-
-- Users can view details or delete package (if policy allows deletion); only user-installed packages are listed.
-
-- Deleting a package removes settings, profiles, certificates, and apps it contains.
-
-- Use policies to disable manual deletion of packages, installation of unsigned packages, or the installation of any additional packages.
-
-- Update content by installing a new package with same name and new version number.
-
-- Optionally, keep packages when you reset a mobile device. When you reset a desktop, runtime packages are removed.
-
- 
-
-## Learn more
-
-
-- [Provisioning Windows 10 Devices with New Tools](https://go.microsoft.com/fwlink/p/?LinkId=615921)
-
-- [Windows 10 for Mobile Devices: Provisioning Is Not Imaging](https://go.microsoft.com/fwlink/p/?LinkId=615922)
-
-
-
-
-
-
-
-
-
diff --git a/windows/configuration/configure-windows-10-taskbar.md b/windows/configuration/configure-windows-10-taskbar.md
index ac50964c8f..e3a453d899 100644
--- a/windows/configuration/configure-windows-10-taskbar.md
+++ b/windows/configuration/configure-windows-10-taskbar.md
@@ -6,6 +6,8 @@ ms.prod: W10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 01/18/2018
---
diff --git a/windows/configuration/customize-and-export-start-layout.md b/windows/configuration/customize-and-export-start-layout.md
index 2b16353cf8..12baa5bed8 100644
--- a/windows/configuration/customize-and-export-start-layout.md
+++ b/windows/configuration/customize-and-export-start-layout.md
@@ -7,6 +7,8 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 10/16/2017
---
diff --git a/windows/configuration/customize-windows-10-start-screens-by-using-group-policy.md b/windows/configuration/customize-windows-10-start-screens-by-using-group-policy.md
index 41f82753c8..c16fe14512 100644
--- a/windows/configuration/customize-windows-10-start-screens-by-using-group-policy.md
+++ b/windows/configuration/customize-windows-10-start-screens-by-using-group-policy.md
@@ -9,6 +9,7 @@ ms.sitesec: library
author: jdeckerms
ms.localizationpriority: high
ms.author: jdecker
+ms.topic: article
ms.date: 11/15/2017
---
diff --git a/windows/configuration/customize-windows-10-start-screens-by-using-mobile-device-management.md b/windows/configuration/customize-windows-10-start-screens-by-using-mobile-device-management.md
index 0fd4cae9da..2edbb87a07 100644
--- a/windows/configuration/customize-windows-10-start-screens-by-using-mobile-device-management.md
+++ b/windows/configuration/customize-windows-10-start-screens-by-using-mobile-device-management.md
@@ -7,6 +7,8 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
+ms.topic: article
+ms.author: jdecker
ms.localizationpriority: medium
ms.date: 02/08/2018
---
diff --git a/windows/configuration/customize-windows-10-start-screens-by-using-provisioning-packages-and-icd.md b/windows/configuration/customize-windows-10-start-screens-by-using-provisioning-packages-and-icd.md
index c681c90ebd..9fcf13b975 100644
--- a/windows/configuration/customize-windows-10-start-screens-by-using-provisioning-packages-and-icd.md
+++ b/windows/configuration/customize-windows-10-start-screens-by-using-provisioning-packages-and-icd.md
@@ -7,6 +7,8 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 11/15/2017
---
diff --git a/windows/configuration/guidelines-for-assigned-access-app.md b/windows/configuration/guidelines-for-assigned-access-app.md
index 8c88dbc908..8e57f63ebd 100644
--- a/windows/configuration/guidelines-for-assigned-access-app.md
+++ b/windows/configuration/guidelines-for-assigned-access-app.md
@@ -8,6 +8,7 @@ ms.sitesec: library
author: jdeckerms
ms.localizationpriority: high
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/index.md b/windows/configuration/index.md
index c97cd8da4f..5ed671a894 100644
--- a/windows/configuration/index.md
+++ b/windows/configuration/index.md
@@ -8,7 +8,9 @@ ms.sitesec: library
ms.pagetype: security
ms.localizationpriority: high
author: jdeckerms
-ms.date: 01/16/2018
+ms.author: jdecker
+ms.topic: article
+ms.date: 05/11/2018
---
# Configure Windows 10
@@ -19,15 +21,6 @@ Enterprises often need to apply custom configurations to devices for their users
| Topic | Description |
| --- | --- |
-| [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) | Use this article to make informed decisions about how you can configure Windows diagnostic data in your organization. |
-|[Diagnostic Data Viewer overview](diagnostic-data-viewer-overview.md) |Learn about the categories of diagnostic data your device is sending to Microsoft, along with how it's being used.|
-| [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md) | Learn about diagnostic data that is collected at the basic level in Windows 10, version 1709. |
-| [Windows 10, version 1703 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md)| Learn about diagnostic data that is collected at the basic level in Windows 10, version 1703.|
-| [Windows 10, version 1709 enhanced telemetry events and fields used by Windows Analytics](enhanced-diagnostic-data-windows-analytics-events-and-fields.md)|Learn about diagnostic data that is collected by Windows Analytics.|
-| [Windows 10, version 1709 diagnostic data for the Full telemetry level](windows-diagnostic-data.md) | Learn about diagnostic data that is collected at the full level in Windows 10, version 1709. |
-| [Windows 10, version 1703 diagnostic data for the Full telemetry level](windows-diagnostic-data-1703.md) | Learn about diagnostic data that is collected at the full level in Windows 10, version 1703. |
-|[Beginning your General Data Protection Regulation (GDPR) journey for Windows 10](gdpr-win10-whitepaper.md)|Learn about Windows 10 and the upcoming GDPR-compliance requirements.|
-| [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) | Learn about the network connections that Windows components make to Microsoft and also the privacy settings that affect data that is shared with either Microsoft or apps and how they can be managed by an IT Pro. |
| [Manage Wi-Fi Sense in your company](manage-wifi-sense-in-enterprise.md) | Wi-Fi Sense automatically connects you to Wi-Fi, so you can get online quickly in more places. It can connect you to open Wi-Fi hotspots it knows about through crowdsourcing, or to Wi-Fi networks your contacts have shared with you by using Wi-Fi Sense. The initial settings for Wi-Fi Sense are determined by the options you chose when you first set up your PC with Windows 10. |
| [Configure kiosk and shared devices running Windows 10 desktop editions](kiosk-shared-pc.md) | These topics help you configure Windows 10 devices to be shared by multiple users or to run as a kiosk device that runs a single app. |
| [Configure Windows 10 Mobile devices](mobile-devices/configure-mobile.md) | These topics help you configure the features and apps and Start screen for a device running Windows 10 Mobile, as well as how to configure a kiosk device that runs a single app. |
diff --git a/windows/configuration/kiosk-shared-pc.md b/windows/configuration/kiosk-shared-pc.md
index e8eb951b8c..4627f16d24 100644
--- a/windows/configuration/kiosk-shared-pc.md
+++ b/windows/configuration/kiosk-shared-pc.md
@@ -7,6 +7,8 @@ ms.sitesec: library
ms.pagetype: security
ms.localizationpriority: medium
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.date: 08/08/2017
---
diff --git a/windows/configuration/kiosk-xml.md b/windows/configuration/kiosk-xml.md
index e75ba24cdb..74cdfe88e1 100644
--- a/windows/configuration/kiosk-xml.md
+++ b/windows/configuration/kiosk-xml.md
@@ -11,6 +11,7 @@ author: jdeckerms
ms.localizationpriority: medium
ms.date: 04/30/2018
ms.author: jdecker
+ms.topic: article
---
# Assigned Access configuration (kiosk) XML reference
diff --git a/windows/configuration/lock-down-windows-10-applocker.md b/windows/configuration/lock-down-windows-10-applocker.md
index 8615847512..5e2636592b 100644
--- a/windows/configuration/lock-down-windows-10-applocker.md
+++ b/windows/configuration/lock-down-windows-10-applocker.md
@@ -11,6 +11,7 @@ author: jdeckerms
ms.localizationpriority: high
ms.date: 08/14/2017
ms.author: jdecker
+ms.topic: article
---
# Use AppLocker to create a Windows 10 kiosk that runs multiple apps
diff --git a/windows/configuration/lock-down-windows-10-to-specific-apps.md b/windows/configuration/lock-down-windows-10-to-specific-apps.md
index b590917cbd..f1cc7e5caa 100644
--- a/windows/configuration/lock-down-windows-10-to-specific-apps.md
+++ b/windows/configuration/lock-down-windows-10-to-specific-apps.md
@@ -11,6 +11,7 @@ author: jdeckerms
ms.localizationpriority: high
ms.date: 04/30/2018
ms.author: jdecker
+ms.topic: article
---
# Create a Windows 10 kiosk that runs multiple apps
diff --git a/windows/configuration/lockdown-features-windows-10.md b/windows/configuration/lockdown-features-windows-10.md
index c52043f754..c363a342f7 100644
--- a/windows/configuration/lockdown-features-windows-10.md
+++ b/windows/configuration/lockdown-features-windows-10.md
@@ -8,6 +8,8 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: security
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/manage-tips-and-suggestions.md b/windows/configuration/manage-tips-and-suggestions.md
index 6d5acafa78..9d6e6ff5dc 100644
--- a/windows/configuration/manage-tips-and-suggestions.md
+++ b/windows/configuration/manage-tips-and-suggestions.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: devices
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 09/20/2017
---
@@ -45,7 +47,7 @@ Windows 10, version 1607 (also known as the Anniversary Update), provides organi
| Windows 10 Pro Education | Yes (default) | Yes | No (setting cannot be changed) |
| Windows 10 Education | Yes (default) | Yes | No (setting cannot be changed) |
-[Learn more about policy settings for Windows Spotlight.](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight)
+[Learn more about policy settings for Windows Spotlight.](windows-spotlight.md)
## Related topics
diff --git a/windows/configuration/mobile-devices/configure-mobile.md b/windows/configuration/mobile-devices/configure-mobile.md
index 774af0e150..50f896bffe 100644
--- a/windows/configuration/mobile-devices/configure-mobile.md
+++ b/windows/configuration/mobile-devices/configure-mobile.md
@@ -6,8 +6,10 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: security
-ms.localizationpriority: high
+ms.localizationpriority: medium
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/windows/configuration/mobile-devices/lockdown-xml.md b/windows/configuration/mobile-devices/lockdown-xml.md
index aa69f4575a..d5e9143721 100644
--- a/windows/configuration/mobile-devices/lockdown-xml.md
+++ b/windows/configuration/mobile-devices/lockdown-xml.md
@@ -7,7 +7,9 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: security, mobile
author: jdeckerms
-ms.localizationpriority: high
+ms.author: jdecker
+ms.topic: article
+ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/windows/configuration/mobile-devices/mobile-lockdown-designer.md b/windows/configuration/mobile-devices/mobile-lockdown-designer.md
index 04669fdebf..229a7ea1c4 100644
--- a/windows/configuration/mobile-devices/mobile-lockdown-designer.md
+++ b/windows/configuration/mobile-devices/mobile-lockdown-designer.md
@@ -7,6 +7,8 @@ ms.sitesec: library
ms.pagetype: security
ms.localizationpriority: medium
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/windows/configuration/mobile-devices/product-ids-in-windows-10-mobile.md b/windows/configuration/mobile-devices/product-ids-in-windows-10-mobile.md
index 418ff01029..5ad6371d4f 100644
--- a/windows/configuration/mobile-devices/product-ids-in-windows-10-mobile.md
+++ b/windows/configuration/mobile-devices/product-ids-in-windows-10-mobile.md
@@ -8,7 +8,9 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: mobile
author: jdeckerms
-ms.localizationpriority: high
+ms.author: jdecker
+ms.topic: article
+ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/windows/configuration/mobile-devices/provisioning-configure-mobile.md b/windows/configuration/mobile-devices/provisioning-configure-mobile.md
index 360fd98464..141db07726 100644
--- a/windows/configuration/mobile-devices/provisioning-configure-mobile.md
+++ b/windows/configuration/mobile-devices/provisioning-configure-mobile.md
@@ -6,8 +6,10 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: security
-ms.localizationpriority: high
+ms.localizationpriority: medium
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/windows/configuration/mobile-devices/provisioning-nfc.md b/windows/configuration/mobile-devices/provisioning-nfc.md
index 68d77e21b8..0c9dc82c2d 100644
--- a/windows/configuration/mobile-devices/provisioning-nfc.md
+++ b/windows/configuration/mobile-devices/provisioning-nfc.md
@@ -5,7 +5,9 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
-ms.localizationpriority: high
+ms.author: jdecker
+ms.topic: article
+ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/windows/configuration/mobile-devices/provisioning-package-splitter.md b/windows/configuration/mobile-devices/provisioning-package-splitter.md
index 9e119420b3..1ba20bd10c 100644
--- a/windows/configuration/mobile-devices/provisioning-package-splitter.md
+++ b/windows/configuration/mobile-devices/provisioning-package-splitter.md
@@ -5,7 +5,9 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
-ms.localizationpriority: high
+ms.author: jdecker
+ms.topic: article
+ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/windows/configuration/mobile-devices/set-up-a-kiosk-for-windows-10-for-mobile-edition.md b/windows/configuration/mobile-devices/set-up-a-kiosk-for-windows-10-for-mobile-edition.md
index c20161c09b..cf13bbf926 100644
--- a/windows/configuration/mobile-devices/set-up-a-kiosk-for-windows-10-for-mobile-edition.md
+++ b/windows/configuration/mobile-devices/set-up-a-kiosk-for-windows-10-for-mobile-edition.md
@@ -8,7 +8,9 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: mobile
author: jdeckerms
-ms.localizationpriority: high
+ms.author: jdecker
+ms.topic: article
+ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/windows/configuration/mobile-devices/settings-that-can-be-locked-down.md b/windows/configuration/mobile-devices/settings-that-can-be-locked-down.md
index 58dfbc60e2..ca84677bf1 100644
--- a/windows/configuration/mobile-devices/settings-that-can-be-locked-down.md
+++ b/windows/configuration/mobile-devices/settings-that-can-be-locked-down.md
@@ -8,7 +8,9 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: mobile
author: jdeckerms
-ms.localizationpriority: high
+ms.author: jdecker
+ms.topic: article
+ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/windows/configuration/mobile-devices/start-layout-xml-mobile.md b/windows/configuration/mobile-devices/start-layout-xml-mobile.md
index 064ebdc7f6..c8d736b63d 100644
--- a/windows/configuration/mobile-devices/start-layout-xml-mobile.md
+++ b/windows/configuration/mobile-devices/start-layout-xml-mobile.md
@@ -6,7 +6,9 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
-ms.localizationpriority: high
+ms.author: jdecker
+ms.topic: article
+ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/windows/configuration/multi-app-kiosk-troubleshoot.md b/windows/configuration/multi-app-kiosk-troubleshoot.md
index 2d5a8db9fb..0ee82de1b3 100644
--- a/windows/configuration/multi-app-kiosk-troubleshoot.md
+++ b/windows/configuration/multi-app-kiosk-troubleshoot.md
@@ -11,6 +11,7 @@ author: jdeckerms
ms.localizationpriority: medium
ms.date: 09/27/2017
ms.author: jdecker
+ms.topic: article
---
# Troubleshoot multi-app kiosk
diff --git a/windows/configuration/provisioning-apn.md b/windows/configuration/provisioning-apn.md
index 96078d1791..6ac9cc2edb 100644
--- a/windows/configuration/provisioning-apn.md
+++ b/windows/configuration/provisioning-apn.md
@@ -6,6 +6,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerMS
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 04/13/2018
---
diff --git a/windows/configuration/provisioning-packages/how-it-pros-can-use-configuration-service-providers.md b/windows/configuration/provisioning-packages/how-it-pros-can-use-configuration-service-providers.md
index 6478c68d2e..cb66bfc3e5 100644
--- a/windows/configuration/provisioning-packages/how-it-pros-can-use-configuration-service-providers.md
+++ b/windows/configuration/provisioning-packages/how-it-pros-can-use-configuration-service-providers.md
@@ -6,6 +6,8 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: medium
ms.date: 07/27/2017
---
diff --git a/windows/configuration/provisioning-packages/provision-pcs-for-initial-deployment.md b/windows/configuration/provisioning-packages/provision-pcs-for-initial-deployment.md
index 778796176d..cb3b69b082 100644
--- a/windows/configuration/provisioning-packages/provision-pcs-for-initial-deployment.md
+++ b/windows/configuration/provisioning-packages/provision-pcs-for-initial-deployment.md
@@ -7,6 +7,8 @@ ms.prod: W10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/provisioning-packages/provision-pcs-with-apps-and-certificates.md b/windows/configuration/provisioning-packages/provision-pcs-with-apps-and-certificates.md
index 56fddf9b72..d1dce50823 100644
--- a/windows/configuration/provisioning-packages/provision-pcs-with-apps-and-certificates.md
+++ b/windows/configuration/provisioning-packages/provision-pcs-with-apps-and-certificates.md
@@ -6,6 +6,8 @@ ms.prod: W10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/provisioning-packages/provision-pcs-with-apps.md b/windows/configuration/provisioning-packages/provision-pcs-with-apps.md
index 4c5d461287..45e8505f25 100644
--- a/windows/configuration/provisioning-packages/provision-pcs-with-apps.md
+++ b/windows/configuration/provisioning-packages/provision-pcs-with-apps.md
@@ -8,6 +8,7 @@ ms.sitesec: library
author: jdeckerms
ms.localizationpriority: high
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/provisioning-packages/provisioning-apply-package.md b/windows/configuration/provisioning-packages/provisioning-apply-package.md
index 0cabd2b0e7..87dde33a49 100644
--- a/windows/configuration/provisioning-packages/provisioning-apply-package.md
+++ b/windows/configuration/provisioning-packages/provisioning-apply-package.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 08/22/2017
---
diff --git a/windows/configuration/provisioning-packages/provisioning-command-line.md b/windows/configuration/provisioning-packages/provisioning-command-line.md
index 8e96311282..f384439e73 100644
--- a/windows/configuration/provisioning-packages/provisioning-command-line.md
+++ b/windows/configuration/provisioning-packages/provisioning-command-line.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/provisioning-packages/provisioning-create-package.md b/windows/configuration/provisioning-packages/provisioning-create-package.md
index fe4f0b035a..23b72e339c 100644
--- a/windows/configuration/provisioning-packages/provisioning-create-package.md
+++ b/windows/configuration/provisioning-packages/provisioning-create-package.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/provisioning-packages/provisioning-how-it-works.md b/windows/configuration/provisioning-packages/provisioning-how-it-works.md
index 02b9e7e88b..3dc6c92614 100644
--- a/windows/configuration/provisioning-packages/provisioning-how-it-works.md
+++ b/windows/configuration/provisioning-packages/provisioning-how-it-works.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/provisioning-packages/provisioning-install-icd.md b/windows/configuration/provisioning-packages/provisioning-install-icd.md
index b595b81972..2768270176 100644
--- a/windows/configuration/provisioning-packages/provisioning-install-icd.md
+++ b/windows/configuration/provisioning-packages/provisioning-install-icd.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 10/16/2017
---
diff --git a/windows/configuration/provisioning-packages/provisioning-multivariant.md b/windows/configuration/provisioning-packages/provisioning-multivariant.md
index 209590fdc6..d90fb50316 100644
--- a/windows/configuration/provisioning-packages/provisioning-multivariant.md
+++ b/windows/configuration/provisioning-packages/provisioning-multivariant.md
@@ -5,6 +5,7 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.topic: article
ms.localizationpriority: high
ms.date: 11/08/2017
ms.author: jdecker
diff --git a/windows/configuration/provisioning-packages/provisioning-packages.md b/windows/configuration/provisioning-packages/provisioning-packages.md
index 24623f98ae..6630c51ec4 100644
--- a/windows/configuration/provisioning-packages/provisioning-packages.md
+++ b/windows/configuration/provisioning-packages/provisioning-packages.md
@@ -6,6 +6,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/provisioning-packages/provisioning-powershell.md b/windows/configuration/provisioning-packages/provisioning-powershell.md
index e372caf606..df04621808 100644
--- a/windows/configuration/provisioning-packages/provisioning-powershell.md
+++ b/windows/configuration/provisioning-packages/provisioning-powershell.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/provisioning-packages/provisioning-script-to-install-app.md b/windows/configuration/provisioning-packages/provisioning-script-to-install-app.md
index 2e6a4b5c10..4485c8105a 100644
--- a/windows/configuration/provisioning-packages/provisioning-script-to-install-app.md
+++ b/windows/configuration/provisioning-packages/provisioning-script-to-install-app.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/provisioning-packages/provisioning-uninstall-package.md b/windows/configuration/provisioning-packages/provisioning-uninstall-package.md
index 06879c3b1b..40d2d2c8f0 100644
--- a/windows/configuration/provisioning-packages/provisioning-uninstall-package.md
+++ b/windows/configuration/provisioning-packages/provisioning-uninstall-package.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/set-up-shared-or-guest-pc.md b/windows/configuration/set-up-shared-or-guest-pc.md
index 81445be3ff..eb9dd9e141 100644
--- a/windows/configuration/set-up-shared-or-guest-pc.md
+++ b/windows/configuration/set-up-shared-or-guest-pc.md
@@ -6,6 +6,8 @@ ms.prod: W10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 07/27/2017
---
diff --git a/windows/configuration/setup-kiosk-digital-signage.md b/windows/configuration/setup-kiosk-digital-signage.md
index 42ce7ef57b..a20aa7ba15 100644
--- a/windows/configuration/setup-kiosk-digital-signage.md
+++ b/windows/configuration/setup-kiosk-digital-signage.md
@@ -7,6 +7,8 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 04/30/2018
---
diff --git a/windows/configuration/start-layout-xml-desktop.md b/windows/configuration/start-layout-xml-desktop.md
index e8fae90b09..8f88a18e1c 100644
--- a/windows/configuration/start-layout-xml-desktop.md
+++ b/windows/configuration/start-layout-xml-desktop.md
@@ -7,6 +7,7 @@ ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
ms.author: jdecker
+ms.topic: article
ms.date: 01/02/2018
ms.localizationpriority: high
---
diff --git a/windows/configuration/start-secondary-tiles.md b/windows/configuration/start-secondary-tiles.md
index c12a8cf0c6..9f94fac26d 100644
--- a/windows/configuration/start-secondary-tiles.md
+++ b/windows/configuration/start-secondary-tiles.md
@@ -7,6 +7,8 @@ ms.sitesec: library
ms.pagetype: security
ms.localizationpriority: high
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.date: 08/07/2017
---
diff --git a/windows/configuration/start-taskbar-lockscreen.md b/windows/configuration/start-taskbar-lockscreen.md
index 3b140ca068..1f4782b5d0 100644
--- a/windows/configuration/start-taskbar-lockscreen.md
+++ b/windows/configuration/start-taskbar-lockscreen.md
@@ -7,6 +7,8 @@ ms.sitesec: library
ms.pagetype: security
ms.localizationpriority: high
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.date: 07/27/2017
---
diff --git a/windows/configuration/stop-employees-from-using-microsoft-store.md b/windows/configuration/stop-employees-from-using-microsoft-store.md
index af9099c374..30074759ac 100644
--- a/windows/configuration/stop-employees-from-using-microsoft-store.md
+++ b/windows/configuration/stop-employees-from-using-microsoft-store.md
@@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
ms.pagetype: store, mobile
author: TrudyHa
+ms.author: Trudyha
+ms.topic: conceptual
ms.localizationpriority: high
ms.date: 4/16/2018
---
diff --git a/windows/configuration/wcd/wcd-accountmanagement.md b/windows/configuration/wcd/wcd-accountmanagement.md
index fa63667601..70b495e029 100644
--- a/windows/configuration/wcd/wcd-accountmanagement.md
+++ b/windows/configuration/wcd/wcd-accountmanagement.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-accounts.md b/windows/configuration/wcd/wcd-accounts.md
index 634f668550..b1547d99cd 100644
--- a/windows/configuration/wcd/wcd-accounts.md
+++ b/windows/configuration/wcd/wcd-accounts.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
@@ -41,7 +42,7 @@ Specifies the settings you can configure when joining a device to a domain, incl
| Setting | Value | Description |
| --- | --- | --- |
| Account | string | Account to use to join computer to domain |
-| AccountOU | string | Name of organizational unit for the computer account |
+| AccountOU | Enter the full path for the organizational unit. For example: OU=testOU,DC=domain,DC=Domain,DC=com. | Name of organizational unit for the computer account |
| ComputerName | Specify a unique name for the domain-joined computers using %RAND:x%, where x is an integer less than 15 digits long, or using %SERIAL% characters in the name.ComputerName is a string with a maximum length of 15 bytes of content:- ComputerName can use ASCII characters (1 byte each) and/or multi-byte characters such as Kanji, so long as you do not exceed 15 bytes of content.- ComputerName cannot use spaces or any of the following characters: \{ | \} ~ \[ \\ \] ^ ' : ; < = > ? @ ! " \# $ % ` \( \) + / . , \* &, or contain any spaces.- ComputerName cannot use some non-standard characters, such as emoji.Computer names that cannot be validated through the DnsValidateName function cannot be used, for example, computer names that only contain numbers (0-9). For more information, see the [DnsValidateName function](http://go.microsoft.com/fwlink/?LinkId=257040). | Specifies the name of the Windows device (computer name on PCs) |
