edits
@ -1,4 +1,5 @@
|
||||
{:allowed-branchname-matches ["main" "release-.*"]
|
||||
{:changed-files-limit 60
|
||||
:allowed-branchname-matches ["main" "release-.*"]
|
||||
:allowed-filename-matches ["windows/"]
|
||||
|
||||
:targets
|
||||
|
@ -239,5 +239,19 @@
|
||||
"need_generate_pdf_url_template": true,
|
||||
"contribution_branch_mappings": {},
|
||||
"need_generate_pdf": false,
|
||||
"need_generate_intellisense": false
|
||||
"need_generate_intellisense": false,
|
||||
"redirection_files": [
|
||||
".openpublishing.redirection.browsers.json",
|
||||
".openpublishing.redirection.education.json",
|
||||
".openpublishing.redirection.json",
|
||||
".openpublishing.redirection.store-for-business.json",
|
||||
".openpublishing.redirection.windows-application-management.json",
|
||||
".openpublishing.redirection.windows-client-management.json",
|
||||
".openpublishing.redirection.windows-configuration.json",
|
||||
".openpublishing.redirection.windows-deployment.json",
|
||||
".openpublishing.redirection.windows-hub.json",
|
||||
".openpublishing.redirection.windows-privacy.json",
|
||||
".openpublishing.redirection.windows-security.json",
|
||||
".openpublishing.redirection.windows-whats-new.json"
|
||||
]
|
||||
}
|
174
.openpublishing.redirection.browsers.json
Normal file
@ -0,0 +1,174 @@
|
||||
{
|
||||
"redirections": [
|
||||
{
|
||||
"source_path": "browsers/edge/about-microsoft-edge.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/about-microsoft-edge",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/available-policies.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/available-policies",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/change-history-for-microsoft-edge.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/change-history-for-microsoft-edge",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/edge-technical-demos.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/edge-technical-demos",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/emie-to-improve-compatibility.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/emie-to-improve-compatibility",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/enterprise-guidance-using-microsoft-edge-and-ie11.md",
|
||||
"redirect_url": "/microsoft-edge/deploy/emie-to-improve-compatibility",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/address-bar-settings-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/address-bar-settings-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/adobe-settings-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/adobe-settings-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/books-library-management-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/books-library-management-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/browser-settings-management-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/browser-settings-management-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/developer-settings-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/developer-settings-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/extensions-management-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/extensions-management-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/favorites-management-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/favorites-management-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/home-button-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/home-button-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/interoperability-enterprise-guidance-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/interoperability-enterprise-guidance-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/new-tab-page-settings-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/new-tab-page-settings-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/prelaunch-preload-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/prelaunch-preload-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/search-engine-customization-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/search-engine-customization-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/security-privacy-management-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/security-privacy-management-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/start-pages-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/start-pages-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/sync-browser-settings-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/sync-browser-settings-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/group-policies/telemetry-management-gp.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/group-policies/telemetry-management-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/hardware-and-software-requirements.md",
|
||||
"redirect_url": "/microsoft-edge/deploy/about-microsoft-edge",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/img-microsoft-edge-infographic-lg.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/img-microsoft-edge-infographic-lg",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/managing-group-policy-admx-files.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/managing-group-policy-admx-files",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/microsoft-edge-forrester.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/microsoft-edge-forrester",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/microsoft-edge-kiosk-mode-deploy.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/microsoft-edge-kiosk-mode-deploy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/new-policies.md",
|
||||
"redirect_url": "/microsoft-edge/deploy/change-history-for-microsoft-edge",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/security-enhancements-microsoft-edge.md",
|
||||
"redirect_url": "/microsoft-edge/deploy/group-policies/security-privacy-management-gp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/troubleshooting-microsoft-edge.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/troubleshooting-microsoft-edge",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/use-powershell-to manage-group-policy.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/use-powershell-to manage-group-policy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/edge/web-app-compat-toolkit.md",
|
||||
"redirect_url": "/previous-versions/windows/edge-legacy/web-app-compat-toolkit",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/internet-explorer/ie11-deploy-guide/group-policy-compatability-with-ie11.md",
|
||||
"redirect_url": "/internet-explorer/ie11-deploy-guide/group-policy-compatibility-with-ie11",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "browsers/internet-explorer/kb-support/clear-ie-cache-from-command-line.md",
|
||||
"redirect_url": "/internet-explorer/kb-support/ie-edge-faqs",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
164
.openpublishing.redirection.education.json
Normal file
@ -0,0 +1,164 @@
|
||||
{
|
||||
"redirections": [
|
||||
{
|
||||
"source_path": "education/developers.yml",
|
||||
"redirect_url": "/education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/change-history-ms-edu-get-started.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/configure-microsoft-store-for-education.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy/microsoft-store-for-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/enable-microsoft-teams.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy/set-up-teams-for-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/finish-setup-and-other-tasks.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/get-started-with-microsoft-education.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/inclusive-classroom-it-admin.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy/inclusive-classroom-it-admin",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/index.md",
|
||||
"redirect_url": "/education/get-started/get-started-with-microsoft-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/set-up-office365-edu-tenant.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy/create-your-office-365-tenant",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/set-up-windows-10-education-devices.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy/set-up-windows-10-education-devices",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/set-up-windows-education-devices.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy/set-up-windows-10-education-devices",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/use-intune-for-education.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy/use-intune-for-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/get-started/use-school-data-sync.md",
|
||||
"redirect_url": "/microsoft-365/education/deploy/school-data-sync",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/itadmins.yml",
|
||||
"redirect_url": "/education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/partners.yml",
|
||||
"redirect_url": "/education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/change-history-edu.md",
|
||||
"redirect_url": "/education/windows",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/change-to-pro-education.md",
|
||||
"redirect_url": "/education/windows",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/education-scenarios-store-for-business.md",
|
||||
"redirect_url": "/windows/resources",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/enable-s-mode-on-surface-go-devices.md",
|
||||
"redirect_url": "/windows/deployment/s-mode",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/get-minecraft-device-promotion.md",
|
||||
"redirect_url": "/education/windows/get-minecraft-for-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/s-mode-switch-to-edu.md",
|
||||
"redirect_url": "/education/windows",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/school-get-minecraft.md",
|
||||
"redirect_url": "/education/windows/get-minecraft-for-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/set-up-school-pcs-shared-pc-mode.md",
|
||||
"redirect_url": "/windows/configuration/set-up-shared-or-guest-pc",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/switch-to-pro-education.md",
|
||||
"redirect_url": "/education/windows/change-to-pro-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/swithc-to-pro-de.md",
|
||||
"redirect_url": "/education/windows/switch-to-pro-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/take-a-test-multiple-pcs.md",
|
||||
"redirect_url": "/education/windows/edu-take-a-test-kiosk-mode",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/take-a-test-single-pc.md",
|
||||
"redirect_url": "/education/windows/take-tests-in-windows",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/take-tests-in-windows-10.md",
|
||||
"redirect_url": "/education/windows/take-tests-in-windows",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/teacher-get-minecraft.md",
|
||||
"redirect_url": "/education/windows/get-minecraft-for-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/test-windows10s-for-edu.md",
|
||||
"redirect_url": "/windows/deployment/s-mode",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/windows-10-pro-to-pro-edu-upgrade.md",
|
||||
"redirect_url": "/education/windows/change-to-pro-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/windows-automatic-redeployment.md",
|
||||
"redirect_url": "/education/windows/autopilot-reset",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
124
.openpublishing.redirection.store-for-business.json
Normal file
@ -0,0 +1,124 @@
|
||||
{
|
||||
"redirections": [
|
||||
{
|
||||
"source_path": "store-for-business/acquire-apps-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/acquire-apps-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/add-unsigned-app-to-code-integrity-policy.md",
|
||||
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/deploy-catalog-files-to-support-windows-defender-application-control",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/app-inventory-managemement-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/app-inventory-management-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/app-inventory-management-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/app-inventory-management-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/apps-in-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/apps-in-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/configure-mdm-provider-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/configure-mdm-provider-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/device-guard-signing-portal.md",
|
||||
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/use-device-guard-signing-portal-in-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/distribute-apps-to-your-employees-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/distribute-apps-to-your-employees-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/manage-apps-windows-store-for-business-overview.md",
|
||||
"redirect_url": "/microsoft-store/manage-apps-microsoft-store-for-business-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/manage-mpsa-software-microsoft-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/index",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/manage-orders-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/manage-orders-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/manage-settings-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/manage-settings-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/manage-users-and-groups-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/manage-users-and-groups-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/prerequisites-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/prerequisites-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/roles-and-permissions-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/roles-and-permissions-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/settings-reference-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/settings-reference-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/sign-code-integrity-policy-with-device-guard-signing.md",
|
||||
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/use-signed-policies-to-protect-windows-defender-application-control-against-tampering",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/sign-up-microsoft-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/sign-up-windows-store-for-business-overview.md",
|
||||
"redirect_url": "/microsoft-store/sign-up-microsoft-store-for-business-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/sign-up-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/index",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/troubleshoot-windows-store-for-business.md",
|
||||
"redirect_url": "/microsoft-store/troubleshoot-microsoft-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/update-windows-store-for-business-account-settings.md",
|
||||
"redirect_url": "/microsoft-store/update-microsoft-store-for-business-account-settings",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/windows-store-for-business-overview.md",
|
||||
"redirect_url": "/microsoft-store/microsoft-store-for-business-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "store-for-business/work-with-partner-microsoft-store-business.md",
|
||||
"redirect_url": "/microsoft-365/commerce/manage-partners",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
@ -0,0 +1,29 @@
|
||||
{
|
||||
"redirections": [
|
||||
{
|
||||
"source_path": "windows/application-management/manage-windows-mixed-reality.md",
|
||||
"redirect_url": "/windows/mixed-reality/enthusiast-guide/manage-windows-mixed-reality",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/application-management/msix-app-packaging-tool.md",
|
||||
"redirect_url": "/windows/application-management/overview-windows-apps",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/application-management/provisioned-apps-windows-client-os.md",
|
||||
"redirect_url": "/windows/application-management/overview-windows-apps#windows-apps",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/application-management/system-apps-windows-client-os.md",
|
||||
"redirect_url": "/windows/application-management/overview-windows-apps#windows-apps",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/application-management/apps-in-windows-10.md",
|
||||
"redirect_url": "/windows/application-management/overview-windows-apps",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
924
.openpublishing.redirection.windows-client-management.json
Normal file
@ -0,0 +1,924 @@
|
||||
{
|
||||
"redirections": [
|
||||
{
|
||||
"source_path": "windows/client-management/add-an-azure-ad-tenant-and-azure-ad-subscription.md",
|
||||
"redirect_url": "/azure/active-directory/fundamentals/active-directory-access-create-new-tenant",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/administrative-tools-in-windows-10.md",
|
||||
"redirect_url": "/windows/client-management/client-tools/administrative-tools-in-windows",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/advanced-troubleshooting-802-authentication.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/networking/802-1x-authentication-issues-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/advanced-troubleshooting-boot-problems.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/windows-boot-issues-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/advanced-troubleshooting-wireless-network-connectivity.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/networking/wireless-network-connectivity-issues-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/appv-deploy-and-config.md",
|
||||
"redirect_url": "/windows/application-management/app-v/appv-for-windows",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/assign-seats.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/bulk-assign-and-reclaim-seats-from-user.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/change-default-removal-policy-external-storage-media.md",
|
||||
"redirect_url": "/windows/client-management/client-tools/change-default-removal-policy-external-storage-media",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/change-history-for-mdm-documentation.md",
|
||||
"redirect_url": "/windows/client-management/new-in-windows-mdm-enrollment-management",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/connect-to-remote-aadj-pc.md",
|
||||
"redirect_url": "/windows/client-management/client-tools/connect-to-remote-aadj-pc",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/data-collection-for-802-authentication.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/networking/data-collection-for-troubleshooting-802-1x-authentication-issues",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/data-structures-windows-store-for-business.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/determine-appropriate-page-file-size.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/how-to-determine-the-appropriate-page-file-size-for-64-bit-versions-of-windows",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/diagnose-mdm-failures-in-windows-10.md",
|
||||
"redirect_url": "/windows/client-management/mdm-collect-logs",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/generate-kernel-or-complete-crash-dump.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/generate-a-kernel-or-complete-crash-dump",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/get-inventory.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/get-localized-product-details.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/get-offline-license.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/get-product-details.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/get-product-package.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/get-product-packages.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/get-seat.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/get-seats-assigned-to-a-user.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/get-seats.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/group-policies-for-enterprise-and-education-editions.md",
|
||||
"redirect_url": "https://www.microsoft.com/en-us/search/explore?q=Group+Policy+Settings+Reference+Spreadsheet",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/img-boot-sequence.md",
|
||||
"redirect_url": "/windows/client-management/advanced-troubleshooting-boot-problems#boot-sequence",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/introduction-page-file.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/introduction-to-the-page-file",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/manage-corporate-devices.md",
|
||||
"redirect_url": "/windows/client-management/manage-windows-10-in-your-organization-modern-management",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/manage-device-installation-with-group-policy.md",
|
||||
"redirect_url": "/windows/client-management/client-tools/manage-device-installation-with-group-policy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/manage-settings-app-with-group-policy.md",
|
||||
"redirect_url": "/windows/client-management/client-tools/manage-settings-app-with-group-policy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/management-tool-for-windows-store-for-business.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mandatory-user-profile.md",
|
||||
"redirect_url": "/windows/client-management/client-tools/mandatory-user-profile",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/add-an-azure-ad-tenant-and-azure-ad-subscription.md",
|
||||
"redirect_url": "/windows/client-management/add-an-azure-ad-tenant-and-azure-ad-subscription",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/applocker-xsd.md",
|
||||
"redirect_url": "/windows/client-management/mdm/applocker-csp#policy-xsd-schema",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/appv-deploy-and-config.md",
|
||||
"redirect_url": "/windows/client-management/appv-deploy-and-config",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/assign-seats.md",
|
||||
"redirect_url": "/windows/client-management/assign-seats",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/azure-active-directory-integration-with-mdm.md",
|
||||
"redirect_url": "/windows/client-management/azure-active-directory-integration-with-mdm",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/azure-ad-and-microsoft-intune-automatic-mdm-enrollment-in-the-new-portal.md",
|
||||
"redirect_url": "/windows/client-management/azure-ad-and-microsoft-intune-automatic-mdm-enrollment-in-the-new-portal",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/bootstrap-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/browserfavorite-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-phone-8-1-end-of-support-faq-7f1ef0aa-0aaf-0747-3724-5c44456778a3",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/bulk-assign-and-reclaim-seats-from-user.md",
|
||||
"redirect_url": "/windows/client-management/bulk-assign-and-reclaim-seats-from-user",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md",
|
||||
"redirect_url": "/windows/client-management/bulk-enrollment-using-windows-provisioning-tool",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/certificate-authentication-device-enrollment.md",
|
||||
"redirect_url": "/windows/client-management/certificate-authentication-device-enrollment",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/certificate-renewal-windows-mdm.md",
|
||||
"redirect_url": "/windows/client-management/certificate-renewal-windows-mdm",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/change-history-for-mdm-documentation.md",
|
||||
"redirect_url": "/windows/client-management/new-in-windows-mdm-enrollment-management",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/cm-proxyentries-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/config-lock.md",
|
||||
"redirect_url": "/windows/client-management/config-lock",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/configuration-service-provider-reference.md",
|
||||
"redirect_url": "/windows/client-management/mdm/index",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/create-a-custom-configuration-service-provider.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/data-structures-windows-store-for-business.md",
|
||||
"redirect_url": "/windows/client-management/data-structures-windows-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/design-a-custom-windows-csp.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/device-update-management.md",
|
||||
"redirect_url": "/windows/client-management/device-update-management",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/deviceinstanceservice-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/diagnose-mdm-failures-in-windows-10.md",
|
||||
"redirect_url": "/windows/client-management/mdm-collect-logs",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/disconnecting-from-mdm-unenrollment.md",
|
||||
"redirect_url": "/windows/client-management/disconnecting-from-mdm-unenrollment",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/dmprocessconfigxmlfiltered.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-phone-8-1-end-of-support-faq-7f1ef0aa-0aaf-0747-3724-5c44456778a3",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enable-admx-backed-policies-in-mdm.md",
|
||||
"redirect_url": "/windows/client-management/enable-admx-backed-policies-in-mdm",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enable-offline-updates-for-windows-embedded-8-1-handheld-devices-to-windows-10.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-phone-8-1-end-of-support-faq-7f1ef0aa-0aaf-0747-3724-5c44456778a3",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy.md",
|
||||
"redirect_url": "/windows/client-management/enroll-a-windows-10-device-automatically-using-group-policy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enterprise-app-management.md",
|
||||
"redirect_url": "/windows/client-management/enterprise-app-management",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enterpriseappmanagement-csp.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enterpriseassignedaccess-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enterpriseassignedaccess-ddf.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enterpriseassignedaccess-xsd.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enterprisedesktopappmanagement2-xsd.md",
|
||||
"redirect_url": "/windows/client-management/mdm/enterprisedesktopappmanagement-csp#downloadinstall-xsd-schema",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enterpriseext-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enterpriseext-ddf.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/EnterpriseExtFileSystem-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/EnterpriseExtFileSystem-ddf.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/enterprisemodernappmanagement-xsd.md",
|
||||
"redirect_url": "/windows/client-management/mdm/enterprisemodernappmanagement-csp#enterprisemodernappmanagement-xsd",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/esim-enterprise-management.md",
|
||||
"redirect_url": "/windows/client-management/esim-enterprise-management",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/federated-authentication-device-enrollment.md",
|
||||
"redirect_url": "/windows/client-management/federated-authentication-device-enrollment",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/filesystem-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/get-inventory.md",
|
||||
"redirect_url": "/windows/client-management/get-inventory",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/get-localized-product-details.md",
|
||||
"redirect_url": "/windows/client-management/get-localized-product-details",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/get-offline-license.md",
|
||||
"redirect_url": "/windows/client-management/get-offline-license",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/get-product-details.md",
|
||||
"redirect_url": "/windows/client-management/get-product-details",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/get-product-package.md",
|
||||
"redirect_url": "/windows/client-management/get-product-package",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/get-product-packages.md",
|
||||
"redirect_url": "/windows/client-management/get-product-packages",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/get-seat.md",
|
||||
"redirect_url": "/windows/client-management/get-seat",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/get-seats-assigned-to-a-user.md",
|
||||
"redirect_url": "/windows/client-management/get-seats-assigned-to-a-user",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/get-seats.md",
|
||||
"redirect_url": "/windows/client-management/get-seats",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/hotspot-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/iconfigserviceprovider2.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/iconfigserviceprovider2configmanagernotification.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/iconfigserviceprovider2getnode.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnode.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodeadd.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodeclear.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodecopy.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodedeletechild.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodedeleteproperty.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodeexecute.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodegetchildnodenames.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodegetproperty.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodegetpropertyidentifiers.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodegetvalue.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodemove.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodesetproperty.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodesetvalue.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspnodetransactioning.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/icspvalidate.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/implement-server-side-mobile-application-management.md",
|
||||
"redirect_url": "/windows/client-management/implement-server-side-mobile-application-management",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/management-tool-for-windows-store-for-business.md",
|
||||
"redirect_url": "/windows/client-management/management-tool-for-windows-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/maps-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/maps-ddf-file.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/mdm-enrollment-of-windows-devices.md",
|
||||
"redirect_url": "/windows/client-management/mdm-enrollment-of-windows-devices",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/mdm-overview.md",
|
||||
"redirect_url": "/windows/client-management/mdm-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/messaging-csp.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/messaging-ddf.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/mobile-device-enrollment.md",
|
||||
"redirect_url": "/windows/client-management/mobile-device-enrollment",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md",
|
||||
"redirect_url": "/windows/client-management/new-in-windows-mdm-enrollment-management",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/oma-dm-protocol-support.md",
|
||||
"redirect_url": "/windows/client-management/oma-dm-protocol-support",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/on-premise-authentication-device-enrollment.md",
|
||||
"redirect_url": "/windows/client-management/on-premise-authentication-device-enrollment",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-admx-backed.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csps-admx-backed",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-in-policy-csp-supported-by-iot-core.md",
|
||||
"redirect_url": "/windows/iot-core/manage-your-device/csp-support",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-in-policy-csp-supported-by-iot-enterprise.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-supported-by-group-policy.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csps-supported-by-group-policy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-supported-by-hololens-1st-gen-commercial-suite.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csps-supported-by-hololens-1st-gen-commercial-suite",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-supported-by-hololens-1st-gen-development-edition.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csps-supported-by-hololens-1st-gen-development-edition",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-supported-by-hololens2.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csps-supported-by-hololens2",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-supported-by-iot-core.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csps-supported-by-iot-core",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-supported-by-iot-enterprise.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csps-supported-by-iot-enterprise",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policies-supported-by-surface-hub.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csps-supported-by-surface-hub",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-admx-backed.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-configuration-service-provider",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csp-admx-skydrive.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csp-admx-shellcommandpromptregedittools",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csp-admx-windowsanytimeupgrade.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csp-admx-wordwheel",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csp-admx-windowsfileprotection.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-csp-admx-mobilepcpresentationsettings",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csp-cloudpc.md",
|
||||
"redirect_url": "/windows/client-management/mdm/clouddesktop-csp",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csp-location.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policy-configuration-service-provider",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csps-admx-backed.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policies-in-policy-csp-admx-backed",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csps-supported-by-group-policy.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policies-in-policy-csp-supported-by-group-policy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csps-supported-by-hololens-1st-gen-commercial-suite.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policies-in-policy-csp-supported-by-hololens-1st-gen-commercial-suite",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csps-supported-by-hololens-1st-gen-development-edition.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policies-in-policy-csp-supported-by-hololens-1st-gen-development-edition",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csps-supported-by-hololens2.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policies-in-policy-csp-supported-by-hololens2",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csps-supported-by-iot-core.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policies-in-policy-csp-supported-by-iot-core",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csps-supported-by-iot-enterprise.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policies-in-policy-csp-supported-by-iot-enterprise",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csps-supported-by-surface-hub.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policies-in-policy-csp-supported-by-surface-hub",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-csps-that-can-be-set-using-eas.md",
|
||||
"redirect_url": "/windows/client-management/mdm/policies-in-policy-csp-that-can-be-set-using-eas",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policy-ddf-file.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-ddf",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/policymanager-csp.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/proxy-csp.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/push-notification-windows-mdm.md",
|
||||
"redirect_url": "/windows/client-management/push-notification-windows-mdm",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/reclaim-seat-from-user.md",
|
||||
"redirect_url": "/windows/client-management/reclaim-seat-from-user",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/register-your-free-azure-active-directory-subscription.md",
|
||||
"redirect_url": "/windows/client-management/register-your-free-azure-active-directory-subscription",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/registry-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/registry-ddf-file.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/remotelock-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/remotelock-ddf-file.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/remotering-ddf-file.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/rest-api-reference-windows-store-for-business.md",
|
||||
"redirect_url": "/windows/client-management/rest-api-reference-windows-store-for-business",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/samples-for-writing-a-custom-configuration-service-provider.md",
|
||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-reference",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/server-requirements-windows-mdm.md",
|
||||
"redirect_url": "/windows/client-management/server-requirements-windows-mdm",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/structure-of-oma-dm-provisioning-files.md",
|
||||
"redirect_url": "/windows/client-management/structure-of-oma-dm-provisioning-files",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/understanding-admx-backed-policies.md",
|
||||
"redirect_url": "/windows/client-management/understanding-admx-backed-policies",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/using-powershell-scripting-with-the-wmi-bridge-provider.md",
|
||||
"redirect_url": "/windows/client-management/using-powershell-scripting-with-the-wmi-bridge-provider",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/vpnv2-profile-xsd.md",
|
||||
"redirect_url": "/windows/client-management/mdm/vpnv2-csp#profilexml-xsd-schema",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/win32-and-centennial-app-policy-configuration.md",
|
||||
"redirect_url": "/windows/client-management/win32-and-centennial-app-policy-configuration",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/windows-mdm-enterprise-settings.md",
|
||||
"redirect_url": "/windows/client-management/windows-mdm-enterprise-settings",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/windowssecurityauditing-csp.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/windowssecurityauditing-ddf-file.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/mdm/wmi-providers-supported-in-windows.md",
|
||||
"redirect_url": "/windows/client-management/wmi-providers-supported-in-windows",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/new-policies-for-windows-10.md",
|
||||
"redirect_url": "https://www.microsoft.com/en-us/search/explore?q=Group+Policy+Settings+Reference+Spreadsheet",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/quick-assist.md",
|
||||
"redirect_url": "/windows/client-management/client-tools/quick-assist",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/reclaim-seat-from-user.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/register-your-free-azure-active-directory-subscription.md",
|
||||
"redirect_url": "/microsoft-365/compliance/use-your-free-azure-ad-subscription-in-office-365",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/rest-api-reference-windows-store-for-business.md",
|
||||
"redirect_url": "https://aka.ms/windows/msfb_evolution",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/system-failure-recovery-options.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/configure-system-failure-and-recovery-options",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-event-id-41-restart.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/event-id-41-restart",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-inaccessible-boot-device.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/stop-error-7b-or-inaccessible-boot-device-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-networking.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/networking/networking-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-stop-error-on-broadcom-driver-update.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/stop-error-broadcom-network-driver-update",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-stop-errors.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/stop-error-or-blue-screen-error-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-tcpip-connectivity.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/networking/tcp-ip-connectivity-issues-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-tcpip-netmon.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/networking/collect-data-using-network-monitor",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-tcpip-port-exhaust.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/networking/tcp-ip-port-exhaustion-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-tcpip-rpc-errors.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/networking/rpc-errors-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-tcpip.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/networking/networking-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-windows-freeze.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/windows-based-computer-freeze-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/troubleshoot-windows-startup.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/performance/windows-startup-issues-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/windows-10-support-solutions.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/welcome-windows-client",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/windows-libraries.md",
|
||||
"redirect_url": "/windows/client-management/client-tools/windows-libraries",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/client-management/windows-version-search.md",
|
||||
"redirect_url": "/windows/client-management/client-tools/windows-version-search",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
289
.openpublishing.redirection.windows-configuration.json
Normal file
@ -0,0 +1,289 @@
|
||||
{
|
||||
"redirections": [
|
||||
{
|
||||
"source_path": "windows/configuration/basic-level-windows-diagnostic-events-and-fields-1703.md",
|
||||
"redirect_url": "/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/basic-level-windows-diagnostic-events-and-fields-1709.md",
|
||||
"redirect_url": "/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/basic-level-windows-diagnostic-events-and-fields.md",
|
||||
"redirect_url": "/windows/privacy/basic-level-windows-diagnostic-events-and-fields",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/configure-devices-without-mdm.md",
|
||||
"redirect_url": "/windows/configuration/provisioning-packages/provisioning-packages",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/configure-windows-diagnostic-data-in-your-organization.md",
|
||||
"redirect_url": "/windows/privacy/configure-windows-diagnostic-data-in-your-organization",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/configure-windows-telemetry-in-your-organization.md",
|
||||
"redirect_url": "/windows/configuration/configure-windows-diagnostic-data-in-your-organization",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/cortana-at-work/cortana-at-work-crm.md",
|
||||
"redirect_url": "/windows/resources",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/cortana-at-work/cortana-at-work-powerbi.md",
|
||||
"redirect_url": "/windows/resources",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/diagnostic-data-viewer-overview.md",
|
||||
"redirect_url": "/windows/privacy/diagnostic-data-viewer-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/enhanced-diagnostic-data-windows-analytics-events-and-fields.md",
|
||||
"redirect_url": "/windows/privacy/enhanced-diagnostic-data-windows-analytics-events-and-fields",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/EventName.md",
|
||||
"redirect_url": "/windows/configuration/enhanced-telemetry-windows-analytics-events-and-fields",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/gdpr-win10-whitepaper.md",
|
||||
"redirect_url": "/windows/privacy/gdpr-win10-whitepaper",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/kiosk-shared-pc.md",
|
||||
"redirect_url": "/windows/configuration/kiosk-methods",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/kiosk-troubleshoot.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/shell-experience/kiosk-mode-issues-troubleshooting",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/manage-connections-from-windows-operating-system-components-to-microsoft-services.md",
|
||||
"redirect_url": "/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/manage-wifi-sense-in-enterprise.md",
|
||||
"redirect_url": "/windows/resources",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/manage-windows-endpoints-version-1709.md",
|
||||
"redirect_url": "/windows/privacy/manage-windows-endpoints",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/configure-mobile.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/lockdown-xml.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/mobile-lockdown-designer.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/product-ids-in-windows-10-mobile.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/provisioning-configure-mobile.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/provisioning-nfc.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/provisioning-package-splitter.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/set-up-a-kiosk-for-windows-10-for-mobile-edition.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/settings-that-can-be-locked-down.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/mobile-devices/start-layout-xml-mobile.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/multi-app-kiosk-troubleshoot.md",
|
||||
"redirect_url": "/windows/configuration/kiosk-troubleshoot",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/multi-app-kiosk-xml.md",
|
||||
"redirect_url": "/windows/configuration/kiosk-xml",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/provisioning-packages/provision-pcs-with-apps-and-certificates.md",
|
||||
"redirect_url": "/windows/configuration/provisioning-packages/provision-pcs-with-apps",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/set-up-a-device-for-anyone-to-use.md",
|
||||
"redirect_url": "/windows/configuration/kiosk-shared-pc",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/set-up-a-kiosk-for-windows-10-for-desktop-editions.md",
|
||||
"redirect_url": "/windows/configuration/setup-kiosk-digital-signage",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/setup-kiosk-digital-signage.md",
|
||||
"redirect_url": "/windows/configuration/kiosk-single-app",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/start-layout-troubleshoot.md",
|
||||
"redirect_url": "/troubleshoot/windows-client/shell-experience/troubleshoot-start-menu-errors",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/start-taskbar-lockscreen.md",
|
||||
"redirect_url": "/windows/configuration/windows-10-start-layout-options-and-policies",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/stop-employees-from-using-the-windows-store.md",
|
||||
"redirect_url": "/windows/configuration/stop-employees-from-using-microsoft-store",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/use-json-customize-start-menu-windows.md",
|
||||
"redirect_url": "/windows/configuration/customize-start-menu-layout-windows-11",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-automatictime.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-callandmessagingenhancement.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-calling.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-deviceinfo.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-embeddedlockdownprofiles.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-initialsetup.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-internetexplorer.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-messaging.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-modemconfigurations.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-multivariant.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-nfc.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-otherassets.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-rcspresence.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-shell.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-textinput.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/wcd/wcd-theme.md",
|
||||
"redirect_url": "https://support.microsoft.com/windows/windows-10-mobile-end-of-support-faq-8c2dd1cf-a571-00f0-0881-bb83926d05c5",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/windows-10-accessibility-for-ITPros.md",
|
||||
"redirect_url": "/windows/configuration/windows-accessibility-for-ITPros",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/windows-diagnostic-data-1703.md",
|
||||
"redirect_url": "/windows/privacy/windows-diagnostic-data-1703",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/windows-diagnostic-data-1709.md",
|
||||
"redirect_url": "/windows/configuration/windows-diagnostic-data",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/windows-diagnostic-data.md",
|
||||
"redirect_url": "/windows/privacy/windows-diagnostic-data",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
1119
.openpublishing.redirection.windows-deployment.json
Normal file
19
.openpublishing.redirection.windows-hub.json
Normal file
@ -0,0 +1,19 @@
|
||||
{
|
||||
"redirections": [
|
||||
{
|
||||
"source_path": "windows/hub/release-information.md",
|
||||
"redirect_url": "/windows/release-health/release-information",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/hub/windows-10-landing.yml",
|
||||
"redirect_url": "/windows/windows-10",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/hub/windows-10.yml",
|
||||
"redirect_url": "/windows/windows-10",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
59
.openpublishing.redirection.windows-privacy.json
Normal file
@ -0,0 +1,59 @@
|
||||
{
|
||||
"redirections": [
|
||||
{
|
||||
"source_path": "windows/privacy/basic-level-windows-diagnostic-events-and-fields.md",
|
||||
"redirect_url": "/windows/privacy/required-windows-diagnostic-data-events-and-fields-2004",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/deploy-data-processor-service-windows.md",
|
||||
"redirect_url": "/windows/privacy/windows-10-and-privacy-compliance",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/gdpr-it-guidance.md",
|
||||
"redirect_url": "/windows/privacy/windows-10-and-privacy-compliance",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/gdpr-win10-whitepaper.md",
|
||||
"redirect_url": "/windows/privacy/windows-10-and-privacy-compliance",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/license-terms-windows-diagnostic-data-for-powershell.md",
|
||||
"redirect_url": "/legal/windows/license-terms-windows-diagnostic-data-for-powershell",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/manage-windows-1709-endpoints.md",
|
||||
"redirect_url": "/windows/privacy/manage-windows-21h2-endpoints",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/manage-windows-1803-endpoints.md",
|
||||
"redirect_url": "/windows/privacy/manage-windows-21h2-endpoints",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/manage-windows-endpoints.md",
|
||||
"redirect_url": "/windows/privacy/manage-windows-2004-endpoints",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/windows-endpoints-1709-non-enterprise-editions.md",
|
||||
"redirect_url": "/windows/privacy/windows-endpoints-21h1-non-enterprise-editions",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/windows-endpoints-1803-non-enterprise-editions.md",
|
||||
"redirect_url": "/windows/privacy/windows-endpoints-21h1-non-enterprise-editions",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/privacy/windows-personal-data-services-configuration.md",
|
||||
"redirect_url": "/windows/privacy/windows-10-and-privacy-compliance",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
7419
.openpublishing.redirection.windows-security.json
Normal file
114
.openpublishing.redirection.windows-whats-new.json
Normal file
@ -0,0 +1,114 @@
|
||||
{
|
||||
"redirections": [
|
||||
{
|
||||
"source_path": "windows/whats-new/applocker.md",
|
||||
"redirect_url": "/windows/whats-new/whats-new-windows-10-version-1507-and-1511",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/bitlocker.md",
|
||||
"redirect_url": "/windows/whats-new/whats-new-windows-10-version-1507-and-1511",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/change-history-for-what-s-new-in-windows-10.md",
|
||||
"redirect_url": "/windows/whats-new/index",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/contribute-to-a-topic.md",
|
||||
"redirect_url": "https://github.com/MicrosoftDocs/windows-itpro-docs/blob/public/CONTRIBUTING.md#editing-windows-it-professional-documentation",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/credential-guard.md",
|
||||
"redirect_url": "/windows/whats-new/whats-new-windows-10-version-1507-and-1511",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/device-guard-overview.md",
|
||||
"redirect_url": "/windows/security/threat-protection/device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/device-management.md",
|
||||
"redirect_url": "/windows/client-management/index",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/edge-ie11-whats-new-overview.md",
|
||||
"redirect_url": "/microsoft-edge/deploy/emie-to-improve-compatibility",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/edp-whats-new-overview.md",
|
||||
"redirect_url": "/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/lockdown-features-windows-10.md",
|
||||
"redirect_url": "/windows/configuration/lockdown-features-windows-10",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/microsoft-passport.md",
|
||||
"redirect_url": "/windows/access-protection/hello-for-business/hello-identity-verification",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/new-provisioning-packages.md",
|
||||
"redirect_url": "/windows/configuration/provisioning-packages/provisioning-packages",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/security-auditing.md",
|
||||
"redirect_url": "/windows/whats-new/whats-new-windows-10-version-1507-and-1511",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/security.md",
|
||||
"redirect_url": "/windows/threat-protection/overview-of-threat-mitigations-in-windows-10",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/trusted-platform-module.md",
|
||||
"redirect_url": "/windows/device-security/tpm/trusted-platform-module-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/user-account-control.md",
|
||||
"redirect_url": "/windows/whats-new/whats-new-windows-10-version-1507-and-1511",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/windows-10-insider-preview.md",
|
||||
"redirect_url": "/windows/whats-new",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/windows-11-whats-new.md",
|
||||
"redirect_url": "/windows/whats-new/windows-11-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/windows-11.md",
|
||||
"redirect_url": "/windows/whats-new/windows-11-whats-new",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/windows-spotlight.md",
|
||||
"redirect_url": "/windows/configuration/windows-spotlight",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/windows-store-for-business-overview.md",
|
||||
"redirect_url": "/microsoft-store/windows-store-for-business-overview",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/whats-new/windows-update-for-business.md",
|
||||
"redirect_url": "/windows/whats-new/whats-new-windows-10-version-1507-and-1511",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
@ -35,11 +35,10 @@
|
||||
],
|
||||
"breadcrumb_path": "/microsoft-edge/breadcrumbs/toc.json",
|
||||
"ROBOTS": "INDEX, FOLLOW",
|
||||
"ms.technology": "microsoft-edge",
|
||||
"audience": "ITPro",
|
||||
"ms.topic": "article",
|
||||
"manager": "dansimp",
|
||||
"ms.prod": "edge",
|
||||
"ms.prod": "microsoft-edge",
|
||||
"feedback_system": "None",
|
||||
"hideEdit": true,
|
||||
"_op_documentIdPathDepotMapping": {
|
||||
|
@ -8,7 +8,7 @@ metadata:
|
||||
description: Find the tools and resources you need to help deploy and use Microsoft Edge in your organization. # Required; article description that is displayed in search results. < 160 chars.
