diff --git a/windows/client-management/mdm/windowsadvancedthreatprotection-csp.md b/windows/client-management/mdm/windowsadvancedthreatprotection-csp.md
index c2440b73fd..fc74d86711 100644
--- a/windows/client-management/mdm/windowsadvancedthreatprotection-csp.md
+++ b/windows/client-management/mdm/windowsadvancedthreatprotection-csp.md
@@ -49,34 +49,34 @@ WindowsAdvancedThreatProtection
The following list describes the characteristics and parameters.
-**./Device/Vendor/MSFT/WindowsAdvancedThreatProtection**
+**./Device/Vendor/MSFT/WindowsAdvancedThreatProtection**
The root node for the Windows Defender Advanced Threat Protection configuration service provider.
Supported operation is Get.
-**Onboarding**
+**Onboarding**
Sets Windows Defender Advanced Threat Protection Onboarding blob and initiates onboarding to Windows Defender Advanced Threat Protection.
The data type is a string.
Supported operations are Get and Replace.
-**HealthState**
+**HealthState**
Node that represents the Windows Defender Advanced Threat Protection health state.
-**HealthState/LastConnected**
+**HealthState/LastConnected**
Contains the timestamp of the last successful connection.
Supported operation is Get.
-**HealthState/SenseIsRunning**
+**HealthState/SenseIsRunning**
Boolean value that identifies the Windows Defender Advanced Threat Protection Sense running state.
The default value is false.
Supported operation is Get.
-**HealthState/OnboardingState**
+**HealthState/OnboardingState**
Represents the onboarding state.
Supported operation is Get.
@@ -86,15 +86,15 @@ The following list shows the supported values:
- 0 (default) – Not onboarded
- 1 – Onboarded
-**HealthState/OrgId**
+**HealthState/OrgId**
String that represents the OrgID.
Supported operation is Get.
-**Configuration**
+**Configuration**
Represents Windows Defender Advanced Threat Protection configuration.
-**Configuration/SampleSharing**
+**Configuration/SampleSharing**
Returns or sets the Windows Defender Advanced Threat Protection Sample Sharing configuration parameter.
The following list shows the supported values:
@@ -104,7 +104,7 @@ The following list shows the supported values:
Supported operations are Get and Replace.
-**Configuration/TelemetryReportingFrequency**
+**Configuration/TelemetryReportingFrequency**
Added in Windows 10, version 1703. Returns or sets the Windows Defender Advanced Threat Protection diagnostic data reporting frequency.
The following list shows the supported values:
@@ -114,31 +114,31 @@ The following list shows the supported values:
Supported operations are Get and Replace.
-**Configuration/AadDeviceId**
+**Configuration/AadDeviceId**
Returns or sets the Intune's reported known AadDeviceId for the machine
Supported operations are Get and Replace.
-**Offboarding**
+**Offboarding**
Sets the Windows Defender Advanced Threat Protection Offboarding blob and initiates offboarding to Windows Defender Advanced Threat Protection.
The data type is a string.
Supported operations are Get and Replace.
-**DeviceTagging**
+**DeviceTagging**
Added in Windows 10, version 1709. Represents Windows Defender Advanced Threat Protection configuration for managing role based access and device tagging.
Supported operation is Get.
-**DeviceTagging/Group**
+**DeviceTagging/Group**
Added in Windows 10, version 1709. Device group identifiers.
The data type is a string.
Supported operations are Get and Replace.
-**DeviceTagging/Criticality**
+**DeviceTagging/Criticality**
Added in Windows 10, version 1709. Asset criticality value. Supported values:
- 0 - Normal