| DomainName | string (cannot be empty) | Specify the name of the domain that the device will join |
| Password | string (cannot be empty) | Corresponds to the password of the user account that's authorized to join the computer account to the domain. |
diff --git a/windows/configuration/wcd/wcd-admxingestion.md b/windows/configuration/wcd/wcd-admxingestion.md
index 4360cfac59..b6410ee421 100644
--- a/windows/configuration/wcd/wcd-admxingestion.md
+++ b/windows/configuration/wcd/wcd-admxingestion.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
@@ -77,7 +78,7 @@ Use the following PowerShell cmdlet to remove carriage returns and line feeds fr
```PS
$path="file path"
-(Get-Content $path -Raw).Replace("'r'n","") | Set-Content $path -Force
+(Get-Content $admxFile -Raw).Replace("`r`n","") | Set-Content $path -Force
```
## Category and policy in ADMX
diff --git a/windows/configuration/wcd/wcd-applicationmanagement.md b/windows/configuration/wcd/wcd-applicationmanagement.md
index 8cef1f4bf4..058450c727 100644
--- a/windows/configuration/wcd/wcd-applicationmanagement.md
+++ b/windows/configuration/wcd/wcd-applicationmanagement.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/12/2017
---
diff --git a/windows/configuration/wcd/wcd-assignedaccess.md b/windows/configuration/wcd/wcd-assignedaccess.md
index 8826fda44a..ae8d42c8ee 100644
--- a/windows/configuration/wcd/wcd-assignedaccess.md
+++ b/windows/configuration/wcd/wcd-assignedaccess.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-automatictime.md b/windows/configuration/wcd/wcd-automatictime.md
index 6a1cf3d4e8..272d9117a7 100644
--- a/windows/configuration/wcd/wcd-automatictime.md
+++ b/windows/configuration/wcd/wcd-automatictime.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-browser.md b/windows/configuration/wcd/wcd-browser.md
index f05f37908b..3ed958488d 100644
--- a/windows/configuration/wcd/wcd-browser.md
+++ b/windows/configuration/wcd/wcd-browser.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-callandmessagingenhancement.md b/windows/configuration/wcd/wcd-callandmessagingenhancement.md
index 09358607f5..2c27545f28 100644
--- a/windows/configuration/wcd/wcd-callandmessagingenhancement.md
+++ b/windows/configuration/wcd/wcd-callandmessagingenhancement.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/21/2017
---
diff --git a/windows/configuration/wcd/wcd-calling.md b/windows/configuration/wcd/wcd-calling.md
index eac321d014..5e1b0c5274 100644
--- a/windows/configuration/wcd/wcd-calling.md
+++ b/windows/configuration/wcd/wcd-calling.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-cellcore.md b/windows/configuration/wcd/wcd-cellcore.md
index 3b03be572a..66fd0b6bc1 100644
--- a/windows/configuration/wcd/wcd-cellcore.md
+++ b/windows/configuration/wcd/wcd-cellcore.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-cellular.md b/windows/configuration/wcd/wcd-cellular.md
index 1e6bdf31fa..290e3f52cb 100644
--- a/windows/configuration/wcd/wcd-cellular.md
+++ b/windows/configuration/wcd/wcd-cellular.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/21/2017
---
diff --git a/windows/configuration/wcd/wcd-certificates.md b/windows/configuration/wcd/wcd-certificates.md
index 34575878e2..56aa4f2379 100644
--- a/windows/configuration/wcd/wcd-certificates.md
+++ b/windows/configuration/wcd/wcd-certificates.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-cleanpc.md b/windows/configuration/wcd/wcd-cleanpc.md
index 0841fd7fe6..fa17758467 100644
--- a/windows/configuration/wcd/wcd-cleanpc.md
+++ b/windows/configuration/wcd/wcd-cleanpc.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-connections.md b/windows/configuration/wcd/wcd-connections.md
index 417868145f..cf22b5e590 100644
--- a/windows/configuration/wcd/wcd-connections.md
+++ b/windows/configuration/wcd/wcd-connections.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-connectivityprofiles.md b/windows/configuration/wcd/wcd-connectivityprofiles.md
index d9e4b4c677..b79f7c9f6a 100644
--- a/windows/configuration/wcd/wcd-connectivityprofiles.md
+++ b/windows/configuration/wcd/wcd-connectivityprofiles.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-countryandregion.md b/windows/configuration/wcd/wcd-countryandregion.md
index 7e0322107e..63428e442e 100644
--- a/windows/configuration/wcd/wcd-countryandregion.md
+++ b/windows/configuration/wcd/wcd-countryandregion.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-desktopbackgroundandcolors.md b/windows/configuration/wcd/wcd-desktopbackgroundandcolors.md
index 516d965076..f2cf8486fa 100644
--- a/windows/configuration/wcd/wcd-desktopbackgroundandcolors.md
+++ b/windows/configuration/wcd/wcd-desktopbackgroundandcolors.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/21/2017
---
diff --git a/windows/configuration/wcd/wcd-developersetup.md b/windows/configuration/wcd/wcd-developersetup.md
index 619c43ad8f..a37e897815 100644
--- a/windows/configuration/wcd/wcd-developersetup.md
+++ b/windows/configuration/wcd/wcd-developersetup.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-deviceformfactor.md b/windows/configuration/wcd/wcd-deviceformfactor.md
index c9f81cda00..3a05a093c8 100644
--- a/windows/configuration/wcd/wcd-deviceformfactor.md
+++ b/windows/configuration/wcd/wcd-deviceformfactor.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-deviceinfo.md b/windows/configuration/wcd/wcd-deviceinfo.md
index 97e88fe617..891a4c6de2 100644
--- a/windows/configuration/wcd/wcd-deviceinfo.md
+++ b/windows/configuration/wcd/wcd-deviceinfo.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/21/2017
---
diff --git a/windows/configuration/wcd/wcd-devicemanagement.md b/windows/configuration/wcd/wcd-devicemanagement.md
index 29bc56d848..70a65ed02e 100644
--- a/windows/configuration/wcd/wcd-devicemanagement.md
+++ b/windows/configuration/wcd/wcd-devicemanagement.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-dmclient.md b/windows/configuration/wcd/wcd-dmclient.md
index f8942889ea..274f251c85 100644
--- a/windows/configuration/wcd/wcd-dmclient.md
+++ b/windows/configuration/wcd/wcd-dmclient.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-editionupgrade.md b/windows/configuration/wcd/wcd-editionupgrade.md
index 02d0b6819d..8b9e9e37e7 100644
--- a/windows/configuration/wcd/wcd-editionupgrade.md
+++ b/windows/configuration/wcd/wcd-editionupgrade.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-embeddedlockdownprofiles.md b/windows/configuration/wcd/wcd-embeddedlockdownprofiles.md
index 8728978340..9ad65e569c 100644
--- a/windows/configuration/wcd/wcd-embeddedlockdownprofiles.md
+++ b/windows/configuration/wcd/wcd-embeddedlockdownprofiles.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-firewallconfiguration.md b/windows/configuration/wcd/wcd-firewallconfiguration.md
index 7a3d133608..a0a581baec 100644
--- a/windows/configuration/wcd/wcd-firewallconfiguration.md
+++ b/windows/configuration/wcd/wcd-firewallconfiguration.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-firstexperience.md b/windows/configuration/wcd/wcd-firstexperience.md
index 7c02ecd47d..3c2044f533 100644
--- a/windows/configuration/wcd/wcd-firstexperience.md
+++ b/windows/configuration/wcd/wcd-firstexperience.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-folders.md b/windows/configuration/wcd/wcd-folders.md
index 86b86075f8..69797f84fa 100644
--- a/windows/configuration/wcd/wcd-folders.md
+++ b/windows/configuration/wcd/wcd-folders.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-hotspot.md b/windows/configuration/wcd/wcd-hotspot.md
index 31693b3461..d3dbe83cdf 100644
--- a/windows/configuration/wcd/wcd-hotspot.md
+++ b/windows/configuration/wcd/wcd-hotspot.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-initialsetup.md b/windows/configuration/wcd/wcd-initialsetup.md
index 59ca15a3aa..f75a6811ab 100644
--- a/windows/configuration/wcd/wcd-initialsetup.md
+++ b/windows/configuration/wcd/wcd-initialsetup.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-internetexplorer.md b/windows/configuration/wcd/wcd-internetexplorer.md
index 02987bcc9a..e9fe891193 100644
--- a/windows/configuration/wcd/wcd-internetexplorer.md
+++ b/windows/configuration/wcd/wcd-internetexplorer.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-licensing.md b/windows/configuration/wcd/wcd-licensing.md
index d939f1c11f..c905f3ec39 100644
--- a/windows/configuration/wcd/wcd-licensing.md
+++ b/windows/configuration/wcd/wcd-licensing.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-maps.md b/windows/configuration/wcd/wcd-maps.md
index 442b1d2ba4..8bff1e1a34 100644
--- a/windows/configuration/wcd/wcd-maps.md
+++ b/windows/configuration/wcd/wcd-maps.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-messaging.md b/windows/configuration/wcd/wcd-messaging.md
index 2cd7c834a0..b48bfa9e23 100644
--- a/windows/configuration/wcd/wcd-messaging.md
+++ b/windows/configuration/wcd/wcd-messaging.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
@@ -289,7 +290,7 @@ Setting | Description
--- | ---
TaiwanAlertEnabled | Receive Taiwan alerts.
TaiwanEmergencyAlertEnabled | Receive Taiwan emergency alerts.
-TaiwanPresidentialAlertEnabled | Receive Taiwan Presidential alerts.
+TaiwanPresidentialAlertEnabled | Receive alerts from the Leader of the Taiwan Area.
TaiwanRequiredMonthlytestEnabled | Receive Taiwan Required Monthly Test alerts.
diff --git a/windows/configuration/wcd/wcd-modemconfigurations.md b/windows/configuration/wcd/wcd-modemconfigurations.md
index d9e44fcdec..7282a3f54d 100644
--- a/windows/configuration/wcd/wcd-modemconfigurations.md
+++ b/windows/configuration/wcd/wcd-modemconfigurations.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/12/2017
---
diff --git a/windows/configuration/wcd/wcd-multivariant.md b/windows/configuration/wcd/wcd-multivariant.md
index 040e99d17d..f5604d8c64 100644
--- a/windows/configuration/wcd/wcd-multivariant.md
+++ b/windows/configuration/wcd/wcd-multivariant.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-networkproxy.md b/windows/configuration/wcd/wcd-networkproxy.md
index e14688c052..f48d289c4d 100644
--- a/windows/configuration/wcd/wcd-networkproxy.md
+++ b/windows/configuration/wcd/wcd-networkproxy.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-networkqospolicy.md b/windows/configuration/wcd/wcd-networkqospolicy.md
index a70fff2d1c..3f8d2822e2 100644
--- a/windows/configuration/wcd/wcd-networkqospolicy.md
+++ b/windows/configuration/wcd/wcd-networkqospolicy.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-nfc.md b/windows/configuration/wcd/wcd-nfc.md
index 46fd5e425a..3aebb6e738 100644
--- a/windows/configuration/wcd/wcd-nfc.md
+++ b/windows/configuration/wcd/wcd-nfc.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-oobe.md b/windows/configuration/wcd/wcd-oobe.md
index e875e3889c..35acf44bc2 100644
--- a/windows/configuration/wcd/wcd-oobe.md
+++ b/windows/configuration/wcd/wcd-oobe.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-otherassets.md b/windows/configuration/wcd/wcd-otherassets.md
index 1a62876716..d26f543e2b 100644
--- a/windows/configuration/wcd/wcd-otherassets.md
+++ b/windows/configuration/wcd/wcd-otherassets.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-personalization.md b/windows/configuration/wcd/wcd-personalization.md
index 375aeb8cd6..14a361651f 100644
--- a/windows/configuration/wcd/wcd-personalization.md
+++ b/windows/configuration/wcd/wcd-personalization.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md
index 42a9ac4d3e..786afaaed1 100644
--- a/windows/configuration/wcd/wcd-policies.md
+++ b/windows/configuration/wcd/wcd-policies.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-provisioningcommands.md b/windows/configuration/wcd/wcd-provisioningcommands.md
index 6cb6f9afbf..744ae6a3b6 100644
--- a/windows/configuration/wcd/wcd-provisioningcommands.md
+++ b/windows/configuration/wcd/wcd-provisioningcommands.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-rcspresence.md b/windows/configuration/wcd/wcd-rcspresence.md
index a6e9ee52e6..ece81a2a9a 100644
--- a/windows/configuration/wcd/wcd-rcspresence.md
+++ b/windows/configuration/wcd/wcd-rcspresence.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-sharedpc.md b/windows/configuration/wcd/wcd-sharedpc.md
index 09a13d662b..09c6c4a000 100644
--- a/windows/configuration/wcd/wcd-sharedpc.md
+++ b/windows/configuration/wcd/wcd-sharedpc.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 10/16/2017
---
diff --git a/windows/configuration/wcd/wcd-shell.md b/windows/configuration/wcd/wcd-shell.md
index c235c4d8e1..e1ba0a5685 100644
--- a/windows/configuration/wcd/wcd-shell.md
+++ b/windows/configuration/wcd/wcd-shell.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-smisettings.md b/windows/configuration/wcd/wcd-smisettings.md
index fdc91f9f6c..2f7f8216e2 100644
--- a/windows/configuration/wcd/wcd-smisettings.md
+++ b/windows/configuration/wcd/wcd-smisettings.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 03/30/2018
---
diff --git a/windows/configuration/wcd/wcd-start.md b/windows/configuration/wcd/wcd-start.md
index 97c6af5208..186c30961e 100644
--- a/windows/configuration/wcd/wcd-start.md
+++ b/windows/configuration/wcd/wcd-start.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-startupapp.md b/windows/configuration/wcd/wcd-startupapp.md
index 510db01214..79d6d0234d 100644
--- a/windows/configuration/wcd/wcd-startupapp.md
+++ b/windows/configuration/wcd/wcd-startupapp.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-startupbackgroundtasks.md b/windows/configuration/wcd/wcd-startupbackgroundtasks.md
index 8ebd2c7d1b..7288d82979 100644
--- a/windows/configuration/wcd/wcd-startupbackgroundtasks.md
+++ b/windows/configuration/wcd/wcd-startupbackgroundtasks.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-surfacehubmanagement.md b/windows/configuration/wcd/wcd-surfacehubmanagement.md
index 08a7ebf56f..0b2df57999 100644
--- a/windows/configuration/wcd/wcd-surfacehubmanagement.md
+++ b/windows/configuration/wcd/wcd-surfacehubmanagement.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-tabletmode.md b/windows/configuration/wcd/wcd-tabletmode.md
index fb480ab268..3eb2ee43c6 100644
--- a/windows/configuration/wcd/wcd-tabletmode.md
+++ b/windows/configuration/wcd/wcd-tabletmode.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-takeatest.md b/windows/configuration/wcd/wcd-takeatest.md
index ebcde22c71..e03db6ddda 100644
--- a/windows/configuration/wcd/wcd-takeatest.md
+++ b/windows/configuration/wcd/wcd-takeatest.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-textinput.md b/windows/configuration/wcd/wcd-textinput.md
index f37bea8555..505962070a 100644
--- a/windows/configuration/wcd/wcd-textinput.md
+++ b/windows/configuration/wcd/wcd-textinput.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/15/2017
---
diff --git a/windows/configuration/wcd/wcd-theme.md b/windows/configuration/wcd/wcd-theme.md
index d916af1dba..8c35de922d 100644
--- a/windows/configuration/wcd/wcd-theme.md
+++ b/windows/configuration/wcd/wcd-theme.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-unifiedwritefilter.md b/windows/configuration/wcd/wcd-unifiedwritefilter.md
index d8fb020e8a..9102c70cbe 100644
--- a/windows/configuration/wcd/wcd-unifiedwritefilter.md
+++ b/windows/configuration/wcd/wcd-unifiedwritefilter.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/06/2017
---
diff --git a/windows/configuration/wcd/wcd-universalappinstall.md b/windows/configuration/wcd/wcd-universalappinstall.md
index c9e427a13b..9a9127182d 100644
--- a/windows/configuration/wcd/wcd-universalappinstall.md
+++ b/windows/configuration/wcd/wcd-universalappinstall.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-universalappuninstall.md b/windows/configuration/wcd/wcd-universalappuninstall.md
index 030b3a9e27..0d99231dba 100644
--- a/windows/configuration/wcd/wcd-universalappuninstall.md
+++ b/windows/configuration/wcd/wcd-universalappuninstall.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/14/2017
---
diff --git a/windows/configuration/wcd/wcd-usberrorsoemoverride.md b/windows/configuration/wcd/wcd-usberrorsoemoverride.md
index cd08ba4359..d59c223809 100644
--- a/windows/configuration/wcd/wcd-usberrorsoemoverride.md
+++ b/windows/configuration/wcd/wcd-usberrorsoemoverride.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 09/14/2017
---
diff --git a/windows/configuration/wcd/wcd-weakcharger.md b/windows/configuration/wcd/wcd-weakcharger.md
index 588b5cf039..19ec5a2ffd 100644
--- a/windows/configuration/wcd/wcd-weakcharger.md
+++ b/windows/configuration/wcd/wcd-weakcharger.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-windowsteamsettings.md b/windows/configuration/wcd/wcd-windowsteamsettings.md
index b6bb5189e2..038fb15ffa 100644
--- a/windows/configuration/wcd/wcd-windowsteamsettings.md
+++ b/windows/configuration/wcd/wcd-windowsteamsettings.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-wlan.md b/windows/configuration/wcd/wcd-wlan.md
index f39d201a7e..546e98f694 100644
--- a/windows/configuration/wcd/wcd-wlan.md
+++ b/windows/configuration/wcd/wcd-wlan.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd-workplace.md b/windows/configuration/wcd/wcd-workplace.md
index 82ade46236..be349f8742 100644
--- a/windows/configuration/wcd/wcd-workplace.md
+++ b/windows/configuration/wcd/wcd-workplace.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/wcd/wcd.md b/windows/configuration/wcd/wcd.md
index 6cf786c7ee..53eeaa689f 100644
--- a/windows/configuration/wcd/wcd.md
+++ b/windows/configuration/wcd/wcd.md
@@ -7,6 +7,7 @@ ms.sitesec: library
author: jdeckerMS
ms.localizationpriority: medium
ms.author: jdecker
+ms.topic: article
ms.date: 04/30/2018
---
diff --git a/windows/configuration/windows-10-start-layout-options-and-policies.md b/windows/configuration/windows-10-start-layout-options-and-policies.md
index 615d0cdf01..4ae9863908 100644
--- a/windows/configuration/windows-10-start-layout-options-and-policies.md
+++ b/windows/configuration/windows-10-start-layout-options-and-policies.md
@@ -7,6 +7,8 @@ ms.prod: w10
ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 10/31/2017
---
diff --git a/windows/configuration/windows-spotlight.md b/windows/configuration/windows-spotlight.md
index 8698db70b2..433ab343c2 100644
--- a/windows/configuration/windows-spotlight.md
+++ b/windows/configuration/windows-spotlight.md
@@ -7,6 +7,8 @@ ms.prod: w10
ms.mktglfcycl: explore
ms.sitesec: library
author: jdeckerms
+ms.author: jdecker
+ms.topic: article
ms.localizationpriority: high
ms.date: 04/30/2018
---
diff --git a/windows/deployment/update/update-compliance-wd-av-status.md b/windows/deployment/update/update-compliance-wd-av-status.md
index 0d7eaadd5a..c0f974d0c0 100644
--- a/windows/deployment/update/update-compliance-wd-av-status.md
+++ b/windows/deployment/update/update-compliance-wd-av-status.md
@@ -5,16 +5,19 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: deploy
-author: DaniHalfin
-ms.author: daniha
-ms.date: 10/13/2017
+author: jaimeo
+ms.author: jaimeo
+ms.date: 05/17/2018
---
# Windows Defender AV Status

-The Windows Defender AV Status section deals with data concerning signature and threat status for devices that use Windows Defender Antivirus. The section tile in the [Overview Blade](update-compliance-using.md#overview-blade) provides the percentage of devices with insufficient protection – this percentage only considers devices using Windows Defender Antivirus.
+The Windows Defender AV Status section deals with data concerning signature and threat status for devices that use Windows Defender Antivirus. The section tile in the [Overview Blade](update-compliance-using.md#overview-blade) provides the percentage of devices with insufficient protection – this percentage only considers devices using Windows Defender Antivirus.
+
+>[!NOTE]
+>Customers with E5 licenses can monitor the Windows Defender AV status by using the Windows Defender ATP portal. For more information about monitoring devices with this portal, see [Onboard Windows 10 machines](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection).
The **Protection Status** blade gives a count for devices that have either out-of-date signatures or real-time protection turned off. Below, it gives a more detailed breakdown of the two issues. Clicking any of these statuses will navigate you to a Log Search view containing the query.
diff --git a/windows/deployment/update/windows-analytics-FAQ-troubleshooting.md b/windows/deployment/update/windows-analytics-FAQ-troubleshooting.md
index 94cc5759c2..6738eb3517 100644
--- a/windows/deployment/update/windows-analytics-FAQ-troubleshooting.md
+++ b/windows/deployment/update/windows-analytics-FAQ-troubleshooting.md
@@ -81,7 +81,7 @@ Devices must be able to reach the endpoints specified in [Enrolling devices in W
If you are using proxy server authentication, it is worth taking extra care to check the configuration. Prior to Windows 10, version 1703, WER uploads error reports in the machine context. Both user (typically authenticated) and machine (typically anonymous) contexts require access through proxy servers to the diagnostic endpoints. In Windows 10, version 1703, and later WER will attempt to use the context of the user that is logged on for proxy authentication such that only the user account requires proxy access.
-Therefore, it's important to ensure that both machine and user accounts have access to the endpoints using authentication (or to whitelist the endpoints so that outbound proxy authentication is not required). For suggested methods, see [Enrolling devices in Windows Analytics](windows-analytics-get-started.md#configuring-endpoint-access-with-proxy-servers).
+Therefore, it's important to ensure that both machine and user accounts have access to the endpoints using authentication (or to whitelist the endpoints so that outbound proxy authentication is not required). For suggested methods, see [Enrolling devices in Windows Analytics](windows-analytics-get-started.md#configuring-endpoint-access-with-proxy-server-authentication).
To test access as a given user, you can run this Windows PowerShell cmdlet *while logged on as that user*:
diff --git a/windows/deployment/update/windows-analytics-get-started.md b/windows/deployment/update/windows-analytics-get-started.md
index 832d82c286..03892db937 100644
--- a/windows/deployment/update/windows-analytics-get-started.md
+++ b/windows/deployment/update/windows-analytics-get-started.md
@@ -54,16 +54,18 @@ To enable data sharing, configure your proxy sever to whitelist the following en
>[!NOTE]
->If you have SSL Inspection enabled on your proxy server, you might need to add the above URLs to your SSL inspection exclusion list to allow data to reach Microsoft endpoints.
+>Proxy authentation and SSL inspections are frequent challenges for enterprises. See the following sections for configuration options.
-### Configuring endpoint access with proxy servers
+### Configuring endpoint access with SSL inspection
+To ensure privacy and data integrity Windows checks for a Microsoft SSL certificate when communicating with the diagnostic data endpoints. Accordingly SSL interception and inspection is not possible. To use Windows Analytics services you should exclude the above endpoints from SSL inspection.
+
+### Configuring endpoint access with proxy server authentication
If your organization uses proxy server authentication for outbound traffic, use one or more of the following approaches to ensure that the diagnostic data is not blocked by proxy authentication:
-- **Best option:** Configure your proxy servers to **not** require proxy authentication for any traffic to the diagnostic data endpoints. In particular, disable SSL inspection. Windows checks for a Microsoft SSL certificate on the site, and this will be stripped and replaced if the proxy performs inspection. This is the most comprehensive solution and it works for all versions of Windows 10.
-- **User proxy authentication:** Alternatively, you can configure devices on the user side. First, update the devices to Windows 10, version 1703 or later. Then, ensure that users of the devices have proxy permission to reach the diagnostic data endpoints. This requires that the devices have console users with proxy permissions, so you couldn't use this method with headless devices.
+- **Best option: Bypass** Configure your proxy servers to **not** require proxy authentication for traffic to the diagnostic data endpoints. This is the most comprehensive solution and it works for all versions of Windows 10.
+- **User proxy authentication:** Alternatively, you can configure devices to use the logged on user's context for proxy authentication. First, update the devices to Windows 10, version 1703 or later. Then, ensure that users of the devices have proxy permission to reach the diagnostic data endpoints. This requires that the devices have console users with proxy permissions, so you couldn't use this method with headless devices.
- **Device proxy authentication:** Another option--the most complex--is as follows: First, configure a system level proxy server on the devices. Then, configure these devices to use machine-account-based outbound proxy authentication. Finally, configure proxy servers to allow the machine accounts access to the diagnostic data endpoints.