|
||||
keywords: Microsoft Edge Legacy, Windows 10
|
||||
ms.localizationpriority: medium
|
||||
ms.prod: edge
|
||||
ms.prod: microsoft-edge
|
||||
author: dougeby
|
||||
ms.author: pashort
|
||||
ms.topic: landing-page
|
||||
|
@ -10,7 +10,6 @@ metadata:
|
||||
keywords: Microsoft Edge Legacy, Windows 10
|
||||
ms.localizationpriority: medium
|
||||
ms.topic: landing-page # Required
|
||||
ms.collection: collection # Optional; Remove if no collection is used.
|
||||
author: dougeby #Required; your GitHub user alias, with correct capitalization.
|
||||
ms.author: pashort #Required; microsoft alias of author; optional team alias.
|
||||
ms.date: 07/07/2020 #Required; mm/dd/yyyy format.
|
||||
|
@ -8,7 +8,7 @@ metadata:
|
||||
description: Answers to frequently asked questions about Microsoft Edge features, integration, support, and potential problems.
|
||||
author: dansimp
|
||||
ms.author: dansimp
|
||||
ms.prod: edge
|
||||
ms.prod: microsoft-edge
|
||||
ms.topic: faq
|
||||
ms.mktglfcycl: general
|
||||
ms.sitesec: library
|
||||
|
@ -7,7 +7,7 @@ metadata:
|
||||
title: Microsoft Edge Legacy # Required; page title displayed in search results. Include the brand. < 60 chars.
|
||||
description: Find the tools and resources you need to help deploy and use Microsoft Edge in your organization. # Required; article description that is displayed in search results. < 160 chars.
|
||||
keywords: Microsoft Edge, issues, fixes, announcements, Windows Server, advisories
|
||||
ms.prod: edge
|
||||
ms.prod: microsoft-edge
|
||||
ms.localizationpriority: medium
|
||||
author: aczechowski
|
||||
ms.author: aaroncz
|
||||
|
@ -2,7 +2,6 @@
|
||||
metadata:
|
||||
title: IE and Microsoft Edge FAQ for IT Pros
|
||||
description: Describes frequently asked questions about Internet Explorer and Microsoft Edge for IT professionals.
|
||||
audience: ITPro
|
||||
manager: msmets
|
||||
author: ramakoni1
|
||||
ms.author: ramakoni
|
||||
@ -10,7 +9,6 @@ metadata:
|
||||
ms.prod: internet-explorer
|
||||
ms.technology:
|
||||
ms.topic: faq
|
||||
ms.custom: CI=111020
|
||||
ms.localizationpriority: medium
|
||||
ms.date: 01/23/2020
|
||||
title: Internet Explorer and Microsoft Edge frequently asked questions (FAQ) for IT Pros
|
||||
|
@ -41,7 +41,7 @@
|
||||
"manager": "aaroncz",
|
||||
"ms.localizationpriority": "medium",
|
||||
"breadcrumb_path": "/education/breadcrumb/toc.json",
|
||||
"uhfHeaderId": "MSDocsHeader-M365-IT",
|
||||
"uhfHeaderId": "MSDocsHeader-Windows",
|
||||
"feedback_system": "GitHub",
|
||||
"feedback_github_repo": "MicrosoftDocs/windows-itpro-docs",
|
||||
"feedback_product_url": "https://support.microsoft.com/windows/send-feedback-to-microsoft-with-the-feedback-hub-app-f59187f8-8739-22d6-ba93-f66612949332",
|
||||
@ -65,7 +65,8 @@
|
||||
"v-dihans",
|
||||
"garycentric",
|
||||
"v-stsavell",
|
||||
"beccarobins"
|
||||
"beccarobins",
|
||||
"v-stchambers"
|
||||
]
|
||||
},
|
||||
"fileMetadata": {
|
||||
|
@ -2,24 +2,20 @@
|
||||
|
||||
|
||||
|
||||
## Week of April 10, 2023
|
||||
## Week of September 11, 2023
|
||||
|
||||
|
||||
| Published On |Topic title | Change |
|
||||
|------|------------|--------|
|
||||
| 4/11/2023 | [Configure federated sign-in for Windows devices](/education/windows/federated-sign-in) | modified |
|
||||
| 9/11/2023 | [Configure education themes for Windows 11](/education/windows/edu-themes) | modified |
|
||||
| 9/11/2023 | [Configure federated sign-in for Windows devices](/education/windows/federated-sign-in) | modified |
|
||||
|
||||
|
||||
## Week of March 20, 2023
|
||||
## Week of September 04, 2023
|
||||
|
||||
|
||||
| Published On |Topic title | Change |
|
||||
|------|------------|--------|
|
||||
| 3/21/2023 | [Windows 11 SE Overview](/education/windows/windows-11-se-overview) | modified |
|
||||
| 3/22/2023 | [Configure Stickers for Windows 11 SE](/education/windows/edu-stickers) | modified |
|
||||
| 3/22/2023 | [Configure Take a Test in kiosk mode](/education/windows/edu-take-a-test-kiosk-mode) | modified |
|
||||
| 3/22/2023 | [Configure federated sign-in for Windows devices](/education/windows/federated-sign-in) | modified |
|
||||
| 3/22/2023 | [Reset devices with Autopilot Reset](/education/windows/autopilot-reset) | modified |
|
||||
| 3/22/2023 | [Deploy Windows 10 in a school district (Windows 10)](/education/windows/deploy-windows-10-in-a-school-district) | modified |
|
||||
| 3/22/2023 | [Deploy Windows 10 in a school (Windows 10)](/education/windows/deploy-windows-10-in-a-school) | modified |
|
||||
| 3/22/2023 | [Deployment recommendations for school IT administrators](/education/windows/edu-deployment-recommendations) | modified |
|
||||
| 9/5/2023 | [Configure federated sign-in for Windows devices](/education/windows/federated-sign-in) | modified |
|
||||
| 9/5/2023 | [Windows for Education documentation](/education/windows/index) | modified |
|
||||
| 9/5/2023 | [Windows 11 SE Overview](/education/windows/windows-11-se-overview) | modified |
|
||||
|
@ -1,12 +1,12 @@
|
||||
---
|
||||
title: Upgrade Windows Home to Windows Education on student-owned devices
|
||||
description: Learn how IT Pros can upgrade student-owned devices from Windows Home to Windows Education using Mobile Device Management or Kivuto OnTheHub with qualifying subscriptions.
|
||||
ms.date: 08/10/2022
|
||||
ms.date: 08/07/2023
|
||||
ms.topic: how-to
|
||||
author: scottbreenmsft
|
||||
ms.author: scbree
|
||||
ms.reviewer: paoloma
|
||||
manager: jeffbu
|
||||
manager: aaroncz
|
||||
ms.collection:
|
||||
- tier3
|
||||
- education
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Configure federation between Google Workspace and Azure AD
|
||||
description: Configuration of a federated trust between Google Workspace and Azure AD, with Google Workspace acting as an identity provider (IdP) for Azure AD.
|
||||
ms.date: 04/04/2023
|
||||
ms.date: 09/11/2023
|
||||
ms.topic: how-to
|
||||
appliesto:
|
||||
---
|
||||
@ -41,7 +41,7 @@ To test federation, the following prerequisites must be met:
|
||||
1. In the search results page, hover over the *Microsoft Office 365 - Web (SAML)* app and select **Select**
|
||||
:::image type="content" source="images/google/google-admin-search-app.png" alt-text="Screenshot showing Google Workspace and the search button for Microsoft Office 365 SAML app.":::
|
||||
1. On the **Google Identity Provider details** page, select **Download Metadata** and take note of the location where the **IdP metadata** - *GoogleIDPMetadata.xml* - file is saved, as it will be used to setup Azure AD later
|
||||
1. On the **Service provider detail*s** page
|
||||
1. On the **Service provider detail's** page
|
||||
- Select the option **Signed response**
|
||||
- Verify that the Name ID format is set to **PERSISTENT**
|
||||
- Depending on how the Azure AD users have been provisioned in Azure AD, you may need to adjust the **Name ID** mapping.\
|
||||
|
@ -139,7 +139,7 @@ Provide an ad-free experience that is a safer, more private search option for K
|
||||
#### Azure AD and Office 365 Education tenant
|
||||
To suppress ads when searching with Bing on Microsoft Edge on any network, follow these steps:
|
||||
|
||||
1. Ensure your Office 365 tenant is registered as an education tenant. For more information, see [Verify your Office 365 domain to prove education status](https://support.office.com/article/Verify-your-Office-365-domain-to-prove-ownership-nonprofit-or-education-status-or-to-activate-Yammer-87d1844e-aa47-4dc0-a61b-1b773fd4e590).
|
||||
1. Ensure your Office 365 tenant is registered as an education tenant. For more information, see [Verify your Office 365 domain to prove education status](https://support.office.com/article/Verify-your-Office-365-domain-to-prove-ownership-nonprofit-or-education-status-or-to-activate-viva-engage-87d1844e-aa47-4dc0-a61b-1b773fd4e590).
|
||||
2. Domain join the Windows 10 PCs to your Azure AD tenant (this tenant is the same as your Office 365 tenant).
|
||||
3. Configure **SetEduPolicies** according to one of the methods described in the previous sections in this topic.
|
||||
4. Have students sign in with their Azure AD identity, which is the same as your Office 365 identity, to use the PC.
|
||||
|
@ -113,7 +113,7 @@ Office 365 Education allows:
|
||||
|
||||
* Students and faculty to use Office 365 Video to manage videos.
|
||||
|
||||
* Students and faculty to use Yammer to collaborate through private social networking.
|
||||
* Students and faculty to use Viva Engage to collaborate through private social networking.
|
||||
|
||||
* Students and faculty to access classroom resources from anywhere on any device (including iOS and Android devices).
|
||||
|
||||
|
@ -68,7 +68,7 @@ Office 365 Education allows:
|
||||
- Students and faculty to access up to 1 TB of personal cloud storage that users inside and outside the educational institution can share through OneDrive for Business.
|
||||
- Teachers to provide collaboration in the classroom through Microsoft SharePoint Online team sites.
|
||||
- Students and faculty to use Office 365 Video to manage videos.
|
||||
- Students and faculty to use Yammer to collaborate through private social networking.
|
||||
- Students and faculty to use Viva Engage to collaborate through private social networking.
|
||||
- Students and faculty to access classroom resources from anywhere on any device (including iOS and Android devices).
|
||||
|
||||
For more information about Office 365 Education features and a FAQ, go to [Office 365 Education](https://www.microsoft.com/microsoft-365/academic/compare-office-365-education-plans).
|
||||
@ -236,7 +236,7 @@ Now that you've created your new Office 365 Education subscription, add the doma
|
||||
To make it easier for faculty and students to join your Office 365 Education subscription (or *tenant*), allow them to automatically sign up to your tenant (*automatic tenant join*). In automatic tenant join, when a faculty member or student signs up for Office 365, Office 365 automatically adds (joins) the user to your Office 365 tenant.
|
||||
|
||||
> [!NOTE]
|
||||
> By default, automatic tenant join is enabled in Office 365 Education, except for certain areas in Europe, the Middle East, and Africa. These countries require opt-in steps to add new users to existing Office 365 tenants. Check your country requirements to determine the automatic tenant join default configuration. Also, if you use Azure AD Connect, then automatic tenant join is disabled.
|
||||
> By default, automatic tenant join is enabled in Office 365 Education, except for certain areas in Europe, the Middle East, and Africa. These countries/regions require opt-in steps to add new users to existing Office 365 tenants. Check your country/region requirements to determine the automatic tenant join default configuration. Also, if you use Azure AD Connect, then automatic tenant join is disabled.
|
||||
|
||||
Office 365 uses the domain portion of the user’s email address to know which Office 365 tenant to join. For example, if a faculty member or student provides an email address of user@contoso.edu, then Office 365 automatically performs one of the following tasks:
|
||||
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Deployment recommendations for school IT administrators
|
||||
description: Provides guidance on ways to customize the OS privacy settings, and some of the apps, for Windows-based devices used in schools so that you can choose what information is shared with Microsoft.
|
||||
ms.topic: conceptual
|
||||
ms.topic: best-practice
|
||||
ms.date: 08/10/2022
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10</a>
|
||||
|
@ -33,14 +33,14 @@ Stickers aren't enabled by default. Follow the instructions below to configure y
|
||||
|
||||
#### [:::image type="icon" source="images/icons/intune.svg"::: **Intune**](#tab/intune)
|
||||
|
||||
[!INCLUDE [intune-custom-settings-1](includes/intune-custom-settings-1.md)]
|
||||
[!INCLUDE [intune-custom-settings-1](../../includes/configure/intune-custom-settings-1.md)]
|
||||
|
||||
| Setting |
|
||||
|--------|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/Stickers/EnableStickers`** </li><li>Data type: **Integer** </li><li>Value: **1**</li>|
|
||||
|
||||
[!INCLUDE [intune-custom-settings-2](includes/intune-custom-settings-2.md)]
|
||||
[!INCLUDE [intune-custom-settings-info](includes/intune-custom-settings-info.md)]
|
||||
[!INCLUDE [intune-custom-settings-2](../../includes/configure/intune-custom-settings-2.md)]
|
||||
[!INCLUDE [intune-custom-settings-info](../../includes/configure/intune-custom-settings-info.md)]
|
||||
|
||||
> [!TIP]
|
||||
> Use the following Graph call to automatically create the custom policy in your tenant without assignments nor scope tags. <sup>[1](#footnote1)</sup>
|
||||
|
@ -53,7 +53,7 @@ To configure devices using Intune for Education, follow these steps:
|
||||
|
||||
### Configure Take a Test with a custom policy
|
||||
|
||||
[!INCLUDE [intune-custom-settings-1](includes/intune-custom-settings-1.md)]
|
||||
[!INCLUDE [intune-custom-settings-1](../../includes/configure/intune-custom-settings-1.md)]
|
||||
|
||||
| Setting |
|
||||
|--------|
|
||||
@ -67,8 +67,8 @@ To configure devices using Intune for Education, follow these steps:
|
||||
|
||||
:::image type="content" source="./images/takeatest/intune-take-a-test-custom-profile.png" alt-text="Intune portal - creation of a custom policy to configure Take a Test." lightbox="./images/takeatest/intune-take-a-test-custom-profile.png" border="true":::
|
||||
|
||||
[!INCLUDE [intune-custom-settings-2](includes/intune-custom-settings-2.md)]
|
||||
[!INCLUDE [intune-custom-settings-info](includes/intune-custom-settings-info.md)]
|
||||
[!INCLUDE [intune-custom-settings-2](../../includes/configure/intune-custom-settings-2.md)]
|
||||
[!INCLUDE [intune-custom-settings-info](../../includes/configure/intune-custom-settings-info.md)]
|
||||
|
||||
#### [:::image type="icon" source="images/icons/provisioning-package.svg"::: **PPKG**](#tab/ppkg)
|
||||
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Configure education themes for Windows 11
|
||||
description: Learn about education themes for Windows 11 and how to configure them via Intune and provisioning package.
|
||||
ms.date: 09/15/2022
|
||||
ms.date: 09/11/2023
|
||||
ms.topic: how-to
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11</a>
|
||||
@ -12,25 +12,30 @@ appliesto:
|
||||
|
||||
Starting in **Windows 11, version 22H2**, you can deploy education themes to your devices. The education themes are designed for students using devices in a school.
|
||||
|
||||
:::image type="content" source="./images/win-11-se-themes-1.png" alt-text="Windows 11 desktop with 3 stickers" border="true":::
|
||||
:::image type="content" source="./images/win-11-se-themes-1.png" alt-text="Screenshot of Windows 11 desktop with 3 stickers" border="true":::
|
||||
|
||||
Themes allow the end user to quickly configure the look and feel of the device, with preset wallpaper, accent color, and other settings.
|
||||
Students can choose their own themes, making it feel the device is their own. When students feel more ownership over their device, they tend to take better care of it. This is great news for schools looking to give that same device to a new student the next year.
|
||||
Students can choose their own themes, making it feel the device is their own. When students feel more ownership over their device, they tend to take better care of it.
|
||||
|
||||
## Enable education themes
|
||||
|
||||
Education themes aren't enabled by default. Follow the instructions below to configure your devices using either Microsoft Intune or a provisioning package (PPKG).
|
||||
Education themes aren't enabled by default. The following instructions describe how to configure your devices using either Microsoft Intune or a provisioning package (PPKG).
|
||||
|
||||
#### [:::image type="icon" source="images/icons/intune.svg"::: **Intune**](#tab/intune)
|
||||
|
||||
[!INCLUDE [intune-custom-settings-1](includes/intune-custom-settings-1.md)]
|
||||
[!INCLUDE [intune-settings-catalog-1](../../includes/configure/intune-settings-catalog-1.md)]
|
||||
|
||||
| Category | Setting name | Value |
|
||||
|--|--|--|
|
||||
| Education | Enable Edu Themes | Enabled |
|
||||
|
||||
[!INCLUDE [intune-settings-catalog-2](../../includes/configure/intune-settings-catalog-2.md)]
|
||||
|
||||
Alternatively, you can configure devices using a [custom policy][INT-1] with the following settings:
|
||||
|
||||
| Setting |
|
||||
|--------|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/Education/EnableEduThemes`** </li><li>Data type: **Integer** </li><li>Value: **1**</li>|
|
||||
|
||||
[!INCLUDE [intune-custom-settings-2](includes/intune-custom-settings-2.md)]
|
||||
[!INCLUDE [intune-custom-settings-info](includes/intune-custom-settings-info.md)]
|
||||
| **OMA-URI**: `./Vendor/MSFT/Policy/Config/Education/EnableEduThemes`<br>**Data type**: int<br>**Value**: `1`|
|
||||
|
||||
#### [:::image type="icon" source="images/icons/provisioning-package.svg"::: **PPKG**](#tab/ppkg)
|
||||
|
||||
@ -46,15 +51,15 @@ Follow the steps in [Apply a provisioning package][WIN-2] to apply the package t
|
||||
|
||||
## How to use the education themes
|
||||
|
||||
Once the education themes are enabled, the device will download them as soon as a user signs in to the device.
|
||||
Once the education themes are enabled, the device downloads them as soon as a user signs in to the device.
|
||||
|
||||
To change the theme, select **Settings** > **Personalization** > **Themes** > **Select a theme**
|
||||
|
||||
:::image type="content" source="./images/win-11-se-themes.png" alt-text="Windows 11 education themes selection" border="true":::
|
||||
:::image type="content" source="./images/win-11-se-themes.png" alt-text="Screenshot of Windows 11 education themes selection" border="true":::
|
||||
|
||||
-----------
|
||||
|
||||
[MEM-1]: /mem/intune/configuration/custom-settings-windows-10
|
||||
[INT-1]: /mem/intune/configuration/custom-settings-windows-10
|
||||
|
||||
[WIN-1]: /windows/configuration/provisioning-packages/provisioning-create-package
|
||||
[WIN-2]: /windows/configuration/provisioning-packages/provisioning-apply-package
|
@ -1,13 +1,12 @@
|
||||
---
|
||||
title: Configure federated sign-in for Windows devices
|
||||
description: Description of federated sign-in feature for the Education SKUs of Windows 11 and how to configure it via Intune or provisioning packages.
|
||||
ms.date: 05/01/2023
|
||||
description: Learn about federated sign-in in Windows how to configure it.
|
||||
ms.date: 09/11/2023
|
||||
ms.topic: how-to
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11</a>
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE</a>
|
||||
ms.collection:
|
||||
- highpri
|
||||
- tier1
|
||||
- education
|
||||
---
|
||||
@ -77,21 +76,25 @@ To use web sign-in with a federated identity provider, your devices must be conf
|
||||
|
||||
#### [:::image type="icon" source="images/icons/intune.svg"::: **Intune**](#tab/intune)
|
||||
|
||||
To configure federated sign-in using Microsoft Intune, [create a custom profile][MEM-1] with the following settings:
|
||||
[!INCLUDE [intune-settings-catalog-1](../../includes/configure/intune-settings-catalog-1.md)]
|
||||
|
||||
[!INCLUDE [intune-custom-settings-1](includes/intune-custom-settings-1.md)]
|
||||
| Category | Setting name | Value |
|
||||
|--|--|--|
|
||||
| Education | Is Education Environment | Enabled |
|
||||
| Federated Authentication | Enable Web Sign In For Primary User | Enabled |
|
||||
| Authentication | Configure Web Sign In Allowed Urls | Semicolon separated list of domains, for example: `samlidp.clever.com;clever.com;mobile-redirector.clever.com` |
|
||||
| Authentication | Configure Webcam Access Domain Names | This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: `clever.com` |
|
||||
|
||||
[!INCLUDE [intune-settings-catalog-2](../../includes/configure/intune-settings-catalog-2.md)]
|
||||
|
||||
Alternatively, you can configure devices using a [custom policy][INT-1] with the following settings:
|
||||
|
||||
| Setting |
|
||||
|--------|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/Education/IsEducationEnvironment`** </li><li>Data type: **Integer** </li><li>Value: **1**</li>|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/FederatedAuthentication/EnableWebSignInForPrimaryUser`** </li><li>Data type: **Integer** </li><li>Value: **1**</li>|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/Authentication/ConfigureWebSignInAllowedUrls`** </li><li>Data type: **String** </li><li>Value: Semicolon separated list of domains, for example: **`samlidp.clever.com;clever.com;mobile-redirector.clever.com`**</li>|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/Authentication/ConfigureWebCamAccessDomainNames`** </li><li>Data type: **String** </li><li>Value: This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: **`clever.com`**</li>|
|
||||
|
||||
:::image type="content" source="images/federated-sign-in-settings-intune.png" alt-text="Custom policy showing the settings to be configured to enable federated sign-in" lightbox="images/federated-sign-in-settings-intune.png" border="true":::
|
||||
|
||||
[!INCLUDE [intune-custom-settings-2](includes/intune-custom-settings-2.md)]
|
||||
[!INCLUDE [intune-custom-settings-info](includes/intune-custom-settings-info.md)]
|
||||
| **OMA-URI**: `./Vendor/MSFT/Policy/Config/Education/IsEducationEnvironment`<br>**Data type**: int<br>**Value**: `1`|
|
||||
| **OMA-URI**: `./Vendor/MSFT/Policy/Config/FederatedAuthentication/EnableWebSignInForPrimaryUser`<br>**Data type**: int<br>**Value**: `1`|
|
||||
| **OMA-URI**: `./Vendor/MSFT/Policy/Config/Authentication/ConfigureWebSignInAllowedUrls`<br>**Data type**: String <br>**Value**: Semicolon separated list of domains, for example: `samlidp.clever.com;clever.com;mobile-redirector.clever.com`|
|
||||
| **OMA-URI**: `./Vendor/MSFT/Policy/Config/Authentication/ConfigureWebCamAccessDomainNames`** <br>**Data type**: String <br>**Value**: This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: `clever.com`|
|
||||
|
||||
#### [:::image type="icon" source="images/icons/provisioning-package.svg"::: **PPKG**](#tab/ppkg)
|
||||
|
||||
@ -99,12 +102,12 @@ To configure federated sign-in using a provisioning package, use the following s
|
||||
|
||||
| Setting |
|
||||
|--------|
|
||||
| <li> Path: **`Education/IsEducationEnvironment`** </li><li>Value: **Enabled**</li>|
|
||||
| <li> Path: **`FederatedAuthentication/EnableWebSignInForPrimaryUser`** </li><li>Value: **Enabled**</li>|
|
||||
| <li> Path: **`Policies/Authentication/ConfigureWebSignInAllowedUrls`** </li><li>Value: Semicolon separated list of domains, for example: **`samlidp.clever.com;clever.com;mobile-redirector.clever.com`**</li>|
|
||||
| <li> Path: **`Policies/Authentication/ConfigureWebCamAccessDomainNames`** </li><li>Value: This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: **`clever.com`**</li>|
|
||||
| **Path**: `Education/IsEducationEnvironment` <br>**Value**: Enabled|
|
||||
| **Path**: `FederatedAuthentication/EnableWebSignInForPrimaryUser` <br>**Value**: Enabled|
|
||||
| **Path**: `Policies/Authentication/ConfigureWebSignInAllowedUrls` <br>**Value**: Semicolon separated list of domains, for example: `samlidp.clever.com;clever.com;mobile-redirector.clever.com`|
|
||||
| **Path**: `Policies/Authentication/ConfigureWebCamAccessDomainNames` <br>**Value**: This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: `clever.com`|
|
||||
|
||||
:::image type="content" source="images/federated-sign-in-settings-ppkg.png" alt-text="Custom policy showing the settings to be configured to enable federated sign-in" lightbox="images/federated-sign-in-settings-ppkg.png" border="true":::
|
||||
:::image type="content" source="images/federated-sign-in-settings-ppkg.png" alt-text="Screenshot of Custom policy showing the settings to be configured to enable federated sign-in" lightbox="images/federated-sign-in-settings-ppkg.png" border="true":::
|
||||
|
||||
Apply the provisioning package to the single-user devices that require federated sign-in.
