From ab02a38d43cea426d1a6bc65d6299433709f683d Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Mon, 7 Aug 2023 12:27:06 +0200 Subject: [PATCH 01/26] [EDU] Landing page --- education/docfx.json | 3 +- windows/education/index.yml | 181 ++++++++++++++++++++++++++++++++++++ 2 files changed, 182 insertions(+), 2 deletions(-) create mode 100644 windows/education/index.yml diff --git a/education/docfx.json b/education/docfx.json index 29a46f0323..7767861daa 100644 --- a/education/docfx.json +++ b/education/docfx.json @@ -76,8 +76,7 @@ "✅ Windows 11 SE", "✅ Windows 10" ] - }, - "uhfHeaderId": "MSDocsHeader-Windows" + } }, "externalReference": [], "template": "op.html", diff --git a/windows/education/index.yml b/windows/education/index.yml new file mode 100644 index 0000000000..fc06f5531c --- /dev/null +++ b/windows/education/index.yml @@ -0,0 +1,181 @@ +### YamlMime:Hub + +title: Windows for Education documentation +summary: Learn how to deploy, secure, and manage Windows clients in an education environment. +brand: windows + +metadata: + ms.topic: hub-page + ms.prod: windows-client + ms.technology: itpro-edu + ms.collection: + - education + - highpri + - tier1 + author: paolomatarazzo + ms.author: paoloma + manager: aaroncz + ms.date: 07/28/2023 + +highlightedContent: + items: + - title: Get started with Windows 11 + itemType: get-started + url: /windows/whats-new/windows-11-overview + - title: Windows 11, version 22H2 + itemType: whats-new + url: /windows/whats-new/whats-new-windows-11-version-22H2 + - title: Windows 11, version 22H2 group policy settings reference + itemType: download + url: https://www.microsoft.com/en-us/download/details.aspx?id=104594 + - title: Windows release health + itemType: whats-new + url: /windows/release-health + - title: Windows commercial licensing + itemType: overview + url: /windows/whats-new/windows-licensing + - title: Windows 365 documentation + itemType: overview + url: /windows-365 + - title: Explore all Windows trainings and learning paths for IT pros + itemType: learn + url: https://learn.microsoft.com/en-us/training/browse/?products=windows&roles=administrator + - title: Enroll Windows client devices in Microsoft Intune + itemType: how-to-guide + url: /mem/intune/fundamentals/deployment-guide-enrollment-windows + +productDirectory: + title: Get started + items: + + - title: Hardware security + imageSrc: /media/common/i_usb.svg + links: + - url: /windows/security/hardware-security/tpm/trusted-platform-module-overview + text: Trusted Platform Module + - url: /windows/security/hardware-security/pluton/microsoft-pluton-security-processor + text: Microsoft Pluton + - url: /windows/security/hardware-security/how-hardware-based-root-of-trust-helps-protect-windows + text: Windows Defender System Guard + - url: /windows-hardware/design/device-experiences/oem-vbs + text: Virtualization-based security (VBS) + - url: /windows-hardware/design/device-experiences/oem-highly-secure-11 + text: Secured-core PC + - url: /windows/security/hardware-security + text: Learn more about hardware security > + + - title: OS security + imageSrc: /media/common/i_threat-protection.svg + links: + - url: /windows/security/operating-system-security + text: Trusted boot + - url: /windows/security/operating-system-security/system-security/windows-defender-security-center/windows-defender-security-center + text: Windows security settings + - url: /windows/security/operating-system-security/data-protection/bitlocker/ + text: BitLocker + - url: /windows/security/operating-system-security/device-management/windows-security-configuration-framework/windows-security-baselines + text: Windows security baselines + - url: /windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/ + text: MMicrosoft Defender SmartScreen + - url: /windows/security/operating-system-security + text: Learn more about OS security > + + - title: Identity protection + imageSrc: /media/common/i_identity-protection.svg + links: + - url: /windows/security/identity-protection/hello-for-business + text: Windows Hello for Business + - url: /windows/security/identity-protection/credential-guard + text: Windows Defender Credential Guard + - url: /windows-server/identity/laps/laps-overview + text: Windows LAPS (Local Administrator Password Solution) + - url: /windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/enhanced-phishing-protection + text: Enhanced phishing protection with SmartScreen + - url: /education/windows/federated-sign-in + text: Federated sign-in (EDU) + - url: /windows/security/identity-protection + text: Learn more about identity protection > + + - title: Application security + imageSrc: /media/common/i_queries.svg + links: + - url: /windows/security/application-security/application-control/windows-defender-application-control/ + text: Windows Defender Application Control (WDAC) + - url: /windows/security/application-security/application-control/user-account-control + text: User Account Control (UAC) + - url: /windows/security/application-security/application-control/windows-defender-application-control/design/microsoft-recommended-driver-block-rules + text: Microsoft vulnerable driver blocklist + - url: /windows/security/application-security/application-isolation/microsoft-defender-application-guard/md-app-guard-overview + text: Microsoft Defender Application Guard (MDAG) + - url: /windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview + text: Windows Sandbox + - url: /windows/security/application-security + text: Learn more about application security > + + - title: Security foundations + imageSrc: /media/common/i_build.svg + links: + - url: /windows/security/security-foundations/certification/fips-140-validation + text: FIPS 140-2 validation + - url: /windows/security/security-foundations/certification/windows-platform-common-criteria + text: Common Criteria Certifications + - url: /windows/security/security-foundations/msft-security-dev-lifecycle + text: Microsoft Security Development Lifecycle (SDL) + - url: https://www.microsoft.com/msrc/bounty-windows-insider-preview + text: Microsoft Windows Insider Preview bounty program + - url: https://www.microsoft.com/security/blog/2020/09/15/microsoft-onefuzz-framework-open-source-developer-tool-fix-bugs/ + text: OneFuzz service + - url: /windows/security/security-foundations + text: Learn more about security foundations > + + - title: Cloud security + imageSrc: /media/common/i_cloud-security.svg + links: + - url: /mem/intune/protect/security-baselines + text: Security baselines with Intune + - url: /windows/deployment/windows-autopatch + text: Windows Autopatch + - url: /windows/deployment/windows-autopilot + text: Windows Autopilot + - url: /universal-print + text: Universal Print + - url: /windows/client-management/mdm/remotewipe-csp + text: Remote wipe + - url: /windows/security/cloud-security + text: Learn more about cloud security > + +additionalContent: + sections: + - title: More Windows resources + items: + + - title: Windows Server + links: + - text: Windows Server documentation + url: /windows-server + - text: What's new in Windows Server 2022? + url: /windows-server/get-started/whats-new-in-windows-server-2022 + - text: Windows Server blog + url: https://cloudblogs.microsoft.com/windowsserver/ + + - title: Windows product site and blogs + links: + - text: Find out how Windows enables your business to do more + url: https://www.microsoft.com/microsoft-365/windows + - text: Windows blogs + url: https://blogs.windows.com/ + - text: Windows IT Pro blog + url: https://techcommunity.microsoft.com/t5/windows-it-pro-blog/bg-p/Windows10Blog + - text: Microsoft Intune blog + url: https://techcommunity.microsoft.com/t5/microsoft-intune-blog/bg-p/MicrosoftEndpointManagerBlog + - text: "Windows help & learning: end-user documentation" + url: https://support.microsoft.com/windows + + - title: Participate in the community + links: + - text: Windows community + url: https://techcommunity.microsoft.com/t5/windows/ct-p/Windows10 + - text: Microsoft Intune community + url: https://techcommunity.microsoft.com/t5/microsoft-intune/bd-p/Microsoft-Intune + - text: Microsoft Support community + url: https://answers.microsoft.com/windows/forum \ No newline at end of file From e20eb84d372ec9fd06b1b8a15217623e8d0ef61d Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Mon, 7 Aug 2023 12:40:15 +0200 Subject: [PATCH 02/26] updates --- education/windows/index.old.yml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/education/windows/index.old.yml b/education/windows/index.old.yml index 849e1d3e1d..691901dcf2 100644 --- a/education/windows/index.old.yml +++ b/education/windows/index.old.yml @@ -1,3 +1,25 @@ +### YamlMime:Landing + +title: Windows for Education documentation +summary: Evaluate, plan, deploy, and manage Windows devices in an education environment + +metadata: + title: Windows for Education documentation + description: Learn about how to plan, deploy and manage Windows devices in an education environment with Microsoft Intune + ms.topic: landing-page + ms.prod: windows-client + ms.technology: itpro-edu + ms.collection: + - education + - highpri + - tier1 + author: paolomatarazzo + ms.author: paoloma + ms.date: 03/09/2023 + manager: aaroncz + +landingContent: + - title: Get started linkLists: - linkListType: tutorial From 546db8d9bcdfc6cc68b70e9278df9d211b948055 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Mon, 7 Aug 2023 14:33:53 +0200 Subject: [PATCH 03/26] move EDU under hub --- windows/{ => hub}/education/index.yml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename windows/{ => hub}/education/index.yml (100%) diff --git a/windows/education/index.yml b/windows/hub/education/index.yml similarity index 100% rename from windows/education/index.yml rename to windows/hub/education/index.yml From 190e68d4b062be6d0636b39b51f7e6ad69073562 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Tue, 8 Aug 2023 07:21:19 +0200 Subject: [PATCH 04/26] updates --- education/windows/index.old.yml | 20 ---- education/windows/index.yml | 123 ++++------------------ windows/hub/education/index.yml | 181 -------------------------------- 3 files changed, 22 insertions(+), 302 deletions(-) delete mode 100644 windows/hub/education/index.yml diff --git a/education/windows/index.old.yml b/education/windows/index.old.yml index 691901dcf2..4a46f98e09 100644 --- a/education/windows/index.old.yml +++ b/education/windows/index.old.yml @@ -1,23 +1,3 @@ -### YamlMime:Landing - -title: Windows for Education documentation -summary: Evaluate, plan, deploy, and manage Windows devices in an education environment - -metadata: - title: Windows for Education documentation - description: Learn about how to plan, deploy and manage Windows devices in an education environment with Microsoft Intune - ms.topic: landing-page - ms.prod: windows-client - ms.technology: itpro-edu - ms.collection: - - education - - highpri - - tier1 - author: paolomatarazzo - ms.author: paoloma - ms.date: 03/09/2023 - manager: aaroncz - landingContent: - title: Get started diff --git a/education/windows/index.yml b/education/windows/index.yml index fc06f5531c..1ff5d4989c 100644 --- a/education/windows/index.yml +++ b/education/windows/index.yml @@ -15,28 +15,16 @@ metadata: author: paolomatarazzo ms.author: paoloma manager: aaroncz - ms.date: 07/28/2023 + ms.date: 08/07/2023 highlightedContent: items: - - title: Get started with Windows 11 + - title: Get started with Windows 11 SE itemType: get-started url: /windows/whats-new/windows-11-overview - title: Windows 11, version 22H2 itemType: whats-new url: /windows/whats-new/whats-new-windows-11-version-22H2 - - title: Windows 11, version 22H2 group policy settings reference - itemType: download - url: https://www.microsoft.com/en-us/download/details.aspx?id=104594 - - title: Windows release health - itemType: whats-new - url: /windows/release-health - - title: Windows commercial licensing - itemType: overview - url: /windows/whats-new/windows-licensing - - title: Windows 365 documentation - itemType: overview - url: /windows-365 - title: Explore all Windows trainings and learning paths for IT pros itemType: learn url: https://learn.microsoft.com/en-us/training/browse/?products=windows&roles=administrator @@ -47,102 +35,35 @@ highlightedContent: productDirectory: title: Get started items: - - - title: Hardware security - imageSrc: /media/common/i_usb.svg + - title: Learn how to deploy Windows + imageSrc: /media/common/i_deploy.svg links: - - url: /windows/security/hardware-security/tpm/trusted-platform-module-overview - text: Trusted Platform Module - - url: /windows/security/hardware-security/pluton/microsoft-pluton-security-processor - text: Microsoft Pluton - - url: /windows/security/hardware-security/how-hardware-based-root-of-trust-helps-protect-windows - text: Windows Defender System Guard - - url: /windows-hardware/design/device-experiences/oem-vbs - text: Virtualization-based security (VBS) - - url: /windows-hardware/design/device-experiences/oem-highly-secure-11 - text: Secured-core PC - - url: /windows/security/hardware-security - text: Learn more about hardware security > + - url: /windows/deployment + text: Learn more about Windows deployment > - - title: OS security - imageSrc: /media/common/i_threat-protection.svg + - title: Learn how to secure Windows + imageSrc: /media/common/i_security-management.svg links: - - url: /windows/security/operating-system-security - text: Trusted boot - - url: /windows/security/operating-system-security/system-security/windows-defender-security-center/windows-defender-security-center - text: Windows security settings - - url: /windows/security/operating-system-security/data-protection/bitlocker/ - text: BitLocker - - url: /windows/security/operating-system-security/device-management/windows-security-configuration-framework/windows-security-baselines - text: Windows security baselines - - url: /windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/ - text: MMicrosoft Defender SmartScreen - - url: /windows/security/operating-system-security - text: Learn more about OS security > + - url: /windows/security + text: Learn more about Windows security > - - title: Identity protection - imageSrc: /media/common/i_identity-protection.svg + - title: Learn about privacy in Windows + imageSrc: /media/common/i_lock.svg links: - - url: /windows/security/identity-protection/hello-for-business - text: Windows Hello for Business - - url: /windows/security/identity-protection/credential-guard - text: Windows Defender Credential Guard - - url: /windows-server/identity/laps/laps-overview - text: Windows LAPS (Local Administrator Password Solution) - - url: /windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/enhanced-phishing-protection - text: Enhanced phishing protection with SmartScreen - - url: /education/windows/federated-sign-in - text: Federated sign-in (EDU) - - url: /windows/security/identity-protection - text: Learn more about identity protection > + - url: /windows/privacy + text: Learn more about privacy in Windows > - - title: Application security - imageSrc: /media/common/i_queries.svg + - title: Learn how to manage Windows + imageSrc: /media/common/i_management.svg links: - - url: /windows/security/application-security/application-control/windows-defender-application-control/ - text: Windows Defender Application Control (WDAC) - - url: /windows/security/application-security/application-control/user-account-control - text: User Account Control (UAC) - - url: /windows/security/application-security/application-control/windows-defender-application-control/design/microsoft-recommended-driver-block-rules - text: Microsoft vulnerable driver blocklist - - url: /windows/security/application-security/application-isolation/microsoft-defender-application-guard/md-app-guard-overview - text: Microsoft Defender Application Guard (MDAG) - - url: /windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview - text: Windows Sandbox - - url: /windows/security/application-security - text: Learn more about application security > + - url: /windows/client-management + text: Learn more about Windows management > - - title: Security foundations - imageSrc: /media/common/i_build.svg + - title: Learn how to configure Windows + imageSrc: /media/common/i_config-tools.svg links: - - url: /windows/security/security-foundations/certification/fips-140-validation - text: FIPS 140-2 validation - - url: /windows/security/security-foundations/certification/windows-platform-common-criteria - text: Common Criteria Certifications - - url: /windows/security/security-foundations/msft-security-dev-lifecycle - text: Microsoft Security Development Lifecycle (SDL) - - url: https://www.microsoft.com/msrc/bounty-windows-insider-preview - text: Microsoft Windows Insider Preview bounty program - - url: https://www.microsoft.com/security/blog/2020/09/15/microsoft-onefuzz-framework-open-source-developer-tool-fix-bugs/ - text: OneFuzz service - - url: /windows/security/security-foundations - text: Learn more about security foundations > - - - title: Cloud security - imageSrc: /media/common/i_cloud-security.svg - links: - - url: /mem/intune/protect/security-baselines - text: Security baselines with Intune - - url: /windows/deployment/windows-autopatch - text: Windows Autopatch - - url: /windows/deployment/windows-autopilot - text: Windows Autopilot - - url: /universal-print - text: Universal Print - - url: /windows/client-management/mdm/remotewipe-csp - text: Remote wipe - - url: /windows/security/cloud-security - text: Learn more about cloud security > + - url: /windows/configuration + text: Learn more about Windows configuration > additionalContent: sections: diff --git a/windows/hub/education/index.yml b/windows/hub/education/index.yml deleted file mode 100644 index fc06f5531c..0000000000 --- a/windows/hub/education/index.yml +++ /dev/null @@ -1,181 +0,0 @@ -### YamlMime:Hub - -title: Windows for Education documentation -summary: Learn how to deploy, secure, and manage Windows clients in an education environment. -brand: windows - -metadata: - ms.topic: hub-page - ms.prod: windows-client - ms.technology: itpro-edu - ms.collection: - - education - - highpri - - tier1 - author: paolomatarazzo - ms.author: paoloma - manager: aaroncz - ms.date: 07/28/2023 - -highlightedContent: - items: - - title: Get started with Windows 11 - itemType: get-started - url: /windows/whats-new/windows-11-overview - - title: Windows 11, version 22H2 - itemType: whats-new - url: /windows/whats-new/whats-new-windows-11-version-22H2 - - title: Windows 11, version 22H2 group policy settings reference - itemType: download - url: https://www.microsoft.com/en-us/download/details.aspx?id=104594 - - title: Windows release health - itemType: whats-new - url: /windows/release-health - - title: Windows commercial licensing - itemType: overview - url: /windows/whats-new/windows-licensing - - title: Windows 365 documentation - itemType: overview - url: /windows-365 - - title: Explore all Windows trainings and learning paths for IT pros - itemType: learn - url: https://learn.microsoft.com/en-us/training/browse/?products=windows&roles=administrator - - title: Enroll Windows client devices in Microsoft Intune - itemType: how-to-guide - url: /mem/intune/fundamentals/deployment-guide-enrollment-windows - -productDirectory: - title: Get started - items: - - - title: Hardware security - imageSrc: /media/common/i_usb.svg - links: - - url: /windows/security/hardware-security/tpm/trusted-platform-module-overview - text: Trusted Platform Module - - url: /windows/security/hardware-security/pluton/microsoft-pluton-security-processor - text: Microsoft Pluton - - url: /windows/security/hardware-security/how-hardware-based-root-of-trust-helps-protect-windows - text: Windows Defender System Guard - - url: /windows-hardware/design/device-experiences/oem-vbs - text: Virtualization-based security (VBS) - - url: /windows-hardware/design/device-experiences/oem-highly-secure-11 - text: Secured-core PC - - url: /windows/security/hardware-security - text: Learn more about hardware security > - - - title: OS security - imageSrc: /media/common/i_threat-protection.svg - links: - - url: /windows/security/operating-system-security - text: Trusted boot - - url: /windows/security/operating-system-security/system-security/windows-defender-security-center/windows-defender-security-center - text: Windows security settings - - url: /windows/security/operating-system-security/data-protection/bitlocker/ - text: BitLocker - - url: /windows/security/operating-system-security/device-management/windows-security-configuration-framework/windows-security-baselines - text: Windows security baselines - - url: /windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/ - text: MMicrosoft Defender SmartScreen - - url: /windows/security/operating-system-security - text: Learn more about OS security > - - - title: Identity protection - imageSrc: /media/common/i_identity-protection.svg - links: - - url: /windows/security/identity-protection/hello-for-business - text: Windows Hello for Business - - url: /windows/security/identity-protection/credential-guard - text: Windows Defender Credential Guard - - url: /windows-server/identity/laps/laps-overview - text: Windows LAPS (Local Administrator Password Solution) - - url: /windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/enhanced-phishing-protection - text: Enhanced phishing protection with SmartScreen - - url: /education/windows/federated-sign-in - text: Federated sign-in (EDU) - - url: /windows/security/identity-protection - text: Learn more about identity protection > - - - title: Application security - imageSrc: /media/common/i_queries.svg - links: - - url: /windows/security/application-security/application-control/windows-defender-application-control/ - text: Windows Defender Application Control (WDAC) - - url: /windows/security/application-security/application-control/user-account-control - text: User Account Control (UAC) - - url: /windows/security/application-security/application-control/windows-defender-application-control/design/microsoft-recommended-driver-block-rules - text: Microsoft vulnerable driver blocklist - - url: /windows/security/application-security/application-isolation/microsoft-defender-application-guard/md-app-guard-overview - text: Microsoft Defender Application Guard (MDAG) - - url: /windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview - text: Windows Sandbox - - url: /windows/security/application-security - text: Learn more about application security > - - - title: Security foundations - imageSrc: /media/common/i_build.svg - links: - - url: /windows/security/security-foundations/certification/fips-140-validation - text: FIPS 140-2 validation - - url: /windows/security/security-foundations/certification/windows-platform-common-criteria - text: Common Criteria Certifications - - url: /windows/security/security-foundations/msft-security-dev-lifecycle - text: Microsoft Security Development Lifecycle (SDL) - - url: https://www.microsoft.com/msrc/bounty-windows-insider-preview - text: Microsoft Windows Insider Preview bounty program - - url: https://www.microsoft.com/security/blog/2020/09/15/microsoft-onefuzz-framework-open-source-developer-tool-fix-bugs/ - text: OneFuzz service - - url: /windows/security/security-foundations - text: Learn more about security foundations > - - - title: Cloud security - imageSrc: /media/common/i_cloud-security.svg - links: - - url: /mem/intune/protect/security-baselines - text: Security baselines with Intune - - url: /windows/deployment/windows-autopatch - text: Windows Autopatch - - url: /windows/deployment/windows-autopilot - text: Windows Autopilot - - url: /universal-print - text: Universal Print - - url: /windows/client-management/mdm/remotewipe-csp - text: Remote wipe - - url: /windows/security/cloud-security - text: Learn more about cloud security > - -additionalContent: - sections: - - title: More Windows resources - items: - - - title: Windows Server - links: - - text: Windows Server documentation - url: /windows-server - - text: What's new in Windows Server 2022? - url: /windows-server/get-started/whats-new-in-windows-server-2022 - - text: Windows Server blog - url: https://cloudblogs.microsoft.com/windowsserver/ - - - title: Windows product site and blogs - links: - - text: Find out how Windows enables your business to do more - url: https://www.microsoft.com/microsoft-365/windows - - text: Windows blogs - url: https://blogs.windows.com/ - - text: Windows IT Pro blog - url: https://techcommunity.microsoft.com/t5/windows-it-pro-blog/bg-p/Windows10Blog - - text: Microsoft Intune blog - url: https://techcommunity.microsoft.com/t5/microsoft-intune-blog/bg-p/MicrosoftEndpointManagerBlog - - text: "Windows help & learning: end-user documentation" - url: https://support.microsoft.com/windows - - - title: Participate in the community - links: - - text: Windows community - url: https://techcommunity.microsoft.com/t5/windows/ct-p/Windows10 - - text: Microsoft Intune community - url: https://techcommunity.microsoft.com/t5/microsoft-intune/bd-p/Microsoft-Intune - - text: Microsoft Support community - url: https://answers.microsoft.com/windows/forum \ No newline at end of file From b58813ce7af77856287e3485b109979d74edb75c Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Tue, 8 Aug 2023 13:08:41 +0200 Subject: [PATCH 05/26] updates --- education/windows/index.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/education/windows/index.yml b/education/windows/index.yml index 1ff5d4989c..af7a9de69e 100644 --- a/education/windows/index.yml +++ b/education/windows/index.yml @@ -21,7 +21,7 @@ highlightedContent: items: - title: Get started with Windows 11 SE itemType: get-started - url: /windows/whats-new/windows-11-overview + url: windows-11-se-overview.md - title: Windows 11, version 22H2 itemType: whats-new url: /windows/whats-new/whats-new-windows-11-version-22H2 From f6c37f69158e90c1d80177b1d7ca23c0bf2514ea Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Tue, 8 Aug 2023 13:20:33 +0200 Subject: [PATCH 06/26] update --- education/windows/{index.old.yml => index.old.txt} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename education/windows/{index.old.yml => index.old.txt} (100%) diff --git a/education/windows/index.old.yml b/education/windows/index.old.txt similarity index 100% rename from education/windows/index.old.yml rename to education/windows/index.old.txt From bd46cecf8cc08c50ff6b09b0158dde0139c10246 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Tue, 8 Aug 2023 13:56:48 +0200 Subject: [PATCH 07/26] updates --- education/docfx.json | 2 +- education/windows/index.old.txt | 16 ---------------- education/windows/index.yml | 26 +++++++++++++++----------- 3 files changed, 16 insertions(+), 28 deletions(-) diff --git a/education/docfx.json b/education/docfx.json index 7767861daa..a9579639a6 100644 --- a/education/docfx.json +++ b/education/docfx.json @@ -41,7 +41,7 @@ "manager": "aaroncz", "ms.localizationpriority": "medium", "breadcrumb_path": "/education/breadcrumb/toc.json", - "uhfHeaderId": "MSDocsHeader-M365-IT", + "uhfHeaderId": "MSDocsHeader-Windows", "feedback_system": "GitHub", "feedback_github_repo": "MicrosoftDocs/windows-itpro-docs", "feedback_product_url": "https://support.microsoft.com/windows/send-feedback-to-microsoft-with-the-feedback-hub-app-f59187f8-8739-22d6-ba93-f66612949332", diff --git a/education/windows/index.old.txt b/education/windows/index.old.txt index 4a46f98e09..3713530ec3 100644 --- a/education/windows/index.old.txt +++ b/education/windows/index.old.txt @@ -1,19 +1,3 @@ -landingContent: - - - title: Get started - linkLists: - - linkListType: tutorial - links: - - text: Deploy and manage Windows devices in a school - url: tutorial-school-deployment/index.md - - text: Prepare your tenant - url: tutorial-school-deployment/set-up-azure-ad.md - - text: Configure settings and applications with Microsoft Intune - url: tutorial-school-deployment/configure-devices-overview.md - - text: Manage devices with Microsoft Intune - url: tutorial-school-deployment/manage-overview.md - - text: Management functionalities for Surface devices - url: tutorial-school-deployment/manage-surface-devices.md - title: Learn about Windows 11 SE linkLists: diff --git a/education/windows/index.yml b/education/windows/index.yml index af7a9de69e..782e82d9ce 100644 --- a/education/windows/index.yml +++ b/education/windows/index.yml @@ -28,9 +28,9 @@ highlightedContent: - title: Explore all Windows trainings and learning paths for IT pros itemType: learn url: https://learn.microsoft.com/en-us/training/browse/?products=windows&roles=administrator - - title: Enroll Windows client devices in Microsoft Intune + - title: Deploy applications to Windows 11 SE with Intune itemType: how-to-guide - url: /mem/intune/fundamentals/deployment-guide-enrollment-windows + url: /education/windows/tutorial-deploy-apps-winse productDirectory: title: Get started @@ -38,6 +38,8 @@ productDirectory: - title: Learn how to deploy Windows imageSrc: /media/common/i_deploy.svg links: + - url: /education/windows/tutorial-school-deployment/ + text: "Tutorial: deploy and manage Windows devices in a school" - url: /windows/deployment text: Learn more about Windows deployment > @@ -47,23 +49,25 @@ productDirectory: - url: /windows/security text: Learn more about Windows security > - - title: Learn about privacy in Windows - imageSrc: /media/common/i_lock.svg - links: - - url: /windows/privacy - text: Learn more about privacy in Windows > - - - title: Learn how to manage Windows + - title: Learn how to manage Windows devices imageSrc: /media/common/i_management.svg links: + - url: tutorial-school-deployment/manage-overview.md + text: Manage devices with Microsoft Intune + - url: tutorial-school-deployment/manage-surface-devices.md + text: Management functionalities for Surface devices + - url: /education/windows/get-minecraft-for-education + text: Get and deploy Minecraft Education + - url: + text: Configure settings and applications with Microsoft Intune - url: /windows/client-management text: Learn more about Windows management > - title: Learn how to configure Windows imageSrc: /media/common/i_config-tools.svg links: - - url: /windows/configuration - text: Learn more about Windows configuration > + - url: /windows/configuration/education/windows/federated-sign-in + text: Configure federated sign-in for Windows devices additionalContent: sections: From ce9cc02335822c608fd045030bc1243704b21529 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Tue, 8 Aug 2023 14:14:49 +0200 Subject: [PATCH 08/26] updates --- education/windows/index.old.txt | 19 ------------------- education/windows/index.yml | 8 +++++++- 2 files changed, 7 insertions(+), 20 deletions(-) diff --git a/education/windows/index.old.txt b/education/windows/index.old.txt index 3713530ec3..b2d43e8fe6 100644 --- a/education/windows/index.old.txt +++ b/education/windows/index.old.txt @@ -20,25 +20,6 @@ - text: Deploy Windows 11 SE using Set up School PCs url: https://www.youtube.com/watch?v=Ql2fbiOop7c - - title: Deploy devices with Set up School PCs - linkLists: - - linkListType: concept - links: - - text: What is Set up School PCs? - url: set-up-school-pcs-technical.md - - linkListType: how-to-guide - links: - - text: Use the Set up School PCs app - url: use-set-up-school-pcs-app.md - - linkListType: reference - links: - - text: Provisioning package settings - url: set-up-school-pcs-provisioning-package.md - - linkListType: video - links: - - text: Use the Set up School PCs App - url: https://www.youtube.com/watch?v=2ZLup_-PhkA - - title: Configure devices linkLists: - linkListType: concept diff --git a/education/windows/index.yml b/education/windows/index.yml index 782e82d9ce..8249653b52 100644 --- a/education/windows/index.yml +++ b/education/windows/index.yml @@ -40,6 +40,8 @@ productDirectory: links: - url: /education/windows/tutorial-school-deployment/ text: "Tutorial: deploy and manage Windows devices in a school" + - url: use-set-up-school-pcs-app.md + text: Deploy devices with Set up School PCs - url: /windows/deployment text: Learn more about Windows deployment > @@ -58,7 +60,7 @@ productDirectory: text: Management functionalities for Surface devices - url: /education/windows/get-minecraft-for-education text: Get and deploy Minecraft Education - - url: + - url: get-minecraft-for-education.md text: Configure settings and applications with Microsoft Intune - url: /windows/client-management text: Learn more about Windows management > @@ -68,6 +70,10 @@ productDirectory: links: - url: /windows/configuration/education/windows/federated-sign-in