-
## Deploy the compatibility update and related updates
The compatibility update scans your devices and enables application usage tracking. If you don’t already have these updates installed, you can download the applicable version from the Microsoft Update Catalog or deploy it using Windows Server Update Services (WSUS) or your software distribution solution, such as System Center Configuration Manager.
diff --git a/windows/deployment/upgrade/windows-10-upgrade-paths.md b/windows/deployment/upgrade/windows-10-upgrade-paths.md
index 45eeec2f16..e6f428797e 100644
--- a/windows/deployment/upgrade/windows-10-upgrade-paths.md
+++ b/windows/deployment/upgrade/windows-10-upgrade-paths.md
@@ -7,7 +7,7 @@ ms.sitesec: library
ms.localizationpriority: high
ms.pagetype: mobile
author: greg-lindsay
-ms.date: 01/18/2018
+ms.date: 05/18/2018
---
# Windows 10 upgrade paths
@@ -20,6 +20,8 @@ ms.date: 01/18/2018
This topic provides a summary of available upgrade paths to Windows 10. You can upgrade to Windows 10 from Windows 7 or a later operating system. This includes upgrading from one release of Windows 10 to later release of Windows 10. Migrating from one edition of Windows 10 to a different edition of the same release is also supported. For more information about migrating to a different edition of Windows 10, see [Windows 10 edition upgrade](windows-10-edition-upgrades.md).
+>**Windows 10 version upgrade**: You can directly upgrade a supported version of Windows 10 to a newer version of Windows 10, even if it involves skipping versions. Work with your account representative if your current version of Windows is out of support. See the [Windows lifecycle fact sheet](https://support.microsoft.com/help/13853/windows-lifecycle-fact-sheet) for availability and service information.
+
>**Windows 10 LTSC/LTSB**: Due to [naming changes](https://docs.microsoft.com/en-us/windows/deployment/update/waas-overview#naming-changes), product versions that display Windows 10 LTSB will be replaced with Windows 10 LTSC in subsequent feature updates. The term LTSC is used here to refer to all long term servicing versions.
>In-place upgrade from Windows 7, Windows 8.1, or Windows 10 semi-annual channel to Windows 10 LTSC is not supported. **Note**: Windows 10 LTSC 2015 did not block this upgrade path. This was corrected in the Windows 10 LTSC 2016 release, which will now only allow data-only and clean install options. You can upgrade from Windows 10 LTSC to Windows 10 semi-annual channel, provided that you upgrade to the same or a newer build version. For example, Windows 10 Enterprise 2016 LTSB can be upgraded to Windows 10 Enterprise version 1607 or later.
diff --git a/windows/deployment/windows-10-pro-in-s-mode.md b/windows/deployment/windows-10-pro-in-s-mode.md
index 9a4f995859..65d8ce2bec 100644
--- a/windows/deployment/windows-10-pro-in-s-mode.md
+++ b/windows/deployment/windows-10-pro-in-s-mode.md
@@ -42,8 +42,10 @@ Worried about your LOB apps not working in S mode? Using Desktop Bridge will ena
[Explore Desktop Bridge](https://docs.microsoft.com/en-us/windows/uwp/porting/desktop-to-uwp-root)
->[!NOTE]
->The only way to revert to Windows 10 in S mode is to perform a BMR factory reset. This will allow you to reimage a device.
+> [!IMPORTANT]
+> While it’s free to switch to Windows 10 Pro, it’s not reversible. The only way to rollback this kind of switch is through a BMR factory reset..
+
+[Recovery media (bare metal recovery)](https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/create-media-to-run-push-button-reset-features-s14) helps restore a Windows device to the factory state, even if the user needs to replace the hard drive or completely wipe the drive clean. If a device is switched out of S mode via the Microsoft Store, it will remain out of S mode even after the device is reset.
### Windows 10 in S mode is safe, secure, and fast.
We recommend staying in S mode. However, in some limited scenarios, you might need to switch to Windows 10 Pro. You can switch devices running Windows 10, version 1709 or later. Use the following information to switch to Windows 10 Pro through the Microsoft Store.
@@ -56,8 +58,6 @@ If you’re running Windows 10, version 1709 or version 1803, you can switch to
3. In the offer, click **Buy**, **Get**, OR **Learn more.**
You'll be prompted to save your files before the switch starts. Follow the prompts to switch to Windows 10 Pro.
-> [!IMPORTANT]
-> While it’s free to switch to Windows 10 Pro, it’s not reversible. The only way to rollback this kind of switch is through a BMR factory reset.
## Related topics
diff --git a/windows/deployment/windows-autopilot/windows-10-autopilot-demo-vm.md b/windows/deployment/windows-autopilot/windows-10-autopilot-demo-vm.md
index 9efe482c59..3314bb3171 100644
--- a/windows/deployment/windows-autopilot/windows-10-autopilot-demo-vm.md
+++ b/windows/deployment/windows-autopilot/windows-10-autopilot-demo-vm.md
@@ -7,9 +7,9 @@ ms.mktglfcycl: deploy
ms.localizationpriority: high
ms.sitesec: library
ms.pagetype: deploy
-author: DaniHalfin
-ms.author: daniha
-ms.date: 12/21/2017
+author: coreyp-at-msft
+ms.author: coreyp
+ms.date: 05/09/18
---
# Demo the Windows Autopilot Deployment Program on a Virtual Machine
@@ -18,7 +18,10 @@ ms.date: 12/21/2017
- Windows 10
-In this topic you'll learn how to set-up a Windows Autopilot deployment for a Virtual Machine using Hyper-V.
+In this topic you'll learn how to set-up a Windows Autopilot deployment for a Virtual Machine using Hyper-V. Watch the following video to see an overview of the process:
+
+
+
## Prerequisites
diff --git a/windows/deployment/windows-autopilot/windows-10-autopilot.md b/windows/deployment/windows-autopilot/windows-10-autopilot.md
index 8c15ecda5f..2ba3acaf9e 100644
--- a/windows/deployment/windows-autopilot/windows-10-autopilot.md
+++ b/windows/deployment/windows-autopilot/windows-10-autopilot.md
@@ -7,9 +7,9 @@ ms.mktglfcycl: deploy
ms.localizationpriority: high
ms.sitesec: library
ms.pagetype: deploy
-author: DaniHalfin
-ms.author: daniha
-ms.date: 05/17/2018
+author: coreyp-at-msft
+ms.author: coreyp
+ms.date: 05/09/2018
---
# Overview of Windows Autopilot
@@ -21,7 +21,10 @@ ms.date: 05/17/2018
Windows Autopilot is a collection of technologies used to set up and pre-configure new devices, getting them ready for productive use. In addition, you can use Windows Autopilot to reset, repurpose and recover devices.
This solution enables an IT department to achieve the above with little to no infrastructure to manage, with a process that's easy and simple.
-For a quick overview of the
+The following video shows the process of setting up Autopilot:
+
+
+
## Benefits of Windows Autopilot
@@ -71,7 +74,7 @@ MDM enrollment ensures policies are applied, apps are installed and setting are
#### Device registration and OOBE customization
-In order to register devices, you will need to acquire their hardware ID and register it. We are actively working with various hardware vendors to enable them to provide the required information to you, or upload it on your behalf.
+To register devices, you will need to acquire their hardware ID and register it. We are actively working with various hardware vendors to enable them to provide the required information to you, or upload it on your behalf.
If you would like to capture that information by yourself, you can use the [Get-WindowsAutopilotInfo PowerShell script](https://www.powershellgallery.com/packages/Get-WindowsAutopilotInfo), which will generate a .csv file with the device's hardware ID.
diff --git a/windows/hub/TOC.md b/windows/hub/TOC.md
index cb339d35c0..9a147ba933 100644
--- a/windows/hub/TOC.md
+++ b/windows/hub/TOC.md
@@ -6,5 +6,6 @@
## [Client management](/windows/client-management)
## [Application management](/windows/application-management)
## [Security](/windows/security)
+## [Privacy](/windows/privacy)
## [Troubleshooting](/windows/client-management/windows-10-support-solutions)
## [Other Windows client versions](https://docs.microsoft.com/previous-versions/windows)
\ No newline at end of file
diff --git a/windows/hub/breadcrumb/toc.yml b/windows/hub/breadcrumb/toc.yml
index 2d61591d22..dd69dd086f 100644
--- a/windows/hub/breadcrumb/toc.yml
+++ b/windows/hub/breadcrumb/toc.yml
@@ -25,6 +25,9 @@
- name: Mobile Device Management
tocHref: /windows/client-management/mdm/
topicHref: /windows/client-management/mdm/index
+ - name: Privacy
+ tocHref: /windows/privacy/
+ topicHref: /windows/privacy/index
- name: Security
tocHref: /windows/security/
topicHref: /windows/security/index
diff --git a/windows/privacy/TOC.md b/windows/privacy/TOC.md
index 06913f7aef..eae0db11d9 100644
--- a/windows/privacy/TOC.md
+++ b/windows/privacy/TOC.md
@@ -1 +1,17 @@
-# [Index](index.md)
\ No newline at end of file
+# [Privacy](index.yml)
+## [Beginning your General Data Protection Regulation (GDPR) journey for Windows 10](gdpr-win10-whitepaper.md)
+## [Windows 10 and the GDPR for IT Decision Makers](gdpr-it-guidance.md)
+## [Windows 10 personal data services configuration](windows-personal-data-services-configuration.md)
+## [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md)
+## [Diagnostic Data Viewer Overview](diagnostic-data-viewer-overview.md)
+## Basic level diagnostics events and fields
+### [Windows 10, version 1803 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md)
+### [Windows 10, version 1709 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md)
+### [Windows 10, version 1703 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md)
+## Enhanced level diagnostics events and fields
+### [Windows 10, version 1709 enhanced diagnostic data events and fields used by Windows Analytics](enhanced-diagnostic-data-windows-analytics-events-and-fields.md)
+## Full level diagnostics events and fields
+### [Windows 10, version 1709 and newer diagnostic data for the Full level](windows-diagnostic-data.md)
+### [Windows 10, version 1703 diagnostic data for the Full level](windows-diagnostic-data-1703.md)
+## [Manage Windows 10 connection endpoints](manage-windows-endpoints.md)
+## [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md)
diff --git a/windows/configuration/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md
similarity index 100%
rename from windows/configuration/basic-level-windows-diagnostic-events-and-fields-1703.md
rename to windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md
diff --git a/windows/configuration/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md
similarity index 100%
rename from windows/configuration/basic-level-windows-diagnostic-events-and-fields-1709.md
rename to windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md
diff --git a/windows/configuration/basic-level-windows-diagnostic-events-and-fields.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields.md
similarity index 99%
rename from windows/configuration/basic-level-windows-diagnostic-events-and-fields.md
rename to windows/privacy/basic-level-windows-diagnostic-events-and-fields.md
index a57aebf1fb..187e7a2c48 100644
--- a/windows/configuration/basic-level-windows-diagnostic-events-and-fields.md
+++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields.md
@@ -33,7 +33,7 @@ You can learn more about Windows functional and diagnostic data through these ar
- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md)
- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md)
- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md)
-- [Manage Windows 10 connection endpoints](manage-windows-endpoints-version-1709.md)
+- [Manage Windows 10 connection endpoints](manage-windows-endpoints.md)
- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md)
diff --git a/windows/privacy/breadcrumb/toc.yml b/windows/privacy/breadcrumb/toc.yml
deleted file mode 100644
index 61d8fca61e..0000000000
--- a/windows/privacy/breadcrumb/toc.yml
+++ /dev/null
@@ -1,3 +0,0 @@
-- name: Docs
- tocHref: /
- topicHref: /
\ No newline at end of file
diff --git a/windows/configuration/configure-windows-diagnostic-data-in-your-organization.md b/windows/privacy/configure-windows-diagnostic-data-in-your-organization.md
similarity index 94%
rename from windows/configuration/configure-windows-diagnostic-data-in-your-organization.md
rename to windows/privacy/configure-windows-diagnostic-data-in-your-organization.md
index b3e7a68de0..3fda54cb26 100644
--- a/windows/configuration/configure-windows-diagnostic-data-in-your-organization.md
+++ b/windows/privacy/configure-windows-diagnostic-data-in-your-organization.md
@@ -32,7 +32,7 @@ To frame a discussion about diagnostic data, it is important to understand Micro
This article applies to Windows and Windows Server diagnostic data only. Other Microsoft or third-party apps, such as System Center Configuration Manager, System Center Endpoint Protection, or System Center Data Protection Manager, might send data to their cloud services in ways that are inconsistent with this guide. Their publishers are responsible for notifying users of their privacy policies, diagnostic data controls, and so on. This article describes the types of diagnostic data we may gather, the ways you might manage it in your organization, and some examples of how diagnostic data can provide you with valuable insights into your enterprise deployments. Microsoft uses the data to quickly identify and address issues affecting its customers.
-Use this article to make informed decisions about how you might configure diagnostic data in your organization. Diagnostic data is a term that means different things to different people and organizations. For this article, we discuss diagnostic data as system data that is uploaded by the Connected User Experiences and Telemetry component. The diagnostic data data is used to help keep Windows devices secure by identifying malware trends and other threats and to help Microsoft improve the quality of Windows and Microsoft services.
+Use this article to make informed decisions about how you might configure diagnostic data in your organization. Diagnostic data is a term that means different things to different people and organizations. For this article, we discuss diagnostic data as system data that is uploaded by the Connected User Experiences and Telemetry component. The diagnostic data is used to help keep Windows devices secure by identifying malware trends and other threats and to help Microsoft improve the quality of Windows and Microsoft services.
We are always striving to improve our documentation and welcome your feedback. You can provide feedback by contacting telmhelp@microsoft.com.
@@ -95,7 +95,7 @@ Windows diagnostic data also helps Microsoft better understand how customers use
- **Cortana.** We use diagnostic data to monitor the scalability of our cloud service, improving search performance.
- **Application switching.** Research and observations from earlier Windows versions showed that people rarely used Alt+Tab to switch between applications. After discussing this with some users, we learned they loved the feature, saying that it would be highly productive, but they did not know about it previously. Based on this, we created the Task View button in Windows 10 to make this feature more discoverable. Later diagnostic data showed significantly higher usage of this feature.
-**These examples show how the use of diagnostic data data enables Microsoft to build or enhance features which can help organizations increase employee productivity while lowering help desk calls.**
+**These examples show how the use of diagnostic data enables Microsoft to build or enhance features which can help organizations increase employee productivity while lowering help desk calls.**
### Insights into your own organization
@@ -122,7 +122,7 @@ Use Upgrade Readiness to get:
The Upgrade Readiness workflow steps you through the discovery and rationalization process until you have a list of computers that are ready to be upgraded.
-## How is diagnostic data data handled by Microsoft?
+## How is diagnostic data handled by Microsoft?
### Data collection
@@ -131,13 +131,13 @@ Windows 10 and Windows Server 2016 includes the Connected User Experiences and T
1. Operating system features and some management applications are instrumented to publish events and data. Examples of management applications include Virtual Machine Manager (VMM), Server Manager, and Storage Spaces.
2. Events are gathered using public operating system event logging and tracing APIs.
3. You can configure the diagnostic data level by using MDM policy, Group Policy, or registry settings.
-4. The Connected User Experiences and Telemetry component transmits the diagnostic data data.
+4. The Connected User Experiences and Telemetry component transmits the diagnostic data.
Info collected at the Enhanced and Full levels of diagnostic data is typically gathered at a fractional sampling rate, which can be as low as 1% of devices reporting data at those levels.
### Data transmission
-All diagnostic data data is encrypted using SSL and uses certificate pinning during transfer from the device to the Microsoft Data Management Service. With Windows 10, data is uploaded on a schedule that is sensitive to event priority, battery use, and network cost. Real-time events, such as Windows Defender Advanced Threat Protection, are always sent immediately. Normal events are not uploaded on metered networks, unless you are on a metered server connection. On a free network, normal events can be uploaded every 4 hours if on battery, or every 15 minutes if on A/C power. Diagnostic and crash data are only uploaded on A/C power and free networks.
+All diagnostic data is encrypted using SSL and uses certificate pinning during transfer from the device to the Microsoft Data Management Service. With Windows 10, data is uploaded on a schedule that is sensitive to event priority, battery use, and network cost. Real-time events, such as Windows Defender Advanced Threat Protection, are always sent immediately. Normal events are not uploaded on metered networks, unless you are on a metered server connection. On a free network, normal events can be uploaded every 4 hours if on battery, or every 15 minutes if on A/C power. Diagnostic and crash data are only uploaded on A/C power and free networks.
The data transmitted at the Basic and Enhanced data diagnostic levels is quite small; typically less than 1 MB per device per day, but occasionally up to 2 MB per device per day).
@@ -163,7 +163,7 @@ The following table defines the endpoints for other diagnostic data services:
### Data use and access
-The principle of least privileged access guides access to diagnostic data data. Microsoft does not share personal data of our customers with third parties, except at the customer’s discretion or for the limited purposes described in the [Privacy Statement](https://privacy.microsoft.com/privacystatement). Microsoft may share business reports with OEMs and third-party partners that include aggregated and anonymized diagnostic data information. Data-sharing decisions are made by an internal team including privacy, legal, and data management.
+The principle of least privileged access guides access to diagnostic data. Microsoft does not share personal data of our customers with third parties, except at the customer’s discretion or for the limited purposes described in the [Privacy Statement](https://privacy.microsoft.com/privacystatement). Microsoft may share business reports with OEMs and third-party partners that include aggregated and anonymized diagnostic data information. Data-sharing decisions are made by an internal team including privacy, legal, and data management.
### Retention
@@ -172,7 +172,7 @@ Microsoft believes in and practices information minimization. We strive to gathe
## Diagnostic data levels
This section explains the different diagnostic data levels in Windows 10, Windows Server 2016, and System Center. These levels are available on all desktop and mobile editions of Windows 10, except for the **Security** level, which is limited to Windows 10 Enterprise, Windows 10 Education, Windows 10 Mobile Enterprise, Windows 10 IoT Core (IoT Core), and Windows Server 2016.
-The diagnostic data data is categorized into four levels:
+The diagnostic data is categorized into four levels:
- **Security**. Information that’s required to help keep Windows, Windows Server, and System Center secure, including data about the Connected User Experiences and Telemetry component settings, the Malicious Software Removal Tool, and Windows Defender.
@@ -193,7 +193,7 @@ The Security level gathers only the diagnostic data info that is required to kee
> [!NOTE]
> If your organization relies on Windows Update for updates, you shouldn’t use the **Security** level. Because no Windows Update information is gathered at this level, important information about update failures is not sent. Microsoft uses this information to fix the causes of those failures and improve the quality of our updates.
-Windows Server Update Services (WSUS) and System Center Configuration Manager functionality is not affected at this level, nor is diagnostic data data about Windows Server features or System Center gathered.
+Windows Server Update Services (WSUS) and System Center Configuration Manager functionality is not affected at this level, nor is diagnostic data about Windows Server features or System Center gathered.
The data gathered at this level includes:
@@ -217,7 +217,7 @@ No user content, such as user files or communications, is gathered at the **Secu
### Basic level
-The Basic level gathers a limited set of data that’s critical for understanding the device and its configuration. This level also includes the **Security** level data. This level helps to identify problems that can occur on a specific hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a specific driver version. The Connected User Experiences and Telemetry component does not gather diagnostic data data about System Center, but it can transmit diagnostic data for other non-Windows applications if they have user consent.
+The Basic level gathers a limited set of data that’s critical for understanding the device and its configuration. This level also includes the **Security** level data. This level helps to identify problems that can occur on a specific hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a specific driver version. The Connected User Experiences and Telemetry component does not gather diagnostic data about System Center, but it can transmit diagnostic data for other non-Windows applications if they have user consent.
The normal upload range for the Basic diagnostic data level is between 109 KB - 159 KB per day, per device.
@@ -327,7 +327,7 @@ However, before more data is gathered, Microsoft’s privacy governance team, in
## Enterprise management
-Sharing diagnostic data data with Microsoft provides many benefits to enterprises, so we do not recommend turning it off. For most enterprise customers, simply adjusting the diagnostic data level and managing specific components is the best option.
+Sharing diagnostic data with Microsoft provides many benefits to enterprises, so we do not recommend turning it off. For most enterprise customers, simply adjusting the diagnostic data level and managing specific components is the best option.
Customers can set the diagnostic data level in both the user interface and with existing management tools. Users can change the diagnostic data level in the **Diagnostic data** setting. In the **Settings** app, it is in **Privacy\Feedback & diagnostics**. They can choose between Basic and Full. The Enhanced level will only be displayed as an option when Group Policy or Mobile Device Management (MDM) are invoked with this level. The Security level is not available.
diff --git a/windows/configuration/diagnostic-data-viewer-overview.md b/windows/privacy/diagnostic-data-viewer-overview.md
similarity index 100%
rename from windows/configuration/diagnostic-data-viewer-overview.md
rename to windows/privacy/diagnostic-data-viewer-overview.md
diff --git a/windows/privacy/docfx.json b/windows/privacy/docfx.json
index e1cbc9d653..801539efd6 100644
--- a/windows/privacy/docfx.json
+++ b/windows/privacy/docfx.json
@@ -9,8 +9,6 @@
"exclude": [
"**/obj/**",
"**/includes/**",
- "_themes/**",
- "_themes.pdf/**",
"README.md",
"LICENSE",
"LICENSE-CODE",
@@ -22,21 +20,27 @@
{
"files": [
"**/*.png",
- "**/*.jpg"
+ "**/*.jpg",
+ "**/*.gif"
],
"exclude": [
"**/obj/**",
- "**/includes/**",
- "_themes/**",
- "_themes.pdf/**"
+ "**/includes/**"
]
}
],
"overwrite": [],
"externalReference": [],
"globalMetadata": {
- "breadcrumb_path": "/windows/privacy/breadcrumb/toc.json",
- "extendBreadcrumb": true
+ "uhfHeaderId": "MSDocsHeader-WindowsIT",
+ "breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
+ "ms.technology": "windows",
+ "ms.topic": "article",
+ "ms.author": "daniha",
+ "ms.date": "05/10/2018",
+ "feedback_system": "GitHub",
+ "feedback_github_repo": "MicrosoftDocs/windows-itpro-docs",
+ "feedback_product_url": "https://support.microsoft.com/help/4021566/windows-10-send-feedback-to-microsoft-with-feedback-hub-app"
},
"fileMetadata": {},
"template": [],
diff --git a/windows/configuration/enhanced-diagnostic-data-windows-analytics-events-and-fields.md b/windows/privacy/enhanced-diagnostic-data-windows-analytics-events-and-fields.md
similarity index 100%
rename from windows/configuration/enhanced-diagnostic-data-windows-analytics-events-and-fields.md
rename to windows/privacy/enhanced-diagnostic-data-windows-analytics-events-and-fields.md
diff --git a/windows/privacy/gdpr-it-guidance.md b/windows/privacy/gdpr-it-guidance.md
new file mode 100644
index 0000000000..a87e41b1a2
--- /dev/null
+++ b/windows/privacy/gdpr-it-guidance.md
@@ -0,0 +1,248 @@
+---
+title: Windows 10 and the GDPR for IT Decision Makers
+description: Use this topic to understand the relationship between users in your organization and Microsoft in the context of the GDPR (General Data Protection Regulation).
+keywords: privacy, GDPR, windows, IT
+ms.prod: w10
+ms.mktglfcycl: manage
+ms.sitesec: library
+ms.pagetype: security
+ms.localizationpriority: high
+author: danihalfin
+ms.author: daniha
+ms.date: 05/11/2018
+---
+# Windows 10 and the GDPR for IT Decision Makers
+
+Applies to:
+- Windows 10, version 1803
+- Windows 10, version 1709
+- Windows 10, version 1703
+
+This topic provides IT Decision Makers with a basic understanding of the relationship between users in an organization and Microsoft in the context of the GDPR (General Data Protection Regulation). You will also learn what role an IT organization plays for that relationship.
+
+For more information about the GDPR, see:
+* [Microsoft GDPR Overview](https://aka.ms/GDPROverview)
+* [Microsoft Trust Center FAQs about the GDPR](https://aka.ms/gdpr-faq)
+* [Microsoft Service Trust Portal (STP)](https://aka.ms/stp)
+* [Get Started: Support for GDPR Accountability](https://servicetrust.microsoft.com/ViewPage/GDPRGetStarted)
+
+## GDPR fundamentals
+
+Here are some GDPR fundamentals:
+
+* On May 25, 2018, this EU data privacy law is implemented. It sets a new global bar for data privacy rights, security, and compliance.
+* The GDPR is fundamentally about protecting and enabling the privacy rights of individuals – both customers and employees.
+* The European law establishes strict global data privacy requirements governing how organizations manage and protect personal data while respecting individual choice – no matter where data is sent, processed, or stored.
+* A request by an individual to an organization to take an action on their personal data is referred to here as a *data subject request*, or *DSR*.
+
+Microsoft believes data privacy is a fundamental right, and that the GDPR is an important step forward for clarifying and enabling individual privacy rights. We also recognize that the GDPR requires significant changes by organizations all over the world with regard to the discovery, management, protection, and reporting of personal data that is collected, processed, and stored within an organization.
+
+### What is personal data under the GDPR?
+
+Article 4 (1) of [the GDPR](http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=en) defines personal data as any information relating to an identified or identifiable person. There is no distinction between a person’s private, public, or work roles. As defined by the GDPR, personal data includes, but is not limited to:
+* Name
+* Email address
+* Credit card numbers
+* IP addresses
+* Social media posts
+* Location information
+* Handwriting patterns
+* Voice input to cloud-based speech services
+
+### Controller and processor under the GDPR: Who does what
+
+#### Definition
+
+The GDPR describes specific requirements for allocating responsibility for controller and processor activities related to personal data. Thus, every organization that processes personal data must determine whether it is acting as a controller or processor for a specific scenario.