|
||||
|
||||
@ -119,20 +122,27 @@ To use web sign-in with a federated identity provider, your devices must be conf
|
||||
|
||||
#### [:::image type="icon" source="images/icons/intune.svg"::: **Intune**](#tab/intune)
|
||||
|
||||
To configure federated sign-in using Microsoft Intune, [create a custom profile][MEM-1] with the following settings:
|
||||
[!INCLUDE [intune-settings-catalog-1](../../includes/configure/intune-settings-catalog-1.md)]
|
||||
|
||||
[!INCLUDE [intune-custom-settings-1](includes/intune-custom-settings-1.md)]
|
||||
| Category | Setting name | Value |
|
||||
|--|--|--|
|
||||
| Education | Is Education Environment | Enabled |
|
||||
| SharedPC | Enable Shared PC Mode With OneDrive Sync | True |
|
||||
| Authentication | Enable Web Sign In | Enabled |
|
||||
| Authentication | Configure Web Sign In Allowed Urls | Semicolon separated list of domains, for example: `samlidp.clever.com;clever.com;mobile-redirector.clever.com` |
|
||||
| Authentication | Configure Webcam Access Domain Names | This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: `clever.com` |
|
||||
|
||||
[!INCLUDE [intune-settings-catalog-2](../../includes/configure/intune-settings-catalog-2.md)]
|
||||
|
||||
Alternatively, you can configure devices using a [custom policy][INT-1] with the following settings:
|
||||
|
||||
| Setting |
|
||||
|--------|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/Education/IsEducationEnvironment`** </li><li>Data type: **Integer** </li><li>Value: **1**</li>|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/SharedPC/EnableSharedPCModeWithOneDriveSync`** </li><li>Data type: **Boolean** </li><li>Value: **True**</li>|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/Authentication/EnableWebSignIn`** </li><li>Data type: **Integer** </li><li>Value: **1**</li>|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/Authentication/ConfigureWebSignInAllowedUrls`** </li><li>Data type: **String** </li><li>Value: Semicolon separated list of domains, for example: **`samlidp.clever.com;clever.com;mobile-redirector.clever.com`**</li>|
|
||||
| <li> OMA-URI: **`./Vendor/MSFT/Policy/Config/Authentication/ConfigureWebCamAccessDomainNames`** </li><li>Data type: **String** </li><li>Value: This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: **`clever.com`**</li>|
|
||||
|
||||
[!INCLUDE [intune-custom-settings-2](includes/intune-custom-settings-2.md)]
|
||||
[!INCLUDE [intune-custom-settings-info](includes/intune-custom-settings-info.md)]
|
||||
| **OMA-URI**: `./Vendor/MSFT/Policy/Config/Education/IsEducationEnvironment`<br>**Data type**: int<br>**Value**: `1`|
|
||||
| **OMA-URI**: `./Vendor/MSFT/SharedPC/EnableSharedPCModeWithOneDriveSync`<br>**Data type**: Boolean<br>**Value**: True|
|
||||
| **OMA-URI**: `./Vendor/MSFT/Policy/Config/Authentication/EnableWebSignIn`<br>**Data type**: Integer<br>**Value**: `1`|
|
||||
| **OMA-URI**: `./Vendor/MSFT/Policy/Config/Authentication/ConfigureWebSignInAllowedUrls`<br>**Data type**: String <br>**Value**: Semicolon separated list of domains, for example: `samlidp.clever.com;clever.com;mobile-redirector.clever.com`|
|
||||
| **OMA-URI**: `./Vendor/MSFT/Policy/Config/Authentication/ConfigureWebCamAccessDomainNames`<br>**Data type**: String <br>**Value**: This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: `clever.com`|
|
||||
|
||||
#### [:::image type="icon" source="images/icons/provisioning-package.svg"::: **PPKG**](#tab/ppkg)
|
||||
|
||||
@ -140,11 +150,11 @@ To configure federated sign-in using a provisioning package, use the following s
|
||||
|
||||
| Setting |
|
||||
|--------|
|
||||
| <li> Path: **`Education/IsEducationEnvironment`** </li><li>Value: **Enabled**</li>|
|
||||
| <li> Path: **`SharedPC/EnableSharedPCModeWithOneDriveSync`** </li><li>Value: **True**</li>|
|
||||
| <li> Path: **`Policies/Authentication/EnableWebSignIn`** </li><li>Value: **Enabled**</li>|
|
||||
| <li> Path: **`Policies/Authentication/ConfigureWebSignInAllowedUrls`** </li><li>Value: Semicolon separated list of domains, for example: **`samlidp.clever.com;clever.com;mobile-redirector.clever.com`**</li>|
|
||||
| <li> Path: **`Policies/Authentication/ConfigureWebCamAccessDomainNames`** </li><li>Value: This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: **`clever.com`**</li>|
|
||||
| <li> Path: **`Education/IsEducationEnvironment`**<br>Value: **Enabled**|
|
||||
| <li> Path: **`SharedPC/EnableSharedPCModeWithOneDriveSync`**<br>Value: **True**|
|
||||
| <li> Path: **`Policies/Authentication/EnableWebSignIn`**<br>Value: **Enabled**|
|
||||
| <li> Path: **`Policies/Authentication/ConfigureWebSignInAllowedUrls`**<br>Value: Semicolon separated list of domains, for example: **`samlidp.clever.com;clever.com;mobile-redirector.clever.com`**|
|
||||
| <li> Path: **`Policies/Authentication/ConfigureWebCamAccessDomainNames`**<br>Value: This setting is optional, and it should be configured if you need to use the webcam during the sign-in process. Specify the list of domains that are allowed to use the webcam during the sign-in process, separated by a semicolon. For example: **`clever.com`**|
|
||||
|
||||
Apply the provisioning package to the shared devices that require federated sign-in.
|
||||
|
||||
@ -159,7 +169,7 @@ Once the devices are configured, a new sign-in experience becomes available.
|
||||
|
||||
As users enter their username, they're redirected to the identity provider sign-in page. Once the Idp authenticates the users, they're signed-in. In the following animation, you can observe how the first sign-in process works for a student assigned (1:1) device:
|
||||
|
||||
:::image type="content" source="./images/win-11-se-federated-sign-in.gif" alt-text="Windows 11 SE sign-in using federated sign-in through Clever and QR code badge, in a student assigned (1:1) device." border="false":::
|
||||
:::image type="content" source="./images/win-11-se-federated-sign-in.gif" alt-text="Screenshot of Windows 11 SE sign-in using federated sign-in through Clever and QR code badge, in a student assigned (1:1) device." border="false":::
|
||||
|
||||
> [!IMPORTANT]
|
||||
> For student assigned (1:1) devices, once the policy is enabled, the first user who sign-in to the device will also set the disambiguation page to the identity provider domain on the device. This means that the device will be defaulting to that IdP. The user can exit the federated sign-in flow by pressing <kbd>Ctrl</kbd>+<kbd>Alt</kbd>+<kbd>Delete</kbd> to get back to the standard Windows sign-in screen.
|
||||
@ -203,7 +213,7 @@ After the token sent by the IdP is validated, Azure AD searches for a matching u
|
||||
|
||||
If the matching object is found, the user is signed-in. Otherwise, the user is presented with an error message. The following picture shows that a user with the ImmutableId *260051* can't be found:
|
||||
|
||||
:::image type="content" source="images/federation/user-match-lookup-failure.png" alt-text="Azure AD sign-in error: a user with a matching ImmutableId can't be found in the tenant." lightbox="images/federation/user-match-lookup-failure.png":::
|
||||
:::image type="content" source="images/federation/user-match-lookup-failure.png" alt-text="Screenshot of Azure AD sign-in error: a user with a matching ImmutableId can't be found in the tenant." lightbox="images/federation/user-match-lookup-failure.png":::
|
||||
|
||||
> [!IMPORTANT]
|
||||
> The ImmutableId matching is case-sensitive.
|
||||
@ -245,7 +255,7 @@ Update-MgUser -UserId alton@example.onmicrosoft.com -UserPrincipalName alton@exa
|
||||
[GRAPH-1]: /graph/api/user-post-users?tabs=powershell
|
||||
|
||||
[EXT-1]: https://support.clever.com/hc/s/articles/000001546
|
||||
[MEM-1]: /mem/intune/configuration/custom-settings-windows-10
|
||||
[INT-1]: /mem/intune/configuration/custom-settings-windows-10
|
||||
|
||||
[MSFT-1]: https://www.microsoft.com/download/details.aspx?id=56843
|
||||
|
||||
|
@ -2,9 +2,8 @@
|
||||
title: Get and deploy Minecraft Education
|
||||
description: Learn how to obtain and distribute Minecraft Education to Windows devices.
|
||||
ms.topic: how-to
|
||||
ms.date: 02/23/2023
|
||||
ms.date: 09/11/2023
|
||||
ms.collection:
|
||||
- highpri
|
||||
- education
|
||||
- tier2
|
||||
---
|
||||
|
Before Width: | Height: | Size: 102 KiB |
@ -1,13 +0,0 @@
|
||||
---
|
||||
ms.date: 02/22/2022
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
To configure devices with Microsoft Intune, use a custom policy:
|
||||
|
||||
1. Go to the <a href="https://intune.microsoft.com" target="_blank"><b>Microsoft Intune admin center</b></a>
|
||||
2. Select **Devices > Configuration profiles > Create profile**
|
||||
3. Select **Platform > Windows 10 and later** and **Profile type > Templates > Custom**
|
||||
4. Select **Create**
|
||||
5. Specify a **Name** and, optionally, a **Description > Next**
|
||||
6. Add the following settings:
|
@ -1,9 +0,0 @@
|
||||
---
|
||||
ms.date: 11/08/2022
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
7. Select **Next**
|
||||
8. Assign the policy to a security group that contains as members the devices or users that you want to configure > **Next**
|
||||
9. Under **Applicability Rules**, select **Next**
|
||||
10. Review the policy configuration and select **Create**
|
@ -1,95 +1,181 @@
|
||||
### YamlMime:Landing
|
||||
### YamlMime:Hub
|
||||
|
||||
title: Windows for Education documentation
|
||||
summary: Evaluate, plan, deploy, and manage Windows devices in an education environment
|
||||
summary: Learn how to deploy, secure, and manage Windows clients in an education environment.
|
||||
brand: windows
|
||||
|
||||
metadata:
|
||||
title: Windows for Education documentation
|
||||
description: Learn about how to plan, deploy and manage Windows devices in an education environment with Microsoft Intune
|
||||
ms.topic: landing-page
|
||||
ms.topic: hub-page
|
||||
ms.prod: windows-client
|
||||
ms.technology: itpro-edu
|
||||
ms.collection:
|
||||
- education
|
||||
- highpri
|
||||
- tier1
|
||||
- education
|
||||
- highpri
|
||||
- tier1
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 03/09/2023
|
||||
manager: aaroncz
|
||||
ms.date: 07/28/2023
|
||||
|
||||
landingContent:
|
||||
highlightedContent:
|
||||
items:
|
||||
- title: Get started with Windows 11
|
||||
itemType: get-started
|
||||
url: /windows/whats-new/windows-11-overview
|
||||
- title: Windows 11, version 22H2
|
||||
itemType: whats-new
|
||||
url: /windows/whats-new/whats-new-windows-11-version-22H2
|
||||
- title: Windows 11, version 22H2 group policy settings reference
|
||||
itemType: download
|
||||
url: https://www.microsoft.com/en-us/download/details.aspx?id=104594
|
||||
- title: Windows release health
|
||||
itemType: whats-new
|
||||
url: /windows/release-health
|
||||
- title: Windows commercial licensing
|
||||
itemType: overview
|
||||
url: /windows/whats-new/windows-licensing
|
||||
- title: Windows 365 documentation
|
||||
itemType: overview
|
||||
url: /windows-365
|
||||
- title: Explore all Windows trainings and learning paths for IT pros
|
||||
itemType: learn
|
||||
url: https://learn.microsoft.com/en-us/training/browse/?products=windows&roles=administrator
|
||||
- title: Enroll Windows client devices in Microsoft Intune
|
||||
itemType: how-to-guide
|
||||
url: /mem/intune/fundamentals/deployment-guide-enrollment-windows
|
||||
|
||||
- title: Get started
|
||||
linkLists:
|
||||
- linkListType: tutorial
|
||||
links:
|
||||
- text: Deploy and manage Windows devices in a school
|
||||
url: tutorial-school-deployment/index.md
|
||||
- text: Prepare your tenant
|
||||
url: tutorial-school-deployment/set-up-azure-ad.md
|
||||
- text: Configure settings and applications with Microsoft Intune
|
||||
url: tutorial-school-deployment/configure-devices-overview.md
|
||||
- text: Manage devices with Microsoft Intune
|
||||
url: tutorial-school-deployment/manage-overview.md
|
||||
- text: Management functionalities for Surface devices
|
||||
url: tutorial-school-deployment/manage-surface-devices.md
|
||||
productDirectory:
|
||||
title: Get started
|
||||
items:
|
||||
|
||||
- title: Learn about Windows 11 SE
|
||||
linkLists:
|
||||
- linkListType: concept
|
||||
links:
|
||||
- text: What is Windows 11 SE?
|
||||
url: windows-11-se-overview.md
|
||||
- text: Windows 11 SE settings
|
||||
url: windows-11-se-settings-list.md
|
||||
- linkListType: whats-new
|
||||
links:
|
||||
- text: Configure federated sign-in
|
||||
url: federated-sign-in.md
|
||||
- text: Configure education themes
|
||||
url: edu-themes.md
|
||||
- text: Configure Stickers
|
||||
url: edu-stickers.md
|
||||
- linkListType: video
|
||||
links:
|
||||
- text: Deploy Windows 11 SE using Set up School PCs
|
||||
url: https://www.youtube.com/watch?v=Ql2fbiOop7c
|
||||
- title: Hardware security
|
||||
imageSrc: /media/common/i_usb.svg
|
||||
links:
|
||||
- url: /windows/security/hardware-security/tpm/trusted-platform-module-overview
|
||||
text: Trusted Platform Module
|
||||
- url: /windows/security/hardware-security/pluton/microsoft-pluton-security-processor
|
||||
text: Microsoft Pluton
|
||||
- url: /windows/security/hardware-security/how-hardware-based-root-of-trust-helps-protect-windows
|
||||
text: Windows Defender System Guard
|
||||
- url: /windows-hardware/design/device-experiences/oem-vbs
|
||||
text: Virtualization-based security (VBS)
|
||||
- url: /windows-hardware/design/device-experiences/oem-highly-secure-11
|
||||
text: Secured-core PC
|
||||
- url: /windows/security/hardware-security
|
||||
text: Learn more about hardware security >
|
||||
|
||||
- title: Deploy devices with Set up School PCs
|
||||
linkLists:
|
||||
- linkListType: concept
|
||||
links:
|
||||
- text: What is Set up School PCs?
|
||||
url: set-up-school-pcs-technical.md
|
||||
- linkListType: how-to-guide
|
||||
links:
|
||||
- text: Use the Set up School PCs app
|
||||
url: use-set-up-school-pcs-app.md
|
||||
- linkListType: reference
|
||||
links:
|
||||
- text: Provisioning package settings
|
||||
url: set-up-school-pcs-provisioning-package.md
|
||||
- linkListType: video
|
||||
links:
|
||||
- text: Use the Set up School PCs App
|
||||
url: https://www.youtube.com/watch?v=2ZLup_-PhkA
|
||||
- title: OS security
|
||||
imageSrc: /media/common/i_threat-protection.svg
|
||||
links:
|
||||
- url: /windows/security/operating-system-security
|
||||
text: Trusted boot
|
||||
- url: /windows/security/operating-system-security/system-security/windows-defender-security-center/windows-defender-security-center
|
||||
text: Windows security settings
|
||||
- url: /windows/security/operating-system-security/data-protection/bitlocker/
|
||||
text: BitLocker
|
||||
- url: /windows/security/operating-system-security/device-management/windows-security-configuration-framework/windows-security-baselines
|
||||
text: Windows security baselines
|
||||
- url: /windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/
|
||||
text: MMicrosoft Defender SmartScreen
|
||||
- url: /windows/security/operating-system-security
|
||||
text: Learn more about OS security >
|
||||
|
||||
- title: Configure devices
|
||||
linkLists:
|
||||
- linkListType: concept
|
||||
links:
|
||||
- text: Take tests and assessments in Windows
|
||||
url: take-tests-in-windows.md
|
||||
- text: Considerations for shared and guest devices
|
||||
url: /windows/configuration/shared-devices-concepts?context=/education/context/context
|
||||
- text: Change Windows editions
|
||||
url: change-home-to-edu.md
|
||||
- linkListType: how-to-guide
|
||||
links:
|
||||
- text: Configure Take a Test in kiosk mode
|
||||
url: edu-take-a-test-kiosk-mode.md
|
||||
- text: Configure Shared PC
|
||||
url: /windows/configuration/set-up-shared-or-guest-pc?context=/education/context/context
|
||||
- text: Get and deploy Minecraft Education
|
||||
url: get-minecraft-for-education.md
|
||||
- title: Identity protection
|
||||
imageSrc: /media/common/i_identity-protection.svg
|
||||
links:
|
||||
- url: /windows/security/identity-protection/hello-for-business
|
||||
text: Windows Hello for Business
|
||||
- url: /windows/security/identity-protection/credential-guard
|
||||
text: Credential Guard
|
||||
- url: /windows-server/identity/laps/laps-overview
|
||||
text: Windows LAPS (Local Administrator Password Solution)
|
||||
- url: /windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/enhanced-phishing-protection
|
||||
text: Enhanced phishing protection with SmartScreen
|
||||
- url: /education/windows/federated-sign-in
|
||||
text: Federated sign-in (EDU)
|
||||
- url: /windows/security/identity-protection
|
||||
text: Learn more about identity protection >
|
||||
|
||||
- title: Application security
|
||||
imageSrc: /media/common/i_queries.svg
|
||||
links:
|
||||
- url: /windows/security/application-security/application-control/windows-defender-application-control/
|
||||
text: Windows Defender Application Control (WDAC)
|
||||
- url: /windows/security/application-security/application-control/user-account-control
|
||||
text: User Account Control (UAC)
|
||||
- url: /windows/security/application-security/application-control/windows-defender-application-control/design/microsoft-recommended-driver-block-rules
|
||||
text: Microsoft vulnerable driver blocklist
|
||||
- url: /windows/security/application-security/application-isolation/microsoft-defender-application-guard/md-app-guard-overview
|
||||
text: Microsoft Defender Application Guard (MDAG)
|
||||
- url: /windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview
|
||||
text: Windows Sandbox
|
||||
- url: /windows/security/application-security
|
||||
text: Learn more about application security >
|
||||
|
||||
- title: Security foundations
|
||||
imageSrc: /media/common/i_build.svg
|
||||
links:
|
||||
- url: /windows/security/security-foundations/certification/fips-140-validation
|
||||
text: FIPS 140-2 validation
|
||||
- url: /windows/security/security-foundations/certification/windows-platform-common-criteria
|
||||
text: Common Criteria Certifications
|
||||
- url: /windows/security/security-foundations/msft-security-dev-lifecycle
|
||||
text: Microsoft Security Development Lifecycle (SDL)
|
||||
- url: https://www.microsoft.com/msrc/bounty-windows-insider-preview
|
||||
text: Microsoft Windows Insider Preview bounty program
|
||||
- url: https://www.microsoft.com/security/blog/2020/09/15/microsoft-onefuzz-framework-open-source-developer-tool-fix-bugs/
|
||||
text: OneFuzz service
|
||||
- url: /windows/security/security-foundations
|
||||
text: Learn more about security foundations >
|
||||
|
||||
- title: Cloud security
|
||||
imageSrc: /media/common/i_cloud-security.svg
|
||||
links:
|
||||
- url: /mem/intune/protect/security-baselines
|
||||
text: Security baselines with Intune
|
||||
- url: /windows/deployment/windows-autopatch
|
||||
text: Windows Autopatch
|
||||
- url: /windows/deployment/windows-autopilot
|
||||
text: Windows Autopilot
|
||||
- url: /universal-print
|
||||
text: Universal Print
|
||||
- url: /windows/client-management/mdm/remotewipe-csp
|
||||
text: Remote wipe
|
||||
- url: /windows/security/cloud-security
|
||||
text: Learn more about cloud security >
|
||||
|
||||
additionalContent:
|
||||
sections:
|
||||
- title: More Windows resources
|
||||
items:
|
||||
|
||||
- title: Windows Server
|
||||
links:
|
||||
- text: Windows Server documentation
|
||||
url: /windows-server
|
||||
- text: What's new in Windows Server 2022?
|
||||
url: /windows-server/get-started/whats-new-in-windows-server-2022
|
||||
- text: Windows Server blog
|
||||
url: https://cloudblogs.microsoft.com/windowsserver/
|
||||
|
||||
- title: Windows product site and blogs
|
||||
links:
|
||||
- text: Find out how Windows enables your business to do more
|
||||
url: https://www.microsoft.com/microsoft-365/windows
|
||||
- text: Windows blogs
|
||||
url: https://blogs.windows.com/
|
||||
- text: Windows IT Pro blog
|
||||
url: https://techcommunity.microsoft.com/t5/windows-it-pro-blog/bg-p/Windows10Blog
|
||||
- text: Microsoft Intune blog
|
||||
url: https://techcommunity.microsoft.com/t5/microsoft-intune-blog/bg-p/MicrosoftEndpointManagerBlog
|
||||
- text: "Windows help & learning: end-user documentation"
|
||||
url: https://support.microsoft.com/windows
|
||||
|
||||
- title: Participate in the community
|
||||
links:
|
||||
- text: Windows community
|
||||
url: https://techcommunity.microsoft.com/t5/windows/ct-p/Windows10
|
||||
- text: Microsoft Intune community
|
||||
url: https://techcommunity.microsoft.com/t5/microsoft-intune/bd-p/Microsoft-Intune
|
||||
- text: Microsoft Support community
|
||||
url: https://answers.microsoft.com/windows/forum
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Azure AD Join with Set up School PCs app
|
||||
description: Learn how Azure AD Join is configured in the Set up School PCs app.
|
||||
ms.topic: article
|
||||
ms.topic: reference
|
||||
ms.date: 08/10/2022
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10</a>
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: What's in Set up School PCs provisioning package
|
||||
description: List of the provisioning package settings that are configured in the Set up School PCs app.
|
||||
ms.date: 08/10/2022
|
||||
description: Learn about the settings that are configured in the provisioning package created with the Set up School PCs app.
|
||||
ms.date: 06/02/2023
|
||||
ms.topic: reference
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10</a>
|
||||
@ -11,115 +11,122 @@ appliesto:
|
||||
|
||||
The Set up School PCs app builds a specialized provisioning package with school-optimized settings.
|
||||
|
||||
A key feature of the provisioning package is Shared PC mode. To view the technical framework of Shared PC mode, including the description of each setting, see the [Manage multi-user and guest Windows devices with Shared PC](/windows/configuration/shared-pc-technical) article.
|
||||
A key feature of the provisioning package is SharedPC mode. To learn about the technical framework of SharedPC mode, including the description of each setting, see the [Manage multi-user and guest Windows devices with Shared PC](/windows/configuration/shared-pc-technical) article.
|
||||
|
||||
## Shared PC Mode policies
|
||||
This table outlines the policies applied to devices in shared PC mode. If you select to optimize a device for use by a single student, you'll see differences in the following policies:
|
||||
* Disk level deletion
|
||||
* Inactive threshold
|
||||
* Restrict local storage
|
||||
|
||||
The following table outlines the policies applied to devices in SharedPC mode. If you select to optimize a device for use by a single student, you find differences in the policies applied:
|
||||
|
||||
- Disk level deletion
|
||||
- Inactive threshold
|
||||
- Restrict local storage
|
||||
|
||||
In the table, *True* means that the setting is enabled, allowed, or applied. Use the **Description** column to help you understand the context for each setting.
|
||||
|
||||
For a more detailed look at the policies, see the Windows article [Set up shared or guest PC](/windows/configuration/set-up-shared-or-guest-pc#policies-set-by-shared-pc-mode).
|
||||
|
||||
|Policy name|Default value|Description|
|
||||
|---------|---------|---------|
|
||||
|Enable Shared PC mode|True| Configures the PCs so they're in shared PC mode.|
|
||||
|Set education policies | True | School-optimized settings are applied to the PCs so that they're appropriate for an educational environment. To see all recommended and enabled policies, see [Windows 10 configuration recommendation for education customers](./configure-windows-for-education.md). |
|
||||
|Account Model| Only guest, Domain-joined only, or Domain-joined and guest |Controls how users can sign in on the PC. Configurable from the Set up School PCs app. Choosing domain-joined will enable any user in the domain to sign in. Specifying the guest option will add the Guest option to the sign-in screen and enable anonymous guest access to the PC. |
|
||||
|Deletion policy | Delete at disk space threshold and inactive threshold | Delete at disk space threshold will start deleting accounts when available disk space falls below the threshold you set for disk level deletion. It will stop deleting accounts when the available disk space reaches the threshold you set for disk level caching. Accounts are deleted in order of oldest accessed to most recently accessed. Also deletes accounts if they haven't signed in within the number of days specified by inactive threshold policy. |
|
||||
|Disk level caching | 50% | Sets 50% of total disk space to be used as the disk space threshold for account caching. |
|
||||
|Disk level deletion | For shared device setup, 25%; for single device-student setup, 0%. | When your devices are optimized for shared use across multiple PCs, this policy sets 25% of total disk space to be used as the disk space threshold for account caching. When your devices are optimized for use by a single student, this policy sets the value to 0% and doesn't delete accounts. |
|
||||
|Enable account manager | True | Enables automatic account management. |
|
||||
|Inactive threshold| For shared device setup, 30 days; for single device-student setup, 180 days.| After 30 or 180 days, respectively, if an account hasn't signed in, it will be deleted.
|
||||
|Kiosk Mode AMUID | Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy!App | Configures the kiosk account on student devices to only run the Take a Test secure assessment browser. |
|
||||
|Kiosk Mode User Tile Display Text | Take a Test | Displays "Take a Test" as the name of the kiosk account on student devices. |
|
||||
|Restrict local storage | For shared device setup, True; for single device-student setup, False. | When devices are optimized for shared use across multiple PCs, this policy forces students to save to the cloud to prevent data loss. When your devices are optimized for use by a single student, this policy doesn't prevent students from saving on the PCs local hard drive. |
|
||||
|Maintenance start time | 0 - midnight | The maintenance start time when automatic maintenance tasks, such as Windows Update, run on student devices. |
|
||||
|Max page file size in MB| 1024| Sets the maximum size of the paging file to 1024 MB. Applies only to systems with less than 32-GB storage and at least 3 GB of RAM.|
|
||||
|Set power policies | True | Prevents users from changing power settings and turns off hibernate. Also overrides all power state transitions to sleep, such as lid close. |
|
||||
|Sign in on resume | True | Requires the device user to sign in with a password when the PC wakes from sleep. |
|
||||
|Sleep timeout | 3600 seconds | Specifies the maximum idle time before the PC should sleep. If you don't set sleep timeout, the default time, 3600 seconds (1 hour), is applied. |
|
||||
| Policy name | Default value | Description |
|
||||
|--|--|--|
|
||||
| Enable Shared PC mode | True | Configures the PCs so they're in shared PC mode. |
|
||||
| Set education policies | True | School-optimized settings are applied to the PCs so that they're appropriate for an educational environment. To see all recommended and enabled policies, see [Windows 10 configuration recommendation for education customers](./configure-windows-for-education.md). |
|
||||
| Account Model | Only guest, Domain-joined only, or Domain-joined and guest | Controls how users can sign in on the PC. Configurable from the Set up School PCs app. Choosing domain-joined enables any user in the domain to sign in. Specifying the guest option adds the Guest option to the sign-in screen and enable anonymous guest access to the PC. |
|
||||
| Deletion policy | Delete at disk space threshold and inactive threshold | Delete at disk space threshold starts deleting accounts when available disk space falls below the threshold you set for disk level deletion. It stops deleting accounts when the available disk space reaches the threshold you set for disk level caching. Accounts are deleted in order of oldest accessed to most recently accessed. Also deletes accounts if they haven't signed in within the number of days specified by inactive threshold policy. |
|
||||
| Disk level caching | 50% | Sets 50% of total disk space to be used as the disk space threshold for account caching. |
|
||||
| Disk level deletion | For shared device setup, 25%; for single device-student setup, 0%. | When devices are optimized for shared use, the policy sets 25% of total disk space as the disk space threshold for account caching. When devices are optimized for use by a single student, the policy sets the value to 0% and doesn't delete accounts. |
|
||||
| Enable account manager | True | Enables automatic account management. |
|
||||
| Inactive threshold | For shared device setup, 30 days; for single device-student setup, 180 days. | After 30 or 180 days, respectively, if an account hasn't signed in, it will be deleted. |
|
||||
| Kiosk Mode AMUID | `Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy!App` | Configures the kiosk account on student devices to only run the Take a Test secure assessment browser. |
|
||||
| Kiosk Mode User Tile Display Text | Take a Test | Displays "Take a Test" as the name of the kiosk account on student devices. |
|
||||
| Restrict local storage | For shared device setup, True; for single device-student setup, False. | When devices are optimized for shared use across multiple PCs, this policy forces students to save to the cloud to prevent data loss. When your devices are optimized for use by a single student, this policy doesn't prevent students from saving on the PCs local hard drive. |
|
||||
| Maintenance start time | 0 - midnight | The maintenance start time when automatic maintenance tasks, such as Windows Update, run on student devices. |
|
||||
| Max page file size in MB | 1024 | Sets the maximum size of the paging file to 1024 MB. Applies only to systems with less than 32-GB storage and at least 3 GB of RAM. |
|
||||
| Set power policies | True | Prevents users from changing power settings and turns off hibernate. Also overrides all power state transitions to sleep, such as lid close. |
|
||||
| Sign in on resume | True | Requires the device user to sign in with a password when the PC wakes from sleep. |
|
||||
| Sleep timeout | 3600 seconds | Specifies the maximum idle time before the PC should sleep. If you don't set sleep timeout, the default time, 3600 seconds (1 hour), is applied. |
|
||||
|
||||
## MDM and local group policies
|
||||
|
||||
This section lists only the MDM and local group policies that are configured uniquely for the Set up School PCs app.
|
||||
|
||||
For a more detailed look of each policy listed, see [Policy CSP](/windows/client-management/mdm/policy-configuration-service-provider) in the Windows IT Pro Center documentation.