text: Configure federated sign-in for Windows devices + - url: set-up-school-pcs-provisioning-package.md + text: Provisioning package settings + - url: https://www.youtube.com/watch?v=2ZLup_-PhkA + text: "Video: Use the Set up School PCs App" additionalContent: sections: From f5fb8b7ae4ffd3b592098e22754dca47ac7e26eb Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Tue, 8 Aug 2023 15:59:11 +0200 Subject: [PATCH 09/26] updates --- education/windows/index.yml | 41 +++++++++++++++++++++++++++---------- 1 file changed, 30 insertions(+), 11 deletions(-) diff --git a/education/windows/index.yml b/education/windows/index.yml index 8249653b52..542b61300f 100644 --- a/education/windows/index.yml +++ b/education/windows/index.yml @@ -68,7 +68,7 @@ productDirectory: - title: Learn how to configure Windows imageSrc: /media/common/i_config-tools.svg links: - - url: /windows/configuration/education/windows/federated-sign-in + - url: federated-sign-in.md text: Configure federated sign-in for Windows devices - url: set-up-school-pcs-provisioning-package.md text: Provisioning package settings @@ -77,17 +77,36 @@ productDirectory: additionalContent: sections: - - title: More Windows resources - items: + - title: For developers # < 60 chars (optional) + summary: Are you an app developer looking for information about developing solutions on Microsoft Education products? Start here. # < 160 chars (optional) + - items: + # Card + - title: UWP apps for education + summary: Learn how to write universal apps for education. + url: /windows/uwp/apps-for-education/ + # Card + - title: Take a test API + summary: Learn how web applications can use the API to provide a locked down experience for taking tests. + url: /windows/uwp/apps-for-education/take-a-test-api - - title: Windows Server - links: - - text: Windows Server documentation - url: /windows-server - - text: What's new in Windows Server 2022? - url: /windows-server/get-started/whats-new-in-windows-server-2022 - - text: Windows Server blog - url: https://cloudblogs.microsoft.com/windowsserver/ + - title: Office dev center + summary: Integrate with Office 365 across devices and services to extend Microsoft enterprise-scale compliance and security to students, teachers, and staff in your education app. + url: https://developer.microsoft.com/office/ + + - title: Data Streamer + summary: Bring new STEM experiences into the classroom with real-time data in Excel using Data Streamer. Data Streamer can send data to Excel from a sensor or application. + url: /microsoft-365/education/data-streamer + - title: For partners # < 60 chars (optional) + summary: Looking for resources available to Microsoft Education partners? Start here. # < 160 chars (optional) + - items: + + - title: Microsoft Partner Network + summary: Discover the latest news and resources for Microsoft Education products, solutions, licensing and readiness. + url: https://partner.microsoft.com/explore/education + + - title: Education Partner community Yammer group + summary: Sign in with your Microsoft Partner account and join the Education Partner community private group on Yammer. + url: https://www.yammer.com/mepn/ - title: Windows product site and blogs links: From d379ad71ae2e745e2960264d9ac97d93e5fed1a6 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Tue, 8 Aug 2023 16:11:07 +0200 Subject: [PATCH 10/26] removed SFB article --- store-for-business/sfb-change-history.md | 86 ------------------------ 1 file changed, 86 deletions(-) delete mode 100644 store-for-business/sfb-change-history.md diff --git a/store-for-business/sfb-change-history.md b/store-for-business/sfb-change-history.md deleted file mode 100644 index 0bd887f0d4..0000000000 --- a/store-for-business/sfb-change-history.md +++ /dev/null @@ -1,86 +0,0 @@ ---- -title: Change history for Microsoft Store for Business and Education -description: Summary of topic changes for Microsoft Store for Business and Microsoft Store for Education. -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -author: TrudyHa -ms.author: TrudyHa -ms.topic: conceptual -ms.date: 3/2/2019 -ms.reviewer: -manager: dansimp -ms.localizationpriority: medium ---- - -# Change history for Microsoft Store for Business and Microsoft Store for Education - -## March 2019 - -| New or changed topic | Description | -| --- | --- | -| [Understand your Microsoft Customer Agreement invoice](billing-understand-your-invoice-msfb.md) | New topic | -| [Understand billing profiles](billing-profile.md) | New topic | -| [Payment methods](payment-methods.md) | New topic | -| [Update Microsoft Store for Business and Microsoft Store for Education account settings](update-microsoft-store-for-business-account-settings.md) | Update with information on billing accounts. | -| [Roles and permissions in Microsoft Store for Business and Education](roles-and-permissions-microsoft-store-for-business.md) | Add info for purchasing roles and permissions. | - -## April 2018 - -| New or changed topic | Description | -| --- | --- | -| [Configure access to Microsoft Store](/windows/configuration/stop-employees-from-using-microsoft-store#a-href-idblock-store-group-policyablock-microsoft-store-using-group-policy) | Update on app updates when Microsoft Store is blocked. | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | - -## March 2018 - -| New or changed topic | Description | -| --- | --- | -| [Manage software purchased with Microsoft Products and