+
+* **Controller**: GDPR Article 4 (7) defines the ‘controller’ as the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
+* **Processor**: According to the GDPR Article 4 (8) ‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
+
+#### Controller scenario
+
+For example, when an organization is using Microsoft Windows Defender Advanced Threat Protection (ATP) to detect, investigate, and respond to advanced threats on their networks as part of their IT operations, that organization is collecting data from the user’s device – data, that might include personal data. In this scenario, the organization is the *controller* of the respective personal data, since the organization controls the purpose and means of the processing for data being collected from the devices that have Windows Defender ATP enabled.
+
+#### Processor scenario
+
+In the controller scenario described above, Microsoft is a *processor* because Microsoft provides data processing services to that controller (in the given example, an organization that subscribed to Windows Defender ATP and enabled it for the user’s device). As processor, Microsoft only processes data on behalf of the enterprise customer and does not have the right to process data beyond their instructions as specified in a written contract, such as the [Microsoft Product Terms and the Microsoft Online Services Terms (OST)](https://www.microsoft.com/en-us/licensing/product-licensing/products.aspx).
+
+## GDPR relationship between a Windows 10 user and Microsoft
+
+For Windows 10 services, Microsoft usually is the controller (with exceptions, such as Windows Defender ATP). The following sections describe what that means for the related data.
+
+### Types of data exchanged with Microsoft
+
+Microsoft collects data from or generates data through interactions with users of Windows 10 devices. This information can contain personal data, as defined in [Article 4 (1) of the GDPR](http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L:2016:119:FULL&from=EN), that may be used to provide, support, and improve Windows 10 services.
+
+Microsoft discloses data collection and privacy practices in detail, for example:
+* As part of the Windows 10 installation;
+* In the Windows 10 privacy settings;
+* Via the web-based [Microsoft Privacy dashboard](https://account.microsoft.com/privacy); and
+* In the [Microsoft Privacy Statement](https://privacy.microsoft.com/en-us/privacystatement).
+
+It is important to differentiate between two distinct types of data Windows services are dealing with.
+
+#### Windows functional data
+
+A user action, such as performing a Skype call, usually triggers the collection and transmission of Windows *functional data*. Some Windows components and applications connecting to Microsoft services also exchange Windows functional data to provide user functionality.
+
+Some other examples of Windows functional data:
+* The Weather app which uses the device’s location to retrieve local weather or community news.
+* Wallpaper and desktop settings that are synchronized across multiple devices.
+
+For more info on how IT Professionals can manage Windows functional data sent from an organization to Microsoft, see [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md).
+
+#### Windows diagnostic data
+
+Windows diagnostic data is used to keep the operating system secure and up-to-date, troubleshoot problems, and make product improvements. The data is encrypted before being sent back to Microsoft.
+
+Some examples of diagnostic data include:
+* The type of hardware being used, information about installed apps and usage details, and reliability data on drivers running on the device.
+* For users who have turned on “Tailored experiences”, it can be used to offer personalized tips, ads, and recommendations to enhance Microsoft products and services for the needs of the user.
+
+To find more about what information is collected, how it is handled, and the available Windows diagnostic data levels, see [Understanding Windows diagnostic data](configure-windows-diagnostic-data-in-your-organization.md#understanding-windows-diagnostic-data) and [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md).
+
+>[!IMPORTANT]
+>Other Microsoft services as well as 3rd party applications and drivers running on Windows devices may implement their own functionality, independently from Windows, to transport their diagnostic data to the respective publisher. Please contact them for further guidance on how to control the diagnostic data collection level and transmission of these publishers.
+
+### Windows services where Microsoft is the processor under the GDPR
+
+Most Windows 10 services are controller services in terms of the GDPR – for both Windows functional data and Windows diagnostic data. But there are a few Windows services where Microsoft is a processor for functional data under the GDPR, such as [Windows Analytics](https://www.microsoft.com/windowsforbusiness/windows-analytics) and [Windows Defender Advanced Threat Protection (ATP)](https://www.microsoft.com/windowsforbusiness/windows-atp).
+
+>[!NOTE]
+>Both Windows Analytics and Windows Defender ATP are subscription services for organizations. Some functionality requires a certain license (please see [Compare Windows 10 editions](https://www.microsoft.com/en-us/windowsforbusiness/compare)).
+
+#### Windows Analytics
+
+[Windows Analytics](https://www.microsoft.com/en-us/windowsforbusiness/windows-analytics) is a service that provides rich, actionable information for helping organizations to gain deep insights into the operational efficiency and health of the Windows devices in their environment. It uses Windows diagnostic data from devices enrolled by the IT organization of an enterprise into the Windows Analytics service.
+
+Windows [transmits Windows diagnostic data](enhanced-diagnostic-data-windows-analytics-events-and-fields.md) to Microsoft datacenters, where that data is analyzed and stored. With Windows Analytics, the IT organization can then view the analyzed data to detect and fix issues or to improve their processes for upgrading to Windows 10.
+
+As a result, in terms of the GDPR, the organization that has subscribed to Windows Analytics is acting as the controller, while Microsoft is the processor for Windows Analytics.
+>[!NOTE]
+>The IT organization must explicitly enable Windows Analytics for a device after the organization subscribes.
+
+>[!IMPORTANT]
+>Windows Analytics does not collect Windows Diagnostic data by itself. Instead, Windows Analytics only uses a subset of Windows Diagnostic data that is collected by Windows for a particular device. The Windows Diagnostic data collection is controlled by the IT department of an organization or the user of a device.
+
+#### Windows Defender ATP
+
+[Windows Defender ATP](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp) is cloud-based service that collects and analyzes usage data from an organization’s devices to detect security threats. Some of the data can contain personal data as defined by the GDPR. Enrolled devices transmit usage data to Microsoft datacenters, where that data is analyzed, processed, and stored. The security operations center (SOC) of the organization can view the analyzed data using the [Windows Defender ATP portal](https://securitycenter.windows.com/).
+
+As a result, in terms of the GDPR, the organization that has subscribed to Windows Defender ATP is acting as the controller, while Microsoft is the processor for Windows Defender ATP.
+
+>[!NOTE]
+>The IT organization must explicitly enable Windows Defender ATP for a device after the organization subscribes.
+
+#### At a glance – Windows 10 services GDPR mode of operations
+
+The following table lists in what GDPR mode – controller or processor – Windows 10 services are operating.
+
+| Service | Microsoft GDPR mode of operation |
+| --- | --- |
+| Windows Functional data | Controller |
+| Windows Diagnostic data | Controller |
+| Windows Analytics | Processor |
+| Windows Defender Advanced Threat Detection (ATP) | Processor |
+
+*Table 1: Windows 10 GDPR modes of operations for different Windows 10 services*
+
+## Recommended diagnostic data level settings
+
+Windows diagnostic data collection level can be set by a user in Windows (*Start > Settings > Privacy > Diagnostics & feedback*) or by the IT department of an organization, using Group Policy or Mobile Device Management (MDM) techniques.
+
+* For Windows 10, version 1803, Microsoft recommends setting the Windows diagnostic level to “Enhanced”. This enables organizations to get the full functionality of [Windows Analytics](#windows-analytics). Those organizations who wish to share the smallest set of events for Windows Analytics can use the “Limit Enhanced diagnostic data to the minimum required by Windows Analytics” filtering mechanism that Microsoft introduced in Windows 10, version 1709. When enabled, this feature limits the operating system diagnostic data events included in the Enhanced level to the smallest set of data required by Windows Analytics.
+
+>[!NOTE]
+>For more information on the Enhanced level, see [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md).
+
+* For Windows 10, version 1709, and Windows 10, version 1703, the recommended Windows diagnostic level configuration for EEA and Switzerland residents is “Basic”.
+
+## Controlling the data collection and notification about it
+
+Windows 10 sends diagnostic data to Microsoft services, and some of that data can contain personal data. Both the user and the IT organization have the ability to control the transmission of that data to Microsoft.
+
+### Adjusting privacy settings by the user
+
+A user has the ability to adjust additional privacy settings in Windows by navigating to *Start > Settings > Privacy*. For example, a user can control if location is enabled or disabled, whether or not to transmit feedback on inking and typing input to Microsoft for improving the personal accuracy of these services, or if Windows collects activities for syncing it with other devices.
+
+For a standard user in an organization, some privacy settings might be controlled by their IT department. This is done using Group Policies or Mobile Device Management (MDM) settings. If this is the case, the user will see an alert that says ‘Some settings are hidden or managed by your organization’ when they navigate to *Start > Settings > Privacy*. As such, the user can only change some settings, but not all.
+
+### Users can lower the diagnostic level
+
+Starting with Windows 10, version 1803, a user can change the Windows diagnostics data level for their device below to what was set by their IT department. Organizations can allow or disallow this feature by configuring the Group Policy **Computer Configuration\Administrative Templates\Windows Components\Data Collection and Preview Builds\Configure telemetry opt-in setting user interface** or the MDM policy **ConfigureTelemetryOptInSettingsUx**.
+
+If an IT organization has not disabled this policy, users within the organization can change their own Windows diagnostic data collection level in *Start > Settings > Privacy > Diagnostics & feedback*. For example, if the IT organization enabled this policy and set the level to “Full”, a user can modify the Windows diagnostics data level setting to “Basic”.
+
+### Notification at logon
+
+Windows 10, version 1803, and later can provide users with a notification during their logon. If the IT organization has not disabled the Group Policy **Computer Configuration\Administrative Templates\Windows Components\Data Collection and Preview Builds\Configure telemetry opt-in change notifications** or the MDM policy **ConfigureTelemetryOptInChangeNotification**, Windows diagnostic data notifications can appear at logon so that the users of a device are aware of the data collection.
+
+This notification can also be shown when the diagnostic level for the device was changed. For instance, if the diagnostic level on the device is set to “Basic” and the IT organization changes it to “Full”, users will be notified on their next logon.
+
+### Diagnostic Data Viewer (DDV)
+
+In Windows 10, version 1803 and later, users can invoke the [Diagnostic Data Viewer (DDV)](diagnostic-data-viewer-overview.md) to see what Windows diagnostic data is collected on their local device. This app lets a user review the diagnostic data collected on his device that is being sent to Microsoft. The DDV groups the information into simple categories based on how it is used by Microsoft.
+
+A user can turn on Windows diagnostic data viewing by going to go to *Start > Settings > Privacy > Diagnostics & feedback*. Under the ‘Diagnostic data viewer’ section, the user has to enable the ‘If data viewing is enabled, you can see your diagnostics data’ option. After DDV is installed on the device, the user can start it by clicking the ‘Diagnostic Data Viewer’ in the ‘Diagnostic data viewer’ section of *Start > Settings > Privacy > Diagnostics & feedback*.
+
+Also, the user can delete all Windows diagnostic data collected from the device. This is done by clicking the ‘Delete’ button in the ‘Delete diagnostic data’ section of *Start > Settings > Privacy > Diagnostics & feedback*.
+
+### Windows 10 personal data services configuration
+
+Microsoft assembled a list of Windows 10 services configuration settings that are useful for personal data privacy protection and related regulations, such as the General Data Protection Regulation (GDPR). There is one section with settings for service data that is managed at Microsoft and a section for local data that is managed by an IT organization.
+
+IT Professionals that are interested in this configuration, see [Windows 10 personal data services configuration](windows-personal-data-services-configuration.md).
+
+### Windows 10 connections to Microsoft
+
+To find out more about the network connections that Windows components make to Microsoft as well as the privacy settings that affect data shared with either Microsoft or apps, see [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) and [Manage Windows 10 connection endpoints](manage-windows-endpoints.md). These articles describe how these settings can be managed by an IT Professional.
+
+## At-a-glance: the relationship between an IT organization and the GDPR
+
+Because Microsoft is a controller for data collected by Windows 10, the user can work with Microsoft to satisfy GDPR requirements. While this relationship between Microsoft and a user is evident in a consumer scenario, an IT organization can influence that relationship in an enterprise scenario. For example, the IT organization has the ability to centrally configure the Windows diagnostic data level by using Group Policy or MDM settings.
+
+## Further reading
+
+### Optional settings / features that further improve the protection of personal data
+
+Personal data protection is one of the goals of the GDPR. One way of improving personal data protection is to use the modern and advanced security features of Windows 10. An IT organization can learn more at [Mitigate threats by using Windows 10 security features](/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10) and [Standards for a highly secure Windows 10 device](https://docs.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-highly-secure).
+
+>[!NOTE]
+>Some of these features might require a particular Windows hardware, such as a computer with a Trusted Platform Module (TPM) chip, and can depend on a particular Windows product (such as Windows 10 E5).
+
+### Windows Security Baselines
+
+Microsoft has created Windows Security Baselines to efficiently configure Windows 10. For more information, please visit [Windows Security Baselines](/windows/security/threat-protection/windows-security-baselines).
+
+### Windows Restricted Traffic Limited Functionality Baseline
+
+To make it easier to deploy settings that restrict connections from Windows 10 to Microsoft, IT Professionals can apply the Windows Restricted Traffic Limited Functionality Baseline, available [here](https://go.microsoft.com/fwlink/?linkid=828887).
+
+>[!IMPORTANT]
+>Some of the settings of the Windows Restricted Traffic Limited Functionality Baseline will reduce the functionality and security configuration of a device in the organization and are therefore not recommended.
+
+### Microsoft Trust Center and Service Trust Portal
+
+Please visit our [GDPR section of the Microsoft Trust Center](https://www.microsoft.com/en-us/trustcenter/privacy/gdpr) to obtain additional resources and to learn more about how Microsoft can help you fulfill specific GDPR requirements. There you can find lots of useful information about the GDPR, including how Microsoft is helping customers to successfully master the GDPR, a FAQ list, and a list of [resources for GDPR compliance](https://www.microsoft.com/en-us/TrustCenter/Privacy/gdpr/resources). Also, please check out the [Compliance Manager](https://aka.ms/compliancemanager) of the Microsoft [Service Trust Portal (STP)](https://aka.ms/stp) and [Get Started: Support for GDPR Accountability](https://servicetrust.microsoft.com/ViewPage/GDPRGetStarted).
+
+### Additional resources
+
+#### FAQs
+
+* [Windows 10 feedback, diagnostics, and privacy](https://privacy.microsoft.com/windows-10-feedback-diagnostics-and-privacy)
+* [Microsoft Edge and privacy](https://privacy.microsoft.com/windows-10-microsoft-edge-and-privacy)
+* [Windows Hello and privacy](https://privacy.microsoft.com/windows-10-windows-hello-and-privacy)
+* [Wi-Fi Sense](https://privacy.microsoft.com/windows-10-about-wifi-sense)
+
+#### Blogs
+
+* [Privacy and Windows 10](https://blogs.windows.com/windowsexperience/2015/09/28/privacy-and-windows-10)
+
+#### Privacy Statement
+
+* [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement)
+
+#### Other resources
+
+* [Privacy at Microsoft](http://privacy.microsoft.com/)
\ No newline at end of file
diff --git a/windows/configuration/gdpr-win10-whitepaper.md b/windows/privacy/gdpr-win10-whitepaper.md
similarity index 100%
rename from windows/configuration/gdpr-win10-whitepaper.md
rename to windows/privacy/gdpr-win10-whitepaper.md
diff --git a/windows/privacy/images/checkmark.png b/windows/privacy/images/checkmark.png
new file mode 100644
index 0000000000..f9f04cd6bd
Binary files /dev/null and b/windows/privacy/images/checkmark.png differ
diff --git a/windows/configuration/images/ddv-data-viewing.png b/windows/privacy/images/ddv-data-viewing.png
similarity index 100%
rename from windows/configuration/images/ddv-data-viewing.png
rename to windows/privacy/images/ddv-data-viewing.png
diff --git a/windows/configuration/images/ddv-device-sample.png b/windows/privacy/images/ddv-device-sample.png
similarity index 100%
rename from windows/configuration/images/ddv-device-sample.png
rename to windows/privacy/images/ddv-device-sample.png
diff --git a/windows/configuration/images/ddv-event-sample.png b/windows/privacy/images/ddv-event-sample.png
similarity index 100%
rename from windows/configuration/images/ddv-event-sample.png
rename to windows/privacy/images/ddv-event-sample.png
diff --git a/windows/configuration/images/ddv-problem-reports-screen.png b/windows/privacy/images/ddv-problem-reports-screen.png
similarity index 100%
rename from windows/configuration/images/ddv-problem-reports-screen.png
rename to windows/privacy/images/ddv-problem-reports-screen.png
diff --git a/windows/configuration/images/ddv-settings-launch.png b/windows/privacy/images/ddv-settings-launch.png
similarity index 100%
rename from windows/configuration/images/ddv-settings-launch.png
rename to windows/privacy/images/ddv-settings-launch.png
diff --git a/windows/configuration/images/ddv-settings-off.png b/windows/privacy/images/ddv-settings-off.png
similarity index 100%
rename from windows/configuration/images/ddv-settings-off.png
rename to windows/privacy/images/ddv-settings-off.png
diff --git a/windows/configuration/images/gdpr-azure-info-protection.png b/windows/privacy/images/gdpr-azure-info-protection.png
similarity index 100%
rename from windows/configuration/images/gdpr-azure-info-protection.png
rename to windows/privacy/images/gdpr-azure-info-protection.png
diff --git a/windows/configuration/images/gdpr-comp-info-protection.png b/windows/privacy/images/gdpr-comp-info-protection.png
similarity index 100%
rename from windows/configuration/images/gdpr-comp-info-protection.png
rename to windows/privacy/images/gdpr-comp-info-protection.png
diff --git a/windows/configuration/images/gdpr-cve-graph.png b/windows/privacy/images/gdpr-cve-graph.png
similarity index 100%
rename from windows/configuration/images/gdpr-cve-graph.png
rename to windows/privacy/images/gdpr-cve-graph.png
diff --git a/windows/configuration/images/gdpr-intelligent-security-graph.png b/windows/privacy/images/gdpr-intelligent-security-graph.png
similarity index 100%
rename from windows/configuration/images/gdpr-intelligent-security-graph.png
rename to windows/privacy/images/gdpr-intelligent-security-graph.png
diff --git a/windows/configuration/images/gdpr-security-center.png b/windows/privacy/images/gdpr-security-center.png
similarity index 100%
rename from windows/configuration/images/gdpr-security-center.png
rename to windows/privacy/images/gdpr-security-center.png
diff --git a/windows/configuration/images/gdpr-security-center2.png b/windows/privacy/images/gdpr-security-center2.png
similarity index 100%
rename from windows/configuration/images/gdpr-security-center2.png
rename to windows/privacy/images/gdpr-security-center2.png
diff --git a/windows/configuration/images/gdpr-security-center3.png b/windows/privacy/images/gdpr-security-center3.png
similarity index 100%
rename from windows/configuration/images/gdpr-security-center3.png
rename to windows/privacy/images/gdpr-security-center3.png
diff --git a/windows/configuration/images/gdpr-steps-diagram.png b/windows/privacy/images/gdpr-steps-diagram.png
similarity index 100%
rename from windows/configuration/images/gdpr-steps-diagram.png
rename to windows/privacy/images/gdpr-steps-diagram.png
diff --git a/windows/configuration/images/priv-telemetry-levels.png b/windows/privacy/images/priv-telemetry-levels.png
similarity index 100%
rename from windows/configuration/images/priv-telemetry-levels.png
rename to windows/privacy/images/priv-telemetry-levels.png
diff --git a/windows/privacy/index.md b/windows/privacy/index.md
deleted file mode 100644
index f20ef925b9..0000000000
--- a/windows/privacy/index.md
+++ /dev/null
@@ -1 +0,0 @@
-# Welcome to privacy!
\ No newline at end of file
diff --git a/windows/privacy/index.yml b/windows/privacy/index.yml
new file mode 100644
index 0000000000..5a42697604
--- /dev/null
+++ b/windows/privacy/index.yml
@@ -0,0 +1,150 @@
+### YamlMime:YamlDocument
+
+documentType: LandingData
+
+title: Windows Privacy
+
+metadata:
+
+ document_id:
+
+ title: Windows Privacy
+
+ description: Learn about how privacy is managed in Windows.
+
+ keywords: Windows 10, Windows Server, Windows Server 2016, privacy, GDPR, compliance, endpoints
+
+ ms.localizationpriority: high
+
+ author: danihalfin
+
+ ms.author: daniha
+
+ ms.date: 04/25/2018
+
+ ms.topic: article
+
+ ms.devlang: na
+
+sections:
+
+- items:
+
+ - type: markdown
+
+ text: Get ready for General Data Protection Regulation (GDPR) by viewing and configuring diagnostics data in your organization.
+
+- items:
+
+ - type: list
+
+ style: cards
+
+ className: cardsM
+
+ columns: 3
+
+ items:
+
+ - href: \windows\privacy\gdpr-win10-whitepaper
+
+ html:
Learn about GDPR and how Microsoft helps you get started towards compliance
+
\ No newline at end of file
diff --git a/windows/configuration/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md
similarity index 99%
rename from windows/configuration/manage-connections-from-windows-operating-system-components-to-microsoft-services.md
rename to windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md
index d776b3e988..d80ca22032 100644
--- a/windows/configuration/manage-connections-from-windows-operating-system-components-to-microsoft-services.md
+++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md
@@ -1847,7 +1847,7 @@ If you're not running Windows 10, version 1607 or later, you can use the other o
- Create a new REG\_DWORD registry setting named **DisableWindowsConsumerFeatures** in **HKEY\_LOCAL\_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CloudContent** with a value of 1 (one).
-For more info, see [Windows Spotlight on the lock screen](windows-spotlight.md).
+For more info, see [Windows Spotlight on the lock screen](/windows/configuration/windows-spotlight).
### 26. Microsoft Store
diff --git a/windows/configuration/manage-windows-endpoints-version-1709.md b/windows/privacy/manage-windows-endpoints.md
similarity index 79%
rename from windows/configuration/manage-windows-endpoints-version-1709.md
rename to windows/privacy/manage-windows-endpoints.md
index 1ce981a341..d0be3c4145 100644
--- a/windows/configuration/manage-windows-endpoints-version-1709.md
+++ b/windows/privacy/manage-windows-endpoints.md
@@ -14,7 +14,7 @@ ms.date: 11/21/2017
**Applies to**
-- Windows 10, version 1709
+- Windows 10, version 1709 and later
Some Windows components, app, and related services transfer data to Microsoft network endpoints. Some examples include:
@@ -24,13 +24,13 @@ Some Windows components, app, and related services transfer data to Microsoft ne
- Connecting to the cloud to store and access backups.
- Using your location to show a weather forecast.
-This article lists different endpoints that are available on a clean installation of Windows 10 Enterprise, version 1709.
+This article lists different endpoints that are available on a clean installation of Windows 10, version 1709 and later.
Details about the different ways to control traffic to these endpoints are covered in [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md).
Where applicable, each endpoint covered in this topic includes a link to specific details about how to control traffic to it.
We used the following methodology to derive these network endpoints:
-1. Set up Windows 10 Enterprise, version 1709 test virtual machine using the default settings.
+1. Set up the latest version of Windows 10 on a test virtual machine using the default settings.
2. Leave the devices running idle for a week (that is, a user is not interacting with the system/device).
3. Use globally accepted network protocol analyzer/capturing tools and log all background egress traffic.
4. Compile reports on traffic going to public IP addresses.
@@ -39,254 +39,259 @@ We used the following methodology to derive these network endpoints:
> [!NOTE]
> Microsoft uses global load balancers that can appear in network trace-routes. For example, an endpoint for *.akadns.net might be used to load balance requests to an Azure datacenter, which can change over time.
+## Windows 10 Enterprise connection endpoints
+
## Apps
The following endpoint is used to download updates to the Weather app Live Tile.
If you [turn off traffic to this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles), no Live Tiles will be updated.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| explorer | HTTP | tile-service.weather.microsoft.com/en-US/livetile/preinstall?region=US&appid=C98EA5B0842DBB9405BBF071E1DA76512D21FE36&FORM=Threshold |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| explorer | HTTP | tile-service.weather.microsoft.com | 1709 |
+| | HTTP | blob.weather.microsoft.com | 1803 |
The following endpoint is used for OneNote Live Tile.
To turn off traffic for this endpoint, either uninstall OneNote or [disable the Microsoft Store](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore).
If you disable the Microsoft store, other Store apps cannot be installed or updated.
Additionally, the Microsoft Store won't be able to revoke malicious Store apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTPS | cdn.onenote.net/livetile/?Language=en-US |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | HTTPS | cdn.onenote.net/livetile/?Language=en-US | 1709 |
The following endpoints are used for Twitter updates.
To turn off traffic for these endpoints, either uninstall Twitter or [disable the Microsoft Store](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore).
If you disable the Microsoft store, other Store apps cannot be installed or updated.
Additionally, the Microsoft Store won't be able to revoke malicious Store apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTPS | wildcard.twimg.com |
-| svchost.exe | | oem.twimg.com/windows/tile.xml |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | HTTPS | wildcard.twimg.com | 1709 |
+| svchost.exe | | oem.twimg.com/windows/tile.xml | 1709 |
The following endpoint is used for Facebook updates.
To turn off traffic for this endpoint, either uninstall Facebook or [disable the Microsoft Store](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore).
If you disable the Microsoft store, other Store apps cannot be installed or updated.
Additionally, the Microsoft Store won't be able to revoke malicious Store apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | | star-mini.c10r.facebook.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | | star-mini.c10r.facebook.com | 1709 |
The following endpoint is used by the Photos app to download configuration files, and to connect to the Office 365 portal's shared infrastructure, including Office Online.