|
||||
|
||||
| Policy name | Default value | Description |
|
||||
|--|--|--|
|
||||
| Authority | User-defined | Authenticates the admin user. Value is set automatically when signed in to Azure AD. |
|
||||
| BPRT | User-defined | Value is set automatically when signed in to Azure AD. Allows you to create the provisioning package. |
|
||||
| WLAN Setting | XML is generated from the Wi-Fi profile in the Set up School PCs app. | Configures settings for wireless connectivity. |
|
||||
| Hide OOBE for desktop | True | Hides the interactive OOBE flow for Windows 10. |
|
||||
| Download Mode | 1 - HTTP blended with peering behind the same NAT | Specifies the download method that Delivery Optimization can use in downloads of Windows Updates, Apps, and App updates |
|
||||
| Select when Preview Builds and Feature Updates are received | 32 - Semi-annual Channel. Device gets feature updates from Semi-annual Channel | Specifies how frequently devices receive preview builds and feature updates. |
|
||||
| Allow auto update | 4 - Auto-installs and restarts without device-user control | When an auto update is available, it auto-installs and restarts the device without any input or action from the device user. |
|
||||
| Configure automatic updates | 3 - Set to install at 3am | Scheduled time to install updates. |
|
||||
| Update power policy for cart restarts | 1 - Configured | Skips all restart checks to ensure that the reboot will happen at the scheduled install time. |
|
||||
| Select when Preview Builds and Feature Updates are received | 365 days | Defers Feature Updates for the specified number of days. When not specified, defaults to 365 days. |
|
||||
| Allow all trusted apps | Disabled | Prevents untrusted apps from being installed to device |
|
||||
| Allow developer unlock | Disabled | Students can't unlock the PC and use it in developer mode |
|
||||
| Allow Cortana | Disabled | Cortana isn't allowed on the device. |
|
||||
| Allow manual MDM unenrollment | Disabled | Students can't remove the mobile device manager from their device. |
|
||||
| Settings page visibility | Enabled | Specific pages in the System Settings app aren't visible or accessible to students. |
|
||||
| Allow add provisioning package | Disabled | Students can't add and upload new provisioning packages to their device. |
|
||||
| Allow remove provisioning package | Disabled | Students can't remove packages that you've uploaded to their device, including the Set up School PCs app |
|
||||
| Start Layout | Enabled | Lets you specify the Start layout for users and prevents them from changing the configuration. |
|
||||
| Import Edge Assets | Enabled | Import Microsoft Edge assets, such as PNG and JPG files, for secondary tiles on the Start layout. Tiles will appear as weblinks and will be tied to the relevant image asset files. |
|
||||
| Allow pinned folder downloads | 1 - The shortcut is visible and disables the setting in the Settings app | Makes the Downloads shortcut on the Start menu visible to students. |
|
||||
| Allow pinned folder File Explorer | 1 - The shortcut is visible and disables the setting in the Settings app | Makes the File Explorer shortcut on the Start menu visible to students. |
|
||||
| Personalization | Deploy lock screen image | Set to the image you picked when you customized the lock screen during device setup. If you didn't customize the image, the computer will show the default. |
|
||||
| Personalization | Lock screen image URL | Image filename |
|
||||
| Update | Active hours end | 5 PM |
|
||||
| Update | Active hours start | 7 AM |
|
||||
| Updates Windows | Nightly | Sets Windows to update on a nightly basis. |
|
||||
|
||||
| Policy name | Default value | Description |
|
||||
|-------------------------------------------------------------|--------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| Authority | User-defined | Authenticates the admin user. Value is set automatically when signed in to Azure AD. |
|
||||
| BPRT | User-defined | Value is set automatically when signed in to Azure AD. Allows you to create the provisioning package. |
|
||||
| WLAN Setting | XML is generated from the Wi-Fi profile in the Set up School PCs app. | Configures settings for wireless connectivity. |
|
||||
| Hide OOBE for desktop | True | Hides the interactive OOBE flow for Windows 10. |
|
||||
| Download Mode | 1 - HTTP blended with peering behind the same NAT | Specifies the download method that Delivery Optimization can use in downloads of Windows Updates, Apps, and App updates |
|
||||
| Select when Preview Builds and Feature Updates are received | 32 - Semi-annual Channel. Device gets feature updates from Semi-annual Channel | Specifies how frequently devices receive preview builds and feature updates. |
|
||||
| Allow auto update | 4 - Auto-installs and restarts without device-user control | When an auto update is available, it auto-installs and restarts the device without any input or action from the device user. |
|
||||
| Configure automatic updates | 3 - Set to install at 3am | Scheduled time to install updates. |
|
||||
| Update power policy for cart restarts | 1 - Configured | Skips all restart checks to ensure that the reboot will happen at the scheduled install time. |
|
||||
| Select when Preview Builds and Feature Updates are received | 365 days | Defers Feature Updates for the specified number of days. When not specified, defaults to 365 days. |
|
||||
| Allow all trusted apps | Disabled | Prevents untrusted apps from being installed to device |
|
||||
| Allow developer unlock | Disabled | Students can't unlock the PC and use it in developer mode |
|
||||
| Allow Cortana | Disabled | Cortana isn't allowed on the device. |
|
||||
| Allow manual MDM unenrollment | Disabled | Students can't remove the mobile device manager from their device. |
|
||||
| Settings page visibility | Enabled | Specific pages in the System Settings app aren't visible or accessible to students. |
|
||||
| Allow add provisioning package | Disabled | Students can't add and upload new provisioning packages to their device. |
|
||||
| Allow remove provisioning package | Disabled | Students can't remove packages that you've uploaded to their device, including the Set up School PCs app |
|
||||
| Start Layout | Enabled | Lets you specify the Start layout for users and prevents them from changing the configuration. |
|
||||
| Import Edge Assets | Enabled | Import Microsoft Edge assets, such as PNG and JPG files, for secondary tiles on the Start layout. Tiles will appear as weblinks and will be tied to the relevant image asset files. |
|
||||
| Allow pinned folder downloads | 1 - The shortcut is visible and disables the setting in the Settings app | Makes the Downloads shortcut on the Start menu visible to students. |
|
||||
| Allow pinned folder File Explorer | 1 - The shortcut is visible and disables the setting in the Settings app | Makes the File Explorer shortcut on the Start menu visible to students. |
|
||||
| Personalization | Deploy lock screen image | Set to the image you picked when you customized the lock screen during device setup. If you didn't customize the image, the computer will show the default. |
|
||||
| Personalization | Lock screen image URL | Image filename |
|
||||
| Update | Active hours end | 5 PM |
|
||||
| Update | Active hours start | 7 AM |
|
||||
| Updates Windows | Nightly | Sets Windows to update on a nightly basis. |
|
||||
## Apps uninstalled from Windows devices
|
||||
|
||||
## Apps uninstalled from Windows 10 devices
|
||||
Set up School PCs app uses the Universal app uninstall policy. This policy identifies default apps that aren't relevant to the classroom experience, and uninstalls them from each device. ALl apps uninstalled from Windows 10 devices include:
|
||||
Set up School PCs app uses the Universal app uninstall policy. The policy identifies default apps that aren't relevant to the classroom experience, and uninstalls them from each device. The apps uninstalled from Windows devices are:
|
||||
|
||||
- Mixed Reality Viewer
|
||||
- Weather
|
||||
- Desktop App Installer
|
||||
- Tips
|
||||
- Messaging
|
||||
- My Office
|
||||
- Microsoft Solitaire Collection
|
||||
- Mobile Plans
|
||||
- Feedback Hub
|
||||
- Xbox
|
||||
- Mail/Calendar
|
||||
- Skype
|
||||
|
||||
* Mixed Reality Viewer
|
||||
* Weather
|
||||
* Desktop App Installer
|
||||
* Tips
|
||||
* Messaging
|
||||
* My Office
|
||||
* Microsoft Solitaire Collection
|
||||
* Mobile Plans
|
||||
* Feedback Hub
|
||||
* Xbox
|
||||
* Mail/Calendar
|
||||
* Skype
|
||||
## Apps installed on Windows devices
|
||||
|
||||
## Apps installed on Windows 10 devices
|
||||
Set up School PCs uses the Universal app install policy to install school-relevant apps on all Windows 10 devices. Apps that are installed include:
|
||||
* OneDrive
|
||||
* OneNote
|
||||
* Sway
|
||||
Set up School PCs uses the Universal app install policy to install school-relevant apps on all Windows 10 devices. The following apps are installed:
|
||||
|
||||
- OneDrive
|
||||
- OneNote
|
||||
- Sway
|
||||
|
||||
## Provisioning time estimates
|
||||
|
||||
The time it takes to install a package on a device depends on the:
|
||||
|
||||
* Strength of network connection
|
||||
* Number of policies and apps within the package
|
||||
* Other configurations made to the device
|
||||
- Strength of network connection
|
||||
- Number of policies and apps within the package
|
||||
- Other configurations made to the device
|
||||
|
||||
Review the table below to estimate your expected provisioning time. A package that only applies Set Up School PC's default configurations will provision the fastest. A package that removes pre-installed apps, through CleanPC, will take much longer to provision.
|
||||
Review the table below to estimate your expected provisioning time. A package that only applies Set Up School PC's default configurations will provision the fastest. A package that removes preinstalled apps, through CleanPC, will take much longer to provision.
|
||||
|
||||
|Configurations |Connection type |Estimated provisioning time |
|
||||
|---------|---------|---------|
|
||||
|Default settings only | Wi-Fi | 3 to 5 minutes |
|
||||
|Default settings + apps | Wi-Fi | 10 to 15 minutes |
|
||||
|Default settings + remove pre-installed apps (CleanPC) | Wi-Fi | 60 minutes |
|
||||
|Default settings + other settings (Not CleanPC) | Wi-Fi | 5 minutes |
|
||||
| Configurations | Connection type | Estimated provisioning time |
|
||||
|--|--|--|
|
||||
| Default settings only | Wi-Fi | 3 to 5 minutes |
|
||||
| Default settings + apps | Wi-Fi | 10 to 15 minutes |
|
||||
| Default settings + remove preinstalled apps (CleanPC) | Wi-Fi | 60 minutes |
|
||||
| Default settings + other settings (Not CleanPC) | Wi-Fi | 5 minutes |
|
||||
|
||||
## Next steps
|
||||
|
||||
Learn more about setting up devices with the Set up School PCs app.
|
||||
* [Azure AD Join with Set up School PCs](set-up-school-pcs-azure-ad-join.md)
|
||||
* [Set up School PCs technical reference](set-up-school-pcs-technical.md)
|
||||
* [Set up Windows 10 devices for education](set-up-windows-10.md)
|
||||
|
||||
- [Azure AD Join with Set up School PCs](set-up-school-pcs-azure-ad-join.md)
|
||||
- [Set up School PCs technical reference](set-up-school-pcs-technical.md)
|
||||
- [Set up Windows 10 devices for education](set-up-windows-10.md)
|
||||
|
||||
When you're ready to create and apply your provisioning package, see [Use Set up School PCs app](use-set-up-school-pcs-app.md).
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Set up School PCs app technical reference overview
|
||||
description: Describes the purpose of the Set up School PCs app for Windows 10 devices.
|
||||
ms.topic: conceptual
|
||||
ms.topic: overview
|
||||
ms.date: 08/10/2022
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10</a>
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Set up Windows devices for education
|
||||
description: Decide which option for setting up Windows 10 is right for you.
|
||||
ms.topic: article
|
||||
ms.topic: overview
|
||||
ms.date: 08/10/2022
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10</a>
|
||||
@ -10,8 +10,9 @@ appliesto:
|
||||
# Set up Windows devices for education
|
||||
|
||||
You have two tools to choose from to set up PCs for your classroom:
|
||||
* Set up School PCs
|
||||
* Windows Configuration Designer
|
||||
|
||||
- Set up School PCs
|
||||
- Windows Configuration Designer
|
||||
|
||||
Choose the tool that is appropriate for how your students will sign in (Active Directory, Azure Active Directory, or no account).
|
||||
|
||||
@ -29,4 +30,4 @@ You can use the following diagram to compare the tools.
|
||||
## Related topics
|
||||
|
||||
[Take tests in Windows](take-tests-in-windows.md)
|
||||
[Deploy Windows 10 in a school](deploy-windows-10-in-a-school.md)
|
||||
[Deploy Windows 10 in a school](deploy-windows-10-in-a-school.md)S
|
@ -2,7 +2,7 @@
|
||||
title: Take tests and assessments in Windows
|
||||
description: Learn about the built-in Take a Test app for Windows and how to use it.
|
||||
ms.date: 03/31/2023
|
||||
ms.topic: conceptual
|
||||
ms.topic: how-to
|
||||
---
|
||||
|
||||
# Take tests and assessments in Windows
|
||||
|
@ -6,6 +6,8 @@ items:
|
||||
items:
|
||||
- name: Deploy and manage Windows devices in a school
|
||||
href: tutorial-school-deployment/toc.yml
|
||||
- name: Deploy applications to Windows 11 SE
|
||||
href: tutorial-deploy-apps-winse/toc.yml
|
||||
- name: Concepts
|
||||
items:
|
||||
- name: Windows 11 SE
|
@ -0,0 +1,53 @@
|
||||
---
|
||||
title: Important considerations before deploying apps with managed installer
|
||||
description: Learn about important aspects to consider before deploying apps with managed installer.
|
||||
ms.date: 06/19/2023
|
||||
ms.topic: tutorial
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE, version 22H2 and later</a>
|
||||
---
|
||||
|
||||
# Important considerations before deploying apps with Managed Installer
|
||||
|
||||
This article describes important aspects to consider before deploying apps with managed installer.
|
||||
|
||||
## Existing apps deployed in Intune
|
||||
|
||||
If you have Windows 11 SE devices that already have apps deployed through Intune, the apps won't get retroactively tagged with the *managed installer* mark. You may need to redeploy the apps through Intune to get them properly tagged with managed installer and allowed to run.
|
||||
|
||||
## Enrollment Status Page
|
||||
|
||||
The Enrollment Status Page (ESP) is compatible with Windows 11 SE. However, due to the Windows 11 SE base policy, devices can be blocked from completing enrollment if:
|
||||
|
||||
1. You have the ESP configured to block device use until required apps are installed, and
|
||||
2. You deploy an app that is blocked by the Windows 11 SE base policy, not installable via a managed installer (without more policies), and not allowed by any supplemental policies or AppLocker policies
|
||||
<!--
|
||||
For example, if you deploy a UWP LOB app but haven't deployed a supplemental policy to allow the app, ESP will fail.-->
|
||||
|
||||
If you choose to block device use on the installation of apps, you must ensure that apps are also not blocked from installation.
|
||||
|
||||
:::image type="content" source="./images/esp-error.png" alt-text="Screenshot of the Enrollment Status Page showing an error in OOBE on Windows 11 SE." border="false":::
|
||||
|
||||
### ESP errors mitigation
|
||||
|
||||
To ensure that you don't run into installation or enrollment blocks, you can pick one of the following options, in accordance with your internal policies:
|
||||
|
||||
1. Ensure that all apps are unblocked from installation. Apps must be compatible with the Windows 11 SE managed installer flow, and if they aren't compatible out-of-box, have the corresponding supplemental policy to allow them
|
||||
2. Don't deploy apps that you haven't validated
|
||||
3. Set your Enrollment Status Page configuration to not block device use based on required apps
|
||||
|
||||
To learn more about the ESP, see [Set up the Enrollment Status Page][MEM-1].
|
||||
|
||||
## Potential impact to events collected by Log Analytics integrations
|
||||
|
||||
Log Analytics is a cloud service that can be used to collect data from AppLocker policy events. Windows 11 SE devices enrolled in an Intune Education tenant will automatically receive an AppLocker policy. The result is an increase in events generated by the AppLocker policy.
|
||||
|
||||
If your organization is using Log Analytics, it's recommended to review your Log Analytics setup to:
|
||||
|
||||
- Ensure there's an appropriate data collection cap in place to avoid unexpected billing costs
|
||||
- Turn off the collection of non-error AppLocker events in Log Analytics, except for MSI and Script logs
|
||||
|
||||
For more information, see [Use Event Viewer with AppLocker][WIN-1]
|
||||
|
||||
[MEM-1]: /mem/intune/enrollment/windows-enrollment-status
|
||||
[WIN-1]: /windows/security/threat-protection/windows-defender-application-control/applocker/using-event-viewer-with-applocker
|
210
education/windows/tutorial-deploy-apps-winse/create-policies.md
Normal file
@ -0,0 +1,210 @@
|
||||
---
|
||||
title: Create policies to enable applications
|
||||
description: Learn how to create policies to enable the installation and execution of apps on Windows SE.
|
||||
ms.date: 06/19/2023
|
||||
ms.topic: tutorial
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE, version 22H2 and later</a>
|
||||
---
|
||||
|
||||
# Create policies to enable applications
|
||||
|
||||
:::row:::
|
||||
:::column span="":::
|
||||
<a href="deploy-apps.md"><img src="images/phase-1-off.svg" alt="Icon representing the first phase."/></a><br>
|
||||
[**Deploy an application via Microsoft Intune**](deploy-apps.md)
|
||||
:::column-end:::
|
||||
:::column span="":::
|
||||
<a href="validate-apps.md"><img src="images/phase-2-off.svg" alt="Icon representing the second phase."/></a><br>
|
||||
[**Validate the application**](validate-apps.md)
|
||||
:::column-end:::
|
||||
:::column span="":::
|
||||
<a href="create-policies.md"><img src="images/phase-3-on.svg" alt="Icon representing the third phase."/></a><br>
|
||||
[**Create additional policies (optional)**](create-policies.md)
|
||||
:::column-end:::
|
||||
:::row-end:::
|
||||
|
||||
|
||||
You can create AppLocker policies to allow apps that are [semi-compatible](./validate-apps.md#semi-compatible-apps) or [incompatible](./validate-apps.md#incompatible-apps) with the managed installer to run.
|
||||
|
||||
<!--
|
||||
You can create policies to allow applications that are [semi-compatible](./validate-apps.md#semi-compatible-apps) or [incompatible](./validate-apps.md#incompatible-apps) with the managed installer.
|
||||
|
||||
The following table details the two policy types to allow apps to run:
|
||||
|
||||
| **Policy type** | **How it works** | **When should I use this policy?** | **Security risk** |
|
||||
|---|---|---|---|
|
||||
| WDAC supplemental policy | Allows apps meeting the rule criteria to run | For executables that the Windows 11 SE base policy blocks. The blocked executables are visible from the Event Viewer in the [CodeIntegrity events](./troubleshoot.md). | Low |
|
||||
| AppLocker policy | Sets an app to be considered as a managed installer | Only for executables that do installations or updates, that the Windows 11 SE base policy blocks. | High |
|
||||
|
||||
> [!NOTE]
|
||||
> The specifics of the policy you will need to create vary from app to app. Public documentation can help you determine which rules would be useful for your app.
|
||||
|
||||
|
||||
## WDAC supplemental policies
|
||||
|
||||
A *supplemental policy* can expand only one base policy, but multiple supplemental policies can expand the same base policy. When you use supplemental policies, the apps allowed by the base or its supplemental policies will be allowed to execute.\
|
||||
The base policy that you must target for Windows SE devices has a PolicyID of **{82443e1e-8a39-4b4a-96a8-f40ddc00b9f3}**.
|
||||
|
||||
> [!WARNING]
|
||||
> The maximum number of active policies is 32, which includes the Windows 11 SE base policy, the Microsoft vulnerable driver block list, and potentially other inbox policies. When planning your supplemental policy strategy, avoid adding too many. For example, avoid creating a supplemental policy per app, which can add up very quickly.
|
||||
|
||||
After you create WDAC supplemental policies, you must sign them and deploy them through Intune.\
|
||||
To create supplemental policies, download and install the [WDAC Policy Wizard][EXT-1] from a **non-Windows SE device**.
|
||||
|
||||
The following video provides an overview and explains how to create supplemental policies for apps blocked by the Windows 11 SE base policy.
|
||||
|
||||
> [!VIDEO https://www.microsoft.com/en-us/videoplayer/embed/RWWReO]
|
||||
|
||||
### Create a supplemental policy for Win32 apps
|
||||
|
||||
There are different ways to write a supplemental policy. The suggested method is to use [audit events][WIN-3], as they list the actions that Windows 11 SE would block. From the audit events, you can create a policy to allow those actions.\
|
||||
From a non-Windows SE device with the WDAC Policy Wizard installed, follow these steps:
|
||||
|
||||
1. Apply an audit mode WDAC Base policy. The WDAC Wizard includes a template policy called *WinSEPolicy.xml*, which is based on the Windows 11 SE base policy:
|
||||
- Open the **WDAC Wizard** and select **Policy Editor**
|
||||
- In the Policy Path to Edit field, browse for *%ProgramFiles%\WindowsApps\Microsoft.WDAC\** and select the file called *WinSEPolicy.xml*. Select **Next**
|
||||
:::image type="content" source="images/wdac-winsepolicy.png" alt-text="Screenshot of the WDAC wizard - creation of a policy targeting the base WinSEPolicy.xml policy.":::
|
||||
- Toggle the option for **Audit Mode** and complete the wizard. Note the location of the *.cip* and *.xml* files shown on the final page of the wizard
|
||||
- From an elevated PowerShell session, run the following command to activate the policy:
|
||||
|
||||
```cmd
|
||||
citool.exe -up <"Path to the .cip file">
|
||||
```
|
||||
|
||||
1. With the *Base audit mode policy* for Windows 11 SE in place:
|
||||
- Download and run the app install for your app
|
||||
- Launch the app and exercise the app's capabilities
|
||||
- Uninstall the app
|
||||
1. Use the WDAC Wizard to create a policy from audit events:
|
||||
- Open the **WDAC Wizard** and select **Policy Editor**
|
||||
- Select **Convert Event Log to a WDAC Policy** then select **Parse Event Log** to parse from the system Event Viewer. Select **Next**
|
||||
- Review each row in the table and choose the type of rule to create. You may want to sort the table by FileName to group duplicate rows together. You need to create a single rule if the values are duplicates
|
||||
- Complete the wizard to generate the policy. The policy will be a *Base* policy. Note the location of the *.xml* shown, as you'll use it in the next step.
|
||||
- Check the event log **AppLocker** > **MSI and Script** for any events
|
||||
- If any events are shown, you can use the **WDAC Wizard** to edit the policy and add more rules
|
||||
- Alternatively, you can save all events to *.evtx* file and create a policy from audit events, but browse for the saved *.evtx* file rather than parsing events from the system Event Viewer
|
||||
1. Convert the policy created in the previous step to a supplemental policy, specifying the Base audit policy you created in the first step as its base
|
||||
|
||||
```PowerShell
|
||||
Set-CiPolicyIdInfo -FilePath "<Path to.xml file from step #4>" -BasePolicyToSupplementPath "<Path to the WDAC Base policy .xml created from step #2>"
|
||||
```
|
||||
|
||||
1. From an elevated PowerShell session, run the following command to activate the policy:
|
||||
|
||||
```cmd
|
||||
citool.exe -up '<Path to the .cip file>'
|
||||
```
|
||||
|
||||
1. Clear the two event logs:
|
||||
- **CodeIntegrity** > **Operational**
|
||||
- **AppLocker** > **MSI and Script**
|
||||
1. Repeat the app testing from step 3. Repeat these steps as needed until no further events are generated.
|
||||
1. Once you have a policy that works for your app, reset the supplemental policy's Base policy to the official Windows 11 SE BasePolicyId. From an elevated PowerShell session, run the following command:
|
||||
|
||||
```PowerShell
|
||||
Set-CiPolicyIdInfo -FilePath "<Path to .xml from step #4>" -SupplementsBasePolicyId "{82443e1e-8a39-4b4a-96a8-f40ddc00b9f3}"
|
||||
```
|
||||
|
||||
> [!NOTE]
|
||||
> If you have created multiple supplemental policies for different apps, it's recommended to merge all supplemental policies together before deploying. You can merge policies using the WDAC Wizard.
|
||||
1. The creation of the supplemental policy is complete. You must sign and deploy the policy to your devices to take effect.
|
||||
|
||||
### Create a supplemental policy for UWP LOB apps
|
||||
|
||||
UWP apps don't work out-of-box due to the Windows 11 SE Windows 11 SE base policy.\
|
||||
From a non-Windows SE device with the WDAC Policy Wizard installed, you can create and deploy a supplemental policy using these steps:
|
||||
|
||||
1. Open the **WDAC Wizard** and select **Policy Creator > Supplemental policy**
|
||||
- Choose a **Policy Name** and **Policy File Location**
|
||||
- In the **Base Policy** path to, browse for *%ProgramFiles%\WindowsApps\Microsoft.WDAC\** and select the file called *WinSEPolicy.xml*. Select **Next**
|
||||
- In **Policy Rules**, select **Next**
|
||||
- In **Signing Rules**, select **Add Custom Rule** and choose:
|
||||
- **Rule scope**: **Usermode Rule**
|
||||
- **Rule action**: **Allow**
|
||||
- **Rule type**: **Packaged App**
|
||||
- **Package Name**: specify the package name of app. If the app is installed, you can search by name. If the app isn't installed, check the **Use Custom Package Family** box and specify the package family name of the app
|
||||
:::image type="content" source="images/wdac-uwp-policy.png" alt-text="Screenshot of the WDAC wizard - selection of an installed UWP app package.":::
|
||||
- Select the app name
|
||||
- Select **Create Rule**
|
||||
- Select **Next**
|
||||
1. The policy should be created and output an *.xml* and *.cip* files to the policy file location specified earlier
|
||||
1. The policy isn't yet targeting the right base policy. Run the following PowerShell command to set the base policy to the Windows 11 SE Windows 11 SE base policy:
|
||||
|
||||
```PowerShell
|
||||
Set-CiPolicyIdInfo -FilePath "<Path to.xml file from previous step>" -SupplementsBasePolicyId "{82443e1e-8a39-4b4a-96a8-f40ddc00b9f3}"
|
||||
```
|
||||
|
||||
1. The creation of the supplemental policy is complete. You must sign and deploy the policy to your devices to take effect.
|
||||
|
||||
### Guidelines for authoring WDAC supplemental policy rules
|
||||
|
||||
Here are some general guidelines to follow when writing WDAC supplemental policies:
|
||||
|
||||
- For packaged apps (*.appx* or *.msix*), choose **PackagedApp** and allow the file by its **PackageFamilyName**
|
||||
- For other apps, try to create **Publisher** rules wherever possible, combining the **Publisher** with other properties like **Product**, **Filename**, and **Version**
|
||||
|
||||
> [!NOTE]
|
||||
> The WDAC Wizard defaults to use all of the properties, if present. In some cases, you may want to combine a subset of the properties to allow multiple files. For example: Publisher + ProductName + Version.
|
||||
|
||||
- When a **Publisher** rule isn't an option (for example, when the file is unsigned), use *Hash* as the most restrictive option
|
||||
- You might have to opt for a **FileAttribute** rule, but it can be easily spoofed
|
||||
|
||||
For additional information:
|
||||
|
||||
- [WDAC Policy Wizard][EXT-1]
|
||||
- [Policy creation for common WDAC usage scenarios][WIN-1]
|
||||
- [Create a new supplemental policy with the wizard][WIN-2]
|
||||
|
||||
## AppLocker policies
|
||||
|
||||
> [!WARNING]
|
||||
> It's recommended to use AppLocker policies for processes that perform **updates** or **install as managed installers** only. The preferred method to allow incompatible applications or other executables to run, is to write **WDAC supplemental policies** instead of modifying AppLocker policies.
|
||||
|
||||
Additional AppLocker policies work by configuring other apps to be *managed installers*. However, since anything downloaded or installed by a managed installer is trusted to run, it creates a significant security risk. For example, if the executable for a third-party browser is set as a managed installer, anything downloaded from that browser will be allowed to run.\
|
||||
Using a WDAC supplemental policy instead, allows you to have more control over what is allowed to run without the risk of those permissions propagating unintentionally.
|
||||
|
||||
To allow apps to run by setting their installers as managed installers, follow the guidance here:
|
||||
-->
|
||||
|
||||
## AppLocker policies
|
||||
|
||||
Additional AppLocker policies work by configuring other apps to be *managed installers*. However, since anything downloaded or installed by a managed installer is trusted to run, it creates a significant security risk. For example, if the executable for a third-party browser is set as a managed installer, anything downloaded from that browser will be allowed to run.
|
||||
|
||||
To allow apps to run by setting their installers as managed installers, follow the guidance here:
|
||||
|
||||
- [Edit an AppLocker policy][WIN-5]
|
||||
- [Allow apps deployed with a WDAC managed installer][WIN-6]
|
||||
|
||||
## Next steps
|
||||
|
||||
<!--
|
||||
Before moving on to the next section, ensure that you've completed the following tasks.
|
||||
|
||||
For a WDAC supplemental policy:
|
||||
|
||||
> [!div class="checklist"]
|
||||
>
|
||||
> - Create a policy, targeting the base policy: **82443e1e-8a39-4b4a-96a8-f40ddc00b9f3**
|
||||
|
||||
For an AppLocker policy:
|
||||
|
||||
> [!div class="checklist"]
|
||||
>
|
||||
> - Only applied to an updater or installer
|
||||
> - Created the policy with the **Merge** option
|
||||
|
||||
Advance to the next article to learn how to deploy the WDAC supplemental policies or AppLocker policies to Windows 11 SE devices.
|
||||
-->
|
||||
|
||||
Advance to the next article to learn how to deploy the AppLocker policies to Windows 11 SE devices.
|
||||
|
||||
> [!div class="nextstepaction"]
|
||||
> [Next: deploy policies >](deploy-policies.md)
|
||||
|
||||
[EXT-1]: https://webapp-wdac-wizard.azurewebsites.net/
|
||||
[WIN-1]: /windows/security/threat-protection/windows-defender-application-control/types-of-devices
|
||||
[WIN-2]: /windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-supplemental-policy
|
||||
[WIN-3]: /windows/security/threat-protection/windows-defender-application-control/audit-windows-defender-application-control-policies
|
||||
[WIN-5]: /windows/security/threat-protection/windows-defender-application-control/applocker/edit-an-applocker-policy
|
||||
[WIN-6]: /windows/security/threat-protection/windows-defender-application-control/configure-authorized-apps-deployed-with-a-managed-installer
|
109
education/windows/tutorial-deploy-apps-winse/deploy-apps.md
Normal file
@ -0,0 +1,109 @@
|
||||
---
|
||||
title: Applications deployment considerations
|
||||
description: Learn how to deploy different types of applications to Windows 11 SE and some considerations before deploying them.
|
||||
ms.date: 05/23/2023
|
||||
ms.topic: tutorial
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE, version 22H2 and later</a>
|
||||
---
|
||||
|
||||
# Applications deployment considerations
|
||||
|
||||
:::row:::
|
||||
:::column span="":::
|
||||
<a href="deploy-apps.md"><img src="images/phase-1-on.svg" alt="Icon representing the first phase."/></a><br>
|
||||
[**Deploy an application via Microsoft Intune**](deploy-apps.md)
|
||||
:::column-end:::
|
||||
:::column span="":::
|
||||
<a href="validate-apps.md"><img src="images/phase-2-off.svg" alt="Icon representing the second phase."/></a><br>
|
||||
[**Validate the application**](validate-apps.md)
|
||||
:::column-end:::
|
||||
:::column span="":::
|
||||
<a href="create-policies.md"><img src="images/phase-3-off.svg" alt="Icon representing the third phase."/></a><br>
|
||||
[**Create additional policies (optional)**](create-policies.md)
|
||||
:::column-end:::
|
||||
:::row-end:::
|
||||
|
||||
The process to deploy applications to Windows SE devices via Microsoft Intune is the same used for non-SE devices. Applications must be defined in Intune, and then assigned to the correct groups.\
|
||||
However, on Windows SE devices, apps may successfully install, but they need validation to be certain that they're functional.
|
||||
|
||||
The following table provides an overview of the applications types that can be deployed to Windows devices via Intune, and considerations about the installation on Windows SE:
|
||||
|
||||
|**Installer/App type**|**Installer extensions**|**Available installation methods via Intune**|**Considerations for Windows 11 SE**|
|
||||
|-|-|-|-|
|
||||
|[Win32][WIN-1]|`.exe`<br>`.msi`|- Intune Management Extension (IME)<br> - Microsoft Store integration|⚠️ There are known limitations that might prevent an app to install or run.|
|
||||
|[Universal Windows Platform (UWP)][WIN-2]|`.appx`<br>`.appxbundle`<br>`.msix`<br>|- For public apps: Microsoft Store integration<br>- For private apps: line-of-business (LOB) apps|⛔ UWP apps are currently unsupported.<!--⚠️ LOB apps require a supplemental policy.-->|
|
||||
|[Progressive Web Apps (PWAs)][EDGE-2] |`.msix`|- Settings catalog policies<br>- Microsoft Store integration|✅ PWAs are supported.|
|
||||
|Web links| n/a |- Windows web links|✅ Web links are supported.|
|
||||
|
||||
<!--after Intune 2307 update the table above with ✅ UWP public apps are supported.<br><br>⛔ UWP private apps are currently unsupported.-->
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Store apps must be installed in device context. Deploying apps in user context fails with error code `0x800711C7`.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Although you'll be able to install apps on Windows 11 SE devices via Intune, some apps may not perform well on these devices due those apps' minimum spec requirements.
|
||||
> Before deploying apps, first check which apps will be targeting your Windows 11 SE devices, and ensure that they meet the requirements.
|
||||
|
||||
## Win32 apps
|
||||
|
||||
The addition of Win32 applications to Intune consists of repackaging the apps and defining the commands to silently install them. The process is described in the article [Add, assign, and monitor a Win32 app in Microsoft Intune][MEM-1].
|
||||
|
||||
> [!IMPORTANT]
|
||||
> If you have Windows 11 SE devices that already have apps deployed through Intune, the apps will not get retroactively tagged with the *managed installer* mark. The reason is to avoid making any security assumptions for these apps. You may need to redeploy the apps through Intune to get them properly tagged with managed installer and allowed to run.
|
||||
|
||||
There are known limitations that might prevent applications to install or execute. For more information, see the next section [validate applications](validate-apps.md).
|
||||
|
||||
## UWP apps
|
||||
|
||||
UWP apps are currently unsupported for Windows 11 SE.
|
||||
|
||||
<!-- 2307
|
||||
### Microsoft Store apps
|
||||
|
||||
Public UWP apps available in the Microsoft Store are supported for Windows 11 SE.
|
||||
|
||||
### Line of business apps
|
||||
|
||||
Private UWP apps are currently unsupported for Windows 11 SE.
|
||||
|
||||
<!--### Line of business apps
|
||||
|
||||
For private, line-of-business (LOB) UWP apps, [deploy as line-of-business apps][MEM-2]
|
||||
|
||||
> [!IMPORTANT]
|
||||
> UWP apps require the creation and deployment of supplemental policies. For more information, see the next section [validate applications](validate-apps.md).
|
||||
|
||||
-->
|
||||
## PWA apps
|
||||
|
||||
PWAs can be deployed using the [Force-installed web Apps][EDGE-1] option via [settings catalog policies][MEM-3], or using the Microsoft Store integration with Intune.
|
||||
|
||||
## Web links
|
||||
|
||||
Web link can be deployed via Intune using [Windows web links][MEM-4], and will be available in the Start menu of the targeted devices.
|
||||
|
||||
## Section review
|
||||
|
||||
Before moving on to the next section, ensure that you've completed the following tasks:
|
||||
|
||||
> [!div class="checklist"]
|
||||
> - `.intunewin` package created (for Win32 apps)
|
||||
> - App uploaded via Intune (for Win32 and UWP LOB apps)
|
||||
> - App assigned to the correct groups
|
||||
|
||||
## Next steps
|
||||
|
||||
Advance to the next article to learn how to validate the applications deployed to Windows 11 SE devices.
|
||||
|
||||
> [!div class="nextstepaction"]
|
||||
> [Next: validate apps >](validate-apps.md)
|
||||
|
||||
[EDGE-1]: /deployedge/microsoft-edge-policies#configure-list-of-force-installed-web-apps
|
||||
[EDGE-2]: /microsoft-edge/progressive-web-apps-chromium
|
||||
[MEM-1]: /mem/intune/apps/apps-win32-add
|
||||
[MEM-2]: /mem/intune/apps/lob-apps-windows
|
||||
[MEM-3]: /mem/intune/configuration/settings-catalog
|
||||
[MEM-4]: /mem/intune/apps/web-app
|
||||
[WIN-1]: /windows/win32
|
||||
[WIN-2]: /windows/uwp/get-started/universal-application-platform-guide
|
@ -0,0 +1,96 @@
|
||||
---
|
||||
title: Deploy policies to enable applications
|
||||
description: Learn how to deploy AppLocker policies to enable apps execution on Windows SE devices.
|
||||
ms.date: 05/23/2023
|
||||
ms.topic: tutorial
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE, version 22H2 and later</a>
|
||||
---
|
||||
|
||||
<!--description: Learn how to sign WDAC policies and how to deploy WDAC and AppLocker policies to enable apps execution on Windows SE devices.-->
|
||||
|
||||
# Deploy policies to enable applications
|
||||
|
||||
Once the policies are created, you must deploy them to the Windows SE devices.\
|
||||
AppLocker policies can be deployed via Intune. This article describes how to deploy AppLocker policies to enable apps execution on Windows SE devices.
|
||||
|
||||
<!--
|
||||
WDAC and AppLocker policies can be deployed via Intune, but WDAC policies must be signed before they can be deployed.
|
||||
|
||||
This article describes how to sign WDAC policies and how to deploy WDAC and AppLocker policies to enable apps execution on Windows SE devices.
|
||||
|
||||
## Sign WDAC supplemental policies
|
||||
|
||||
> [!IMPORTANT]
|
||||
> *This section will be updated when the process using Azure CodeSigning for CI policy is released in April.*
|
||||
|
||||
## Deploy WDAC supplemental policies
|
||||
|
||||
Policies can be deployed via Intune using a custom OMA-URI.
|
||||
|
||||
> [!TIP]
|
||||
> To prevent these policies from being applied to non-Windows SE devices, you can create and target a group with only Windows 11 SE devices in it, or use assignment filters.
|
||||
|
||||
[Deploy WDAC policies using Mobile Device Management][WIN-4]
|
||||
|
||||
### Troubleshoot WDAC policies
|
||||
|
||||
For information how to validate and troubleshoot WDAC supplemental policies, see [WDAC supplemental policy validation](./troubleshoot.md#wdac-supplemental-policy-validation)
|
||||
|
||||
-->
|
||||
|
||||
## Deploy AppLocker policies
|
||||
|
||||
Intune doesn't currently offer the option to modify AppLocker policies. The deployment of AppLocker policies can be done using PowerShell scripts deployed via Intune.
|
||||
|
||||
You can create a PowerShell script that stores the contents of the policy in a variable, then use the `Set-AppLockerPolicy` PowerShell command to merge it. Here's a sample function for the task:
|
||||
|
||||
```PowerShell
|
||||
function MergeAppLockerPolicy([string]$policyXml)
|
||||
{
|
||||
$policyFile = '.\AppLockerPolicy.xml'
|
||||
$policyXml | Out-File $policyFile
|
||||
Write-Host "Merging and setting AppLocker policy"
|
||||
Set-AppLockerPolicy -XmlPolicy $policyFile -Merge -ErrorAction SilentlyContinue
|
||||
Remove-Item $policyFile
|
||||
}
|
||||
```
|
||||
|
||||
> [!WARNING]
|
||||
> Intune deploys a script with the AppLocker policy to set **Intune Management Extension as a managed installer** on all Windows 11 SE devices enrolled into an Intune EDU tenant. If you want to deploy your own AppLocker policy to set another Managed Installer (in addition to Intune), be sure to use the `-Merge` parameter with `Set-AppLockerPolicy`. The `-Merge` parameter ensures that your policy plays well with Intune's AppLocker policy. Without using the `-Merge` parameter, it will result in issues with apps not getting tagged properly and their ability to run on impacted devices. To learn more about AppLocker Merge policy, see [Merge AppLocker policies][WIN-7].
|
||||
|
||||
Once finished, you can deploy the script via Intune. For more information, see [Add PowerShell scripts to Windows devices in Microsoft Intune][MEM-1].
|
||||
|
||||
### Troubleshoot AppLocker policies
|
||||
|
||||
For information how to validate and troubleshoot AppLocker policies, see [AppLocker policy validation](./troubleshoot.md#applocker-policy-validation)
|
||||
|
||||
## Next steps
|
||||
|
||||
<!--
|
||||
Before moving on to the next section, ensure that you've completed the following tasks.
|
||||
|
||||
For a WDAC supplemental policy:
|
||||
|
||||
> [!div class="checklist"]
|
||||
>
|
||||
> - Signed .cip .p7b file with Device Guard
|
||||
> - Policy created in Intune and assigned to the correct groups
|
||||
> - Policy applied in Event Viewer
|
||||
|
||||
For an AppLocker policy:
|
||||
|
||||
> [!div class="checklist"]
|
||||
>
|
||||
> - Policy created in Intune and assigned to the correct groups
|
||||
-->
|
||||
|
||||
Advance to the next article to learn about important considerations when deploying apps and policies to Windows SE devices.
|
||||
|
||||
> [!div class="nextstepaction"]
|
||||
>
|
||||
> [Next: important deployment considerations >](considerations.md)
|
||||
|
||||
[MEM-1]: /mem/intune/apps/intune-management-extension
|
||||
[WIN-4]: /windows/security/threat-protection/windows-defender-application-control/deployment/deploy-windows-defender-application-control-policies-using-intune
|
||||
[WIN-7]: /windows/security/threat-protection/windows-defender-application-control/applocker/merge-applocker-policies-by-using-set-applockerpolicy
|
After Width: | Height: | Size: 58 KiB |
After Width: | Height: | Size: 659 KiB |
After Width: | Height: | Size: 293 KiB |
After Width: | Height: | Size: 165 KiB |
After Width: | Height: | Size: 200 KiB |
@ -0,0 +1,3 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
|
||||
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" width="272px" height="112px" viewBox="-0.5 -0.5 272 112"><defs/><g><rect x="21" y="1" width="250" height="110" rx="4.4" ry="4.4" fill-opacity="0.9" fill="#e6e6e6" stroke="#666666" stroke-opacity="0.9" stroke-width="2" pointer-events="all"/><image x="113" y="18" width="75" height="75" xlink:href="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIGZpbGw9Im5vbmUiIHZpZXdCb3g9IjAgMCAyNCAyNCIgaGVpZ2h0PSIyNCIgd2lkdGg9IjI0Ij4mI3hhOyAgPHBhdGggZmlsbD0iIzIxMjEyMSIgZD0iTTE3LjUgMTJDMjAuNTM3NiAxMiAyMyAxNC40NjI0IDIzIDE3LjVDMjMgMjAuNTM3NiAyMC41Mzc2IDIzIDE3LjUgMjNDMTQuNDYyNCAyMyAxMiAyMC41Mzc2IDEyIDE3LjVDMTIgMTQuNDYyNCAxNC40NjI0IDEyIDE3LjUgMTJaTTE3LjUxMTIgMTQuMDAwMUwxNy40MjcgMTQuMDA1TDE3LjM3MTkgMTQuMDE2NkwxNy4yODg2IDE0LjA0NjdMMTcuMjE1MyAxNC4wODg4TDE3LjE1ODkgMTQuMTM0NEwxNC42NDY0IDE2LjY0NjRMMTQuNTg4NiAxNi43MTU3QzE0LjQ3MDUgMTYuODg2MiAxNC40NzA1IDE3LjExMzggMTQuNTg4NiAxNy4yODQzTDE0LjY0NjQgMTcuMzUzNkwxNC43MTU3IDE3LjQxMTRDMTQuODg2MiAxNy41Mjk1IDE1LjExMzggMTcuNTI5NSAxNS4yODQzIDE3LjQxMTRMMTUuMzUzNiAxNy4zNTM2TDE2Ljk5OSAxNS43MDhMMTcgMjFMMTcuMDA4MSAyMS4wODk5QzE3LjA0NTEgMjEuMjk0IDE3LjIwNiAyMS40NTQ5IDE3LjQxMDEgMjEuNDkxOUwxNy41IDIxLjVMMTcuNTg5OSAyMS40OTE5QzE3Ljc5NCAyMS40NTQ5IDE3Ljk1NDkgMjEuMjk0IDE3Ljk5MTkgMjEuMDg5OUwxOCAyMUwxNy45OTkgMTUuNzA2TDE5LjY0NjQgMTcuMzUzNkwxOS43MTU3IDE3LjQxMTRDMTkuOTEwNiAxNy41NDY0IDIwLjE4IDE3LjUyNzEgMjAuMzUzNiAxNy4zNTM2QzIwLjUyNzEgMTcuMTggMjAuNTQ2NCAxNi45MTA2IDIwLjQxMTQgMTYuNzE1N0wyMC4zNTM2IDE2LjY0NjRMMTcuODA2IDE0LjEwNEwxNy43NTg1IDE0LjA3MTlMMTcuNjkxIDE0LjAzNzhMMTcuNjI4MSAxNC4wMTY2TDE3LjU3MzkgMTQuMDA1NUMxNy41NTI5IDE0LjAwMjMgMTcuNTMxNyAxNC4wMDA2IDE3LjUxMTIgMTQuMDAwMVpNNi4yNSAzSDE3Ljc1QzE5LjQ4MyAzIDIwLjg5OTIgNC4zNTY0NSAyMC45OTQ5IDYuMDY1NThMMjEgNi4yNUwyMS4wMDEyIDEyLjAyMjZDMjAuNTM3OCAxMS43MjU4IDIwLjAzNDIgMTEuNDg2MSAxOS41MDA0IDExLjMxMzZMMTkuNSA4SDQuNVYxNy43NUM0LjUgMTguNjY4MiA1LjIwNzExIDE5LjQyMTIgNi4xMDY0NyAxOS40OTQyTDYuMjUgMTkuNUwxMS4zMTM2IDE5LjUwMDRDMTEuNDg2MSAyMC4wMzQyIDExLjcyNTggMjAuNTM3OCAxMi4wMjI2IDIxLjAwMTJMNi4yNSAyMUM0LjUxNjk3IDIxIDMuMTAwNzUgMTkuNjQzNSAzLjAwNTE0IDE3LjkzNDRMMyAxNy43NVY2LjI1QzMgNC41MTY5NyA0LjM1NjQ1IDMuMTAwNzUgNi4wNjU1OCAzLjAwNTE0TDYuMjUgM1oiLz4mI3hhOzwvc3ZnPg==" preserveAspectRatio="none" opacity="0.5"/><ellipse cx="21" cy="31" rx="20" ry="20" fill="#e6e6e6" stroke="#666666" stroke-width="2" pointer-events="all"/><g transform="translate(-0.5 -0.5)" opacity="0.5"><switch><foreignObject pointer-events="none" width="100%" height="100%" requiredFeatures="http://www.w3.org/TR/SVG11/feature#Extensibility" style="overflow: visible; text-align: left;"><div xmlns="http://www.w3.org/1999/xhtml" style="display: flex; align-items: unsafe center; justify-content: unsafe center; width: 38px; height: 1px; padding-top: 31px; margin-left: 2px;"><div data-drawio-colors="color: rgb(0, 0, 0); " style="box-sizing: border-box; font-size: 0px; text-align: center;"><div style="display: inline-block; font-size: 18px; font-family: "Segoe UI semibold"; color: rgb(0, 0, 0); line-height: 1.2; pointer-events: all; font-weight: bold; white-space: normal; overflow-wrap: normal;">1</div></div></div></foreignObject><text x="21" y="36" fill="rgb(0, 0, 0)" font-family="Segoe UI semibold" font-size="18px" text-anchor="middle" font-weight="bold">1</text></switch></g></g></svg>
|
After Width: | Height: | Size: 3.4 KiB |
@ -0,0 +1,3 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
|
||||
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" width="272px" height="112px" viewBox="-0.5 -0.5 272 112"><defs/><g><rect x="21" y="1" width="250" height="110" rx="4.4" ry="4.4" fill-opacity="0.95" fill="rgb(255, 255, 255)" stroke="#0078d4" stroke-opacity="0.95" stroke-width="2" pointer-events="all"/><image x="113" y="18" width="75" height="75" xlink:href="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIGZpbGw9Im5vbmUiIHZpZXdCb3g9IjAgMCAyNCAyNCIgaGVpZ2h0PSIyNCIgd2lkdGg9IjI0Ij4mI3hhOyAgPHBhdGggZmlsbD0iIzIxMjEyMSIgZD0iTTE3LjUgMTJDMjAuNTM3NiAxMiAyMyAxNC40NjI0IDIzIDE3LjVDMjMgMjAuNTM3NiAyMC41Mzc2IDIzIDE3LjUgMjNDMTQuNDYyNCAyMyAxMiAyMC41Mzc2IDEyIDE3LjVDMTIgMTQuNDYyNCAxNC40NjI0IDEyIDE3LjUgMTJaTTE3LjUxMTIgMTQuMDAwMUwxNy40MjcgMTQuMDA1TDE3LjM3MTkgMTQuMDE2NkwxNy4yODg2IDE0LjA0NjdMMTcuMjE1MyAxNC4wODg4TDE3LjE1ODkgMTQuMTM0NEwxNC42NDY0IDE2LjY0NjRMMTQuNTg4NiAxNi43MTU3QzE0LjQ3MDUgMTYuODg2MiAxNC40NzA1IDE3LjExMzggMTQuNTg4NiAxNy4yODQzTDE0LjY0NjQgMTcuMzUzNkwxNC43MTU3IDE3LjQxMTRDMTQuODg2MiAxNy41Mjk1IDE1LjExMzggMTcuNTI5NSAxNS4yODQzIDE3LjQxMTRMMTUuMzUzNiAxNy4zNTM2TDE2Ljk5OSAxNS43MDhMMTcgMjFMMTcuMDA4MSAyMS4wODk5QzE3LjA0NTEgMjEuMjk0IDE3LjIwNiAyMS40NTQ5IDE3LjQxMDEgMjEuNDkxOUwxNy41IDIxLjVMMTcuNTg5OSAyMS40OTE5QzE3Ljc5NCAyMS40NTQ5IDE3Ljk1NDkgMjEuMjk0IDE3Ljk5MTkgMjEuMDg5OUwxOCAyMUwxNy45OTkgMTUuNzA2TDE5LjY0NjQgMTcuMzUzNkwxOS43MTU3IDE3LjQxMTRDMTkuOTEwNiAxNy41NDY0IDIwLjE4IDE3LjUyNzEgMjAuMzUzNiAxNy4zNTM2QzIwLjUyNzEgMTcuMTggMjAuNTQ2NCAxNi45MTA2IDIwLjQxMTQgMTYuNzE1N0wyMC4zNTM2IDE2LjY0NjRMMTcuODA2IDE0LjEwNEwxNy43NTg1IDE0LjA3MTlMMTcuNjkxIDE0LjAzNzhMMTcuNjI4MSAxNC4wMTY2TDE3LjU3MzkgMTQuMDA1NUMxNy41NTI5IDE0LjAwMjMgMTcuNTMxNyAxNC4wMDA2IDE3LjUxMTIgMTQuMDAwMVpNNi4yNSAzSDE3Ljc1QzE5LjQ4MyAzIDIwLjg5OTIgNC4zNTY0NSAyMC45OTQ5IDYuMDY1NThMMjEgNi4yNUwyMS4wMDEyIDEyLjAyMjZDMjAuNTM3OCAxMS43MjU4IDIwLjAzNDIgMTEuNDg2MSAxOS41MDA0IDExLjMxMzZMMTkuNSA4SDQuNVYxNy43NUM0LjUgMTguNjY4MiA1LjIwNzExIDE5LjQyMTIgNi4xMDY0NyAxOS40OTQyTDYuMjUgMTkuNUwxMS4zMTM2IDE5LjUwMDRDMTEuNDg2MSAyMC4wMzQyIDExLjcyNTggMjAuNTM3OCAxMi4wMjI2IDIxLjAwMTJMNi4yNSAyMUM0LjUxNjk3IDIxIDMuMTAwNzUgMTkuNjQzNSAzLjAwNTE0IDE3LjkzNDRMMyAxNy43NVY2LjI1QzMgNC41MTY5NyA0LjM1NjQ1IDMuMTAwNzUgNi4wNjU1OCAzLjAwNTE0TDYuMjUgM1oiLz4mI3hhOzwvc3ZnPg==" preserveAspectRatio="none"/><ellipse cx="21" cy="31" rx="20" ry="20" fill="#0078d4" stroke="#ffffff" stroke-width="2" pointer-events="all"/><g transform="translate(-0.5 -0.5)"><switch><foreignObject pointer-events="none" width="100%" height="100%" requiredFeatures="http://www.w3.org/TR/SVG11/feature#Extensibility" style="overflow: visible; text-align: left;"><div xmlns="http://www.w3.org/1999/xhtml" style="display: flex; align-items: unsafe center; justify-content: unsafe center; width: 38px; height: 1px; padding-top: 31px; margin-left: 2px;"><div data-drawio-colors="color: #ffffff; " style="box-sizing: border-box; font-size: 0px; text-align: center;"><div style="display: inline-block; font-size: 18px; font-family: "Segoe UI semibold"; color: rgb(255, 255, 255); line-height: 1.2; pointer-events: all; font-weight: bold; white-space: normal; overflow-wrap: normal;">1</div></div></div></foreignObject><text x="21" y="36" fill="#ffffff" font-family="Segoe UI semibold" font-size="18px" text-anchor="middle" font-weight="bold">1</text></switch></g></g></svg>
|
After Width: | Height: | Size: 3.4 KiB |
@ -0,0 +1,3 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
|
||||
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" width="272px" height="112px" viewBox="-0.5 -0.5 272 112"><defs/><g><rect x="21" y="1" width="250" height="110" rx="4.4" ry="4.4" fill-opacity="0.9" fill="#e6e6e6" stroke="#666666" stroke-opacity="0.9" stroke-width="2" pointer-events="all"/><image x="105.5" y="15.5" width="80" height="80" xlink:href="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIGZpbGw9Im5vbmUiIHZpZXdCb3g9IjAgMCAyNCAyNCIgaGVpZ2h0PSIyNCIgd2lkdGg9IjI0Ij4mI3hhOyAgPHBhdGggZmlsbD0iIzIxMjEyMSIgZD0iTTYuMjUgM0M0LjQ1NTA3IDMgMyA0LjQ1NTA3IDMgNi4yNVYxNy43NUMzIDE5LjU0NDkgNC40NTUwNyAyMSA2LjI1IDIxSDE3Ljc1QzE5LjU0NDkgMjEgMjEgMTkuNTQ0OSAyMSAxNy43NVY2LjI1QzIxIDQuNDU1MDcgMTkuNTQ0OSAzIDE3Ljc1IDNINi4yNVpNNC41IDhIMTkuNVYxNy43NUMxOS41IDE4LjcxNjUgMTguNzE2NSAxOS41IDE3Ljc1IDE5LjVINi4yNUM1LjI4MzUgMTkuNSA0LjUgMTguNzE2NSA0LjUgMTcuNzVWOFpNNiAxMC4zNUM2IDkuODgwNTYgNi4zODA1NiA5LjUgNi44NSA5LjVIMTAuMTVDMTAuNjE5NCA5LjUgMTEgOS44ODA1NiAxMSAxMC4zNVYxNy4xNUMxMSAxNy42MTk0IDEwLjYxOTQgMTggMTAuMTUgMThINi44NUM2LjM4MDU2IDE4IDYgMTcuNjE5NCA2IDE3LjE1VjEwLjM1Wk03LjUgMTFWMTYuNUg5LjVWMTFINy41Wk0xMi43NSA5LjVIMTcuMjVDMTcuNjY0MiA5LjUgMTggOS44MzU3OSAxOCAxMC4yNUMxOCAxMC42NjQyIDE3LjY2NDIgMTEgMTcuMjUgMTFIMTIuNzVDMTIuMzM1OCAxMSAxMiAxMC42NjQyIDEyIDEwLjI1QzEyIDkuODM1NzkgMTIuMzM1OCA5LjUgMTIuNzUgOS41Wk0xMiAxMy4yNUMxMiAxMi44MzU4IDEyLjMzNTggMTIuNSAxMi43NSAxMi41SDE2LjI1QzE2LjY2NDIgMTIuNSAxNyAxMi44MzU4IDE3IDEzLjI1QzE3IDEzLjY2NDIgMTYuNjY0MiAxNCAxNi4yNSAxNEgxMi43NUMxMi4zMzU4IDE0IDEyIDEzLjY2NDIgMTIgMTMuMjVaIi8+JiN4YTs8L3N2Zz4=" preserveAspectRatio="none" opacity="0.5"/><ellipse cx="21" cy="31" rx="20" ry="20" fill="#e6e6e6" stroke="#666666" stroke-width="2" pointer-events="all"/><g transform="translate(-0.5 -0.5)" opacity="0.5"><switch><foreignObject pointer-events="none" width="100%" height="100%" requiredFeatures="http://www.w3.org/TR/SVG11/feature#Extensibility" style="overflow: visible; text-align: left;"><div xmlns="http://www.w3.org/1999/xhtml" style="display: flex; align-items: unsafe center; justify-content: unsafe center; width: 38px; height: 1px; padding-top: 31px; margin-left: 2px;"><div data-drawio-colors="color: rgb(0, 0, 0); " style="box-sizing: border-box; font-size: 0px; text-align: center;"><div style="display: inline-block; font-size: 18px; font-family: "Segoe UI semibold"; color: rgb(0, 0, 0); line-height: 1.2; pointer-events: all; font-weight: bold; white-space: normal; overflow-wrap: normal;">2</div></div></div></foreignObject><text x="21" y="36" fill="rgb(0, 0, 0)" font-family="Segoe UI semibold" font-size="18px" text-anchor="middle" font-weight="bold">2</text></switch></g></g></svg>
|
After Width: | Height: | Size: 2.8 KiB |
@ -0,0 +1,3 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
|
||||
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" width="272px" height="112px" viewBox="-0.5 -0.5 272 112"><defs/><g><rect x="21" y="1" width="250" height="110" rx="4.4" ry="4.4" fill-opacity="0.95" fill="rgb(255, 255, 255)" stroke="#0078d4" stroke-opacity="0.95" stroke-width="2" pointer-events="all"/><image x="105.5" y="15.5" width="80" height="80" xlink:href="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIGZpbGw9Im5vbmUiIHZpZXdCb3g9IjAgMCAyNCAyNCIgaGVpZ2h0PSIyNCIgd2lkdGg9IjI0Ij4mI3hhOyAgPHBhdGggZmlsbD0iIzIxMjEyMSIgZD0iTTYuMjUgM0M0LjQ1NTA3IDMgMyA0LjQ1NTA3IDMgNi4yNVYxNy43NUMzIDE5LjU0NDkgNC40NTUwNyAyMSA2LjI1IDIxSDE3Ljc1QzE5LjU0NDkgMjEgMjEgMTkuNTQ0OSAyMSAxNy43NVY2LjI1QzIxIDQuNDU1MDcgMTkuNTQ0OSAzIDE3Ljc1IDNINi4yNVpNNC41IDhIMTkuNVYxNy43NUMxOS41IDE4LjcxNjUgMTguNzE2NSAxOS41IDE3Ljc1IDE5LjVINi4yNUM1LjI4MzUgMTkuNSA0LjUgMTguNzE2NSA0LjUgMTcuNzVWOFpNNiAxMC4zNUM2IDkuODgwNTYgNi4zODA1NiA5LjUgNi44NSA5LjVIMTAuMTVDMTAuNjE5NCA5LjUgMTEgOS44ODA1NiAxMSAxMC4zNVYxNy4xNUMxMSAxNy42MTk0IDEwLjYxOTQgMTggMTAuMTUgMThINi44NUM2LjM4MDU2IDE4IDYgMTcuNjE5NCA2IDE3LjE1VjEwLjM1Wk03LjUgMTFWMTYuNUg5LjVWMTFINy41Wk0xMi43NSA5LjVIMTcuMjVDMTcuNjY0MiA5LjUgMTggOS44MzU3OSAxOCAxMC4yNUMxOCAxMC42NjQyIDE3LjY2NDIgMTEgMTcuMjUgMTFIMTIuNzVDMTIuMzM1OCAxMSAxMiAxMC42NjQyIDEyIDEwLjI1QzEyIDkuODM1NzkgMTIuMzM1OCA5LjUgMTIuNzUgOS41Wk0xMiAxMy4yNUMxMiAxMi44MzU4IDEyLjMzNTggMTIuNSAxMi43NSAxMi41SDE2LjI1QzE2LjY2NDIgMTIuNSAxNyAxMi44MzU4IDE3IDEzLjI1QzE3IDEzLjY2NDIgMTYuNjY0MiAxNCAxNi4yNSAxNEgxMi43NUMxMi4zMzU4IDE0IDEyIDEzLjY2NDIgMTIgMTMuMjVaIi8+JiN4YTs8L3N2Zz4=" preserveAspectRatio="none"/><ellipse cx="21" cy="31" rx="20" ry="20" fill="#0078d4" stroke="#ffffff" stroke-width="2" pointer-events="all"/><g transform="translate(-0.5 -0.5)"><switch><foreignObject pointer-events="none" width="100%" height="100%" requiredFeatures="http://www.w3.org/TR/SVG11/feature#Extensibility" style="overflow: visible; text-align: left;"><div xmlns="http://www.w3.org/1999/xhtml" style="display: flex; align-items: unsafe center; justify-content: unsafe center; width: 38px; height: 1px; padding-top: 31px; margin-left: 2px;"><div data-drawio-colors="color: #ffffff; " style="box-sizing: border-box; font-size: 0px; text-align: center;"><div style="display: inline-block; font-size: 18px; font-family: "Segoe UI semibold"; color: rgb(255, 255, 255); line-height: 1.2; pointer-events: all; font-weight: bold; white-space: normal; overflow-wrap: normal;">2</div></div></div></foreignObject><text x="21" y="36" fill="#ffffff" font-family="Segoe UI semibold" font-size="18px" text-anchor="middle" font-weight="bold">2</text></switch></g></g></svg>
|
After Width: | Height: | Size: 2.7 KiB |
@ -0,0 +1,3 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
|
||||
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" width="272px" height="112px" viewBox="-0.5 -0.5 272 112"><defs/><g><rect x="21" y="1" width="250" height="110" rx="4.4" ry="4.4" fill-opacity="0.9" fill="#e6e6e6" stroke="#666666" stroke-opacity="0.9" stroke-width="2" pointer-events="all"/><image x="105.5" y="15.5" width="80" height="80" xlink:href="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIGZpbGw9Im5vbmUiIHZpZXdCb3g9IjAgMCAyNCAyNCIgaGVpZ2h0PSIyNCIgd2lkdGg9IjI0Ij4mI3hhOyAgPHBhdGggZmlsbD0iIzIxMjEyMSIgZD0iTTE3Ljc0OSAzTDE3LjkzMzQgMy4wMDUxNEMxOS41ODI3IDMuMDk3MzQgMjAuOTAyOSA0LjQxNzUgMjAuOTk1MSA2LjA2NTU4TDIxLjAwMDIgNi4yNVYxMi42MTA4QzIwLjMxMzMgMTIuNDc5MyAxOS42NTU0IDEyLjEwODggMTkuMDA1NCAxMS40MzA1TDE4Ljk5OTQgMTEuNDI0M0wxOC45OTkgOEg1LjAwMDIyTDQuOTk5MDIgMTcuNzVDNC45OTkwMiAxOC4zOTcyIDUuNDkwODkgMTguOTI5NSA2LjEyMTIxIDE4Ljk5MzVMNi4yNDkwMiAxOUgxMy4zNzUzQzEzLjU3ODggMTkuNTk1MyAxMy44NjY5IDIwLjE0NjIgMTQuMjQzOSAyMC42NDU3QzE0LjMzNjEgMjAuNzY3OCAxNC40MzI4IDIwLjg4NTkgMTQuNTM0IDIxSDYuMjQ5MDJDNC41MTU5OSAyMSAzLjA5OTc3IDE5LjY0MzUgMy4wMDQxNiAxNy45MzQ0TDIuOTk5MDIgMTcuNzVWNi4yNUMyLjk5OTAyIDQuNTE2OTcgNC4zNTU0NyAzLjEwMDc1IDYuMDY0NiAzLjAwNTE0TDYuMjQ5MDIgM0gxNy43NDlaTTE4Ljk5OTYgMTIuNzY0NEMxOS42MjUxIDEzLjIzNzUgMjAuMjkwNiAxMy41MjMgMjEuMDAwMiAxMy42MjQ1QzIxLjE5NjYgMTMuNjUyNyAyMS4zOTY0IDEzLjY2NjcgMjEuNTk5NiAxMy42NjY3QzIxLjc5MjkgMTMuNjY2NyAyMS45NTQyIDEzLjgwOTUgMjEuOTkxNSAxMy45OTk0TDIxLjk5OTYgMTQuMDgzM1YxNi41ODQ0QzIxLjk5OTYgMTkuMjY2MyAyMC42ODY2IDIxLjA4OTYgMTguMTI2MSAyMS45Nzg2QzE4LjA0NCAyMi4wMDcxIDE3Ljk1NTIgMjIuMDA3MSAxNy44NzMxIDIxLjk3ODZDMTcuMTQ3OSAyMS43MjY4IDE2LjUyMjcgMjEuNCAxNS45OTkxIDIxQzE1LjI5NyAyMC40NjM2IDE0Ljc3NzYgMTkuNzk1NiAxNC40NDQzIDE5QzE0LjE3NzkgMTguMzY0IDE0LjAzMDYgMTcuNjQ2NiAxNC4wMDQgMTYuODQ5N0wxMy45OTk2IDE2LjU4NDRWMTQuMDgzM0MxMy45OTk2IDEzLjg1MzIgMTQuMTc4NyAxMy42NjY3IDE0LjM5OTYgMTMuNjY2N0MxNS42MjMgMTMuNjY2NyAxNi43MjMgMTMuMTU3NSAxNy43MTc1IDEyLjEyMkMxNy44NzM4IDExLjk1OTIgMTguMTI3MiAxMS45NTk0IDE4LjI4MzMgMTIuMTIyM0MxOC41MTYxIDEyLjM2NTIgMTguNzU0OCAxMi41NzkyIDE4Ljk5OTYgMTIuNzY0NFoiLz4mI3hhOzwvc3ZnPg==" preserveAspectRatio="none" opacity="0.5"/><ellipse cx="21" cy="31" rx="20" ry="20" fill="#e6e6e6" stroke="#666666" stroke-width="2" pointer-events="all"/><g transform="translate(-0.5 -0.5)" opacity="0.5"><switch><foreignObject pointer-events="none" width="100%" height="100%" requiredFeatures="http://www.w3.org/TR/SVG11/feature#Extensibility" style="overflow: visible; text-align: left;"><div xmlns="http://www.w3.org/1999/xhtml" style="display: flex; align-items: unsafe center; justify-content: unsafe center; width: 38px; height: 1px; padding-top: 31px; margin-left: 2px;"><div data-drawio-colors="color: rgb(0, 0, 0); " style="box-sizing: border-box; font-size: 0px; text-align: center;"><div style="display: inline-block; font-size: 18px; font-family: "Segoe UI semibold"; color: rgb(0, 0, 0); line-height: 1.2; pointer-events: all; font-weight: bold; white-space: normal; overflow-wrap: normal;">3</div></div></div></foreignObject><text x="21" y="36" fill="rgb(0, 0, 0)" font-family="Segoe UI semibold" font-size="18px" text-anchor="middle" font-weight="bold">3</text></switch></g></g></svg>
|
After Width: | Height: | Size: 3.3 KiB |
@ -0,0 +1,3 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
|
||||
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" width="272px" height="112px" viewBox="-0.5 -0.5 272 112"><defs/><g><rect x="21" y="1" width="250" height="110" rx="4.4" ry="4.4" fill-opacity="0.95" fill="rgb(255, 255, 255)" stroke="#0078d4" stroke-opacity="0.95" stroke-width="2" pointer-events="all"/><image x="105.5" y="15.5" width="80" height="80" xlink:href="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIGZpbGw9Im5vbmUiIHZpZXdCb3g9IjAgMCAyNCAyNCIgaGVpZ2h0PSIyNCIgd2lkdGg9IjI0Ij4mI3hhOyAgPHBhdGggZmlsbD0iIzIxMjEyMSIgZD0iTTE3Ljc0OSAzTDE3LjkzMzQgMy4wMDUxNEMxOS41ODI3IDMuMDk3MzQgMjAuOTAyOSA0LjQxNzUgMjAuOTk1MSA2LjA2NTU4TDIxLjAwMDIgNi4yNVYxMi42MTA4QzIwLjMxMzMgMTIuNDc5MyAxOS42NTU0IDEyLjEwODggMTkuMDA1NCAxMS40MzA1TDE4Ljk5OTQgMTEuNDI0M0wxOC45OTkgOEg1LjAwMDIyTDQuOTk5MDIgMTcuNzVDNC45OTkwMiAxOC4zOTcyIDUuNDkwODkgMTguOTI5NSA2LjEyMTIxIDE4Ljk5MzVMNi4yNDkwMiAxOUgxMy4zNzUzQzEzLjU3ODggMTkuNTk1MyAxMy44NjY5IDIwLjE0NjIgMTQuMjQzOSAyMC42NDU3QzE0LjMzNjEgMjAuNzY3OCAxNC40MzI4IDIwLjg4NTkgMTQuNTM0IDIxSDYuMjQ5MDJDNC41MTU5OSAyMSAzLjA5OTc3IDE5LjY0MzUgMy4wMDQxNiAxNy45MzQ0TDIuOTk5MDIgMTcuNzVWNi4yNUMyLjk5OTAyIDQuNTE2OTcgNC4zNTU0NyAzLjEwMDc1IDYuMDY0NiAzLjAwNTE0TDYuMjQ5MDIgM0gxNy43NDlaTTE4Ljk5OTYgMTIuNzY0NEMxOS42MjUxIDEzLjIzNzUgMjAuMjkwNiAxMy41MjMgMjEuMDAwMiAxMy42MjQ1QzIxLjE5NjYgMTMuNjUyNyAyMS4zOTY0IDEzLjY2NjcgMjEuNTk5NiAxMy42NjY3QzIxLjc5MjkgMTMuNjY2NyAyMS45NTQyIDEzLjgwOTUgMjEuOTkxNSAxMy45OTk0TDIxLjk5OTYgMTQuMDgzM1YxNi41ODQ0QzIxLjk5OTYgMTkuMjY2MyAyMC42ODY2IDIxLjA4OTYgMTguMTI2MSAyMS45Nzg2QzE4LjA0NCAyMi4wMDcxIDE3Ljk1NTIgMjIuMDA3MSAxNy44NzMxIDIxLjk3ODZDMTcuMTQ3OSAyMS43MjY4IDE2LjUyMjcgMjEuNCAxNS45OTkxIDIxQzE1LjI5NyAyMC40NjM2IDE0Ljc3NzYgMTkuNzk1NiAxNC40NDQzIDE5QzE0LjE3NzkgMTguMzY0IDE0LjAzMDYgMTcuNjQ2NiAxNC4wMDQgMTYuODQ5N0wxMy45OTk2IDE2LjU4NDRWMTQuMDgzM0MxMy45OTk2IDEzLjg1MzIgMTQuMTc4NyAxMy42NjY3IDE0LjM5OTYgMTMuNjY2N0MxNS42MjMgMTMuNjY2NyAxNi43MjMgMTMuMTU3NSAxNy43MTc1IDEyLjEyMkMxNy44NzM4IDExLjk1OTIgMTguMTI3MiAxMS45NTk0IDE4LjI4MzMgMTIuMTIyM0MxOC41MTYxIDEyLjM2NTIgMTguNzU0OCAxMi41NzkyIDE4Ljk5OTYgMTIuNzY0NFoiLz4mI3hhOzwvc3ZnPg==" preserveAspectRatio="none"/><ellipse cx="21" cy="31" rx="20" ry="20" fill="#0078d4" stroke="#ffffff" stroke-width="2" pointer-events="all"/><g transform="translate(-0.5 -0.5)"><switch><foreignObject pointer-events="none" width="100%" height="100%" requiredFeatures="http://www.w3.org/TR/SVG11/feature#Extensibility" style="overflow: visible; text-align: left;"><div xmlns="http://www.w3.org/1999/xhtml" style="display: flex; align-items: unsafe center; justify-content: unsafe center; width: 38px; height: 1px; padding-top: 31px; margin-left: 2px;"><div data-drawio-colors="color: #ffffff; " style="box-sizing: border-box; font-size: 0px; text-align: center;"><div style="display: inline-block; font-size: 18px; font-family: "Segoe UI semibold"; color: rgb(255, 255, 255); line-height: 1.2; pointer-events: all; font-weight: bold; white-space: normal; overflow-wrap: normal;">3</div></div></div></foreignObject><text x="21" y="36" fill="#ffffff" font-family="Segoe UI semibold" font-size="18px" text-anchor="middle" font-weight="bold">3</text></switch></g></g></svg>
|
After Width: | Height: | Size: 3.2 KiB |
After Width: | Height: | Size: 447 KiB |
After Width: | Height: | Size: 594 KiB |
After Width: | Height: | Size: 420 KiB |
After Width: | Height: | Size: 162 KiB |
After Width: | Height: | Size: 304 KiB |
After Width: | Height: | Size: 651 KiB |
85
education/windows/tutorial-deploy-apps-winse/index.md
Normal file
@ -0,0 +1,85 @@
|
||||
---
|
||||
title: Deploy applications to Windows 11 SE with Intune
|
||||
description: Learn how to deploy applications to Windows 11 SE with Intune and how to validate the apps.