To turn off traffic for this endpoint, either uninstall the Photos app or [disable the Microsoft Store](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore).
If you disable the Microsoft store, other Store apps cannot be installed or updated.
Additionally, the Microsoft Store won't be able to revoke malicious Store apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| WindowsApps\Microsoft.Windows.Photos | HTTPS | evoke-windowsservices-tas.msedge.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| WindowsApps\Microsoft.Windows.Photos | HTTPS | evoke-windowsservices-tas.msedge.net | 1709 |
The following endpoint is used for Candy Crush Saga updates.
To turn off traffic for this endpoint, either uninstall Candy Crush Saga or [disable the Microsoft Store](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore).
If you disable the Microsoft store, other Store apps cannot be installed or updated.
Additionally, the Microsoft Store won't be able to revoke malicious Store apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | TLS v1.2 | candycrushsoda.king.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | TLS v1.2 | candycrushsoda.king.com | 1709 |
The following endpoint is used for by the Microsoft Wallet app.
To turn off traffic for this endpoint, either uninstall the Wallet app or [disable the Microsoft Store](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore).
If you disable the Microsoft store, other Store apps cannot be installed or updated.
Additionally, the Microsoft Store won't be able to revoke malicious Store apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| system32\AppHostRegistrationVerifier.exe | HTTPS | wallet.microsoft.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| system32\AppHostRegistrationVerifier.exe | HTTPS | wallet.microsoft.com | 1709 |
The following endpoint is used by the Groove Music app for update HTTP handler status.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-apps-for-websites), apps for websites won't work and customers who visit websites (such as mediaredirect.microsoft.com) that are registered with their associated app (such as Groove Music) will stay at the website and won't be able to directly launch the app.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| system32\AppHostRegistrationVerifier.exe | HTTPS | mediaredirect.microsoft.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| system32\AppHostRegistrationVerifier.exe | HTTPS | mediaredirect.microsoft.com | 1709 |
## Cortana and Search
The following endpoint is used to get images that are used for Microsoft Store suggestions.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana), you will block images that are used for Microsoft Store suggestions.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| searchui | HTTPS | store-images.s-microsoft.com/image/apps.32524.9007199266244048.fc51fce8-175a-4525-b569-14d91f7779c3.0a720951-38e4-4e81-9804-03f833ab1d2e?format=source |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| searchui | HTTPS |store-images.s-microsoft.com | 1709 |
The following endpoint is used to update Cortana greetings, tips, and Live Tiles.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana), you will block updates to Cortana greetings, tips, and Live Tiles.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| backgroundtaskhost | HTTPS | www.bing.com/client/config?cc=US&setlang=en-US |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| backgroundtaskhost | HTTPS | www.bing.com/client | 1709 |
The following endpoint is used to configure parameters, such as how often the Live Tile is updated. It's also used to activate experiments.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana), parameters would not be updated and the device would no longer participate in experiments.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| backgroundtaskhost | HTTPS | www.bing.com/proactive/v2/spark?cc=US&setlang=en-US |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| backgroundtaskhost | HTTPS | www.bing.com/proactive | 1709 |
The following endpoint is used by Cortana to report diagnostic and diagnostic data information.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana), Microsoft won't be aware of issues with Cortana and won't be able to fix them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| searchui backgroundtaskhost | HTTPS | www.bing.com/threshold/xls.aspx |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| searchui backgroundtaskhost | HTTPS | www.bing.com/threshold/xls.aspx | 1709 |
## Certificates
The following endpoint is used by the Automatic Root Certificates Update component to automatically check the list of trusted authorities on Windows Update to see if an update is available. It is possible to [turn off traffic to this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#automatic-root-certificates-update), but that is not recommended because when root certificates are updated over time, applications and websites may stop working because they did not receive an updated root certificate the application uses.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | HTTP | ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?1ba0e83cae791f0d |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | HTTP | ctldl.windowsupdate.com | 1709 |
The following endpoints are used to download certificates that are publicly known to be fraudulent.
These settings are critical for both Windows security and the overall security of the Internet.
We do not recommend blocking this endpoint.
If traffic to this endpoint is turned off, Windows no longer automatically downloads certificates known to be fraudulent, which increases the attack vector on the device.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | HTTP | ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?03376e5589b4a188 |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | HTTP | ctldl.windowsupdate.com | 1709 |
## Device authentication
The following endpoint is used to authenticate a device.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback), the device will not be authenticated.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTPS | login.live.com/ppsecure/deviceaddcredential.srf |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | HTTPS | login.live.com/ppsecure | 1709 |
## Device metadata
The following endpoint is used to retrieve device metadata.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devinst), metadata will not be updated for the device.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | | dmd.metaservices.microsoft.com.akadns.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | | dmd.metaservices.microsoft.com.akadns.net | 1709 |
+| | HTTP | dmd.metaservices.microsoft.com | 1803 |
## Diagnostic Data
The following endpoint is used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback), diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | | cy2.vortex.data.microsoft.com.akadns.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | | cy2.vortex.data.microsoft.com.akadns.net | 1709 |
The following endpoint is used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback), diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | | v10.vortex-win.data.microsoft.com/collect/v1 |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | | v10.vortex-win.data.microsoft.com/collect/v1 | 1709 |
The following endpoints are used by Windows Error Reporting.
To turn off traffic for these endpoints, enable the following Group Policy: Administrative Templates > Windows Components > Windows Error Reporting > Disable Windows Error Reporting. This means error reporting information will not be sent back to Microsoft.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| wermgr | | watson.telemetry.microsoft.com/Telemetry.Request |
-| |TLS v1.2 |modern.watson.data.microsoft.com.akadns.net|
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| wermgr | | watson.telemetry.microsoft.com | 1709 |
+| | TLS v1.2 | modern.watson.data.microsoft.com.akadns.net | 1709 |
## Font streaming
The following endpoints are used to download fonts on demand.
If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#font-streaming), you will not be able to download fonts on demand.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | | fs.microsoft.com |
-| | | fs.microsoft.com/fs/windows/config.json |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | | fs.microsoft.com | 1709 |
+| | | fs.microsoft.com/fs/windows/config.json | 1709 |
## Licensing
The following endpoint is used for online activation and some app licensing.
To turn off traffic for this endpoint, disable the Windows License Manager Service. This will also block online activation and app licensing may not work.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| licensemanager | HTTPS | licensing.mp.microsoft.com/v7.0/licenses/content |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| licensemanager | HTTPS | licensing.mp.microsoft.com/v7.0/licenses/content | 1709 |
## Location
The following endpoint is used for location data.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-location), apps cannot use location data.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTP | location-inference-westus.cloudapp.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | HTTP | location-inference-westus.cloudapp.net | 1709 |
## Maps
The following endpoint is used to check for updates to maps that have been downloaded for offline use.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-offlinemaps), offline maps will not be updated.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | HTTPS | *g.akamaiedge.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | HTTPS | *g.akamaiedge.net | 1709 |
## Microsoft account
The following endpoints are used for Microsoft accounts to sign in.
If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-microsoft-account), users cannot sign in with Microsoft accounts.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | | login.msa.akadns6.net |
-| system32\Auth.Host.exe | HTTPS | auth.gfx.ms |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | | login.msa.akadns6.net | 1709 |
+| system32\Auth.Host.exe | HTTPS | auth.gfx.ms | 1709 |
## Microsoft Store
The following endpoint is used for the Windows Push Notification Services (WNS). WNS enables third-party developers to send toast, tile, badge, and raw updates from their own cloud service. This provides a mechanism to deliver new updates to your users in a power-efficient and dependable way.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles), push notifications will no longer work, including MDM device management, mail synchronization, settings synchronization.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | | *.wns.windows.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | | *.wns.windows.com | 1709 |
The following endpoint is used to revoke licenses for malicious apps in the Microsoft Store.
To turn off traffic for this endpoint, either uninstall the app or [disable the Microsoft Store](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore). If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTP | storecatalogrevocation.storequality.microsoft.com/applications/revoked.json/ |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | HTTP | storecatalogrevocation.storequality.microsoft.com | 1709 |
The following endpoints are used to download image files that are called when applications run (Microsoft Store or Inbox MSN Apps).
If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore), the image files won't be downloaded, and apps cannot be installed or updated from the Microsoft Store. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTPS | img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RE1ARmA?ver=e6f4 |
-| | HTTPS | img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RWbW71?ver=c090 |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | HTTPS | img-prod-cms-rt-microsoft-com.akamaized.net | 1709 |
+| backgroundtransferhost | HTTPS | store-images.microsoft.com | 1803 |
The following endpoints are used to communicate with Microsoft Store.
If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore), apps cannot be installed or updated from the Microsoft Store. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTP | storeedgefd.dsx.mp.microsoft.com |
-| | HTTP | pti.store.microsoft.com |
-||TLS v1.2|cy2.\*.md.mp.microsoft.com.\*.|
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | HTTP | storeedgefd.dsx.mp.microsoft.com | 1709 |
+| | HTTP | pti.store.microsoft.com | 1709 |
+||TLS v1.2|cy2.\*.md.mp.microsoft.com.\*.| 1709 |
+| svchost | HTTPS | displaycatalog.mp.microsoft.com | 1803 |
## Network Connection Status Indicator (NCSI)
Network Connection Status Indicator (NCSI) detects Internet connectivity and corporate network connectivity status. NCSI sends a DNS request and HTTP query to this endpoint to determine if the device can communicate with the Internet.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-ncsi), NCSI won't be able to determine if the device is connected to the Internet and the network status tray icon will show a warning.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTP | www.msftconnecttest.com/connecttest.txt |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | HTTP | www.msftconnecttest.com/connecttest.txt | 1709 |
## Office
@@ -294,89 +299,74 @@ The following endpoints are used to connect to the Office 365 portal's shared in
You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps.
If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | | *.a-msedge.net |
-| hxstr | | *.c-msedge.net |
-| | | *.e-msedge.net |
-| | | *.s-msedge.net |
-
-The following endpoint is used to connect to the Office 365 portal's shared infrastructure, including Office Online. For more info, see [Office 365 URLs and IP address ranges](https://support.office.com/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2?ui=en-US&rs=en-US&ad=US#BKMK_Portal-identity).
-You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps.
-If you turn off traffic for this endpoint, users won't be able to save documents to the cloud or see their recently used documents.
-
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| hxstr | | *.c-msedge.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | | *.a-msedge.net | 1709 |
+| hxstr | | *.c-msedge.net | 1709 |
+| | | *.e-msedge.net | 1709 |
+| | | *.s-msedge.net | 1709 |
+| | HTTPS | ocos-office365-s2s.msedge.net | 1803 |
The following endpoint is used to connect to the Office 365 portal's shared infrastructure, including Office Online. For more info, see [Office 365 URLs and IP address ranges](https://support.office.com/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2?ui=en-US&rs=en-US&ad=US#BKMK_Portal-identity).
You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps.
If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| system32\Auth.Host.exe | HTTPS | outlook.office365.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| system32\Auth.Host.exe | HTTPS | outlook.office365.com | 1709 |
The following endpoint is OfficeHub traffic used to get the metadata of Office apps. To turn off traffic for this endpoint, either uninstall the app or [disable the Microsoft Store](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore). If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-|Windows Apps\Microsoft.Windows.Photos|HTTPS|client-office365-tas.msedge.net|
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+|Windows Apps\Microsoft.Windows.Photos|HTTPS|client-office365-tas.msedge.net| 1709 |
## OneDrive
The following endpoint is a redirection service that’s used to automatically update URLs.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-onedrive), anything that relies on g.live.com to get updated URL information will no longer work.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| onedrive | HTTP | g.live.com/1rewlive5skydrive/ODSUProduction |
-
-
-The following endpoint is a redirection service that’s used to automatically update URLs.
-If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-onedrive), anything that relies on g.live.com to get updated URL information will no longer work.
-
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| onedrive | HTTPS | g.live.com/1rewlive5skydrive/OneDriveProduction?OneDriveUpdate=1303f1898483a527eab1d8f57af6 |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| onedrive | HTTP \ HTTPS | g.live.com/1rewlive5skydrive/ODSUProduction | 1709 |
The following endpoint is used by OneDrive for Business to download and verify app updates. For more info, see [Office 365 URLs and IP address ranges](https://support.office.com/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2?ui=en-US&rs=en-US&ad=US).
To turn off traffic for this endpoint, uninstall OneDrive for Business. In this case, your device will not able to get OneDrive for Business app updates.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| onedrive | HTTPS | oneclient.sfx.ms/PreSignInSettings/Prod/PreSignInSettingsConfig.json?OneDriveUpdate=3253474af747a19de2a72deb9a75 |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| onedrive | HTTPS | oneclient.sfx.ms | 1709 |
## Settings
The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback), an app that uses this endpoint may stop working.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| dmclient | | cy2.settings.data.microsoft.com.akadns.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| dmclient | | cy2.settings.data.microsoft.com.akadns.net | 1709 |
The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback), an app that uses this endpoint may stop working.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| dmclient | HTTPS | settings.data.microsoft.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| dmclient | HTTPS | settings.data.microsoft.com | 1709 |
The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as Windows Connected User Experiences and Telemetry component and Windows Insider Program use it.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback), an app that uses this endpoint may stop working.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | HTTPS | settings-win.data.microsoft.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | HTTPS | settings-win.data.microsoft.com | 1709 |
## Skype
The following endpoint is used to retrieve Skype configuration values. To turn off traffic for this endpoint, either uninstall the app or [disable the Microsoft Store](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore). If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-|microsoft.windowscommunicationsapps.exe | HTTPS | config.edge.skype.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+|microsoft.windowscommunicationsapps.exe | HTTPS | config.edge.skype.com | 1709 |
@@ -385,112 +375,102 @@ The following endpoint is used to retrieve Skype configuration values. To turn o
The following endpoint is used for Windows Defender when Cloud-based Protection is enabled.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender), the device will not use Cloud-based Protection.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | | wdcp.microsoft.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | | wdcp.microsoft.com | 1709 |
The following endpoints are used for Windows Defender definition updates.
If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender), definitions will not be updated.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | | definitionupdates.microsoft.com |
-|MpCmdRun.exe|HTTPS|go.microsoft.com|
-
-## Windows Insider Preview builds
-
-The following endpoint is used to retrieve Windows Insider Preview builds.
-If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-previewbuilds), the device will not be notified about new Windows Insider Preview builds.
-
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTPS | insiderppe.cloudapp.net/windows-app-web-link |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | | definitionupdates.microsoft.com | 1709 |
+|MpCmdRun.exe|HTTPS|go.microsoft.com | 1709 |
## Windows Spotlight
The following endpoints are used to retrieve Windows Spotlight metadata that describes content, such as references to image locations, as well as suggested apps, Microsoft account notifications, and Windows tips.
-If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight), Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see [Windows Spotlight](windows-spotlight.md).
+If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight), Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see [Windows Spotlight](/windows/configuration/windows-spotlight).
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| backgroundtaskhost | HTTPS | arc.msn.com |
-| backgroundtaskhost | | g.msn.com.nsatc.net |
-| |TLS v1.2| *.search.msn.com |
-| | HTTPS | ris.api.iris.microsoft.com/v1/a/impression?CID=116000000000270658®ion=US&lang=EN-US&oem=&devFam=WINDOWS.DESKTOP&ossku=ENTERPRISE&cmdVer=10.0.15063.0&mo=&cap=&EID=&&PID=400051553&UIT=G&TargetID=700090861&AN=275357688&PG=PC000P0FR5.0000000G4I&REQASID=D17E3C737583496F8C4CE6553F7395C5&UNID=202914&ANID=&MUID=&ASID=a81b259b93e2425e801d0bb5a5ec2741&PERSID=&AUID=71FA96C64367722E210169966CE8D919&TIME=20170721T015831Z |
-| | HTTPS | query.prod.cms.rt.microsoft.com/cms/api/am/binary/RWaHxi |
-| | HTTPS | query.prod.cms.rt.microsoft.com/cms/api/am/binary/RWaML4 |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| backgroundtaskhost | HTTPS | arc.msn.com | 1709 |
+| backgroundtaskhost | | g.msn.com.nsatc.net | 1709 |
+| |TLS v1.2| *.search.msn.com | 1709 |
+| | HTTPS | ris.api.iris.microsoft.com | 1709 |
+| | HTTPS | query.prod.cms.rt.microsoft.com | 1709 |
## Windows Update
The following endpoint is used for Windows Update downloads of apps and OS updates, including HTTP downloads or HTTP downloads blended with peers.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-updates), Windows Update downloads will not be managed, as critical metadata that is used to make downloads more resilient is blocked. Downloads may be impacted by corruption (resulting in re-downloads of full files). Additionally, downloads of the same update by multiple devices on the same local network will not use peer devices for bandwidth reduction.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | HTTPS | *.prod.do.dsp.mp.microsoft.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | HTTPS | *.prod.do.dsp.mp.microsoft.com | 1709 |
The following endpoints are used to download operating system patches and updates.
If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-wu), the device will not be able to download updates for the operating system.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | | au.download.windowsupdate.com |
-| svchost | HTTP | *.windowsupdate.com |
-| | HTTP | fg.download.windowsupdate.com.c.footprint.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | HTTP | *.windowsupdate.com | 1709 |
+| | HTTP | fg.download.windowsupdate.com.c.footprint.net | 1709 |
The following endpoint is used by the Highwinds Content Delivery Network to perform Windows updates.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-wu), the device will not perform updates.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | | cds.d2s7q6s2.hwcdn.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | | cds.d2s7q6s2.hwcdn.net | 1709 |
The following endpoints are used by the Verizon Content Delivery Network to perform Windows updates.
If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-wu), the device will not perform updates.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | HTTP | *wac.phicdn.net |
-| | | *wac.edgecastcdn.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | HTTP | *wac.phicdn.net | 1709 |
+| | | *wac.edgecastcdn.net | 1709 |
The following endpoint is used to download apps and Windows Insider Preview builds from the Microsoft Store. Time Limited URL (TLU) is a mechanism for protecting the content. For example, it prevents someone from copying the URL and then getting access to the app that the person has not acquired).
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-wu), the updating functionality on this device is essentially in a disabled state, resulting in user unable to get apps from the Store, get latest version of Windows, and so on.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | | *.tlu.dl.delivery.mp.microsoft.com.c.footprint.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | | *.tlu.dl.delivery.mp.microsoft.com.c.footprint.net | 1709 |
The following endpoint is used to download apps from the Microsoft Store. It's used as part of calculating the right ranges for apps.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-wu), users of the device will not able to get apps from the Microsoft Store.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | | emdl.ws.microsoft.com/emdl/c/doc/ph/prod1/msdownload/update/software/defu/2017/07/1024/am_base_82267ed19fb382d07106d5f64257fb815c664b31.exe.json |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | | emdl.ws.microsoft.com | 1709 |
The following endpoints enable connections to Windows Update, Microsoft Update, and the online services of the Store.
If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-wu), the device will not be able to connect to Windows Update and Microsoft Update to help keep the device secure. Also, the device will not be able to acquire and update apps from the Store.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | HTTPS | fe2.update.microsoft.com/v6/ClientWebService/client.asmx |
-| svchost | | fe3.delivery.mp.microsoft.com/ClientWebService/client.asmx |
-| | | fe3.delivery.dsp.mp.microsoft.com.nsatc.net (an alias for fe3.delivery.mp.microsoft.com) |
-| svchost | HTTPS | sls.update.microsoft.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | HTTPS | fe2.update.microsoft.com | 1709 |
+| svchost | | fe3.delivery.mp.microsoft.com | 1709 |
+| | | fe3.delivery.dsp.mp.microsoft.com.nsatc.net | 1709 |
+| svchost | HTTPS | sls.update.microsoft.com | 1709 |
+| | HTTP | *.dl.delivery.mp.microsoft.com | 1803 |
The following endpoint is used for content regulation.
If you [turn off traffic for this endpoint](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-wu), the Windows Update Agent will be unable to contact the endpoint and fallback behavior will be used. This may result in content being either incorrectly downloaded or not downloaded at all.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| svchost | HTTPS | tsfe.trafficshaping.dsp.mp.microsoft.com |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| svchost | HTTPS | tsfe.trafficshaping.dsp.mp.microsoft.com | 1709 |
The following endpoints are used to download content.
If you [turn off traffic for these endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-wu), you will block any content from being downloaded.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-| | | a122.dscd.akamai.net |
-| | | a1621.g.akamai.net |
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+| | | a122.dscd.akamai.net | 1709 |
+| | | a1621.g.akamai.net | 1709 |
## Microsoft forward link redirection service (FWLink)
@@ -498,9 +478,9 @@ The following endpoint is used by the Microsoft forward link redirection service
If you disable this endpoint, Windows Defender won't be able to update its malware definitions; links from Windows and other Microsoft products to the Web won't work; and PowerShell updateable Help won't update. To disable the traffic, instead disable the traffic that's getting forwarded.
-| Source process | Protocol | Destination |
-|----------------|----------|------------|
-|Various|HTTPS|go.microsoft.com|
+| Source process | Protocol | Destination | Applies from Windows 10 version |
+|----------------|----------|------------|----------------------------------|
+|Various|HTTPS|go.microsoft.com| 1709 |
## Endpoints for other Windows editions
diff --git a/windows/configuration/windows-diagnostic-data-1703.md b/windows/privacy/windows-diagnostic-data-1703.md
similarity index 100%
rename from windows/configuration/windows-diagnostic-data-1703.md
rename to windows/privacy/windows-diagnostic-data-1703.md
diff --git a/windows/configuration/windows-diagnostic-data.md b/windows/privacy/windows-diagnostic-data.md
similarity index 100%
rename from windows/configuration/windows-diagnostic-data.md
rename to windows/privacy/windows-diagnostic-data.md
diff --git a/windows/privacy/windows-personal-data-services-configuration.md b/windows/privacy/windows-personal-data-services-configuration.md
new file mode 100644
index 0000000000..4b824f3b1d
--- /dev/null
+++ b/windows/privacy/windows-personal-data-services-configuration.md
@@ -0,0 +1,400 @@
+---
+title: Windows 10 personal data services configuration
+description: An overview of Windows 10 services configuration settings that are used for personal data privacy protection relevant for regulations, such as the General Data Protection Regulation (GDPR)
+keywords: privacy, GDPR, windows, IT
+ms.prod: w10
+ms.mktglfcycl: manage
+ms.sitesec: library
+ms.pagetype: security
+ms.localizationpriority: high
+author: danihalfin
+ms.author: daniha
+ms.date: 05/11/2018
+---
+# Windows 10 personal data services configuration
+
+Applies to:
+- Windows 10, version 1803
+
+Microsoft assembled a list of Windows 10 services configuration settings that are useful for personal data privacy protection and related regulations, such as the General Data Protection Regulation (GDPR). There is one section with settings for service data that is managed at Microsoft and a section for local data that is managed by an IT organization.
+
+IT Professionals that are interested in applying these settings via group policies can find the configuration for download [here](https://go.microsoft.com/fwlink/?linkid=874149).
+
+## Introduction
+
+Microsoft collects data from or generates it through interactions with users of Windows 10 devices. This information can contain personal data that may be used to provide, support, and improve Windows 10 services.
+
+Many Windows 10 services are controller services. A user can manage data collection settings, for example by opening *Start > Settings > Privacy* or by visiting the [Microsoft Privacy dashboard](https://account.microsoft.com/privacy). While this relationship between Microsoft and a user is evident in a consumer type scenario, an IT organization can influence that relationship. For example, the IT department has the ability to configure the Windows diagnostic data level across their organization by using Group Policy, registry, or Mobile Device Management (MDM) settings.
+
+Below is a collection of settings related to the Windows 10 personal data services configuration that IT Professionals can use as guidance for influencing Windows diagnostic data collection and personal data protection.
+
+## Windows diagnostic data
+
+Windows 10 collects Windows diagnostic data—such as usage data, performance data, inking, typing, and utterance data—and sends it back to Microsoft. That data is used for keeping the operating system secure and up-to-date, to troubleshoot problems, and to make product improvements. For users who have turned on "Tailored experiences", that data can also be used to offer personalized tips, ads, and recommendations to enhance Microsoft products and services for your needs.
+
+The following options for configuring Windows diagnostic data are relevant in this context.
+
+### Diagnostic level
+
+This setting determines the amount of Windows diagnostic data sent to Microsoft.
+
+>[!NOTE]
+>In Windows 10, version 1709, Microsoft introduced a new feature: “Limit Enhanced diagnostic data to the minimum required by Windows Analytics”. When enabled, this feature limits the operating system diagnostic data events included in the Enhanced level to the smallest set of data required by [Windows Analytics](https://www.microsoft.com/windowsforbusiness/windows-analytics). For more information on the Enhanced level, see [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md).
+
+#### Group Policy
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | Computer Configuration\Administrative Templates\Windows Components\Data Collection and Preview Builds |
+>| **Policy Name** | Allow Telemetry |
+>| **Default setting** | 2 - Enhanced |
+>| **Recommended** | 2 - Enhanced |
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | User Configuration\Administrative Templates\Windows Components\Data Collection and Preview Builds |
+>| **Policy Name** | Allow Telemetry |
+>| **Default setting** | 2 - Enhanced |
+>| **Recommended** | 2 - Enhanced |
+
+#### Registry
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKLM\Software\Policies\Microsoft\Windows\DataCollection |
+>| **Value** | AllowTelemetry |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000002" |
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKCU\Software\Policies\Microsoft\Windows\DataCollection |
+>| **Value** | AllowTelemetry |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000002" |
+
+#### MDM
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **MDM CSP** | System |
+>| **Policy** | AllowTelemetry (scope: device and user) |
+>| **Default setting** | 2 – Enhanced |
+>| **Recommended** | 2 – Allowed |
+
+### Diagnostic opt-in change notifications
+
+This setting determines whether a device shows notifications about Windows diagnostic data levels to people on first logon or when changes occur in the diagnostic configuration.