|
||||
ms.date: 06/07/2023
|
||||
ms.topic: tutorial
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE, version 22H2 and later</a>
|
||||
---
|
||||
|
||||
# Tutorial: deploy applications to Windows 11 SE with Intune
|
||||
|
||||
This guide describes how to deploy applications to Windows 11 SE devices that are managed by Microsoft Intune in an education environment. The guide also describes how to validate the apps and how to create policies to allow apps that aren't installable or don't behave as intended.
|
||||
|
||||
## Windows 11 SE and application deployment
|
||||
|
||||
Windows 11 SE is designed to provide a simplified and secure experience for students. Windows 11 SE prevents the installation and execution of third party applications with a technology called *Windows Defender Application Control (WDAC)*.
|
||||
|
||||
WDAC applies an *allowlist* policy called *Windows 11 SE base policy*, which ensures that unwanted apps don't run or get installed. However, it also prevents IT admins from deploying apps to Windows 11 SE devices, unless they're included in the Windows 11 SE base policy.
|
||||
|
||||
With the use of WDAC *supplemental policies*, Intune allows specific third party applications to be installed and executed. The [allowlist process][EDU-1] is done on an app-by-app basis, and the time to request an application to be allowed and have the supplemental policy deployed can be lengthy.
|
||||
|
||||
Starting with Windows 11 SE, version 22H2, IT admins have more flexibility to deploy applications to Windows 11 SE devices. When a Windows 11 SE device is enrolled in an Intune education tenant, it will automatically receive an AppLocker policy that sets the *Intune Management Extension (IME)* as a *managed installer*.
|
||||
|
||||
As a managed installer, applications deployed through the IME will be automatically allowed on Windows 11 SE, removing the allowlist process requirement. For more information about managed installer, see [How does a managed installer work?][WIN-2]
|
||||
|
||||
> [!NOTE]
|
||||
> End-users of Windows 11 SE devices still cannot install and use arbitrary applications without being blocked. Only IT admins can control what apps are allowed.
|
||||
|
||||
## Tutorial objectives
|
||||
|
||||
Even when using managed installer, some applications may not execute due to their type or complexity. In these scenarios, the IT admin must create their own policies that allow the apps execution.\
|
||||
The policies can then be deployed to the Windows SE devices via Intune.
|
||||
|
||||
In this tutorial you'll learn:
|
||||
|
||||
- Which types of apps can be deployed via Intune to Windows 11 SE devices
|
||||
- How to verify that the apps are installed correctly
|
||||
- How to mitigate app installation issues
|
||||
- Special considerations when deploying apps to Windows 11 SE
|
||||
|
||||
## Installation process
|
||||
|
||||
There are three main steps to install an application on Windows 11 SE using the managed installer. Each step will be covered in detail in the next sections of this tutorial:
|
||||
|
||||
:::row:::
|
||||
:::column span="":::
|
||||
<a href="deploy-apps.md"><img src="images/phase-1-on.svg" alt="Icon representing the first phase."/></a><br>
|
||||
[**Deploy an application via Microsoft Intune**](deploy-apps.md)<br>
|
||||
Applications are deployed via Microsoft Intune. There are some restrictions on the types of apps that are compatible with managed installers, but the process is the same used for non-Windows 11 SE devices
|
||||
:::column-end:::
|
||||
:::column span="":::
|
||||
<a href="validate-apps.md"><img src="images/phase-2-on.svg" alt="Icon representing the second phase."/></a><br>
|
||||
[**Validate the application**](validate-apps.md)<br>
|
||||
Applications are validated to ensure that they're installed and execute successfully. The process is the same for non-Windows 11 SE devices. Some applications may be incompatible due to how they're installed, how they execute, or how they update. You'll learn about known limitations in a later section of the tutorial
|
||||
:::column-end:::
|
||||
:::column span="":::
|
||||
<a href="create-policies.md"><img src="images/phase-3-on.svg" alt="Icon representing the third phase."/></a><br>
|
||||
[**Create additional policies (optional)**](create-policies.md)<br>
|
||||
To allow apps that aren't installable or don't behave as intended, more policies can be created and deployed so that the apps can be used
|
||||
:::column-end:::
|
||||
:::row-end:::
|
||||
|
||||
All the steps are done by the IT administrator. Once the steps are complete, users of Windows 11 SE devices should be able to run the applications deployed via Intune.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
To receive policies on your Windows 11 SE devices, allowing app installation from Intune, you must have:
|
||||
|
||||
- Windows 11 SE, version 22H2 with [KB5019980][KB-1] and later
|
||||
- Intune for Education licenses. The license requirement is for the managed installer to deploy apps and supplemental policies via Intune
|
||||
|
||||
If you don't have an Intune for Education license for your devices yet, refer to [Microsoft Intune for Education][EXT-1] for access to a free trial version.
|
||||
|
||||
## Next steps
|
||||
|
||||
Advance to the next article to learn which applications can be deployed to Windows 11 SE devices, and how to deploy them via Intune.
|
||||
|
||||
> [!div class="nextstepaction"]
|
||||
> [Next: deploy apps >](deploy-apps.md)
|
||||
|
||||
[KB-1]: https://support.microsoft.com/kb/5019980
|
||||
[EDU-1]: /education/windows/windows-11-se-overview#add-your-own-applications
|
||||
[EXT-1]: https://www.microsoft.com/en-us/education/intune
|
||||
[WIN-1]: /windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create
|
||||
[WIN-2]: /windows/security/threat-protection/windows-defender-application-control/configure-authorized-apps-deployed-with-a-managed-installer#how-does-a-managed-installer-work
|
17
education/windows/tutorial-deploy-apps-winse/toc.yml
Normal file
@ -0,0 +1,17 @@
|
||||
items:
|
||||
- name: Introduction
|
||||
href: index.md
|
||||
- name: 1. Deploy apps
|
||||
href: deploy-apps.md
|
||||
- name: 2. Validate apps
|
||||
href: validate-apps.md
|
||||
- name: 3. Create and deploy policies to allow apps
|
||||
items:
|
||||
- name: Create policies
|
||||
href: create-policies.md
|
||||
- name: Deploy policies
|
||||
href: deploy-policies.md
|
||||
- name: Important app deployment considerations
|
||||
href: considerations.md
|
||||
- name: Troubleshoot common issues
|
||||
href: troubleshoot.md
|
109
education/windows/tutorial-deploy-apps-winse/troubleshoot.md
Normal file
@ -0,0 +1,109 @@
|
||||
---
|
||||
title: Troubleshoot app deployment issues in Windows SE
|
||||
description: Troubleshoot common issues when deploying apps to Windows SE devices.
|
||||
ms.date: 06/19/2023
|
||||
ms.topic: tutorial
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE, version 22H2 and later</a>
|
||||
---
|
||||
|
||||
# Troubleshoot app deployment issues in Windows SE
|
||||
|
||||
The following table lists common app deployment issues on Windows 11 SE, and options to resolve them:
|
||||
|
||||
| **Problem** | **Potential solution** |
|
||||
|---|---|
|
||||
| **App hasn't installed** | <li>Check the type of app:<ul><li>Win32 apps should be able to install with no problem</li><li>UWP LOB apps apps aren't supported</li></ul></li><li>It's possible the app is trying to execute a blocked binary. Check the AppLocker and CodeIntegrity logs in the Event Viewer and verify if any executables related to the app are blocked. If so, you'll need to write a supplemental policy to support the app</li><li> Check the Intune Management Extension logs to see if there was an attempt to install your app</li>|
|
||||
| **App has problems when running** | It's possible the app is trying to execute a blocked binary<br> Check the **AppLocker** and **CodeIntegrity** logs in Event Viewer to see if any executables related to the app are being blocked. If so, you'll need to write a supplemental policy to support the app. |
|
||||
| **My supplemental policy hasn't deployed** |<li>Your XML policy is malformed. Double-check to see if all markup is tagged correctly</li><li>Check that your policy is correctly applied|
|
||||
|
||||
<!--
|
||||
The following table lists common app deployment issues on Windows 11 SE, and options to resolve them:
|
||||
|
||||
| **Problem** | **Potential solution** |
|
||||
|---|---|
|
||||
| **App hasn't installed** | <li>Check the type of app:<ul><li>Win32 apps should be able to install with no problem</li><li>UWP LOB apps require writing an additional supplemental policy</li><li>Microsoft Sore apps aren't supported</li></ul></li><li>Check that the managed installer policies are deployed correctly</li><li>It's possible the app is trying to execute a blocked binary. Check the AppLocker and CodeIntegrity logs in the Event Viewer and verify if any executables related to the app are blocked. If so, you'll need to write a supplemental policy to support the app</li><li> Check the Intune Management Extension logs to see if there was an attempt to install your app</li>|
|
||||
| **App has problems when running** | It's possible the app is trying to execute a blocked binary<br> Check the **AppLocker** and **CodeIntegrity** logs in Event Viewer to see if any executables related to the app are being blocked. If so, you'll need to write a supplemental policy to support the app. |
|
||||
| **My supplemental policy hasn't deployed** |<li>Your XML policy is malformed. Double-check to see if all markup is tagged correctly</li><li>Check that your policy is correctly applied|
|
||||
|
||||
|
||||
## WDAC Supplemental policy validation
|
||||
|
||||
Use the Event Viewer to see if a supplemental policy is deployed correctly. These rules apply to both the policy that allows managed installers and any supplemental policies that you deploy.
|
||||
|
||||
1. Open the **Event viewer** on a target device
|
||||
1. Expand **Applications and Services > Microsoft > Windows > CodeIntegrity > Operational**
|
||||
1. Check for **event ID 3099**: *the policy was Refreshed and activated*
|
||||
- For example: `Refreshed and activated Code Integrity policy {GUID} . id . Status 0x0`
|
||||
- The policy that allows managed installers is **`C0DB889B-59C5-453C-B297-399C851934E4`**. Checking that this policy is applied correctly, indicates that a device is setup to allow managed installers (and therefore, can allow installation of Win32 apps via the Intune Management Extension).\
|
||||
You can check that the **Managed Installer policy** rule was set in the policy, by checking the **Options** field in the **details** pane. For more information, see: [Understanding Application Control event IDs][WIN-1]
|
||||
|
||||
:::image type="content" source="images/troubleshoot-managed-installer-policy.png" alt-text="Screenshot of the CodeIntegrity operational log." lightbox="images/troubleshoot-managed-installer-policy.png":::
|
||||
|
||||
You can also verify that the policy has been activated by running the following from the <kbd>Win</kbd> + <kbd>R</kbd> *Run dialog* on a target device as an Administrator (hold <kbd>CTRL</kbd> + <kbd>Shift</kbd> when pressing Enter to run the command):
|
||||
|
||||
```
|
||||
citool.exe -lp
|
||||
```
|
||||
|
||||
- For the policy that allows managed installers to run, a policyID `C0DB889B-59C5-453C-B297-399C851934E4` and Friendly Name *[Win-EDU] Microsoft Apps Supplemental Policy - Prod* should be present, and have **Is Currently Enforced** showing as **true**
|
||||
- For any additional policies that you deploy, check that a policy with a matching ID and Friendly Name is shown in the list and the **Is Currently Enforced** and **Is Authorized** properties are both showing as **true**
|
||||
|
||||
:::image type="content" source="images/troubleshoot-citool.png" alt-text="Screenshot of the output of citool.exe with the Win-EDU supplemental policy.":::
|
||||
|
||||
1. Check for **error events** with code **3077**: and reference [Understanding Application Control event IDs][WIN-1]
|
||||
|
||||
:::image type="content" source="images/troubleshoot-codeintegrity-log.png" alt-text="Screenshot of the error in the CodeIntegrity operational log showing that PowerShell execution is prevented by policy." lightbox="images/troubleshoot-codeintegrity-log.png":::
|
||||
|
||||
When checking an error event, you can observe that the information in the *General* tab may show something like the following:
|
||||
|
||||
```
|
||||
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load **\Device\HarddiskVolume3\Windows\System32\WindowsPowerShell\v1.0\powershell.exe** that did not meet the Enterprise signing level requirements or violated code integrity policy (Policy ID:**{82443e1e-8a39-4b4a-96a8-f40ddc00b9f3}**).
|
||||
```
|
||||
|
||||
The important things to parse are:
|
||||
|
||||
- **Failing application**: the path and executable here inform you which application failed. It's important to check that this executable is expected for the application you're validating. (for example. You would expect zoom.exe to fail for Zoom as opposed to cmd.exe.)
|
||||
- **Error reason**: indicates why the application was unable to run. `...did not meet the Enterprise signing level requirements or violated code integrity policy` is what should be seen
|
||||
- **Policy ID**: is the policy that is being violated, meaning that a rule in the policy is preventing the application from running
|
||||
|
||||
> [!NOTE]
|
||||
> **{82443e1e-8a39-4b4a-96a8-f40ddc00b9f3}** is the base policy, which is what restricts most third-party apps from running. If you see another policy ID, it's worth taking note of that.
|
||||
|
||||
Alternatively you can use `cidiag.exe /stop`, which copies all potentially relevant logs and policy files to a folder. The command also parses the critical events from the **CodeIntegrity** and **AppLocker** logs to a text file.
|
||||
|
||||
-->
|
||||
|
||||
## AppLocker policy validation
|
||||
|
||||
To query AppLocker policies and validate that they're configured correctly, follow these steps:
|
||||
|
||||
1. Open the **Local Security Policy** mmc console (`secpol.msc`)
|
||||
1. Select **Security Settings > Application Control Policies**
|
||||
1. Right-click **AppLocker** and select **Export Policy…**
|
||||
:::image type="content" source="images/applocker-export-policy.png" alt-text="Screenshot of the export of the AppLocker policies from the Local Security Policy mmc console." lightbox="images/applocker-export-policy.png" border="false":::
|
||||
1. For the policy that sets the Intune Management Extension as a Managed installer, *MICROSOFT.MANAGEMENT.SERVICES.INTUNEWINDOWSAGENT.EXE* should be nested under a RuleCollection section of Type *ManagedInstaller*
|
||||
:::image type="content" source="images/applocker-policy-validation.png" alt-text="Screenshot of the xml file generated by the get-applockerpolicy PowerShell cmdlet." lightbox="images/applocker-policy-validation.png":::
|
||||
1. For any policies you added to set other executables you want to be managed installers, look for the rules you defined nested under a RuleCollection section of Type *ManagedInstaller*
|
||||
|
||||
### AppLocker service
|
||||
|
||||
To verify that the AppLocker service is running, follow these steps:
|
||||
|
||||
1. Open the **Services** mmc console (`services.msc`)
|
||||
1. Verify that the service **Application Identity** has a status of **Running**
|
||||
|
||||
### AppLocker event log validation
|
||||
|
||||
1. Open the **Event Viewer** on a target device
|
||||
1. Expand **Applications and Services > Microsoft > Windows > AppLocker > MSI and Script**
|
||||
1. Check for **error events** with code **8040**, and reference [Understanding Application Control event IDs][WIN-2]
|
||||
|
||||
## Intune Management Extension
|
||||
|
||||
- [Collect diagnostics from a Windows device][MEM-1]
|
||||
- Logs can be collected from `%programdata%\Microsoft\IntuneManagementExtension\Logs`
|
||||
|
||||
[MEM-1]: /mem/intune/remote-actions/collect-diagnostics
|
||||
[WIN-1]: /windows/security/threat-protection/windows-defender-application-control/event-tag-explanations#policy-activation-event-options
|
||||
[WIN-2]: /windows/security/threat-protection/windows-defender-application-control/event-id-explanations
|
172
education/windows/tutorial-deploy-apps-winse/validate-apps.md
Normal file
@ -0,0 +1,172 @@
|
||||
---
|
||||
title: Validate the applications deployed to Windows SE devices
|
||||
description: Learn how to validate the applications deployed to Windows SE devices via Intune.
|
||||
ms.date: 06/19/2023
|
||||
ms.topic: tutorial
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE, version 22H2 and later</a>
|
||||
---
|
||||
|
||||
# Validate the applications deployed to Windows SE devices
|
||||
|
||||
:::row:::
|
||||
:::column span="":::
|
||||
<a href="deploy-apps.md"><img src="images/phase-1-off.svg" alt="Icon representing the first phase."/></a><br>
|
||||
[**Deploy an application via Microsoft Intune**](deploy-apps.md)
|
||||
:::column-end:::
|
||||
:::column span="":::
|
||||
<a href="validate-apps.md"><img src="images/phase-2-on.svg" alt="Icon representing the second phase."/></a><br>
|
||||
[**Validate the application**](validate-apps.md)
|
||||
:::column-end:::
|
||||
:::column span="":::
|
||||
<a href="create-policies.md"><img src="images/phase-3-off.svg" alt="Icon representing the third phase."/></a><br>
|
||||
[**Create additional policies (optional)**](create-policies.md)
|
||||
:::column-end:::
|
||||
:::row-end:::
|
||||
|
||||
A fundamental step in deploying apps to Windows 11 SE devices is to validate that the apps work as expected.
|
||||
|
||||
Application validation consists of the following steps:
|
||||
|
||||
1. Wait for the application to install
|
||||
1. Verify that the app installed successfully
|
||||
1. Open the app and exercise all user workflows
|
||||
1. Inspect the app and take note of any potential problems
|
||||
|
||||
> [!NOTE]
|
||||
> Apps must be validated on a case-by-case basis. A successful installation doesn't mean that the app will run properly. A successful execution of the app, doesn't mean it will *always* run properly.
|
||||
|
||||
## Wait for the application to install
|
||||
|
||||
Application installation depends on two factors:
|
||||
|
||||
- When the managed installer policies are applied to the device. These policies are automatically applied to Windows SE devices when they are enrolled in Intune
|
||||
- When the apps are deployed to a device
|
||||
|
||||
> [!IMPORTANT]
|
||||
> The Intune management extension agent checks every hour (or on service or device restart) for any new Win32 app assignments.
|
||||
|
||||
If the Windows 11 SE base policy doesn't block the application that you're trying to deploy, the process to deploy the app to Windows SE devices should be consistent with non-SE devices.
|
||||
|
||||
## Check for installation
|
||||
|
||||
There are two ways to verify that an app installed successfully:
|
||||
|
||||
- Intune portal
|
||||
- On the device
|
||||
|
||||
Both options are worth checking. Installation in Intune can be used to check the installation status remotely and to ensure that the installation detection rules are configured correctly. Checking on the device can indicate if the app installed and if it runs properly.
|
||||
|
||||
### Check for installation from Intune
|
||||
|
||||
To check the installation status of an app from the Intune portal:
|
||||
|
||||
1. Sign in to the <a href="https://intune.microsoft.com/" target="_blank"><b>Microsoft Intune admin center</b></a>
|
||||
1. Select **App > All apps**
|
||||
1. Select the application you want to check
|
||||
1. From the **Overview** page, you can verify the overall installation status
|
||||
|
||||
:::image type="content" source="./images/intune-app-install-overview.png" alt-text="Screenshot of the Microsoft Intune admin center - App installation details." lightbox="./images/intune-app-install-overview.png":::
|
||||
|
||||
1. From the **Device install status** page, you can verify the installation status for each device, and the status code that indicates the cause of the failure
|
||||
|
||||
:::image type="content" source="./images/intune-app-install-status.png" alt-text="Screenshot of the Microsoft Intune admin center - App installation status for each device." lightbox="./images/intune-app-install-status.png":::
|
||||
|
||||
> [!NOTE]
|
||||
> A Win32 application may install correctly, but report to Intune as failed.\
|
||||
> A Win32 app may also fail to install, but report as installed to Intune.
|
||||
>
|
||||
> In both cases, the issue may be in the detection rules defined in Intune, which must be configured correctly to detect the installation of the app.
|
||||
|
||||
### Check for installation on the device
|
||||
|
||||
On a Windows SE device, open the **Settings** app and select **Apps** > **Installed apps**. You can see the list of installed apps and validate that your targeted app is listed.
|
||||
|
||||
Another way to validate that the app has installed is to check its installation directory. The path is usually `C:\Program Files` or `C:\Program Files (x86)`, but can vary from app to app.
|
||||
|
||||
Lastly, launch the app to ensure that it has installed correctly.
|
||||
|
||||
## Check for compatibility
|
||||
|
||||
Checking for compatibility often means to execute the app and verify its functionalities. Here are some things to try while testing the behavior of your app:
|
||||
|
||||
- Open the app
|
||||
- Test the core functionality and common user scenarios. Exercise a common workflow that a user would do with the app
|
||||
- Force an update of the app
|
||||
|
||||
Here are things to pay attention to:
|
||||
|
||||
- Know how the apps you deploy are updated, and if they offer controls for automatic updates
|
||||
- Dialogs may pop up during the app use, indicating that something is blocked
|
||||
- Multiple apps are installed, especially if one app appears to be a launcher/updater. For example, Adobe Photoshop includes the Adobe Creative Cloud launcher, which updates Photoshop and other apps
|
||||
- Any messages indicating that the app is doing pre-installation work or downloading more content
|
||||
- Logs in the Event Viewer
|
||||
|
||||
### Compatible apps
|
||||
|
||||
If an app appears to be functioning correctly without being blocked, it's likely compatible with managed installer installation.
|
||||
However, just because an app works initially doesn't mean it will *always* work. Self-updates or separate launchers/clients may update the apps.
|
||||
|
||||
### Semi-compatible apps
|
||||
|
||||
Semi-compatible apps may run without problems initially, but in the future they can be restricted to run after it self-updates or another installer/updater app installs over it.
|
||||
|
||||
### Incompatible apps
|
||||
|
||||
Incompatible apps may launch initially, but immediately begin to download more resources.\
|
||||
These apps are eventually blocked before any of their functionalities can be accessed. Or, these apps may not launch due to a dependent file blocked by the Windows 11 SE base policy.
|
||||
|
||||
### Visual error notifications
|
||||
|
||||
You may see a dialog indicating **This app won't run on your PC**. Check the indicated executable and verify that it matches the executable of the installed application.
|
||||
|
||||
:::image type="content" source="images/winse-app-block.png" alt-text="Screenshot of Windows SE - error window while opening an app.":::
|
||||
|
||||
### Event Viewer
|
||||
|
||||
More detail can be obtained when looking for events indicating blocked executables in the Event Viewer.\
|
||||
The event logs are:
|
||||
|
||||
- **CodeIntegrity > Operational**
|
||||
- **AppLocker > MSI and Script**
|
||||
|
||||
For more information, see the [Troubleshoot](troubleshoot.md) section.
|
||||
|
||||
## Known limitations
|
||||
|
||||
Not all apps are compatible with managed installers, even after installation.
|
||||
|
||||
To learn about known limitations with apps deployed via a managed installer, see [Known limitations with managed installer][WIN-1].
|
||||
|
||||
<!--
|
||||
> [!NOTE]
|
||||
> UWP LOB apps aren't installed using the Intune Management Extension and thus aren't tracked by the managed installer heuristic. LOB apps must be authorized separately in your WDAC policy.