+
+#### Group Policy
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | Computer Configuration\Administrative Templates\Windows Components\Data Collection and Preview Builds |
+>| **Policy Name** | Configure telemetry opt-in change notifications |
+>| **Default setting** | Enabled |
+>| **Recommended** | Enabled |
+
+#### Registry
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKLM\Software\Policies\Microsoft\Windows\DataCollection |
+>| **Value** | DisableTelemetryOptInChangeNotification |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000001" |
+
+#### MDM
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **MDM CSP** | System |
+>| **Policy** | ConfigureTelemetryOptInChangeNotification |
+>| **Default setting** | 0 – Enabled |
+>| **Recommended** | 0 – Enabled |
+
+### Configure telemetry opt-in setting user interface
+
+This setting determines whether people can change their own Windows diagnostic data level in in *Start > Settings > Privacy > Diagnostics & feedback*.
+
+#### Group Policy
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | Computer Configuration\Administrative Templates\Windows Components\Data Collection and Preview Builds |
+>| **Policy Name** | Configure telemetry opt-in setting user interface |
+>| **Default setting** | Enabled |
+>| **Recommended** | Enabled |
+
+#### Registry
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKLM\Software\Policies\Microsoft\Windows\DataCollection |
+>| **Value** | DisableTelemetryOptInSettingsUx |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000001" |
+
+#### MDM
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **MDM CSP** | System |
+>| **Policy** | ConfigureTelemetryOptInSettingsUx |
+>| **Default setting** | 0 – Enabled |
+>| **Recommended** | 0 – Enabled |
+
+## Policies affecting personal data protection managed by the Enterprise IT
+
+There are additional settings usually managed by the Enterprise IT that also affect the protection of personal data.
+
+The following options for configuring these policies are relevant in this context.
+
+### BitLocker
+
+The following settings determine whether fixed and removable drives are protected by the BitLocker Drive Encryption.
+
+#### Fixed Data Drives
+
+#### Group Policy
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | Computer Configuration\Administrative Templates\Windows Components\Bitlocker Drive Encryption\Fixed Data Drives |
+>| **Policy Name** | Deny write access to fixed drives not protected by BitLocker |
+>| **Default setting** | Not configured |
+>| **Recommended** | Enabled |
+
+#### Registry
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKLM\System\CurrentControlSet\Policies\Microsoft\FVE |
+>| **Value** | FDVDenyWriteAccess |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000001" |
+
+#### MDM
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **MDM CSP** | BitLocker |
+>| **Policy** | RemovableDrivesRequireEncryption |
+>| **Default setting** | Disabled |
+>| **Recommended** | Enabled (see [instructions](/windows/client-management/mdm/bitlocker-csp#fixeddrivesrequireencryption)) |
+
+#### Removable Data Drives
+
+#### Group Policy
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | Computer Configuration\Administrative Templates\Windows Components\Bitlocker Drive Encryption\Removable Data Drives |
+>| **Policy Name** | Deny write access to removable drives not protected by BitLocker |
+>| **Default setting** | Not configured |
+>| **Recommended** | Enabled |
+
+#### Registry
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKLM\System\CurrentControlSet\Policies\Microsoft\FVE |
+>| **Value** | RDVDenyWriteAccess |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000001" |
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKLM\Software\Policies\Microsoft\FVE |
+>| **Value** | RDVDenyCrossOrg |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000000" |
+
+#### MDM
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **MDM CSP** | BitLocker |
+>| **Policy** | RemovableDrivesRequireEncryption |
+>| **Default setting** | Disabled |
+>| **Recommended** | Enabled (see [instructions](/windows/client-management/mdm/bitlocker-csp#removabledrivesrequireencryption)) |
+
+### Privacy – AdvertisingID
+
+This setting determines if the advertising ID, which preventing apps from using the ID for experiences across apps, is turned off.
+
+#### Group Policy
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | Computer Configuration\Administrative Templates\System\User Profiles |
+>| **Policy Name** | Turn off the advertising ID |
+>| **Default setting** | Not configured |
+>| **Recommended** | Enabled |
+
+#### Registry
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKLM\Software\Policies\Microsoft\Windows\AdvertisingInfo |
+>| **Value** | DisabledByGroupPolicy |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000001" |
+
+#### MDM
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **MDM CSP** | Privacy |
+>| **Policy** | DisableAdvertisingId |
+>| **Default setting** | 65535 (default) - Not configured |
+>| **Recommended** | 1 – Enabled |
+
+### Edge
+
+These settings whether employees send “Do Not Track” from the Microsoft Edge web browser to websites.
+
+>[!NOTE]
+>Please see [this Microsoft blog post](https://blogs.microsoft.com/on-the-issues/2015/04/03/an-update-on-microsofts-approach-to-do-not-track/) for more details on why the “Do Not Track” is no longer the default setting.
+
+#### Group Policy
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | Computer Configuration\Administrative Templates\Windows Components\Microsoft Edge |
+>| **Policy Name** | Configure Do Not Track |
+>| **Default setting** | Disabled |
+>| **Recommended** | Disabled |
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | User Configuration\Administrative Templates\Windows Components\Microsoft Edge |
+>| **Policy Name** | Configure Do Not Track |
+>| **Default setting** | Disabled |
+>| **Recommended** | Disabled |
+
+#### Registry
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKLM\Software\Policies\Microsoft\MicrosoftEdge\Main |
+>| **Value** | DoNotTrack |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000000" |
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Registry key** | HKCU\Software\Policies\Microsoft\MicrosoftEdge\Main |
+>| **Value** | DoNotTrack |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000000" |
+
+#### MDM
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **MDM CSP** | Browser |
+>| **Policy** | AllowDoNotTrack (scope: device + user) |
+>| **Default setting** | 0 (default) – Not allowed |
+>| **Recommended** | 0 – Not allowed |
+
+### Internet Explorer
+
+These settings whether employees send “Do Not Track” header from the Microsoft Explorer web browser to websites.
+
+#### Group Policy
+
+> [!div class="mx-tableFixed"]
+>| | |
+>|:-|:-|
+>| **Group Policy** | Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page |
+>| **Policy Name** | Always send Do Not Track header |
+>| **Default setting** | Disabled |
+>| **Recommended** | Disabled |
+
+> [!div class="mx-tableFixed"]
+>|||
+>|:-|:-|
+>| **Group Policy** | User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page |
+>| **Policy Name** | Always send Do Not Track header |
+>| **Default setting** | Disabled |
+>| **Recommended** | Disabled |
+
+#### Registry
+
+> [!div class="mx-tableFixed"]
+>|||
+>|:-|:-|
+>| **Registry key** | HKLM\Software\Policies\Microsoft\Internet Explorer\Main |
+>| **Value** | DoNotTrack |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000000" |
+
+> [!div class="mx-tableFixed"]
+>|||
+>|:-|:-|
+>| **Registry key** | HKCU\Software\Policies\Microsoft\Internet Explorer\Main |
+>| **Value** | DoNotTrack |
+>| **Type** | REG_DWORD |
+>| **Setting** | "00000000" |
+
+#### MDM
+
+> [!div class="mx-tableFixed"]
+>|||
+>|:-|:-|
+>| **MDM CSP** | N/A |
+
+## Additional resources
+
+### FAQs
+
+* [Windows 10 feedback, diagnostics, and privacy](https://privacy.microsoft.com/windows-10-feedback-diagnostics-and-privacy)
+* [Microsoft Edge and privacy](https://privacy.microsoft.com/windows-10-microsoft-edge-and-privacy)
+* [Windows Hello and privacy](https://privacy.microsoft.com/windows-10-windows-hello-and-privacy)
+* [Wi-Fi Sense](https://privacy.microsoft.com/windows-10-about-wifi-sense)
+
+### Blogs
+
+* [Privacy and Windows 10](https://blogs.windows.com/windowsexperience/2015/09/28/privacy-and-windows-10)
+
+### Privacy Statement
+
+* [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement)
+
+### Windows Privacy on docs.microsoft.com
+
+* [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md)
+* [Manage Windows 10 connection endpoints](manage-windows-endpoints.md)
+* [Understanding Windows diagnostic data](configure-windows-diagnostic-data-in-your-organization.md#understanding-windows-diagnostic-data)
+* [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md)
+
+### Other resources
+
+* [Privacy at Microsoft](http://privacy.microsoft.com/)
diff --git a/windows/security/hardware-protection/tpm/tpm-recommendations.md b/windows/security/hardware-protection/tpm/tpm-recommendations.md
index a9f0a616d2..5b220439f0 100644
--- a/windows/security/hardware-protection/tpm/tpm-recommendations.md
+++ b/windows/security/hardware-protection/tpm/tpm-recommendations.md
@@ -8,7 +8,7 @@ ms.sitesec: library
ms.pagetype: security
ms.localizationpriority: high
author: brianlic-msft
-ms.date: 10/27/2017
+ms.date: 05/16/2018
---
# TPM recommendations
@@ -102,7 +102,9 @@ The following table defines which Windows features require TPM support.
| Measured Boot | Yes | Yes | Yes | Measured Boot requires TPM 1.2 or 2.0 and UEFI Secure Boot |
| BitLocker | Yes | Yes | Yes | TPM 1.2 or 2.0 is required |
| Device Encryption | Yes | N/A | Yes | Device Encryption requires Modern Standby/Connected Standby certification, which requires TPM 2.0. |
-| Device Guard | No | Yes | Yes | |
+| Windows Defender Application Control (Device Guard) | No | Yes | Yes | |
+| Windows Defender Exploit Guard | Yes | Yes | Yes | |
+| Windows Defender System Guard | Yes | Yes | Yes | |
| Credential Guard | No | Yes | Yes | Windows 10, version 1507 (End of Life as of May 2017) only supported TPM 2.0 for Credential Guard. Beginning with Windows 10, version 1511, TPM 1.2 and 2.0 are supported. |
| Device Health Attestation| Yes | Yes | Yes | |
| Windows Hello/Windows Hello for Business| No | Yes | Yes | Azure AD join supports both versions of TPM, but requires TPM with keyed-hash message authentication code (HMAC) and Endorsement Key (EK) certificate for key attestation support. |
diff --git a/windows/security/identity-protection/credential-guard/credential-guard-manage.md b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
index f54174f44c..a61d552b0f 100644
--- a/windows/security/identity-protection/credential-guard/credential-guard-manage.md
+++ b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
@@ -7,7 +7,7 @@ ms.sitesec: library
ms.pagetype: security
ms.localizationpriority: high
author: brianlic-msft
-ms.date: 01/12/2018
+ms.date: 05/18/2018
---
# Manage Windows Defender Credential Guard
@@ -140,7 +140,7 @@ For client machines that are running Windows 10 1703, LsaIso.exe is running when
## Disable Windows Defender Credential Guard
-If you have to disable Windows Defender Credential Guard on a PC, you can use the following set of procedures, or you can [use the Windows Defender Device Guard and Windows Defender Credential Guard hardware readiness tool](#turn-off-with-hardware-readiness-tool).
+To disable Windows Defender Credential Guard, you can use the following set of procedures or [the Device Guard and Credential Guard hardware readiness tool](#turn-off-with-hardware-readiness-tool). If Credential Guard was enabled with UEFI Lock then you must use the following procedure as the settings are persisted in EFI (firmware) variables and it will require physical presence at the machine to press a function key to accept the change. If Credential Guard was enabled without UEFI Lock then you can turn it off by using Group Policy.
1. If you used Group Policy, disable the Group Policy setting that you used to enable Windows Defender Credential Guard (**Computer Configuration** -> **Administrative Templates** -> **System** -> **Device Guard** -> **Turn on Virtualization Based Security**).
2. Delete the following registry settings:
diff --git a/windows/security/identity-protection/hello-for-business/hello-cert-trust-deploy-mfa.md b/windows/security/identity-protection/hello-for-business/hello-cert-trust-deploy-mfa.md
index 99a39e91b2..2cadf0703a 100644
--- a/windows/security/identity-protection/hello-for-business/hello-cert-trust-deploy-mfa.md
+++ b/windows/security/identity-protection/hello-for-business/hello-cert-trust-deploy-mfa.md
@@ -25,7 +25,7 @@ On-premises deployments must use the On-premises Azure MFA Server using the AD F
## Prerequisites
-The Azure MFA Server and User Portal servers have several perquisites and must have connectivity to the Internet.
+The Azure MFA Server and User Portal servers have several prerequisites and must have connectivity to the Internet.
### Primary MFA Server
@@ -540,4 +540,4 @@ The Multi-Factor Authentication server communicates with the Azure MFA cloud ser
2. [Validate and Configure Public Key Infrastructure](hello-cert-trust-validate-pki.md)
3. [Prepare and Deploy Windows Server 2016 Active Directory Federation Services](hello-cert-trust-adfs.md)
4. [Validate and Deploy Multifactor Authentication Services (MFA)](hello-cert-trust-validate-deploy-mfa.md)
-5. [Configure Windows Hello for Business Policy settings](hello-cert-trust-policy-settings.md)
\ No newline at end of file
+5. [Configure Windows Hello for Business Policy settings](hello-cert-trust-policy-settings.md)
diff --git a/windows/security/identity-protection/vpn/images/custom-vpn-profile.png b/windows/security/identity-protection/vpn/images/custom-vpn-profile.png
new file mode 100644
index 0000000000..b229c96b68
Binary files /dev/null and b/windows/security/identity-protection/vpn/images/custom-vpn-profile.png differ
diff --git a/windows/security/identity-protection/vpn/vpn-profile-options.md b/windows/security/identity-protection/vpn/vpn-profile-options.md
index 4f1b8870a5..eb0e6d5afc 100644
--- a/windows/security/identity-protection/vpn/vpn-profile-options.md
+++ b/windows/security/identity-protection/vpn/vpn-profile-options.md
@@ -6,9 +6,10 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: security, networking
-author: jdeckerms
+author: shortpatti
+ms.author: pashort
ms.localizationpriority: high
-ms.date: 07/27/2017
+ms.date: 05/17/2018
---
# VPN profile options
@@ -37,10 +38,10 @@ The following table lists the VPN settings and whether the setting can be config
| Name resolution: persistent | no |
| Auto-trigger: app trigger | yes |
| Auto-trigger: name trigger | yes |
-| Auto-trigger: Always On | no |
+| Auto-trigger: Always On | yes |
| Auto-trigger: trusted network detection | no |
| LockDown | no |
-| Windows Information Protection (WIP) | no |
+| Windows Information Protection (WIP) | yes |
| Traffic filters | yes |
The ProfileXML node was added to the VPNv2 CSP to allow users to deploy VPN profile as a single blob. This is particularly useful for deploying profiles with features that are not yet supported by MDMs. You can get additional examples in the [ProfileXML XSD](https://msdn.microsoft.com/library/windows/hardware/mt755930.aspx) topic.
@@ -296,9 +297,21 @@ The following is a sample plug-in VPN profile. This blob would fall under the Pr
After you configure the settings that you want using ProfileXML, you can apply it using Intune and a **Custom Configuration (Windows 10 Desktop and Mobile and later)** policy.
-The OMS-URI setting to apply ProfileXML is **./user/vendor/MSFT/*VPN profile name*/ProfileXML**.
+1. Sign into the [Azure portal](https://portal.azure.com).
+2. Go to **Intune** > **Device Configuration** > **Properties**.
+3. Click **Create Profile**.
+4. Enter a name and (optionally) a description.
+5. Choose **Windows 10 and later** as the platform.
+6. Choose **Custom** as the profile type and click **Add**.
+8. Enter a name and (optionally) a description.
+9. Enter the OMA-URI **./user/vendor/MSFT/_VPN profile name_/ProfileXML**.
+10. Set Data type to **String (XML file)**.
+11. Upload the profile XML file.
+12. Click **OK**.
+ 
+13. Click **OK**, then **Create**.
+14. Assign the profile.
-
## Learn more
diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md
index 3b5d442956..1b9179c6b3 100644
--- a/windows/security/threat-protection/windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md
+++ b/windows/security/threat-protection/windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md
@@ -11,7 +11,7 @@ ms.pagetype: security
ms.localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/17/2018
---
# Configure exclusions in Windows Defender AV on Windows Server
@@ -55,6 +55,9 @@ In Windows Server 2016 the predefined exclusions delivered by definition updates
> [!WARNING]
> Opting out of automatic exclusions may adversely impact performance, or result in data corruption. The exclusions that are delivered automatically are optimized for Windows Server 2016 roles.
+> [!NOTE]
+> This setting is only supported on Windows Server 2016. While this setting exists in Windows 10, it doesn't have an effect on exclusions.
+
You can disable the auto-exclusions lists with Group Policy, PowerShell cmdlets, and WMI.
**Use Group Policy to disable the auto-exclusions list on Windows Server 2016:**
@@ -89,9 +92,6 @@ See the following for more information and allowed parameters:
- [Windows Defender WMIv2 APIs](https://msdn.microsoft.com/en-us/library/dn439477(v=vs.85).aspx)
-
-
-
## List of automatic exclusions
The following sections contain the exclusions that are delivered with automatic exclusions file paths and file types.
diff --git a/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus.md
index 5b1594fd3c..c53a13b919 100644
--- a/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus.md
+++ b/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus.md
@@ -11,7 +11,7 @@ ms.pagetype: security
ms.localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/21/2018
---
# Deploy, manage, and report on Windows Defender Antivirus
@@ -47,7 +47,7 @@ PowerShell|Deploy with Group Policy, System Center Configuration Manager, or man
Group Policy and Active Directory (domain-joined)|Use a Group Policy Object to deploy configuration changes and ensure Windows Defender Antivirus is enabled.|Use Group Policy Objects (GPOs) to [Configure update options for Windows Defender Antivirus][] and [Configure Windows Defender features][]|Endpoint reporting is not available with Group Policy. You can generate a list of [Group Policies to determine if any settings or policies are not applied][]
Microsoft Azure|Deploy Microsoft Antimalware for Azure in the [Azure portal, by using Visual Studio virtual machine configuration, or using Azure PowerShell cmdlets](https://docs.microsoft.com/en-us/azure/security/azure-security-antimalware#antimalware-deployment-scenarios). You can also [Install Endpoint protection in Azure Security Center](https://docs.microsoft.com/en-us/azure/security-center/security-center-install-endpoint-protection)|Configure [Microsoft Antimalware for Virtual Machines and Cloud Services with Azure PowerShell cmdlets](https://docs.microsoft.com/en-us/powershell/servicemanagement/azure.antimalware/v3.4.0/azure.antimalware) or [use code samples](https://gallery.technet.microsoft.com/Antimalware-For-Azure-5ce70efe)|Use [Microsoft Antimalware for Virtual Machines and Cloud Services with Azure PowerShell cmdlets](https://docs.microsoft.com/en-us/powershell/servicemanagement/azure.antimalware/v3.4.0/azure.antimalware) to enable monitoring. You can also review usage reports in Azure Active Directory to determine suspicious activity, including the [Possibly infected devices][] report and configure an SIEM tool to report on [Windows Defender Antivirus events][] and add that tool as an app in AAD.
-1. The availability of some functions and features, especially related to cloud-delivered protection, differ between System Center Configuration Manager, current branch (for example, System Center Configuration Manager 2016) and System Center Configuration Manager 2012. In this library, we've focused on Windows 10, Windows Server 2016, and System Center Configuration Manager, current branch (2016). See the [Utilize Microsoft cloud-provided protection in Windows Defender Antivirus](utilize-microsoft-cloud-protection-windows-defender-antivirus.md) topic for a table that describes the major differences. [(Return to table)](#ref2)
+1. The availability of some functions and features, especially related to cloud-delivered protection, differ between System Center Configuration Manager (Current Branch) and System Center Configuration Manager 2012. In this library, we've focused on Windows 10, Windows Server 2016, and System Center Configuration Manager (Current Branch). See [Use Microsoft cloud-provided protection in Windows Defender Antivirus](utilize-microsoft-cloud-protection-windows-defender-antivirus.md) for a table that describes the major differences. [(Return to table)](#ref2)
2. In Windows 10, Windows Defender Antivirus is a component available without installation or deployment of an additional client or service. It will automatically be enabled when third-party antivirus products are either uninstalled or out of date ([except on Windows Server 2016](windows-defender-antivirus-on-windows-server-2016.md)). Traditional deployment therefore is not required. Deployment here refers to ensuring the Windows Defender Antivirus component is available and enabled on endpoints or servers. [(Return to table)](#ref2)
diff --git a/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md
index dc9a8ef5b0..fc5487d680 100644
--- a/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md
+++ b/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md
@@ -11,7 +11,7 @@ ms.pagetype: security
ms.localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/21/2018
---
# Use next-gen technologies in Windows Defender Antivirus through cloud-delivered protection
@@ -63,12 +63,11 @@ Organizations running Windows 10 E5, version 1803 can also take advantage of eme
The following table describes the differences in cloud-delivered protection between recent versions of Windows and System Center Configuration Manager.
-Feature | Windows 8.1 (Group Policy) | Windows 10, version 1607 (Group Policy) | Windows 10, version 1703 (Group Policy) | Configuration manager 2012 | Configuration manager (current branch) | Microsoft Intune
+Feature | Windows 8.1 (Group Policy) | Windows 10, version 1607 (Group Policy) | Windows 10, version 1703 (Group Policy) | System Center Configuration Manager 2012 | System Center Configuration Manager (Current Branch) | Microsoft Intune
---|---|---|---|---|---|---
Cloud-protection service label | Microsoft Advanced Protection Service | Microsoft Advanced Protection Service | Cloud-based Protection | NA | Cloud protection service | Microsoft Advanced Protection Service
Reporting level (MAPS membership level) | Basic, Advanced | Advanced | Advanced | Dependent on Windows version | Dependent on Windows version | Dependent on Windows version
-Block at first sight availability | No | Yes | Yes | Not configurable | Configurable | No
-Cloud block timeout period | No | No | Configurable | Not configurable | Configurable | No
+Cloud block timeout period | No | No | Configurable | Not configurable | Configurable | Configurable
You can also [configure Windows Defender AV to automatically receive new protection updates based on reports from our cloud service](manage-event-based-updates-windows-defender-antivirus.md#cloud-report-updates).
@@ -81,4 +80,4 @@ You can also [configure Windows Defender AV to automatically receive new protect
[Specify the cloud-delivered protection level](specify-cloud-protection-level-windows-defender-antivirus.md) | You can specify the level of protection offered by the cloud with Group Policy and System Center Configuration Manager. The protection level will affect the amount of information shared with the cloud and how aggressively new files are blocked.
[Configure and validate network connections for Windows Defender Antivirus](configure-network-connections-windows-defender-antivirus.md) | There are certain Microsoft URLs that your network and endpoints must be able to connect to for cloud-delivered protection to work effectively. This topic lists the URLs that should be allowed via firewall or network filtering rules, and instructions for confirming your network is properly enrolled in cloud-delivered protection.
[Configure the Block at First Sight feature](configure-block-at-first-sight-windows-defender-antivirus.md) | The Block at First Sight feature can block new malware within seconds, without having to wait hours for a traditional signature. You can enable and configure it with System Center Configuration Manager and Group Policy.
-[Configure the cloud block timeout period](configure-cloud-block-timeout-period-windows-defender-antivirus.md) | Windows Defender Antivirus can block suspicious files from running while it queries our cloud-delivered protection service. You can configure the amount of time the file will be prevented from running with System Center Configuration Manager and Group Policy.
\ No newline at end of file
+[Configure the cloud block timeout period](configure-cloud-block-timeout-period-windows-defender-antivirus.md) | Windows Defender Antivirus can block suspicious files from running while it queries our cloud-delivered protection service. You can configure the amount of time the file will be prevented from running with System Center Configuration Manager and Group Policy.
diff --git a/windows/security/threat-protection/windows-defender-application-control/TOC.md b/windows/security/threat-protection/windows-defender-application-control/TOC.md
index ecceb40ef9..4bf7c5ff89 100644
--- a/windows/security/threat-protection/windows-defender-application-control/TOC.md
+++ b/windows/security/threat-protection/windows-defender-application-control/TOC.md
@@ -11,14 +11,15 @@
## [Windows Defender Application Control deployment guide](windows-defender-application-control-deployment-guide.md)
### [Types of devices](types-of-devices.md)
-### [Use WDAC with a managed installer](use-windows-defender-application-control-with-managed-installer.md)
###Use WDAC with custom policies
#### [Create an initial default policy](create-initial-default-policy.md)
#### [Microsoft recommended block rules](microsoft-recommended-block-rules.md)
### [Audit WDAC policies](audit-windows-defender-application-control-policies.md)
### [Merge WDAC policies](merge-windows-defender-application-control-policies.md)
### [Enforce WDAC policies](enforce-windows-defender-application-control-policies.md)
-### [Deploy WDAC policies](deploy-windows-defender-application-control-policies-using-group-policy.md)
+### [Deploy WDAC with a managed installer](use-windows-defender-application-control-with-managed-installer.md)
+### [Deploy WDAC policies using Group Policy](deploy-windows-defender-application-control-policies-using-group-policy.md)
+### [Deploy WDAC policies using Intune](deploy-windows-defender-application-control-policies-using-intune.md)
### [Use code signing to simplify application control for classic Windows applications](use-code-signing-to-simplify-application-control-for-classic-windows-applications.md)
#### [Optional: Use the Device Guard Signing Portal in the Microsoft Store for Business](use-device-guard-signing-portal-in-microsoft-store-for-business.md)
#### [Optional: Create a code signing cert for WDAC](create-code-signing-cert-for-windows-defender-application-control.md)
diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
new file mode 100644
index 0000000000..8031bc1bbf
--- /dev/null
+++ b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
@@ -0,0 +1,33 @@
+---
+title: Deploy Windows Defender Application Control (WDAC) policies by using Microsoft Intune (Windows 10)
+description: Windows Defender Application Control restricts which applications users are allowed to run and the code that runs in the system core.
+ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb
+ms.prod: w10
+ms.mktglfcycl: deploy
+ms.sitesec: library
+ms.pagetype: security
+author: justinha
+ms.date: 05/17/2018
+---
+
+# Deploy Windows Defender Application Control policies by using Microsoft Intune
+
+**Applies to:**
+
+- Windows 10
+- Windows Server 2016
+
+You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can configure Windows 10 client computers to only run Windows components and Microsoft Store apps, or let them also run reputable apps defined by the Intelligent Security Graph.
+
+1. Open the Microsoft Intune portal and click **Device configuration** > **Profiles** > **Creae profile**.
+
+3. Type a name for the new profile, select **Windows 10 and later** as the **Platform** and **Endpoint protection** as the **Profile type**.
+
+ 
+
+4. Click **Configure** > **Windows Defender Application Control**. for the following settings and then click **OK**:
+
+ - **Application control code intergity policies**: Select **Audit only** to log events but not block any apps from running or select **Enforce** to allow only Windows components and Store apps to run.
+ - **Trust apps with good reputation**: Select **Enable** to allow reputable apps as defined by the Intelligent Security Graph to run in addition to Windows components and Store apps.
+
+ 
diff --git a/windows/security/threat-protection/windows-defender-application-control/images/wdac-intune-create-profile-name.png b/windows/security/threat-protection/windows-defender-application-control/images/wdac-intune-create-profile-name.png
new file mode 100644
index 0000000000..1b5483103b
Binary files /dev/null and b/windows/security/threat-protection/windows-defender-application-control/images/wdac-intune-create-profile-name.png differ
diff --git a/windows/security/threat-protection/windows-defender-application-control/images/wdac-intune-wdac-settings.png b/windows/security/threat-protection/windows-defender-application-control/images/wdac-intune-wdac-settings.png
new file mode 100644
index 0000000000..55f5173b03
Binary files /dev/null and b/windows/security/threat-protection/windows-defender-application-control/images/wdac-intune-wdac-settings.png differ
diff --git a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md
index 4f483a970d..4bbf440bbc 100644
--- a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md
+++ b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md
@@ -79,30 +79,30 @@ Microsoft recommends that you block the following Microsoft-signed applications
```
--
+ 10.0.0.0{A244370E-44C9-4C06-B551-F6016E563076}{2E07F7E4-194C-4D20-B7C9-6F44A6C5A234}
--
--
+
+
--
+
--
+
--
+
--
--
--
+
@@ -159,7 +159,7 @@ Microsoft recommends that you block the following Microsoft-signed applications
--
@@ -383,103 +383,103 @@ Microsoft recommends that you block the following Microsoft-signed applications
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
--
+
+
+
+
--
--
--
+
+
+
diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide.md
index aff1687457..c61f2f8a64 100644
--- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide.md
+++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide.md
@@ -6,7 +6,7 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.localizationpriority: high
author: jsuther1974
-ms.date: 05/03/2018
+ms.date: 05/16/2018
---
# Planning and getting started on the Windows Defender Application Control deployment process
@@ -60,5 +60,25 @@ This topic provides a roadmap for planning and getting started on the Windows De
8. Enable desired virtualization-based security (VBS) features. Hardware-based security features—also called virtualization-based security (VBS) features—strengthen the protections offered by Windows Defender Application Control.
- > [!WARNING]
- > Virtualization-based protection of code integrity may be incompatible with some devices and applications. We strongly recommend testing this configuration in your lab before enabling virtualization-based protection of code integrity on production systems. Failure to do so may result in unexpected failures up to and including data loss or a blue screen error (also called a stop error).
+## Known issues
+
+This section covers known issues with WDAC and Device Guard. Virtualization-based protection of code integrity may be incompatible with some devices and applications, which might cause unexpected failures, data loss, or a blue screen error (also called a stop error).
+Test this configuration in your lab before enabling it in production.
+
+### MSI Installations are blocked by WDAC
+
+Installing .msi files directly from the internet to a computer protected by WDAC will fail.
+For example, this command will not work:
+
+```code
+msiexec –i https://download.microsoft.com/download/2/E/3/2E3A1E42-8F50-4396-9E7E-76209EA4F429/Windows10_Version_1511_ADMX.msi
+```
+
+As a workaround, download the MSI file and run it locally:
+
+
+```code
+msiexec –i c:\temp\Windows10_Version_1511_ADMX.msi
+```
+
+
diff --git a/windows/security/threat-protection/windows-defender-application-guard/reqs-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/reqs-wd-app-guard.md
index 30f2490010..d02f615282 100644
--- a/windows/security/threat-protection/windows-defender-application-guard/reqs-wd-app-guard.md
+++ b/windows/security/threat-protection/windows-defender-application-guard/reqs-wd-app-guard.md
@@ -28,7 +28,7 @@ Your environment needs the following hardware to run Windows Defender Applicatio
|--------|-----------|
|64-bit CPU|A 64-bit computer with minimum 4 cores is required for hypervisor and virtualization-based security (VBS). For more info about Hyper-V, see [Hyper-V on Windows Server 2016](https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server) or [Introduction to Hyper-V on Windows 10](https://docs.microsoft.com/en-us/virtualization/hyper-v-on-windows/about/). For more info about hypervisor, see [Hypervisor Specifications](https://docs.microsoft.com/en-us/virtualization/hyper-v-on-windows/reference/tlfs).|
|CPU virtualization extensions|Extended page tables, also called _Second Level Address Translation (SLAT)_
**-AND-**
One of the following virtualization extensions for VBS:
VT-x (Intel)
**-OR-**
AMD-V|
-|Hardware memory|Microsoft recommends 8GB RAM for optimal performance|
+|Hardware memory|Microsoft requires a minimum of 8GB RAM|
|Hard disk|5 GB free space, solid state disk (SSD) recommended|
|Input/Output Memory Management Unit (IOMMU) support|Not required, but strongly recommended|
diff --git a/windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md
index d74d21d178..f12f23cc7e 100644
--- a/windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md
@@ -10,7 +10,7 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
-ms.date: 04/24/2018
+ms.date: 05/08/2018
---
# Configure advanced features in Windows Defender ATP
@@ -87,6 +87,11 @@ When you enable this feature, you'll be able to share Windows Defender ATP devic
>You'll need to enable the integration on both Intune and Windows Defender ATP to use this feature.
+## Preview features
+Learn about new features in the Windows Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience.
+
+You'll have access to upcoming features which you can provide feedback on to help improve the overall experience before features are generally available.
+
## Enable advanced features
1. In the navigation pane, select **Preferences setup** > **Advanced features**.
2. Select the advanced feature you want to configure and toggle the setting between **On** and **Off**.
diff --git a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md
index 77ffee9999..4510f2dbe7 100644
--- a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md
@@ -42,6 +42,7 @@ Use the following table to understand what the columns represent, its data type,
| AdditionalFields | string | Additional information about the event in JSON array format. |
| AlertId | string | Unique identifier for the alert. |
| ComputerName | string | Fully qualified domain name (FQDN) of the machine. |
+| RemoteComputerName | string | Name of the machine that performed a remote operation on the affected machine. Depending on the event being reported, this name could be a fully-qualified domain name (FQDN), a NetBIOS name, or a host name without domain information. |
| EventId | int | Unique identifier used by Event Tracing for Windows (ETW) for the event type. |
| EventTime | datetime | Date and time when the event was recorded. |
| EventType | string | Table where the record is stored. |
@@ -53,6 +54,7 @@ Use the following table to understand what the columns represent, its data type,
| InitiatingProcessAccountDomain | string | Domain of the account that ran the process responsible for the event. |
| InitiatingProcessAccountName | string | User name of the account that ran the process responsible for the event. |
| InitiatingProcessAccountSid | string | Security Identifier (SID) of the account that ran the process responsible for the event. |
+| InitiatingProcessLogonId | string | Identifier for a logon session of the process that initiated the event. This identifier is unique on the same machine only between restarts. |
| InitiatingProcessCommandLine | string | Command line used to run the process that initiated the event. |
| InitiatingProcessCreationTime | datetime | Date and time when the process that initiated the event was started. |
| InitiatingProcessFileName | string | Name of the process that initiated the event. |
diff --git a/windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md
index 6b4dfc59d6..b4c4800faf 100644
--- a/windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md
@@ -10,7 +10,7 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
-ms.date: 05/03/2018
+ms.date: 05/21/2018
---
# Use Automated investigations to investigate and remediate threats
@@ -65,15 +65,24 @@ While an investigation is running, any other alert generated from the machine wi
If an incriminated entity is seen in another machine, the Automated investigation will expand the investigation to include that machine and a generic machine playbook will start on that machine. If 10 or more machines are found during this expansion process from the same entity, then that expansion action will require an approval and will be seen in the **Pending actions** view.
### How threats are remediated
-Depending on how you set up the machine groups and their level of automation, the Automated investigation will either automatically remediate threats or require user approval (this is the default). For more information, see [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md).
+Depending on how you set up the machine groups and their level of automation, the Automated investigation will either require user approval (default) or automatically remediate threats.
+
+You can configure the following levels of automation:
+
+Automation level | Description
+:---|:---
+Semi - require approval for any remediation | This is the default automation level.
An approval is needed for any remediation action.
+Semi - require approval for non-temp folders remediation | An approval is required on files or executables that are not in temporary folders.
Files or executables in temporary folders, such as the user's download folder or the user's temp folder, will automatically be remediated if needed.
+Semi - require approval for non-temp folders remediation | An approval is required on files or executables that are in the operating system directories such as Windows folder and Program files folder.
Files or executables in all other folders will automatically be remediated if needed.
+Semi - require approval for core folders remediation | An approval is required on files or executables that are in the operating system directories such as Windows folder and Program files folder.
Files or executables in all other folders will automatically be remediated if needed.
+Full - remediate threats automatically | All remediation actions will be performed automatically.
+
+For more information on how to configure these automation levels, see [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md).
The default machine group is configured for semi-automatic remediation. This means that any malicious entity that needs to be remediated requires an approval and the investigation is added to the **Pending actions** section, this can be changed to fully automatic so that no user approval is needed.
When a pending action is approved, the entity is then remediated and this new state is reflected in the **Entities** tab of the investigation.
-### How an Automated investigation is completed
-When the Automated investigation completes its analysis, and all pending actions are resolved, an investigation is considered complete. It's important to understand that an investigation is only considered complete if there are no pending actions on it.
-
## Manage Automated investigations
By default, the Automated investigations list displays investigations initiated in the last week. You can also choose to select other time ranges from the drop-down menu or specify a custom range.
@@ -103,19 +112,15 @@ Status | Description
| No threats found | No malicious entities found during the investigation.
| Failed | A problem has interrupted the investigation, preventing it from completing. |
| Partially remediated | A problem prevented the remediation of some malicious entities. |
-| Action required | Remediation actions require review and approval. |
+| Pending | Remediation actions require review and approval. |
| Waiting for machine | Investigation paused. The investigation will resume as soon as the machine is available. |
| Queued | Investigation has been queued and will resume as soon as other remediation activities are completed. |
| Running | Investigation ongoing. Malicious entities found will be remediated. |
| Remediated | Malicious entities found were successfully remediated. |
-| Terminated by system | Investigation was stopped due to . |
-| Terminated by user | A user stopped the investigation before it could complete. |
-| Not applicable | Automated investigations do not apply to this alert type. |
+| Terminated by system | Investigation was stopped by the system. |
+| Terminated by user | A user stopped the investigation before it could complete.
| Partially investigated | Entities directly related to the alert have been investigated. However, a problem stopped the investigation of collateral entities. |
-| Automated investigation not applicable to alert type | Automated investigation does not apply to this alert type. |
-| Automated investigation does not support OS | Machine is running an OS that is not supported by Automated investigation. |
-| Automated investigation unavailable for preexisting alert | Automated investigation does not apply to alerts that were generated before it was deployed. |
-| Automated investigation unavailable for suppressed alert | Automated investigation does not apply to suppressed alerts. |
+
**Detection source**
diff --git a/windows/security/threat-protection/windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md
index 5c7c425311..10e5212a72 100644
--- a/windows/security/threat-protection/windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md
@@ -102,7 +102,7 @@ Take the following steps to enable conditional access:
### Step 1: Turn on the Microsoft Intune connection
-1. In the navigation pane, select **Settings** > **General** > **Advanced features** > **Microsoft Intune connection**.
+1. In the navigation pane, select **Settings** > **Advanced features** > **Microsoft Intune connection**.
2. Toggle the Microsoft Intune setting to **On**.
3. Click **Save preferences**.
diff --git a/windows/security/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md
index a6f16281b6..595710cac3 100644
--- a/windows/security/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md
@@ -30,26 +30,29 @@ ms.date: 05/01/2018
You can configure Windows Defender ATP to send email notifications to specified recipients for new alerts. This feature enables you to identify a group of individuals who will immediately be informed and can act on alerts based on their severity.
> [!NOTE]
-> Only users with full access can configure email notifications.
+> Only users with 'Manage security settings' permissions can configure email notifications. If you've chosen to use basic permissions management, users with Security Administrator or Global Administrator roles can configure email notifications.
-You can set the alert severity levels that trigger notifications. When you turn enable the email notifications feature, it’s set to high and medium alerts by default.
+You can set the alert severity levels that trigger notifications. You can also add or remove recipients of the email notification. New recipients get notified about alerts encountered after they are added. For more information about alerts, see [View and organize the Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md).
-You can also add or remove recipients of the email notification. New recipients get notified about alerts encountered after they are added. For more information about alerts, see [View and organize the Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md).
+If you're using role-based access control (RBAC), recipients will only receive notifications based on the machine groups that were configured in the notification rule.
+Users with the proper permission can only create, edit, or delete notifications that are limited to their machine group management scope.
+Only users assigned to the Global administrator role can manage notification rules that are configured for all machine groups.
The email notification includes basic information about the alert and a link to the portal where you can do further investigation.
+
## Set up email notifications for alerts
The email notifications feature is turned off by default. Turn it on to start receiving email notifications.
1. On the navigation pane, select **Settings** > **Alert notifications**.
2. Toggle the setting between **On** and **Off**.
-3. Select the alert severity level that you’d like your recipients to receive:
- - **High** – Select this level to send notifications for high-severity alerts.
- - **Medium** – Select this level to send notifications for medium-severity alerts.
+3. Select the alert severity level that youd like your recipients to receive:
+ - **High** Select this level to send notifications for high-severity alerts.
+ - **Medium** Select this level to send notifications for medium-severity alerts.
- **Low** - Select this level to send notifications for low-severity alerts.
- **Informational** - Select this level to send notification for alerts that might not be considered harmful but good to keep track of.
4. In **Email recipients to notify on new alerts**, type the email address then select the + sign.
-5. Click **Save preferences** when you’ve completed adding all the recipients.
+5. Click **Save preferences** when youve completed adding all the recipients.
Check that email recipients are able to receive the email notifications by selecting **Send test email**. All recipients in the list will receive the test email.
@@ -59,10 +62,9 @@ Here's an example email notification:
## Remove email recipients
-1. Select the trash bin icon beside the email address you’d like to remove.
+1. Select the trash bin icon beside the email address youd like to remove.
2. Click **Save preferences**.
-
## Troubleshoot email notifications for alerts
This section lists various issues that you may encounter when using email notifications for alerts.
diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md
index e3b7fb8022..a93c05a236 100644
--- a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md
@@ -36,7 +36,7 @@ ms.date: 04/24/2018
## Onboard machines using Group Policy
1. Open the GP configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
- a. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**.
+ a. In the navigation pane, select **Settings** > **Onboarding**.
b. Select Windows 10 as the operating system.
@@ -122,7 +122,7 @@ For security reasons, the package used to Offboard machines will expire 30 days
1. Get the offboarding package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
- a. In the navigation pane, select **Settings** > **Machine management** > **Offboarding**.
+ a. In the navigation pane, select **Settings** > **Offboarding**.
b. Select Windows 10 as the operating system.
diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md
index c7774a5663..8c10ca727e 100644
--- a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md
@@ -106,7 +106,7 @@ For more information on using Windows Defender ATP CSP see, [WindowsAdvancedThre
1. Open the Microsoft Intune configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
- a. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**.
+ a. In the navigation pane, select **Settings** > **Onboarding**.
b. Select Windows 10 as the operating system.
@@ -189,7 +189,7 @@ For security reasons, the package used to Offboard machines will expire 30 days
1. Get the offboarding package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
- a. In the navigation pane, select **Settings** > **Machine management** > **Offboarding**.
+ a. In the navigation pane, select **Settings** > **Offboarding**.
b. Select Windows 10 as the operating system.
diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md
index 450371174d..edb65b80d5 100644
--- a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md
@@ -34,7 +34,7 @@ You'll need to take the following steps to onboard non-Windows machines:
### Turn on third-party integration
-1. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**. Make sure the third-party solution is listed.
+1. In the navigation pane, select **Settings** > **Onboarding**. Make sure the third-party solution is listed.
2. Select Mac and Linux as the operating system.
@@ -59,7 +59,7 @@ To effectively offboard the machine from the service, you'll need to disable the
1. Follow the third-party documentation to opt-out on the third-party service side.
-2. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**.
+2. In the navigation pane, select **Settings** > **Onboarding**.
3. Turn off the third-party solution integration.
diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md
index ab8da7cafa..a65ad2ad0f 100644
--- a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md
@@ -49,7 +49,7 @@ You can use existing System Center Configuration Manager functionality to create
1. Open the SCCM configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
- a. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**.
+ a. In the navigation pane, select **Settings** > **Onboarding**.
b. Select Windows 10 as the operating system.
@@ -127,7 +127,7 @@ For security reasons, the package used to Offboard machines will expire 30 days
1. Get the offboarding package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
- a. In the navigation pane, select **Settings** > **Machine management** > **Offboarding**.
+ a. In the navigation pane, select **Settings** > **Offboarding**.
b. Select Windows 10 as the operating system.
diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md
index 4dbf933ec5..884edde275 100644
--- a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md
@@ -36,7 +36,7 @@ You can also manually onboard individual machines to Windows Defender ATP. You m
## Onboard machines
1. Open the GP configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
- a. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**.
+ a. In the navigation pane, select **Settings** > **Onboarding**.
b. Select Windows 10 as the operating system.
@@ -94,7 +94,7 @@ For security reasons, the package used to Offboard machines will expire 30 days
1. Get the offboarding package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
- a. In the navigation pane, select **Settings** > **Machine management** > **Offboarding**.
+ a. In the navigation pane, select **Settings** > **Offboarding**.
b. Select Windows 10 as the operating system.
diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md
index 3053183884..58d6bfd4b4 100644
--- a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md
@@ -40,7 +40,7 @@ You can onboard VDI machines using a single entry or multiple entries for each m
1. Open the VDI configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
- a. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**.
+ a. In the navigation pane, select **Settings** > **Onboarding**.
b. Select Windows 10 as the operating system.
diff --git a/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md
index e1c5a11e0c..bfc0e1cb53 100644
--- a/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md
@@ -9,7 +9,7 @@ ms.sitesec: library
ms.pagetype: security
author: mjcaparas
localizationpriority: high
-ms.date: 05/03/2018
+ms.date: 05/08/2018
---
# Onboard servers to the Windows Defender ATP service
@@ -71,8 +71,8 @@ Once completed, you should see onboarded servers in the portal within an hour.
- Each Windows server must be able to connect to the Internet using HTTPS. This connection can be direct, using a proxy, or through the [OMS Gateway](https://docs.microsoft.com/en-us/azure/log-analytics/log-analytics-oms-gateway).
- If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning (SSL inspection) is enabled, make sure that the following URLs are white-listed to permit communication with Windows Defender ATP service:
-| Agent Resource | Ports |
-|------------------------------------|-------------|
+Agent Resource | Ports
+:---|:---
| *.oms.opinsights.azure.com | 443 |
| *.blob.core.windows.net | 443 |
| *.azure-automation.net | 443 |
@@ -81,6 +81,10 @@ Once completed, you should see onboarded servers in the portal within an hour.
| winatp-gw-eus.microsoft.com | 443 |
| winatp-gw-neu.microsoft.com | 443 |
| winatp-gw-weu.microsoft.com | 443 |
+|winatp-gw-uks.microsoft.com | 443 |
+|winatp-gw-ukw.microsoft.com | 443 |
+| winatp-gw-aus.microsoft.com | 443|
+| winatp-gw-aue.microsoft.com |443 |
## Onboard Windows Server, version 1803
You’ll be able to onboard in the same method available for Windows 10 client machines. For more information, see [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). Support for Windows Server, version 1803 provides deeper insight into activities happening on the server, coverage for kernel and memory attack detection, and enables response actions on Windows Server endpoint as well.
@@ -111,7 +115,9 @@ You’ll be able to onboard in the same method available for Windows 10 client m
If the result is ‘The specified service does not exist as an installed service’, then you'll need to install Windows Defender AV. For more information, see [Windows Defender Antivirus in Windows 10](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10).
## Offboard servers
-You have two options to offboard servers from the service:
+You can offboard Windows Server, version 1803 in the same method available for Windows 10 client machines.
+
+For other server versions, you have two options to offboard servers from the service:
- Uninstall the MMA agent
- Remove the Windows Defender ATP workspace configuration
@@ -139,7 +145,7 @@ To offboard the server, you can use either of the following methods:
#### Run a PowerShell command to remove the configuration
1. Get your Workspace ID:
- a. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**.
+ a. In the navigation pane, select **Settings** > **Onboarding**.
b. Select **Windows server 2012, 2012R2 and 2016** as the operating system and get your Workspace ID:
diff --git a/windows/security/threat-protection/windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md
index be0b750935..6be4590640 100644
--- a/windows/security/threat-protection/windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md
@@ -139,6 +139,10 @@ Use the solution explorer to view alerts in Splunk.
5. Find the query you saved in the list and click **Run**. The results are displayed based on your query.
+>[!TIP]
+> To mininimize alert duplications, you can use the following query:
+>```source="rest://windows atp alerts" | spath | dedup _raw | table *```
+
## Related topics
- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md)
- [Configure ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md)
diff --git a/windows/security/threat-protection/windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md
index 2f1642def7..06921f27cf 100644
--- a/windows/security/threat-protection/windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md
@@ -28,7 +28,7 @@ ms.date: 04/24/2018
During the onboarding process, a wizard takes you through the general settings of Windows Defender ATP. After onboarding, you might want to update the data retention settings.
-1. In the navigation pane, select **Settings** > **General** > **Data rention**.
+1. In the navigation pane, select **Settings** > **Data rention**.
2. Select the data retention duration from the drop-down list.
diff --git a/windows/security/threat-protection/windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md
index babca11760..d9b646f4e0 100644
--- a/windows/security/threat-protection/windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md
@@ -29,7 +29,7 @@ ms.date: 04/24/2018
Before you can create custom threat intelligence (TI) using REST API, you'll need to set up the custom threat intelligence application through the Windows Defender ATP portal.
-1. In the navigation pane, select **Settings** > **APIs** > **Threat intel**.
+1. In the navigation pane, select **Settings** > **Threat intel**.

diff --git a/windows/security/threat-protection/windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md
index 472a8abc15..1feb834265 100644
--- a/windows/security/threat-protection/windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md
@@ -30,7 +30,7 @@ Set the baselines for calculating the score of Windows Defender security control
>[!NOTE]
>Changes might take up to a few hours to reflect on the dashboard.
-1. In the navigation pane, select **Settings** > **General** > **Secure Score**.
+1. In the navigation pane, select **Settings** > **Secure Score**.

diff --git a/windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md
index 183ecc286d..bb4aff5ce2 100644
--- a/windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md
@@ -29,7 +29,7 @@ ms.date: 04/24/2018
Enable security information and event management (SIEM) integration so you can pull alerts from the Windows Defender ATP portal using your SIEM solution or by connecting directly to the alerts REST API.
-1. In the navigation pane, select **Settings** > **APIs** > **SIEM**.
+1. In the navigation pane, select **Settings** > **SIEM**.

diff --git a/windows/security/threat-protection/windows-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md
index 221bfd7884..88190566eb 100644
--- a/windows/security/threat-protection/windows-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md
@@ -10,7 +10,7 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
-ms.date: 04/24/2018
+ms.date: 05/08/2018
---
# Create and manage machine groups in Windows Defender ATP
@@ -33,61 +33,61 @@ In Windows Defender ATP, you can create machine groups and use them to:
- Configure different auto-remediation settings for different sets of machines
As part of the process of creating a machine group, you'll:
-- Set the automated remediation level for that group
-- Define a matching rule based on the machine name, domain, tags, and OS platform to determine which machines belong to the group. If a machine is also matched to other groups, it is added only to the highest ranked machine group.