|
||||
-->
|
||||
|
||||
## Section review
|
||||
|
||||
Before moving on to the next section, ensure that you've completed the following tasks:
|
||||
|
||||
> [!div class="checklist"]
|
||||
> - Verified any installation errors from Intune
|
||||
> - Verified the app installation on the device
|
||||
> - Checked for any errors when opening the app from the device
|
||||
> - Checked for any errors in the Event Viewer
|
||||
|
||||
## Next steps
|
||||
|
||||
Select one of the following options to learn the next steps:
|
||||
|
||||
<!--- If the apps don't work as expected, you must create and deploy WDAC or AppLocker policies to allow the apps to run-->
|
||||
- If the apps don't work as expected, you must create and deploy AppLocker policies to allow the apps to run
|
||||
> [!div class="nextstepaction"]
|
||||
> [Next: Create policies>](create-policies.md)
|
||||
- If the applications you are deploying don't have any issues, you can skip to important considerations when deploying apps and policies
|
||||
> [!div class="nextstepaction"]
|
||||
> [Next: Important deployment considerations>](considerations.md)
|
||||
|
||||
[M365-1]: /microsoft-365/education/deploy/microsoft-store-for-education
|
||||
|
||||
[WIN-1]: /windows/security/threat-protection/windows-defender-application-control/configure-authorized-apps-deployed-with-a-managed-installer#known-limitations-with-managed-installer
|
||||
[WIN-2]: /windows/msix/
|
||||
[WIN-3]: /windows/security/threat-protection/windows-defender-application-control/manage-packaged-apps-with-windows-defender-application-control
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Configure applications with Microsoft Intune
|
||||
description: Learn how to configure applications with Microsoft Intune in preparation for device deployment.
|
||||
ms.date: 08/31/2022
|
||||
ms.date: 03/08/2023
|
||||
ms.topic: tutorial
|
||||
---
|
||||
|
||||
@ -54,21 +54,10 @@ To assign applications to a group of users or devices:
|
||||
|
||||
## Considerations for Windows 11 SE
|
||||
|
||||
Windows 11 SE supports all web applications and a *curated list* of desktop applications.
|
||||
You can prepare and add a desktop app to Microsoft Intune as a Win32 app from the [approved app list][EDU-1].
|
||||
Windows 11 SE prevents the installation and execution of third party applications with a technology called **Windows Defender Application Control** (WDAC).
|
||||
WDAC applies an *allowlist* policy, which ensures that unwanted apps don't run or get installed. However, it also prevents IT admins from deploying apps to Windows 11 SE devices, unless they're included in the E Mode policy.
|
||||
|
||||
The process to add Win32 applications to Intune is described in the article [Add, assign, and monitor a Win32 app in Microsoft Intune][MEM-1].
|
||||
|
||||
> [!NOTE]
|
||||
> If the applications you need aren't included in the list, anyone in your school district can submit an application request at <a href="https://edusupport.microsoft.com/support?product_id=win11se" target="_blank"><u>Microsoft Education Support</u></a>.
|
||||
|
||||
> [!CAUTION]
|
||||
> If you assign an app to a device running **Windows 11 SE** and receive the **0x87D300D9** error code with a **Failed** state:
|
||||
> - Be sure the app is on the [<u>approved app list</u>][EDU-1]
|
||||
> - If you submitted a request to add your own app and it was approved, check that the app meets package requirements
|
||||
> - If the app is not approved, it will not run on Windows 11 SE. In this case, you will have to verify if the app can run in a web browser, such as a web app or PWA
|
||||
|
||||
________________________________________________________
|
||||
To learn more about which apps are supported in Windows 11 SE, and how to deploy them, see the tutorial [Deploy applications to Windows 11 SE with Intune][EDU-1].
|
||||
|
||||
## Next steps
|
||||
|
||||
@ -79,7 +68,7 @@ With the applications configured, you can now deploy students' and teachers' dev
|
||||
|
||||
<!-- Reference links in article -->
|
||||
|
||||
[EDU-1]: /education/windows/windows-11-se-overview
|
||||
[EDU-1]: ../tutorial-deploy-apps-winse/index.md
|
||||
|
||||
[MEM-1]: /mem/intune/apps/apps-win32-add
|
||||
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Enrollment in Intune with Windows Autopilot
|
||||
description: Learn how to join Azure AD and enroll in Intune using Windows Autopilot.
|
||||
ms.date: 08/31/2022
|
||||
ms.date: 03/08/2023
|
||||
ms.topic: tutorial
|
||||
---
|
||||
|
||||
@ -97,7 +97,7 @@ To deploy the ESP to devices, you need to create an ESP profile in Microsoft Int
|
||||
For more information, see [Set up the Enrollment Status Page][MEM-3].
|
||||
|
||||
> [!CAUTION]
|
||||
> When targeting an ESP to **Windows 11 SE** devices, only applications included in the [<u>approved app list</u>][EDU-1] should part of the ESP configuration.
|
||||
> The Enrollment Status Page (ESP) is compatible with Windows 11 SE. However, due to the E Mode policy, devices may not complete the enrollment. For more information, see [Enrollment Status Page][EDU-3].
|
||||
|
||||
### Autopilot end-user experience
|
||||
|
||||
@ -144,5 +144,6 @@ With the devices joined to Azure AD tenant and managed by Intune, you can use In
|
||||
|
||||
[EDU-1]: /education/windows/windows-11-se-overview
|
||||
[EDU-2]: /intune-education/windows-11-se-overview#windows-autopilot
|
||||
[EDU-3]: ../tutorial-deploy-apps-winse/considerations.md#enrollment-status-page
|
||||
|
||||
[SURF-1]: /surface/surface-autopilot-registration-support
|
@ -2,7 +2,7 @@
|
||||
title: Introduction to the tutorial deploy and manage Windows devices in a school
|
||||
description: Introduction to deployment and management of Windows devices in education environments.
|
||||
ms.date: 08/31/2022
|
||||
ms.topic: conceptual
|
||||
ms.topic: tutorial
|
||||
---
|
||||
|
||||
# Tutorial: deploy and manage Windows devices in a school
|
||||
|
@ -33,6 +33,9 @@ sections:
|
||||
- question: Can I load Windows 11 SE on any hardware?
|
||||
answer: |
|
||||
Windows 11 SE is only available on devices that are built for education. To learn more, see [Windows 11 SE Overview](/education/windows/windows-11-se-overview).
|
||||
- question: Can I PXE boot a Windows SE device?
|
||||
answer: |
|
||||
No, Secure Boot prevents Windows SE devices from booting via PXE. As a workaround, you can use a UEFI bootable USB device to boot the device.
|
||||
- name: Applications and settings
|
||||
questions:
|
||||
- question: How can I install applications on Windows 11 SE?
|
||||
|
@ -1,8 +1,8 @@
|
||||
---
|
||||
title: Windows 11 SE Overview
|
||||
description: Learn about Windows 11 SE, and the apps that are included with the operating system.
|
||||
ms.topic: article
|
||||
ms.date: 03/09/2023
|
||||
ms.topic: overview
|
||||
ms.date: 08/03/2023
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE</a>
|
||||
ms.collection:
|
||||
@ -35,11 +35,11 @@ The following table lists the different application types available in Windows o
|
||||
| --- | --- | :---: | ---|
|
||||
|Progressive Web Apps (PWAs) | PWAs are web-based applications that can run in a browser and that can be installed as standalone apps. |✅|PWAs are enabled by default in Windows 11 SE.|
|
||||
| Web apps | Web apps are web-based applications that run in a browser. | ✅ | Web apps are enabled by default in Windows 11 SE. |
|
||||
|Win32| Win32 applications are Windows classic applications that may require installation |⛔| If users try to install or execute Win32 applications that haven't been allowed to run, they'll fail.|
|
||||
|Universal Windows Platform (UWP)/Store apps |UWP apps are commonly obtained from the Microsoft Store and may require installation |⛔|If users try to install or execute UWP applications that haven't been allowed to run, they'll fail.|
|
||||
|`Win32`| `Win32` applications are Windows classic applications that may require installation |⛔| If users try to install or execute `Win32` applications that haven't been allowed to run, they fail.|
|
||||
|Universal Windows Platform (UWP)/Store apps |UWP apps are commonly obtained from the Microsoft Store and may require installation |⛔|If users try to install or execute UWP applications that haven't been allowed to run, they fail.|
|
||||
|
||||
> [!IMPORTANT]
|
||||
> If there are specific Win32 or UWP applications that you want to allow, work with Microsoft to get them enabled. For more information, see [Add your own applications](#add-your-own-applications).
|
||||
> If there are specific `Win32` or UWP applications that you want to allow, work with Microsoft to get them enabled. For more information, see [Add your own applications](#add-your-own-applications).
|
||||
|
||||
## Applications included in Windows 11 SE
|
||||
|
||||
@ -50,10 +50,10 @@ The following table lists all the applications included in Windows 11 SE and the
|
||||
| Alarm & Clock | UWP | | |
|
||||
| Calculator | UWP | ✅ | |
|
||||
| Camera | UWP | ✅ | |
|
||||
| Microsoft Edge | Win32 | ✅ | ✅ |
|
||||
| Excel | Win32 | ✅ | |
|
||||
| Microsoft Edge | `Win32` | ✅ | ✅ |
|
||||
| Excel | `Win32` | ✅ | |
|
||||
| Feedback Hub | UWP | | |
|
||||
| File Explorer | Win32 | | ✅ |
|
||||
| File Explorer | `Win32` | | ✅ |
|
||||
| FlipGrid | PWA | | |
|
||||
| Get Help | UWP | | |
|
||||
| Media Player | UWP | ✅ | |
|
||||
@ -61,108 +61,120 @@ The following table lists all the applications included in Windows 11 SE and the
|
||||
| Minecraft: Education Edition | UWP | | |
|
||||
| Movies & TV | UWP | | |
|
||||
| News | UWP | | |
|
||||
| Notepad | Win32 | | |
|
||||
| OneDrive | Win32 | | |
|
||||
| OneNote | Win32 | ✅ | |
|
||||
| Notepad | `Win32` | | |
|
||||
| OneDrive | `Win32` | | |
|
||||
| OneNote | `Win32` | ✅ | |
|
||||
| Outlook | PWA | ✅ | |
|
||||
| Paint | Win32 | ✅ | |
|
||||
| Paint | `Win32` | ✅ | |
|
||||
| Photos | UWP | | |
|
||||
| PowerPoint | Win32 | ✅ | |
|
||||
| PowerPoint | `Win32` | ✅ | |
|
||||
| Settings | UWP | ✅ | |
|
||||
| Snip & Sketch | UWP | | |
|
||||
| Sticky Notes | UWP | | |
|
||||
| Teams | Win32 | ✅ | |
|
||||
| Teams | `Win32` | ✅ | |
|
||||
| To Do | UWP | | |
|
||||
| Whiteboard | UWP | ✅ | |
|
||||
| Word | Win32 | ✅ | |
|
||||
| Word | `Win32` | ✅ | |
|
||||
|
||||
## Available applications
|
||||
|
||||
The following applications can also run on Windows 11 SE, and can be deployed using Intune for Education. For more information, see [Configure applications with Microsoft Intune][EDUWIN-1]
|
||||
The following applications can also run on Windows 11 SE, and can be deployed using Intune for Education. For more information, see [Configure applications with Microsoft Intune][EDUWIN-1].
|
||||
|
||||
| Application | Supported version | App Type | Vendor |
|
||||
|-------------------------------------------|-------------------|----------|-------------------------------------------|
|
||||
| `3d builder` | 18.0.1931.0 | Win32 | `Microsoft` |
|
||||
| `Absolute Software Endpoint Agent` | 7.20.0.1 | Win32 | `Absolute Software Corporation` |
|
||||
| `AirSecure` | 8.0.0 | Win32 | `AIR` |
|
||||
| `Alertus Desktop` | 5.4.48.0 | Win32 | `Alertus technologies` |
|
||||
| `Brave Browser` | 106.0.5249.119 | Win32 | `Brave` |
|
||||
| `3d builder` | 18.0.1931.0 | `Win32` | `Microsoft` |
|
||||
| `Absolute Software Endpoint Agent` | 7.20.0.1 | `Win32` | `Absolute Software Corporation` |
|
||||
| `AirSecure` | 8.0.0 | `Win32` | `AIR` |
|
||||
| `Alertus Desktop` | 5.4.48.0 | `Win32` | `Alertus technologies` |
|
||||
| `Brave Browser` | 106.0.5249.119 | `Win32` | `Brave` |
|
||||
| `Bulb Digital Portfolio` | 0.0.7.0 | `Store` | `Bulb` |
|
||||
| `CA Secure Browser` | 14.0.0 | Win32 | `Cambium Development` |
|
||||
| `Cisco Umbrella` | 3.0.110.0 | Win32 | `Cisco` |
|
||||
| `CKAuthenticator` | 3.6+ | Win32 | `ContentKeeper` |
|
||||
| `Class Policy` | 116.0.0 | Win32 | `Class Policy` |
|
||||
| `Classroom.cloud` | 1.40.0004 | Win32 | `NetSupport` |
|
||||
| `CoGat Secure Browser` | 11.0.0.19 | Win32 | `Riverside Insights` |
|
||||
| `ColorVeil` | 4.0.0.175 | Win32 | `East-Tec` |
|
||||
| `ContentKeeper Cloud` | 9.01.45 | Win32 | `ContentKeeper Technologies` |
|
||||
| `DigiExam` | 14.0.6 | Win32 | `Digiexam` |
|
||||
| `Dragon Professional Individual` | 15.00.100 | Win32 | `Nuance Communications` |
|
||||
| `CA Secure Browser` | 14.0.0 | `Win32` | `Cambium Development` |
|
||||
| `Cisco Umbrella` | 3.0.343.0 | `Win32` | `Cisco` |
|
||||
| `CKAuthenticator` | 3.6+ | `Win32` | `ContentKeeper` |
|
||||
| `Class Policy` | 116.0.0 | `Win32` | `Class Policy` |
|
||||
| `Classroom.cloud` | 1.40.0004 | `Win32` | `NetSupport` |
|
||||
| `Clipchamp` | 2.5.2. | `Store` | `Microsoft` |
|
||||
| `CoGat Secure Browser` | 11.0.0.19 | `Win32` | `Riverside Insights` |
|
||||
| `ColorVeil` | 4.0.0.175 | `Win32` | `East-Tec` |
|
||||
| `ContentKeeper Cloud` | 9.01.45 | `Win32` | `ContentKeeper Technologies` |
|
||||
| `DigiExam` | 14.0.6 | `Win32` | `Digiexam` |
|
||||
| `Dragon Professional Individual` | 15.00.100 | `Win32` | `Nuance Communications` |
|
||||
| `DRC INSIGHT Online Assessments` | 13.0.0.0 | `Store` | `Data recognition Corporation` |
|
||||
| `Duo from Cisco` | 3.0.0 | Win32 | `Cisco` |
|
||||
| `e-Speaking Voice and Speech recognition` | 4.4.0.8 | Win32 | `e-speaking` |
|
||||
| `EasyReader` | 10.0.3.481 | Win32 | `Dolphin Computer Access` |
|
||||
| `Epson iProjection` | 3.31 | Win32 | `Epson` |
|
||||
| `eTests` | 4.0.25 | Win32 | `CASAS` |
|
||||
| `Exam Writepad` | 22.10.14.1834 | Win32 | `Sheldnet` |
|
||||
| `FirstVoices Keyboard` | 15.0.270 | Win32 | `SIL International` |
|
||||
| `FortiClient` | 7.2.0.4034+ | Win32 | `Fortinet` |
|
||||
| `Free NaturalReader` | 16.1.2 | Win32 | `Natural Soft` |
|
||||
| `Ghotit Real Writer & Reader` | 10.14.2.3 | Win32 | `Ghotit Ltd` |
|
||||
| `GoGuardian` | 1.4.4 | Win32 | `GoGuardian` |
|
||||
| `Google Chrome` | 110.0.5481.178 | Win32 | `Google` |
|
||||
| `GuideConnect` | 1.23 | Win32 | `Dolphin Computer Access` |
|
||||
| `Illuminate Lockdown Browser` | 2.0.5 | Win32 | `Illuminate Education` |
|
||||
| `Immunet` | 7.5.8.21178 | Win32 | `Immunet` |
|
||||
| `Impero Backdrop Client` | 4.4.86 | Win32 | `Impero Software` |
|
||||
| `IMT Lazarus` | 2.86.0 | Win32 | `IMTLazarus` |
|
||||
| `Inspiration 10` | 10.11 | Win32 | `TechEdology Ltd` |
|
||||
| `JAWS for Windows` | 2022.2112.24 | Win32 | `Freedom Scientific` |
|
||||
| `Kite Student Portal` | 9.0.0.0 | Win32 | `Dynamic Learning Maps` |
|
||||
| `Keyman` | 16.0.138 | Win32 | `SIL International`
|
||||
| `Duo from Cisco` | 3.0.0 | `Win32` | `Cisco` |
|
||||
| `Dyknow` | 7.9.13.7 | `Win32` | `Dyknow` |
|
||||
| `e-Speaking Voice and Speech recognition` | 4.4.0.11 | `Win32` | `e-speaking` |
|
||||
| `EasyReader` | 10.0.4.498 | `Win32` | `Dolphin Computer Access` |
|
||||
| `Easysense 2` | 1.32.0001 | `Win32` | `Data Harvest` |
|
||||
| `Epson iProjection` | 3.31 | `Win32` | `Epson` |
|
||||
| `eTests` | 4.0.25 | `Win32` | `CASAS` |
|
||||
| `Exam Writepad` | 23.2.4.2338 | `Win32` | `Sheldnet` |
|
||||
| `FirstVoices Keyboard` | 15.0.270 | `Win32` | `SIL International` |
|
||||
| `FortiClient` | 7.2.0.4034+ | `Win32` | `Fortinet` |
|
||||
| `Free NaturalReader` | 16.1.2 | `Win32` | `Natural Soft` |
|
||||
| `Ghotit Real Writer & Reader` | 10.14.2.3 | `Win32` | `Ghotit Ltd` |
|
||||
| `GoGuardian` | 1.4.4 | `Win32` | `GoGuardian` |
|
||||
| `Google Chrome` | 110.0.5481.178 | `Win32` | `Google` |
|
||||
| `GuideConnect` | 1.24 | `Win32` | `Dolphin Computer Access` |
|
||||
| `Illuminate Lockdown Browser` | 2.0.5 | `Win32` | `Illuminate Education` |
|
||||
| `Immunet` | 7.5.8.21178 | `Win32` | `Immunet` |
|
||||
| `Impero Backdrop Client` | 5.0.87 | `Win32` | `Impero Software` |
|
||||
| `IMT Lazarus` | 2.86.0 | `Win32` | `IMTLazarus` |
|
||||
| `Inspiration 10` | 10.11 | `Win32` | `TechEdology Ltd` |
|
||||
| `JAWS for Windows` | 2022.2112.24 | `Win32` | `Freedom Scientific` |
|
||||
| `Kite Student Portal` | 9.0.0.0 | `Win32` | `Dynamic Learning Maps` |
|
||||
| `Keyman` | 16.0.138 | `Win32` | `SIL International` |
|
||||
| `Kortext` | 2.3.433.0 | `Store` | `Kortext` |
|
||||
| `Kurzweil 3000 Assistive Learning` | 20.13.0000 | Win32 | `Kurzweil Educational Systems` |
|
||||
| `LanSchool Classic` | 9.1.0.46 | Win32 | `Stoneware, Inc.` |
|
||||
| `LanSchool Air` | 2.0.13312 | Win32 | `Stoneware, Inc.` |
|
||||
| `Lightspeed Smart Agent` | 1.9.1 | Win32 | `Lightspeed Systems` |
|
||||
| `Kurzweil 3000 Assistive Learning` | 20.13.0000 | `Win32` | `Kurzweil Educational Systems` |
|
||||
| `LanSchool Classic` | 9.1.0.46 | `Win32` | `Stoneware, Inc.` |
|
||||
| `LanSchool Air` | 2.0.13312 | `Win32` | `Stoneware, Inc.` |
|
||||
| `Lightspeed Smart Agent` | 1.9.1 | `Win32` | `Lightspeed Systems` |
|
||||
| `Lightspeed Filter Agent` | 2.3.4 | `Win32` | `Lightspeed Systems` |
|
||||
| `MetaMoJi ClassRoom` | 3.12.4.0 | `Store` | `MetaMoJi Corporation` |
|
||||
| `Microsoft Connect` | 10.0.22000.1 | `Store` | `Microsoft` |
|
||||
| `Mozilla Firefox` | 105.0.0 | Win32 | `Mozilla` |
|
||||
| `NAPLAN` | 5.2.2 | Win32 | `NAP` |
|
||||
| `Netref Student` | 23.1.0 | Win32 | `NetRef` |
|
||||
| `NetSupport Manager` | 12.01.0014 | Win32 | `NetSupport` |
|
||||
| `NetSupport Notify` | 5.10.1.215 | Win32 | `NetSupport` |
|
||||
| `NetSupport School` | 14.00.0012 | Win32 | `NetSupport` |
|
||||
| `NextUp Talker` | 1.0.49 | Win32 | `NextUp Technologies` |
|
||||
| `NonVisual Desktop Access` | 2021.3.1 | Win32 | `NV Access` |
|
||||
| `NWEA Secure Testing Browser` | 5.4.356.0 | Win32 | `NWEA` |
|
||||
| `PaperCut` | 22.0.6 | Win32 | `PaperCut Software International Pty Ltd` |
|
||||
| `Pearson TestNav` | 1.10.2.0 | `Store` | `Pearson` |
|
||||
| `Questar Secure Browser` | 5.0.1.456 | Win32 | `Questar, Inc` |
|
||||
| `ReadAndWriteForWindows` | 12.0.74 | Win32 | `Texthelp Ltd.` |
|
||||
| `Remote Desktop client (MSRDC)` | 1.2.3213.0 | Win32 | `Microsoft` |
|
||||
| `Remote Help` | 4.0.1.13 | Win32 | `Microsoft` |
|
||||
| `Respondus Lockdown Browser` | 2.0.9.03 | Win32 | `Respondus` |
|
||||
| `Safe Exam Browser` | 3.4.1.505 | Win32 | `Safe Exam Browser` |
|
||||
| `Senso.Cloud` | 2021.11.15.0 | Win32 | `Senso.Cloud` |
|
||||
| `Smoothwall Monitor` | 2.9.2 | Win32 | `Smoothwall Ltd` |
|
||||
| `SuperNova Magnifier & Screen Reader` | 21.02 | Win32 | `Dolphin Computer Access` |
|
||||
| `SuperNova Magnifier & Speech` | 21.03 | Win32 | `Dolphin Computer Access` |
|
||||
|`TX Secure Browser` | 15.0.0 | Win32 | `Cambium Development` |
|
||||
| `VitalSourceBookShelf` | 10.2.26.0 | Win32 | `VitalSource Technologies Inc` |
|
||||
| `Winbird` | 19 | Win32 | `Winbird Co., Ltd.` |
|
||||
| `WordQ` | 5.4.29 | Win32 | `WordQ` |
|
||||
| `Zoom` | 5.12.8 (10232) | Win32 | `Zoom` |
|
||||
| `ZoomText Fusion` | 2022.2109.10 | Win32 | `Freedom Scientific` |
|
||||
| `ZoomText Magnifier/Reader` | 2022.2109.25 | Win32 | `Freedom Scientific` |
|
||||
| `Mozilla Firefox` | 105.0.0 | `Win32` | `Mozilla` |
|
||||
| `Mobile Plans` | 5.1911.3171.0 | `Store` | `Microsoft Corporation` |
|
||||
| `NAPLAN` | 5.2.2 | `Win32` | `NAP` |
|
||||
| `Netref Student` | 23.1.0 | `Win32` | `NetRef` |
|
||||
| `NetSupport DNA` | 4.80.0000 | `Win32` | `NetSupport` |
|
||||
| `NetSupport Manager` | 14.00.0012 | `Win32` | `NetSupport` |
|
||||
| `NetSupport Notify` | 5.10.1.223 | `Win32` | `NetSupport` |
|
||||
| `NetSupport School` | 14.00.0012 | `Win32` | `NetSupport` |
|
||||
| `NextUp Talker` | 1.0.49 | `Win32` | `NextUp Technologies` |
|
||||
| `NonVisual Desktop Access` | 2021.3.1 | `Win32` | `NV Access` |
|
||||
| `NWEA Secure Testing Browser` | 5.4.387.0 | `Win32` | `NWEA` |
|
||||
| `PC Talker Neo` | 2209 | `Win32` | `Kochi System Development` |
|
||||
| `PC Talker Neo Plus` | 2209 | `Win32` | `Kochi System Development` |
|
||||
| `PaperCut` | 22.0.6 | `Win32` | `PaperCut Software International Pty Ltd` |
|
||||
| `Pearson TestNav` | 1.11.3 | `Store` | `Pearson` |
|
||||
| `Project Monarch Outlook` | 1.2022.2250001 | `Store` | `Microsoft` |
|
||||
| `Questar Secure Browser` | 5.0.1.456 | `Win32` | `Questar, Inc` |
|
||||
| `ReadAndWriteForWindows` | 12.0.74 | `Win32` | `Texthelp Ltd.` |
|
||||
| `Remote Desktop client (MSRDC)` | 1.2.4240.0 | `Win32` | `Microsoft` |
|
||||
| `Remote Help` | 4.0.1.13 | `Win32` | `Microsoft` |
|
||||
| `Respondus Lockdown Browser` | 2.0.9.03 | `Win32` | `Respondus` |
|
||||
| `Safe Exam Browser` | 3.5.0.544 | `Win32` | `Safe Exam Browser` |
|
||||
|`SchoolYear` | 3.4.21 | `Win32` |`SchoolYear` |
|
||||
|`School Manager` | 3.6.8.1109 | `Win32` |`School Manager` |
|
||||
| `Senso.Cloud` | 2021.11.15.0 | `Win32` | `Senso.Cloud` |
|
||||
| `Skoolnext` | 2.19 | `Win32` | `Skool.net` |
|
||||
| `Smoothwall Monitor` | 2.9.2 | `Win32` | `Smoothwall Ltd` |
|
||||
| `SuperNova Magnifier & Screen Reader` | 22.02 | `Win32` | `Dolphin Computer Access` |
|
||||
| `SuperNova Magnifier & Speech` | 21.03 | `Win32` | `Dolphin Computer Access` |
|
||||
|`TX Secure Browser` | 15.0.0 | `Win32` | `Cambium Development` |
|
||||
| `VitalSourceBookShelf` | 10.2.26.0 | `Win32` | `VitalSource Technologies Inc` |
|
||||
| `Winbird` | 19 | `Win32` | `Winbird Co., Ltd.` |
|
||||
| `WordQ` | 5.4.29 | `Win32` | `WordQ` |
|
||||
| `Zoom` | 5.12.8 (10232) | `Win32` | `Zoom` |
|
||||
| `ZoomText Fusion` | 2023.2303.77.400 | `Win32` | `Freedom Scientific` |
|
||||
| `ZoomText Magnifier/Reader` | 2023.2303.33.400 | `Win32` | `Freedom Scientific` |
|
||||
|
||||
## Add your own applications
|
||||
|
||||
If the applications you need aren't in the [available applications list](#available-applications), then you can submit an application request at [aka.ms/eduapprequest](https://aka.ms/eduapprequest). Anyone from a school district can submit the request. In the form, sign in with your school account, such as `user@contoso.edu`. We'll update you using this email account.
|
||||
If the applications you need aren't in the [available applications list](#available-applications), you can submit an application request at [aka.ms/eduapprequest](https://aka.ms/eduapprequest). Anyone from a school district can submit the request. In the form, sign in with your school account, such as `user@contoso.edu`. We'll update you using this email account.
|
||||
|
||||
Microsoft reviews every app request to make sure each app meets the following requirements:
|
||||
|
||||
- Apps can be any native Windows app type, such as a Microsoft Store app, Win32 app, `.MSIX`, `.APPX`, and more
|
||||
- Apps can be any native Windows app type, such as a Microsoft Store app, `Win32` app, `.MSIX`, `.APPX`, and more
|
||||
- Apps must be in one of the following app categories:
|
||||
- Content Filtering apps
|
||||
- Test Taking solutions
|
||||
|
@ -1,8 +1,8 @@
|
||||
---
|
||||
title: Windows 11 SE settings list
|
||||
description: Windows 11 SE automatically configures settings in the operating system. Learn more about the settings you can control and manage, and the settings you can't change.
|
||||
ms.topic: article
|
||||
ms.date: 03/09/2023
|
||||
ms.topic: reference
|
||||
ms.date: 08/18/2023
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11 SE</a>
|
||||
ms.collection:
|
||||
|
@ -1,30 +1,21 @@
|
||||
---
|
||||
title: Windows 10 editions for education customers
|
||||
description: Learn about the two Windows 10 editions that are designed for the needs of education institutions.
|
||||
ms.topic: article
|
||||
ms.date: 08/10/2022
|
||||
ms.topic: overview
|
||||
ms.date: 07/25/2023
|
||||
appliesto:
|
||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10</a>
|
||||
---
|
||||
|
||||
# Windows 10 editions for education customers
|
||||
|
||||
Windows 10, version 1607 (Anniversary Update) continues our commitment to productivity, security, and privacy for all customers. Windows 10 Pro and Windows 10 Enterprise offer the functionality and safety features demanded by business and education customers around the globe. Windows 10 is the most secure Windows we’ve ever built. All of our Windows commercial editions can be configured to support the needs of schools, through group policies, domain join, and more. To learn more about Microsoft’s commitment to security and privacy in Windows 10, see more on both [security](/windows/security/security-foundations) and [privacy](https://go.microsoft.com/fwlink/?LinkId=822620).
|
||||
Windows 10 offers various new features and functionalities, such as simplified provisioning with the [Set up School PCs app](./use-set-up-school-pcs-app.md) or [Windows Configuration Designer](./set-up-students-pcs-to-join-domain.md), easier delivery of digital assessments with [Take a Test](./take-tests-in-windows.md), and faster sign-in performance for shared devices than ever before. These features work with all Windows for desktop editions, excluding Windows 10 Home. You can find more information on [windows.com](https://www.windows.com/).
|
||||
|
||||
Beginning with version 1607, Windows 10 offers various new features and functionality, such as simplified provisioning with the [Set up School PCs app](./use-set-up-school-pcs-app.md) or [Windows Configuration Designer](./set-up-students-pcs-to-join-domain.md), easier delivery of digital assessments with [Take a Test](./take-tests-in-windows.md), and faster sign-in performance for shared devices than ever before. These features work with all Windows for desktop editions, excluding Windows 10 Home. You can find more information on [windows.com](https://www.windows.com/).
|
||||
|
||||
Windows 10, version 1607 introduces two editions designed for the unique needs of K-12 institutions: [Windows 10 Pro Education](#windows-10-pro-education) and [Windows 10 Education](#windows-10-education). These editions provide education-specific default settings for the evolving landscape in K-12 education IT environments.
|
||||
Windows 10 introduces two editions designed for the unique needs of K-12 institutions: [Windows 10 Pro Education](#windows-10-pro-education) and [Windows 10 Education](#windows-10-education). These editions provide education-specific default settings for the evolving landscape in K-12 education IT environments.
|
||||
|
||||
## Windows 10 Pro Education
|
||||
|
||||
Windows 10 Pro Education builds on the commercial version of Windows 10 Pro and provides important management controls needed in schools. Windows 10 Pro Education is effectively a variant of Windows 10 Pro that provides education-specific default settings. These default settings disable tips, tricks and suggestions & Microsoft Store suggestions. More detailed information on these default settings is available in [Manage Windows 10 and Microsoft Store tips, tricks, and suggestions](/windows/configuration/manage-tips-and-suggestions).