-- Determine access to machine group
-- Rank the machine group relative to other groups after it is created
+- Set the automated remediation level for that group. For more information on remediation levels, see [Use Automated investigation to investigate and remediate threats](automated-investigations-windows-defender-advanced-threat-protection.md).
+- Specify the matching rule that determines which machine group belongs to the group based on the machine name, domain, tags, and OS platform. If a machine is also matched to other groups, it is added only to the highest ranked machine group.
+- Select the Azure AD user group that should have access to the machine group.
+- Rank the machine group relative to other groups after it is created.
>[!NOTE]
->All machine groups are accessible to all users if you don’t assign any Azure AD groups to them.
+>A machine group is accessible to all users if you don’t assign any Azure AD groups to it.
## Add a machine group
-1. In the navigation pane, select **Settings > Permissions > Machine groups**.
+1. In the navigation pane, select **Settings** > **Machine groups**.
2. Click **Add machine group**.
-3. Set the machine group details, configure an association rule, preview the results, then assign the group to an Azure user group:
+3. Enter the group name and automation settings and specify the matching rule that determines which machines belong to the group.
- - **Name**
-
- - **Remediation level for automated investigations**
- - **No remediation**
- - **Require approval (all folders)**
- - **Require approval (non-temp folders)**
- - **Require approval (core folders)**
- - **Fully automated**
+ - **Machine group name**
+ - **Automation level**
+ - **Semi - require approval for any remediation**
+ - **Semi - require approval for non-temp folders remediation**
+ - **Semi - require approval for core folders remediation**
+ - **Full - remediate threats automatically**
+
+ >[!NOTE]
+ > For more information on automation levels, see [Understand the Automated investigation flow](automated-investigations-windows-defender-advanced-threat-protection.md#understand-the-automated-investigation-flow).
- **Description**
+ - **Members**
- - **Matching rule** – you can apply the rule based on machine name, domain, tag, or OS version.
+ >[!TIP]
+ >If you want to group machines by organizational unit, you can configure the registry key for the group affiliation. For more information on device tagging, see [Manage machine group and tags](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection#manage-machine-group-and-tags).
- >[!TIP]
- >If you want to group machines by organizational unit, you can configure the registry key for the group affiliation. For more information on device tagging, see [Manage machine group and tags](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection#manage-machine-group-and-tags).
-
-4. Review the result of the preview of matched machines. If you are satisfied with the rules, click the **Access** tab.
+4. Preview several machines that will be matched by this rule. If you are satisfied with the rule, click the **Access** tab.
5. Assign the user groups that can access the machine group you created.
>[!NOTE]
>You can only grant access to Azure AD user groups that have been assigned to RBAC roles.
-6. Click **Close**.
+6. Click **Close**. The configuration changes are applied.
-7. Apply the configuration settings.
-## Understand matching and manage groups
-You can promote the rank of a machine group so that it is given higher priority during matching. When a machine is matched to more than one group, it is added only to the highest ranked group. You can also edit and delete groups.
+## Manage machine groups
+You can promote or demote the rank of a machine group so that it is given higher or lower priority during matching. When a machine is matched to more than one group, it is added only to the highest ranked group. You can also edit and delete groups.
+
+>[!WARNING]
+>Deleting a machine group may affect email notification rules. If a machine group is configured under an email notification rule, it will be removed from that rule. If the machine group is the only group configured for an email notification, that email notification rule will be deleted along with the machine group.
By default, machine groups are accessible to all users with portal access. You can change the default behavior by assigning Azure AD user groups to the machine group.
Machines that are not matched to any groups are added to Ungrouped machines (default) group. You cannot change the rank of this group or delete it. However, you can change the remediation level of this group, and define the Azure AD user groups that can access this group.
>[!NOTE]
->Applying changes to machine group configuration may take up to several minutes.
-
-
+> - Applying changes to machine group configuration may take up to several minutes.
## Related topic
diff --git a/windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md
index 54bc053ce4..34058bc69a 100644
--- a/windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md
@@ -110,7 +110,7 @@ Create custom rules to control when alerts are suppressed, or resolved. You can
### View the list of suppression rules
-1. In the navigation pane, select **Settings** > **Rules** > **Alert suppression**.
+1. In the navigation pane, select **Settings** > **Alert suppression**.
2. The list of suppression rules shows all the rules that users in your organization have created.
diff --git a/windows/security/threat-protection/windows-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md
index abe6240f77..4b6a427b67 100644
--- a/windows/security/threat-protection/windows-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md
@@ -36,7 +36,7 @@ Entities added to the blocked list are considered malicious and will be remediat
You can define the conditions for when entities are identified as malicious or safe based on certain attributes such as hash values or certificates.
## Create an allowed or blocked list
-1. In the navigation pane, select **Settings** > **Rules** > **Automation allowed/blocked list**.
+1. In the navigation pane, select **Settings** > **Automation allowed/blocked list**.
2. Select the type of entity you'd like to create an exclusion for. You can choose any of the following entities:
- File hash
@@ -52,14 +52,14 @@ You can define the conditions for when entities are identified as malicious or s
5. Click **Update rule**.
## Edit a list
-1. In the navigation pane, select **Settings** > **Rules** > **Automation allowed/blocked list**.
+1. In the navigation pane, select **Settings** > **Automation allowed/blocked list**.
2. Select the type of entity you'd like to edit the list from.
3. Update the details of the rule and click **Update rule**.
## Delete a list
-1. In the navigation pane, select **Settings** > **Rules** > **Automation allowed/blocked list**.
+1. In the navigation pane, select **Settings** > **Automation allowed/blocked list**.
2. Select the type of entity you'd like to delete the list from.
diff --git a/windows/security/threat-protection/windows-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md
index a418fca559..0633161ea8 100644
--- a/windows/security/threat-protection/windows-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md
@@ -35,7 +35,7 @@ For example, if you add *exe* and *bat* as file or attachment extension names, t
## Add file extension names and attachment extension names.
-1. In the navigation pane, select **Settings** > **Rules** > **Automation file uploads**.
+1. In the navigation pane, select **Settings** > **Automation file uploads**.
2. Toggle the content analysis setting between **On** and **Off**.
diff --git a/windows/security/threat-protection/windows-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md
index 0388d3e0dd..d754d2cc87 100644
--- a/windows/security/threat-protection/windows-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md
@@ -47,7 +47,7 @@ You can specify the file names that you want to be excluded in a specific direct
## Add an automation folder exclusion
-1. In the navigation pane, select **Settings** > **Rules** > **Automation folder exclusions**.
+1. In the navigation pane, select **Settings** > **Automation folder exclusions**.
2. Click **New folder exclusion**.
@@ -62,14 +62,14 @@ You can specify the file names that you want to be excluded in a specific direct
4. Click **Save**.
## Edit an automation folder exclusion
-1. In the navigation pane, select **Settings** > **Rules** > **Automation folder exclusions**.
+1. In the navigation pane, select **Settings** > **Automation folder exclusions**.
2. Click **Edit** on the folder exclusion.
3. Update the details of the rule and click **Save**.
## Remove an automation folder exclusion
-1. In the navigation pane, select **Settings** > **Rules** > **Automation folder exclusions**.
+1. In the navigation pane, select **Settings** > **Automation folder exclusions**.
2. Click **Remove exclusion**.
diff --git a/windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md
index afd498bd1b..8662980b04 100644
--- a/windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md
@@ -32,7 +32,7 @@ There might be scenarios where you need to suppress alerts from appearing in the
You can view a list of all the suppression rules and manage them in one place. You can also turn an alert suppression rule on or off.
## Turn a suppression rule on or off
-1. In the navigation pane, select **Settings** > **Rules** > **Alert suppression**. The list of suppression rules that users in your organization have created is displayed.
+1. In the navigation pane, select **Settings** > **Alert suppression**. The list of suppression rules that users in your organization have created is displayed.
2. Select a rule by clicking on the check-box beside the rule name.
@@ -40,7 +40,7 @@ You can view a list of all the suppression rules and manage them in one place. Y
## View details of a suppression rule
-1. In the navigation pane, select **Settings** > **Rules** > **Alert suppression**. The list of suppression rules that users in your organization have created is displayed.
+1. In the navigation pane, select **Settings** > **Alert suppression**. The list of suppression rules that users in your organization have created is displayed.
2. Click on a rule name. Details of the rule is displayed. You'll see the rule details such as status, scope, action, number of matching alerts, created by, and date when the rule was created. You can also view associated alerts and the rule conditions.
diff --git a/windows/security/threat-protection/windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md
index ecb07ccd1e..136ce2f153 100644
--- a/windows/security/threat-protection/windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md
@@ -40,7 +40,7 @@ You can access these options from the Windows Defender ATP portal. Both the Powe
## Create a Windows Defender ATP dashboard on Power BI service
Windows Defender ATP makes it easy to create a Power BI dashboard by providing an option straight from the portal.
-1. In the navigation pane, select **Settings** > **General** > **Power BI reports**.
+1. In the navigation pane, select **Settings** > **Power BI reports**.
2. Click **Create dashboard**.
@@ -127,7 +127,7 @@ You can create a custom dashboard in Power BI Desktop to create visualizations t
### Before you begin
1. Make sure you use Power BI Desktop June 2017 and above. [Download the latest version](https://powerbi.microsoft.com/en-us/desktop/).
-2. In the navigation pane, select **Settings** > **General** > **Power BI reports**.
+2. In the navigation pane, select **Settings** > **Power BI reports**.
3. Click **Download connector** to download the WDATPPowerBI.zip file and extract it.
diff --git a/windows/security/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md
index 61315574f8..1e36317ed3 100644
--- a/windows/security/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md
@@ -28,7 +28,7 @@ ms.date: 04/24/2018
Turn on the preview experience setting to be among the first to try upcoming features.
-1. In the navigation pane, select **Settings** > **Preview experience**.
+1. In the navigation pane, select **Settings** > **Advanced features**.

diff --git a/windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection.md
index 63395308fe..4b90b87fb8 100644
--- a/windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection.md
@@ -36,7 +36,7 @@ You'll have access to upcoming features which you can provide feedback on to hel
Turn on the preview experience setting to be among the first to try upcoming features.
-1. In the navigation pane, select **Settings** > **General** > **Advanced features** > **Preview features**.
+1. In the navigation pane, select **Settings** > **Advanced features** > **Preview features**.
2. Toggle the setting between **On** and **Off** and select **Save preferences**.
diff --git a/windows/security/threat-protection/windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md
index fdb452e1ad..4599627b02 100644
--- a/windows/security/threat-protection/windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md
+++ b/windows/security/threat-protection/windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md
@@ -10,7 +10,7 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
-ms.date: 04/24/2018
+ms.date: 05/08/2018
---
# Manage portal access using role-based access control
@@ -76,17 +76,18 @@ Someone with a Windows Defender ATP Global administrator role has unrestricted a
2. Click **Add role**.
-3. Enter the role name, description, and active permissions you’d like to assign to the role.
+3. Enter the role name, description, and permissions you’d like to assign to the role.
- **Role name**
- **Description**
- - **Active permissions**
+ - **Permissions**
- **View data** - Users can view information in the portal.
- **Investigate alerts** - Users can manage alerts, initiate automated investigations, collect investigation packages, manage machine tags, and export machine timeline.
- **Approve or take action** - Users can take response actions and approve or dismiss pending remediation actions.
- **Manage system settings** - Users can configure settings, SIEM and threat intel API settings, advanced settings, preview features, and automated file uploads.
+ - **Manage security settings** - Users can configure alert suppression settings, manage allowed/blocked lists for automation, manage folder exclusions for automation, onboard and offboard machines, and manage email notifications.
4. Click **Next** to assign the role to an Azure AD group.
@@ -102,13 +103,13 @@ Someone with a Windows Defender ATP Global administrator role has unrestricted a
2. Click **Edit**.
-3. Modify the details or the groups that the role is a part of.
+3. Modify the details or the groups that are assigned to the role.
4. Click **Save and close**.
## Delete roles
-1. Select the role row you'd like to delete.
+1. Select the role you'd like to delete.
2. Click the drop-down button and select **Delete role**.
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md
index 74a07d5588..00c9b0bbaa 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md
@@ -11,7 +11,7 @@ ms.pagetype: security
localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/17/2018
---
@@ -42,7 +42,7 @@ ms.date: 04/30/2018
- Configuration service providers for mobile device management
-Attack surface reduction helps prevent actions and apps that are typically used by exploit-seeking malware to infect machines.
+Available in Windows 10 Enterprise E5, Attack surface reduction helps prevent actions and apps that are typically used by exploit-seeking malware to infect machines.
It is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md).
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md
index 2659563ea5..7f34a4b5d1 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md
@@ -11,7 +11,7 @@ ms.pagetype: security
localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/17/2018
---
# Customize Attack surface reduction
@@ -35,7 +35,7 @@ ms.date: 04/30/2018
- Configuration service providers for mobile device management
-Attack surface reduction is a feature that is part of Windows Defender Exploit Guard. It helps prevent actions and apps that are typically used by exploit-seeking malware to infect machines.
+Available in Windows 10 Enterprise E5, Attack surface reduction is a feature that is part of Windows Defender Exploit Guard. It helps prevent actions and apps that are typically used by exploit-seeking malware to infect machines.
This topic describes how to customize Attack surface reduction by [excluding files and folders](#exclude-files-and-folders) or [adding custom text to the notification](#customize-the-notification) alert that appears on a user's computer.
@@ -48,12 +48,14 @@ You can exclude files and folders from being evaluated by most Attack surface re
This could potentially allow unsafe files to run and infect your devices.
>[!WARNING]
->Excluding files or folders can severly reduce the protection provided by Attack surface reduction rules. Files that would have been blocked by a rule will be allowed to run, and there will be no report or event recorded.
+>Excluding files or folders can severely reduce the protection provided by Attack surface reduction rules. Files that would have been blocked by a rule will be allowed to run, and there will be no report or event recorded.
>
>If you are encountering problems with rules detecting files that you believe should not be detected, you should [use audit mode first to test the rule](enable-attack-surface-reduction.md#enable-and-audit-attack-surface-reduction-rules).
You can specify individual files or folders (using folder paths or fully qualified resource names) but you cannot specify if the exclusions should only be applied to individual rules: the exclusions will apply to all rules that are enabled (or placed in audit mode) and that allow exclusions.
+Windows 10, version 1803 supports environment variables and wildcards. For information about using wildcards in Windows Defender Exploit Guard, see [Use wildcards in the file name and folder path or extension exclusion lists](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10).
+
Exclusions will only be applied to certain rules. Some rules will not honor the exclusion list. This means that even if you have added a file to the exclusion list, some rules will still evaluate and potentially block that file if the rule determines the file to be unsafe.
>[!IMPORTANT]
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md
index dd2413afa8..031a513662 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md
@@ -11,7 +11,7 @@ ms.pagetype: security
localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/17/2018
---
@@ -59,7 +59,8 @@ You can add additional folders to be protected, but you cannot remove the defaul
Adding other folders to Controlled folder access can be useful, for example, if you don't store files in the default Windows libraries or you've changed the location of the libraries away from the defaults.
-You can also enter network shares and mapped drives, but environment variables and wildcards are not supported.
+You can also enter network shares and mapped drives. Windows 10, version 1803 supports environment variables and wildcards. For information about using wildcards in Windows Defender Exploit Guard, see [Use wildcards in the file name and folder path or extension exclusion lists](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10).
+
You can use the Windows Defender Security Center app or Group Policy to add and remove additional protected folders.
@@ -86,8 +87,8 @@ You can use the Windows Defender Security Center app or Group Policy to add and
6. Double-click the **Configured protected folders** setting and set the option to **Enabled**. Click **Show** and enter each folder.
-> [!IMPORTANT]
-> Environment variables and wildcards are not supported.
+> [!NOTE]
+> Windows 10, version 1803 supports environment variables and wildcards. For information about using wildcards in Windows Defender Exploit Guard, see [Use wildcards in the file name and folder path or extension exclusion lists](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10).
### Use PowerShell to protect additional folders
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md
index b18cf59c06..0fb9cf5f6b 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md
@@ -11,7 +11,7 @@ ms.pagetype: security
localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/17/2018
---
@@ -36,7 +36,7 @@ ms.date: 04/30/2018
- Configuration service providers for mobile device management
-Attack surface reduction is a feature that is part of Windows Defender Exploit Guard. It helps prevent actions and apps that are typically used by exploit-seeking malware to infect machines.
+Available in Windows 10 Enterprise E5, Attack surface reduction is a feature that is part of Windows Defender Exploit Guard. It helps prevent actions and apps that are typically used by exploit-seeking malware to infect machines.
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md
index 307b9220b4..b2abb2149e 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md
@@ -11,7 +11,7 @@ ms.pagetype: security
localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/17/2018
---
@@ -36,7 +36,7 @@ ms.date: 04/30/2018
- Configuration service providers for mobile device management
-Network protection is a feature that is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md). It helps to prevent employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet.
+Available in Windows 10 Enterprise, Network protection is a feature that is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md). It helps to prevent employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet.
This topic describes how to enable Network protection with Group Policy, PowerShell cmdlets, and configuration service providers (CSPs) for mobile device management (MDM).
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md
index ed2eb10df7..d601c3b522 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md
@@ -37,7 +37,7 @@ ms.date: 04/30/2018
-Attack surface reduction is a feature that is part of Windows Defender Exploit Guard [that helps prevent actions and apps that are typically used by exploit-seeking malware to infect machines](attack-surface-reduction-exploit-guard.md).
+Available in Windows 10 Enterprise E5, Attack surface reduction is a feature that is part of Windows Defender Exploit Guard [that helps prevent actions and apps that are typically used by exploit-seeking malware to infect machines](attack-surface-reduction-exploit-guard.md).
This topic helps you evaluate Attack surface reduction. It explains how to demo the feature using a specialized tool, and how to enable audit mode so you can test the feature directly in your organization.
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md
index 4a55fd3e57..da2a8e6e8e 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md
@@ -11,7 +11,7 @@ ms.pagetype: security
localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/17/2018
---
# Evaluate Network protection
@@ -36,7 +36,7 @@ ms.date: 04/30/2018
-Network protection is a feature that is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md).
+Available in Windows 10 Enterprise, Network protection is a feature that is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md).
It helps to prevent employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet.
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md
index 3c95ea7702..7ba0dd60c9 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md
@@ -11,7 +11,7 @@ ms.pagetype: security
localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/21/2018
---
@@ -63,11 +63,9 @@ Exploit protection works best with [Windows Defender Advanced Threat Protection]
## Requirements
-Exploit protection requires Windows 10 Enterprise E3 and Windows Defender AV real-time protection.
-
Windows 10 version | Windows Defender Advanced Threat Protection
-|-
-Windows 10 version 1709 or later | For full reporting you need a license for [Windows Defender ATP](../windows-defender-atp/windows-defender-advanced-threat-protection.md)
+Windows 10 version 1709 or later | For full reporting, you need a license for [Windows Defender ATP](../windows-defender-atp/windows-defender-advanced-threat-protection.md)
## Review Exploit protection events in Windows Event Viewer
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md
index 896d6f07f7..c928c75ee1 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md
@@ -11,7 +11,7 @@ ms.pagetype: security
localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/17/2018
---
@@ -36,7 +36,7 @@ ms.date: 04/30/2018
- Configuration service providers for mobile device management
-Network protection helps reduce the attack surface of your devices from Internet-based events. It prevents employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet.
+Available in Windows 10 Enterprise, Network protection helps reduce the attack surface of your devices from Internet-based events. It prevents employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet.
It expands the scope of [Windows Defender SmartScreen](../windows-defender-smartscreen/windows-defender-smartscreen-overview.md) to block all outbound HTTP(s) traffic that attempts to connect to low-reputation sources (based on the domain or hostname).
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md
index 9080ea0988..02be571b69 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md
@@ -11,7 +11,7 @@ ms.pagetype: security
ms.localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 04/30/2018
+ms.date: 05/17/2018
---
# Troubleshoot Attack surface reduction rules
@@ -45,7 +45,7 @@ There are four steps to troubleshooting these problems:
Attack surface reduction (ASR) will only work on devices with the following conditions:
>[!div class="checklist"]
-> - Endpoints are running Windows 10 Enterprise edition, version 1709 (also known as the Fall Creators Update).
+> - Endpoints are running Windows 10 Enterprise E5, version 1709 (also known as the Fall Creators Update).
> - Endpoints are using Windows Defender Antivirus as the sole antivirus protection app. [Using any other antivirus app will cause Windows Defender AV to disable itself](../windows-defender-antivirus/windows-defender-antivirus-compatibility.md).
> - [Real-time protection](../windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md) is enabled.
> - Audit mode is not enabled. Use Group Policy to set the rule to **Disabled** (value: **0**) as described in the [Enable ASR topic](enable-attack-surface-reduction.md#use-group-policy-to-enable-or-audit-attack-surface-reduction-rules).
diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md
index 4bd048b729..2b7764fdb5 100644
--- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md
+++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md
@@ -11,7 +11,7 @@ ms.pagetype: security
ms.localizationpriority: medium
author: andreabichsel
ms.author: v-anbic
-ms.date: 12/12/2017
+ms.date: 05/17/2018
---
# Troubleshoot Network protection
diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md
index fe2284a767..180c949a49 100644
--- a/windows/whats-new/whats-new-windows-10-version-1803.md
+++ b/windows/whats-new/whats-new-windows-10-version-1803.md
@@ -6,7 +6,7 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: greg-lindsay
-ms.date: 04/30/2018
+ms.date: 05/10/2018
ms.localizationpriority: high
---
@@ -15,9 +15,11 @@ ms.localizationpriority: high
**Applies to**
- Windows 10, version 1803
-This article lists new and updated features and content that are of interest to IT Pros for Windows 10 version 1803, also known as the Windows 10 April 2018 Update. This update also contains all features and fixes included in previous cumulative updates to Windows 10, version 1709. Also see [What's New in Windows](https://docs.microsoft.com/en-us/windows-hardware/get-started/what-s-new-in-windows) hardware.
+This article lists new and updated features and content that are of interest to IT Pros for Windows 10 version 1803, also known as the Windows 10 April 2018 Update. This update also contains all features and fixes included in previous cumulative updates to Windows 10, version 1709.
-The following 3-minute video summarizes some of the new features that are available in this release.
+>If you are not an IT Pro, see the following topics for information about what's new in Windows 10, version 1803 in [hardware](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows), for [developers](https://docs.microsoft.com/windows/uwp/whats-new/windows-10-build-17134), and for [consumers](https://blogs.windows.com/windowsexperience/2018/04/30/whats-new-in-the-windows-10-april-2018-update).
+
+The following 3-minute video summarizes some of the new features that are available for IT Pros in this release.
@@ -42,7 +44,7 @@ Some additional information about Windows 10 in S mode:
- Microsoft-verified. All of your applications are verified by Microsoft for security and performance.
- Performance that lasts. Start-ups are quick, and S mode is built to keep them that way.
-- Choice and flexibility. Save your files to your favorite cloud, like OneDrive or DropBox, and access them from any device you choose. Browse the Microsoft Store for thousands of apps[]
+- Choice and flexibility. Save your files to your favorite cloud, like OneDrive or DropBox, and access them from any device you choose. Browse the Microsoft Store for thousands of apps.
- S mode, on a range of modern devices. Enjoy all the great Windows multi-tasking features, like snapping Windows, task view and virtual desktops on a range of S mode enabled devices.
If you want to switch out of S mode, you will be able to do so at no charge, regardless of edition. Once you switch out of S mode, you cannot switch back.
@@ -149,7 +151,7 @@ The OS uninstall period is a length of time that users are given when they can o
- Windows Hello is part of the account protection pillar in Windows Defender Security Center. Account Protection will encourage password users to set up Windows Hello Face, Fingerprint or PIN for faster sign in, and will notify Dynamic lock users if Dynamic lock has stopped working because their phone or device Bluetooth is off.
- You can set up Windows Hello from lock screen for MSA accounts. We’ve made it easier for Microsoft account users to set up Windows Hello on their devices for faster and more secure sign-in. Previously, you had to navigate deep into Settings to find Windows Hello. Now, you can set up Windows Hello Face, Fingerprint or PIN straight from your lock screen by clicking the Windows Hello tile under Sign-in options.
- New [public API](https://docs.microsoft.com/en-us/uwp/api/windows.security.authentication.web.core.webauthenticationcoremanager.findallaccountsasync#Windows_Security_Authentication_Web_Core_WebAuthenticationCoreManager_FindAllAccountsAsync_Windows_Security_Credentials_WebAccountProvider_) for secondary account SSO for a particular identity provider.
-- Is is easier to set up Dynamic lock, and WD SC actionable alerts have been added when Dynamic lock stops working (ex: phone Bluetooth is off).
+- It is easier to set up Dynamic lock, and WD SC actionable alerts have been added when Dynamic lock stops working (ex: phone Bluetooth is off).
For more information, see: [Windows Hello and FIDO2 Security Keys enable secure and easy authentication for shared devices](https://blogs.windows.com/business/2018/04/17/windows-hello-fido2-security-keys/#OdKBg3pwJQcEKCbJ.97)