|
||||
|
||||
For Cortana<sup>[1](#footnote1)</sup>:
|
||||
- If you're using version 1607, Cortana is removed.
|
||||
- If you're using new devices with version 1703 or later, Cortana is turned on by default.
|
||||
- If you're upgrading from version 1607 to version 1703 or later, Cortana will be enabled.
|
||||
|
||||
You can use the **AllowCortana** policy to turn off Cortana. For more information, see [Windows 10 configuration recommendations for education customers](configure-windows-for-education.md).
|
||||
Windows 10 Pro Education builds on the commercial version of Windows 10 Pro and provides important management controls needed in schools. Windows 10 Pro Education is a variant of Windows 10 Pro that provides education-specific default settings. These default settings disable tips, tricks and suggestions & Microsoft Store suggestions. More detailed information on these default settings is available in [Manage Windows 10 and Microsoft Store tips, tricks, and suggestions](/windows/configuration/manage-tips-and-suggestions).
|
||||
|
||||
Windows 10 Pro Education is available on new devices pre-installed with Windows 10, version 1607 or newer versions that are purchased with discounted K-12 academic licenses through OEM partners (these discounted licenses are sometimes referred to as National Academic or Shape the Future).
|
||||
|
||||
@ -38,13 +29,6 @@ Customers who deploy Windows 10 Pro are able to configure the product to have si
|
||||
|
||||
Windows 10 Education builds on Windows 10 Enterprise and provides the enterprise-grade manageability and security desired by many schools. Windows 10 Education is effectively a variant of Windows 10 Enterprise that provides education-specific default settings. These default settings disable tips, tricks and suggestions & Microsoft Store suggestions. More detailed information on these default settings is available in [Manage Windows 10 and Microsoft Store tips, tricks, and suggestions](/windows/configuration/manage-tips-and-suggestions).
|
||||
|
||||
For Cortana<sup>1</sup>:
|
||||
- If you're using version 1607, Cortana<sup>1</sup> is removed.
|
||||
- If you're using new devices with version 1703 or later, Cortana is turned on by default.
|
||||
- If you're upgrading from version 1607 to version 1703 or later, Cortana will be enabled.
|
||||
|
||||
You can use the **AllowCortana** policy to turn off Cortana. For more information, see [Windows 10 configuration recommendations for education customers](configure-windows-for-education.md).
|
||||
|
||||
Windows 10 Education is available through Microsoft Volume Licensing. Customers who are already running Windows 10 Education can upgrade to Windows 10, version 1607 or newer versions through Windows Update or from the [Volume Licensing Service Center](https://www.microsoft.com/Licensing/servicecenter/default.aspx). We recommend Windows 10 Education to all K-12 customers as it provides the most complete and secure edition for education environments. If you don't have access to Windows 10 Education, contact your Microsoft representative or see more information [here](https://go.microsoft.com/fwlink/?LinkId=822628).
|
||||
|
||||
Customers who deploy Windows 10 Enterprise are able to configure the product to have similar feature settings to Windows 10 Education using policies. More detailed information on these policies and the configuration steps required is available in [Manage Windows 10 and Microsoft Store tips, tricks, and suggestions](/windows/configuration/manage-tips-and-suggestions). We recommend that K-12 customers using commercial Windows 10 Enterprise read the [document](/windows/configuration/manage-tips-and-suggestions) and apply desired settings for your environment.
|
||||
@ -52,14 +36,11 @@ Customers who deploy Windows 10 Enterprise are able to configure the product to
|
||||
For any other questions, contact [Microsoft Customer Service and Support](https://support.microsoft.com/en-us).
|
||||
|
||||
## Related topics
|
||||
|
||||
- [Switch to Windows 10 Pro Education from Windows 10 Pro or Windows 10 S](change-to-pro-education.md)
|
||||
- [Windows deployment for education](./index.yml)
|
||||
- [Windows 10 upgrade paths](/windows/deployment/upgrade/windows-10-upgrade-paths)
|
||||
- [Volume Activation for Windows 10](/windows/deployment/volume-activation/volume-activation-windows-10)
|
||||
- [Plan for volume activation](/windows/deployment/volume-activation/plan-for-volume-activation-client)
|
||||
- [Windows 10 subscription activation](/windows/deployment/windows-10-subscription-activation)
|
||||
|
||||
|
||||
|
||||
|
||||
<a name="footnote1"></a><sup>1</sup> <small>Cortana available in select markets; experience may vary by region and device.</small>
|
||||
-
|
Before Width: | Height: | Size: 1.1 KiB After Width: | Height: | Size: 1.1 KiB |
3
images/information.svg
Normal file
@ -0,0 +1,3 @@
|
||||
<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path d="M8 7C8.27614 7 8.5 7.22386 8.5 7.5V10.5C8.5 10.7761 8.27614 11 8 11C7.72386 11 7.5 10.7761 7.5 10.5V7.5C7.5 7.22386 7.72386 7 8 7ZM8.00001 6.24907C8.41369 6.24907 8.74905 5.91371 8.74905 5.50003C8.74905 5.08635 8.41369 4.751 8.00001 4.751C7.58633 4.751 7.25098 5.08635 7.25098 5.50003C7.25098 5.91371 7.58633 6.24907 8.00001 6.24907ZM2 8C2 4.68629 4.68629 2 8 2C11.3137 2 14 4.68629 14 8C14 11.3137 11.3137 14 8 14C4.68629 14 2 11.3137 2 8ZM8 3C5.23858 3 3 5.23858 3 8C3 10.7614 5.23858 13 8 13C10.7614 13 13 10.7614 13 8C13 5.23858 10.7614 3 8 3Z" fill="#0078D4" />
|
||||
</svg>
|
After Width: | Height: | Size: 680 B |
Before Width: | Height: | Size: 1.8 KiB After Width: | Height: | Size: 1.8 KiB |
Before Width: | Height: | Size: 215 B After Width: | Height: | Size: 215 B |
9
includes/configure/gpo-settings-1.md
Normal file
@ -0,0 +1,9 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/15/2023
|
||||
ms.topic: include
|
||||
ms.prod: windows-client
|
||||
---
|
||||
|
||||
To configure devices using group policy, [create a group policy object (GPO)](/windows/security/operating-system-security/network-security/windows-firewall/create-a-group-policy-object) and use the following settings:
|
9
includes/configure/gpo-settings-2.md
Normal file
@ -0,0 +1,9 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/15/2023
|
||||
ms.topic: include
|
||||
ms.prod: windows-client
|
||||
---
|
||||
|
||||
The policy settings can be configured locally by using the Local Group Policy Editor (`gpedit.msc`), linked to the domain or organizational units, and filtered to security groups.
|
@ -1,6 +1,9 @@
|
||||
---
|
||||
ms.date: 02/22/2022
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/15/2023
|
||||
ms.topic: include
|
||||
ms.prod: windows-client
|
||||
---
|
||||
|
||||
To configure devices with Microsoft Intune, use a custom policy:
|
@ -1,6 +1,9 @@
|
||||
---
|
||||
ms.date: 11/08/2022
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/15/2023
|
||||
ms.topic: include
|
||||
ms.prod: windows-client
|
||||
---
|
||||
|
||||
7. Select **Next**
|
@ -1,6 +1,9 @@
|
||||
---
|
||||
ms.date: 11/08/2022
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/15/2023
|
||||
ms.topic: include
|
||||
ms.prod: windows-client
|
||||
---
|
||||
|
||||
For more information about how to create custom settings using Intune, see [Use custom settings for Windows devices in Intune](/mem/intune/configuration/custom-settings-windows-10).
|
9
includes/configure/intune-settings-catalog-1.md
Normal file
@ -0,0 +1,9 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/15/2023
|
||||
ms.topic: include
|
||||
ms.prod: windows-client
|
||||
---
|
||||
|
||||
To configure devices using Microsoft Intune, [create a Settings catalog policy](/mem/intune/configuration/settings-catalog) and use the following settings:
|
9
includes/configure/intune-settings-catalog-2.md
Normal file
@ -0,0 +1,9 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/15/2023
|
||||
ms.topic: include
|
||||
ms.prod: windows-client
|
||||
---
|
||||
|
||||
Assign the policy to a group that contains as members the devices or users that you want to configure.
|
9
includes/configure/tab-intro.md
Normal file
@ -0,0 +1,9 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/15/2023
|
||||
ms.topic: include
|
||||
ms.prod: windows-client
|
||||
---
|
||||
|
||||
The following instructions provide details how to configure your devices. Select the option that best suits your needs.
|
@ -1,6 +0,0 @@
|
||||
---
|
||||
ms.date: 11/08/2022
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
For more information about how to create custom settings using Intune, see [Use custom settings for Windows devices in Intune](/mem/intune/configuration/custom-settings-windows-10).
|
@ -1,23 +1,27 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 05/04/2023
|
||||
ms.date: 08/09/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
| Feature name | Windows Pro | Windows Enterprise | Windows Pro Education/SE | Windows Education |
|
||||
|:---|:---:|:---:|:---:|:---:|
|
||||
|**[Access Control (ACLs/SCALS)](/windows/security/identity-protection/access-control/access-control)**|Yes|Yes|Yes|Yes|
|
||||
|**[Access Control (ACL/SACL)](/windows/security/identity-protection/access-control/access-control)**|Yes|Yes|Yes|Yes|
|
||||
|**[Account Lockout Policy](/windows/security/threat-protection/security-policy-settings/account-lockout-policy)**|Yes|Yes|Yes|Yes|
|
||||
|**[Always On VPN (device tunnel)](/windows-server/remote/remote-access/vpn/always-on-vpn/)**|❌|Yes|❌|Yes|
|
||||
|**[App containers](/virtualization/windowscontainers/about/)**|Yes|Yes|Yes|Yes|
|
||||
|**[AppLocker](/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Assigned Access (kiosk mode)](/windows/configuration/kiosk-methods)**|Yes|Yes|Yes|Yes|
|
||||
|**[Attack surface reduction (ASR)](/microsoft-365/security/defender-endpoint/overview-attack-surface-reduction)**|Yes|Yes|Yes|Yes|
|
||||
|**[Azure AD join, Active Directory domain join, and Hybrid Azure AD join with single sign-on (SSO)](/azure/active-directory/devices/concept-azure-ad-join)**|Yes|Yes|Yes|Yes|
|
||||
|**[Azure Code Signing](/windows/security/application-security/application-control/windows-defender-application-control/deployment/use-code-signing-for-better-control-and-protection)**|Yes|Yes|Yes|Yes|
|
||||
|**[BitLocker enablement](/windows/security/information-protection/bitlocker/bitlocker-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[BitLocker management](/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises)**|Yes|Yes|Yes|Yes|
|
||||
|**Bluetooth pairing and connection protection**|Yes|Yes|Yes|Yes|
|
||||
|**[Common Criteria certifications](/windows/security/threat-protection/windows-platform-common-criteria)**|Yes|Yes|Yes|Yes|
|
||||
|**[Controlled folder access](/microsoft-365/security/defender-endpoint/controlled-folders)**|Yes|Yes|Yes|Yes|
|
||||
|**[Credential Guard](/windows/security/identity-protection/credential-guard/credential-guard)**|❌|Yes|❌|Yes|
|
||||
|**[Device health attestation service](/windows/security/threat-protection/protect-high-value-assets-by-controlling-the-health-of-windows-10-based-devices)**|Yes|Yes|Yes|Yes|
|
||||
|**[Direct Access](/windows-server/remote/remote-access/directaccess/directaccess)**|❌|Yes|❌|Yes|
|
||||
|**[Email Encryption (S/MIME)](/windows/security/identity-protection/configure-s-mime)**|Yes|Yes|Yes|Yes|
|
||||
@ -28,10 +32,9 @@ ms.topic: include
|
||||
|**[Federal Information Processing Standard (FIPS) 140 validation](/windows/security/threat-protection/fips-140-validation)**|Yes|Yes|Yes|Yes|
|
||||
|**[Federated sign-in](/education/windows/federated-sign-in)**|❌|❌|Yes|Yes|
|
||||
|**[Hardware-enforced stack protection](https://techcommunity.microsoft.com/t5/windows-os-platform-blog/understanding-hardware-enforced-stack-protection/ba-p/1247815)**|Yes|Yes|Yes|Yes|
|
||||
|**[Hypervisor-protected Code Integrity (HVCI)](/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity)**|Yes|Yes|Yes|Yes|
|
||||
|**[Hypervisor-protected Code Integrity (HVCI)](/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity)**|Yes|Yes|Yes|Yes|
|
||||
|**[Kernel Direct Memory Access (DMA) protection](/windows/security/information-protection/kernel-dma-protection-for-thunderbolt)**|Yes|Yes|Yes|Yes|
|
||||
|**Local Security Authority (LSA) Protection**|Yes|Yes|Yes|Yes|
|
||||
|**[Manage by Mobile Device Management (MDM) and group policy](/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines)**|Yes|Yes|Yes|Yes|
|
||||
|**[Local Security Authority (LSA) Protection](/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)**|Yes|Yes|Yes|Yes|
|
||||
|**[Measured boot](/windows/compatibility/measured-boot)**|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Defender Antivirus](/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-windows)**|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Defender Application Guard (MDAG) configure via MDM](/windows/client-management/mdm/windowsdefenderapplicationguard-csp)**|❌|Yes|❌|Yes|
|
||||
@ -41,40 +44,44 @@ ms.topic: include
|
||||
|**Microsoft Defender Application Guard (MDAG) public APIs**|❌|Yes|❌|Yes|
|
||||
|**[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint)**|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Defender SmartScreen](/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Pluton security processor](/windows/security/information-protection/pluton/microsoft-pluton-security-processor)**|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Vulnerable Driver Blocklist](/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules)**|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Pluton](/windows/security/hardware-security/pluton/microsoft-pluton-security-processor)**|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Security Development Lifecycle (SDL)](/windows/security/security-foundations/msft-security-dev-lifecycle)**|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft vulnerable driver blocklist](/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules)**|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Windows Insider Preview bounty program](https://www.microsoft.com/msrc/bounty-windows-insider-preview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Modern device management through (MDM)](/windows/client-management/mdm-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[OneFuzz service](https://www.microsoft.com/security/blog/2020/09/15/microsoft-onefuzz-framework-open-source-developer-tool-fix-bugs/)**|Yes|Yes|Yes|Yes|
|
||||
|**Opportunistic Wireless Encryption (OWE)**|Yes|Yes|Yes|Yes|
|
||||
|**[Personal data encryption (PDE)](/windows/security/information-protection/personal-data-encryption/overview-pde)**|❌|Yes|❌|Yes|
|
||||
|**Privacy Resource Usage**|Yes|Yes|Yes|Yes|
|
||||
|**Privacy Transparency and Controls**|Yes|Yes|Yes|Yes|
|
||||
|**[Remote Credential Guard](/windows/security/identity-protection/remote-credential-guard)**|Yes|Yes|Yes|Yes|
|
||||
|**[Remote wipe](/windows/client-management/mdm/remotewipe-csp)**|Yes|Yes|Yes|Yes|
|
||||
|**[Secure Boot and Trusted Boot](/windows/security/trusted-boot)**|Yes|Yes|Yes|Yes|
|
||||
|**[Secured-core configuration lock](/windows/client-management/config-lock)**|Yes|Yes|Yes|Yes|
|
||||
|**[Secured-core PC](/windows-hardware/design/device-experiences/oem-highly-secure-11)**|Yes|Yes|Yes|Yes|
|
||||
|**[Secured-core PC firmware protection](/windows-hardware/design/device-experiences/oem-highly-secure-11)**|Yes|Yes|Yes|Yes|
|
||||
|**[Security baselines](/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines)**|Yes|Yes|Yes|Yes|
|
||||
|**[Server Message Block (SMB) file service](/windows-server/storage/file-server/file-server-smb-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Server Message Block Direct (SMB Direct)](/windows-server/storage/file-server/smb-direct)**|Yes|Yes|Yes|Yes|
|
||||
|**[Smart App Control](/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control)**|Yes|Yes|Yes|Yes|
|
||||
|**[Smart Cards for Windows Service](/windows/security/identity-protection/smart-cards/smart-card-smart-cards-for-windows-service)**|Yes|Yes|Yes|Yes|
|
||||
|**Software Bill of Materials (SBOM)**|Yes|Yes|Yes|Yes|
|
||||
|**[Tamper protection settings for MDE](/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection)**|Yes|Yes|Yes|Yes|
|
||||
|**[Transport layer security (TLS)](/windows-server/security/tls/tls-ssl-schannel-ssp-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Trusted Platform Module (TPM) 2.0](/windows/security/information-protection/tpm/trusted-platform-module-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Trusted Platform Module (TPM)](/windows/security/hardware-security/tpm/trusted-platform-module-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Universal Print](/universal-print/)**|Yes|Yes|Yes|Yes|
|
||||
|**[User Account Control (UAC)](/windows/security/identity-protection/user-account-control/user-account-control-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Virtual Private Network (VPN)](/windows/security/identity-protection/vpn/vpn-guide)**|Yes|Yes|Yes|Yes|
|
||||
|**[User Account Control (UAC)](/windows/security/application-security/application-control/user-account-control/)**|Yes|Yes|Yes|Yes|
|
||||
|**[Virtual private network (VPN)](/windows/security/identity-protection/vpn/vpn-guide)**|Yes|Yes|Yes|Yes|
|
||||
|**[Virtualization-based security (VBS)](/windows-hardware/design/device-experiences/oem-vbs)**|Yes|Yes|Yes|Yes|
|
||||
|**[WiFi Security](https://support.microsoft.com/windows/faster-and-more-secure-wi-fi-in-windows-26177a28-38ed-1a8e-7eca-66f24dc63f09)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows application software development kit (SDK)](https://developer.microsoft.com/windows/downloads/windows-sdk/)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Autopatch](/windows/deployment/windows-autopatch/)**|❌|Yes|❌|Yes|
|
||||
|**[Windows Autopilot](/windows/deployment/windows-autopilot)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows containers](/virtualization/windowscontainers/about/)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Defender Application Control (WDAC)](/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Defender Credential Guard](/windows/security/identity-protection/credential-guard/credential-guard)**|❌|Yes|❌|Yes|
|
||||
|**[Windows Defender Remote Credential Guard](/windows/security/identity-protection/remote-credential-guard)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Defender System Guard](/windows/security/threat-protection/windows-defender-system-guard/how-hardware-based-root-of-trust-helps-protect-windows)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Defender System Guard](/windows/security/hardware-security/how-hardware-based-root-of-trust-helps-protect-windows)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Firewall](/windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Hello for Business](/windows/security/identity-protection/hello-for-business)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Hello for Business Enhanced Security Sign-in (ESS)](/windows-hardware/design/device-experiences/windows-hello-enhanced-sign-in-security)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows LAPS](/windows-server/identity/laps/laps-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows presence sensing](https://support.microsoft.com/windows/wake-your-windows-11-pc-when-you-approach-82285c93-440c-4e15-9081-c9e38c1290bb)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Sandbox](/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Security policy settings and auditing](/windows/security/threat-protection/security-policy-settings/security-policy-settings)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Sandbox](/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview)**|Yes|Yes|Yes|Yes|
|
||||
|**[Windows security policy settings and auditing](/windows/security/threat-protection/security-policy-settings/security-policy-settings)**|Yes|Yes|Yes|Yes|
|
||||
|
@ -1,23 +1,27 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 05/04/2023
|
||||
ms.date: 08/09/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
|Feature name|Windows Pro/Pro Education/SE|Windows Enterprise E3|Windows Enterprise E5|Windows Education A3|Windows Education A5|
|
||||
|:---|:---:|:---:|:---:|:---:|:---:|
|
||||
|**[Access Control (ACLs/SCALS)](/windows/security/identity-protection/access-control/access-control)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Access Control (ACL/SACL)](/windows/security/identity-protection/access-control/access-control)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Account Lockout Policy](/windows/security/threat-protection/security-policy-settings/account-lockout-policy)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Always On VPN (device tunnel)](/windows-server/remote/remote-access/vpn/always-on-vpn/)**|❌|Yes|Yes|Yes|Yes|
|
||||
|**[App containers](/virtualization/windowscontainers/about/)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[AppLocker](/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview)**|❌|Yes|Yes|Yes|Yes|
|
||||
|**[Assigned Access (kiosk mode)](/windows/configuration/kiosk-methods)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Attack surface reduction (ASR)](/microsoft-365/security/defender-endpoint/overview-attack-surface-reduction)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Azure AD join, Active Directory domain join, and Hybrid Azure AD join with single sign-on (SSO)](/azure/active-directory/devices/concept-azure-ad-join)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Azure Code Signing](/windows/security/application-security/application-control/windows-defender-application-control/deployment/use-code-signing-for-better-control-and-protection)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[BitLocker enablement](/windows/security/information-protection/bitlocker/bitlocker-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[BitLocker management](/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises)**|❌|Yes|Yes|Yes|Yes|
|
||||
|**Bluetooth pairing and connection protection**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Common Criteria certifications](/windows/security/threat-protection/windows-platform-common-criteria)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Controlled folder access](/microsoft-365/security/defender-endpoint/controlled-folders)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Credential Guard](/windows/security/identity-protection/credential-guard/credential-guard)**|❌|Yes|Yes|Yes|Yes|
|
||||
|**[Device health attestation service](/windows/security/threat-protection/protect-high-value-assets-by-controlling-the-health-of-windows-10-based-devices)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Direct Access](/windows-server/remote/remote-access/directaccess/directaccess)**|❌|Yes|Yes|Yes|Yes|
|
||||
|**[Email Encryption (S/MIME)](/windows/security/identity-protection/configure-s-mime)**|Yes|Yes|Yes|Yes|Yes|
|
||||
@ -28,10 +32,9 @@ ms.topic: include
|
||||
|**[Federal Information Processing Standard (FIPS) 140 validation](/windows/security/threat-protection/fips-140-validation)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Federated sign-in](/education/windows/federated-sign-in)**|❌|❌|❌|Yes|Yes|
|
||||
|**[Hardware-enforced stack protection](https://techcommunity.microsoft.com/t5/windows-os-platform-blog/understanding-hardware-enforced-stack-protection/ba-p/1247815)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Hypervisor-protected Code Integrity (HVCI)](/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Hypervisor-protected Code Integrity (HVCI)](/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Kernel Direct Memory Access (DMA) protection](/windows/security/information-protection/kernel-dma-protection-for-thunderbolt)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**Local Security Authority (LSA) Protection**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Manage by Mobile Device Management (MDM) and group policy](/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Local Security Authority (LSA) Protection](/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Measured boot](/windows/compatibility/measured-boot)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Defender Antivirus](/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-windows)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Defender Application Guard (MDAG) configure via MDM](/windows/client-management/mdm/windowsdefenderapplicationguard-csp)**|❌|Yes|Yes|Yes|Yes|
|
||||
@ -41,40 +44,44 @@ ms.topic: include
|
||||
|**Microsoft Defender Application Guard (MDAG) public APIs**|❌|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint)**|❌|❌|Yes|❌|Yes|
|
||||
|**[Microsoft Defender SmartScreen](/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Pluton security processor](/windows/security/information-protection/pluton/microsoft-pluton-security-processor)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Vulnerable Driver Blocklist](/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Pluton](/windows/security/hardware-security/pluton/microsoft-pluton-security-processor)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Security Development Lifecycle (SDL)](/windows/security/security-foundations/msft-security-dev-lifecycle)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft vulnerable driver blocklist](/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Microsoft Windows Insider Preview bounty program](https://www.microsoft.com/msrc/bounty-windows-insider-preview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Modern device management through (MDM)](/windows/client-management/mdm-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[OneFuzz service](https://www.microsoft.com/security/blog/2020/09/15/microsoft-onefuzz-framework-open-source-developer-tool-fix-bugs/)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**Opportunistic Wireless Encryption (OWE)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Personal data encryption (PDE)](/windows/security/information-protection/personal-data-encryption/overview-pde)**|❌|Yes|Yes|Yes|Yes|
|
||||
|**Privacy Resource Usage**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**Privacy Transparency and Controls**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Remote Credential Guard](/windows/security/identity-protection/remote-credential-guard)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Remote wipe](/windows/client-management/mdm/remotewipe-csp)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Secure Boot and Trusted Boot](/windows/security/trusted-boot)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Secured-core configuration lock](/windows/client-management/config-lock)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Secured-core PC](/windows-hardware/design/device-experiences/oem-highly-secure-11)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Secured-core PC firmware protection](/windows-hardware/design/device-experiences/oem-highly-secure-11)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Security baselines](/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Server Message Block (SMB) file service](/windows-server/storage/file-server/file-server-smb-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Server Message Block Direct (SMB Direct)](/windows-server/storage/file-server/smb-direct)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Smart App Control](/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Smart Cards for Windows Service](/windows/security/identity-protection/smart-cards/smart-card-smart-cards-for-windows-service)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**Software Bill of Materials (SBOM)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Tamper protection settings for MDE](/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Transport layer security (TLS)](/windows-server/security/tls/tls-ssl-schannel-ssp-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Trusted Platform Module (TPM) 2.0](/windows/security/information-protection/tpm/trusted-platform-module-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Trusted Platform Module (TPM)](/windows/security/hardware-security/tpm/trusted-platform-module-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Universal Print](/universal-print/)**|❌|Yes|Yes|Yes|Yes|
|
||||
|**[User Account Control (UAC)](/windows/security/identity-protection/user-account-control/user-account-control-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Virtual Private Network (VPN)](/windows/security/identity-protection/vpn/vpn-guide)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[User Account Control (UAC)](/windows/security/application-security/application-control/user-account-control/)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Virtual private network (VPN)](/windows/security/identity-protection/vpn/vpn-guide)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Virtualization-based security (VBS)](/windows-hardware/design/device-experiences/oem-vbs)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[WiFi Security](https://support.microsoft.com/windows/faster-and-more-secure-wi-fi-in-windows-26177a28-38ed-1a8e-7eca-66f24dc63f09)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows application software development kit (SDK)](https://developer.microsoft.com/windows/downloads/windows-sdk/)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Autopatch](/windows/deployment/windows-autopatch/)**|❌|Yes|Yes|❌|❌|
|
||||
|**[Windows Autopilot](/windows/deployment/windows-autopilot)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows containers](/virtualization/windowscontainers/about/)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Defender Application Control (WDAC)](/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Defender Credential Guard](/windows/security/identity-protection/credential-guard/credential-guard)**|❌|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Defender Remote Credential Guard](/windows/security/identity-protection/remote-credential-guard)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Defender System Guard](/windows/security/threat-protection/windows-defender-system-guard/how-hardware-based-root-of-trust-helps-protect-windows)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Defender System Guard](/windows/security/hardware-security/how-hardware-based-root-of-trust-helps-protect-windows)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Firewall](/windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Hello for Business](/windows/security/identity-protection/hello-for-business)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Hello for Business Enhanced Security Sign-in (ESS)](/windows-hardware/design/device-experiences/windows-hello-enhanced-sign-in-security)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows LAPS](/windows-server/identity/laps/laps-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows presence sensing](https://support.microsoft.com/windows/wake-your-windows-11-pc-when-you-approach-82285c93-440c-4e15-9081-c9e38c1290bb)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Sandbox](/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Security policy settings and auditing](/windows/security/threat-protection/security-policy-settings/security-policy-settings)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows Sandbox](/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|**[Windows security policy settings and auditing](/windows/security/threat-protection/security-policy-settings/security-policy-settings)**|Yes|Yes|Yes|Yes|Yes|
|
||||
|
22
includes/licensing/access-control-aclsacl.md
Normal file
@ -0,0 +1,22 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
## Windows edition and licensing requirements
|
||||
|
||||
The following table lists the Windows editions that support Access Control (ACL/SACL):
|
||||
|
||||
|Windows Pro|Windows Enterprise|Windows Pro Education/SE|Windows Education|
|
||||
|:---:|:---:|:---:|:---:|
|
||||
|Yes|Yes|Yes|Yes|
|
||||
|
||||
Access Control (ACL/SACL) license entitlements are granted by the following licenses:
|
||||
|
||||
|Windows Pro/Pro Education/SE|Windows Enterprise E3|Windows Enterprise E5|Windows Education A3|Windows Education A5|
|
||||
|:---:|:---:|:---:|:---:|:---:|
|
||||
|Yes|Yes|Yes|Yes|Yes|
|
||||
|
||||
For more information about Windows licensing, see [Windows licensing overview](/windows/whats-new/windows-licensing).
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 05/04/2023
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 05/04/2023
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 05/04/2023
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
|
22
includes/licensing/app-containers.md
Normal file
@ -0,0 +1,22 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
## Windows edition and licensing requirements
|
||||
|
||||
The following table lists the Windows editions that support App containers:
|
||||
|
||||
|Windows Pro|Windows Enterprise|Windows Pro Education/SE|Windows Education|
|
||||
|:---:|:---:|:---:|:---:|
|
||||
|Yes|Yes|Yes|Yes|
|
||||
|
||||
App containers license entitlements are granted by the following licenses:
|
||||
|
||||
|Windows Pro/Pro Education/SE|Windows Enterprise E3|Windows Enterprise E5|Windows Education A3|Windows Education A5|
|
||||
|:---:|:---:|:---:|:---:|:---:|
|
||||
|Yes|Yes|Yes|Yes|Yes|
|
||||
|
||||
For more information about Windows licensing, see [Windows licensing overview](/windows/whats-new/windows-licensing).
|
22
includes/licensing/applocker.md
Normal file
@ -0,0 +1,22 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
## Windows edition and licensing requirements
|
||||
|
||||
The following table lists the Windows editions that support AppLocker:
|
||||
|
||||
|Windows Pro|Windows Enterprise|Windows Pro Education/SE|Windows Education|
|
||||
|:---:|:---:|:---:|:---:|
|
||||
|Yes|Yes|Yes|Yes|
|
||||
|
||||
AppLocker license entitlements are granted by the following licenses:
|
||||
|
||||
|Windows Pro/Pro Education/SE|Windows Enterprise E3|Windows Enterprise E5|Windows Education A3|Windows Education A5|
|
||||
|:---:|:---:|:---:|:---:|:---:|
|
||||
|No|Yes|Yes|Yes|Yes|
|
||||
|
||||
For more information about Windows licensing, see [Windows licensing overview](/windows/whats-new/windows-licensing).
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 05/04/2023
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 05/04/2023
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
|
@ -1,7 +1,7 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 05/04/2023
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
|
@ -1,19 +1,19 @@
|
||||
---
|
||||
author: paolomatarazzo
|
||||
ms.author: paoloma
|
||||
ms.date: 05/04/2023
|
||||
ms.date: 08/02/2023
|
||||
ms.topic: include
|
||||
---
|
||||
|
||||
## Windows edition and licensing requirements
|
||||
|
||||
The following table lists the Windows editions that support Windows containers:
|
||||
The following table lists the Windows editions that support Azure Code Signing:
|
||||
|
||||
|Windows Pro|Windows Enterprise|Windows Pro Education/SE|Windows Education|
|
||||
|:---:|:---:|:---:|:---:|
|
||||
|Yes|Yes|Yes|Yes|
|
||||
|
||||
Windows containers license entitlements are granted by the following licenses:
|
||||
Azure Code Signing license entitlements are granted by the following licenses:
|
||||
|
||||
|Windows Pro/Pro Education/SE|Windows Enterprise E3|Windows Enterprise E5|Windows Education A3|Windows Education A5|
|
||||
|:---:|:---:|:---:|:---:|:---:|
|