Services agreement in Microsoft Store for Business](manage-mpsa-software-microsoft-store-for-business.md) | New | -| [Manage private store settings](manage-private-store-settings.md) | Update for adding private store performance improvements. | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | -| [Roles and permissions in Microsoft Store for Business](roles-and-permissions-microsoft-store-for-business.md) | Update | - -## February 2018 - -| New or changed topic | Description | -| --- | --- | -| [Manage private store settings](manage-private-store-settings.md) | Update for adding private store collections. | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | - -## November 2017 - -| New or changed topic | Description | -| --- | --- | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | - -## October 2017 - -| New or changed topic | Description | -| --- | --- | -| [Manage Windows device deployment with Windows Autopilot Deployment](add-profile-to-devices.md) | Update. Add profile settings with supported build info. | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | - -## September 2017 - -| New or changed topic | Description | -| --- | --- | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | New | -| [Acquire apps](acquire-apps-microsoft-store-for-business.md#acquire-apps) | New | -| [Settings reference: Microsoft Store for Business and Education](manage-settings-microsoft-store-for-business.md)
and
[Update Microsoft Store for Business and Microsoft Store for Education account settings](update-microsoft-store-for-business-account-settings.md) | Updates for UI changes in **Settings**. | - -## July 2017 - -| New or changed topic | Description | -| --- | --- | -| [Microsoft Store for Business and Education PowerShell module - preview](microsoft-store-for-business-education-powershell-module.md) | New | -| [Microsoft Store for Business and Education overview - supported markets](./microsoft-store-for-business-overview.md#supported-markets) | Updates for added market support. | -| [Manage Windows device deployment with Windows Autopilot Deployment](add-profile-to-devices.md) | New. Information about Windows Autopilot Deployment Program and how it is used in Microsoft Store for Business and Education. | - -## June 2017 - -| New or changed topic | Description | -| -------------------- | ----------- | -| [Notifications in Microsoft Store for Business and Education](notifications-microsoft-store-business.md) | New. Information about notification model in Microsoft Store for Business and Education. | -| [Get Minecraft: Education Edition with Windows 10 device promotion](/education/windows/get-minecraft-device-promotion) | New. Information about redeeming Minecraft: Education Edition licenses with qualifying purchases of Windows 10 devices. | -| [Microsoft Store for Business and Education overview - supported markets](./microsoft-store-for-business-overview.md#supported-markets) | Updates for added market support. | From a63a533900fa05eea0e1070dc571be2ef427666a Mon Sep 17 00:00:00 2001 From: olkorsha <130001581+olkorsha@users.noreply.github.com> Date: Wed, 25 Oct 2023 14:03:22 -0700 Subject: [PATCH 11/26] Update enable-virtualization-based-protection-of-code-integrity.md delete misleading suggestion --- .../enable-virtualization-based-protection-of-code-integrity.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity.md b/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity.md index 17cc685415..a3404e644a 100644 --- a/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity.md +++ b/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity.md @@ -49,8 +49,6 @@ To enable memory integrity on Windows devices with supporting hardware throughou Beginning with Windows 11 22H2, **Windows Security** shows a warning if memory integrity is turned off. The warning indicator also appears on the Windows Security icon in the Windows Taskbar and in the Windows Notification Center. The user can dismiss the warning from within **Windows Security**. -To proactively dismiss the memory integrity warning, you can set the **Hardware_HVCI_Off** (DWORD) registry value under `HKLM\SOFTWARE\Microsoft\Windows Security Health\State` to 0. After you change the registry value, you must restart the device for the change to take effect. - ### Enable memory integrity using Intune Enabling in Intune requires using the Code Integrity node in the [VirtualizationBasedTechnology CSP](/windows/client-management/mdm/policy-csp-virtualizationbasedtechnology). You can configure these settings by using the [settings catalog](/mem/intune/configuration/settings-catalog). From f1907b7f5936b05d92576e281a699c8c4eec966c Mon Sep 17 00:00:00 2001 From: Jay Simmons Date: Thu, 26 Oct 2023 11:09:42 -0700 Subject: [PATCH 12/26] Document Windows LAPS integraton with smart-card-only policy. --- .../smart-card-group-policy-and-registry-settings.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/smart-cards/smart-card-group-policy-and-registry-settings.md b/windows/security/identity-protection/smart-cards/smart-card-group-policy-and-registry-settings.md index f3f0e7de99..81d22a9785 100644 --- a/windows/security/identity-protection/smart-cards/smart-card-group-policy-and-registry-settings.md +++ b/windows/security/identity-protection/smart-cards/smart-card-group-policy-and-registry-settings.md @@ -411,7 +411,7 @@ The following smart card-related Group Policy settings are in Computer Configura | Group Policy setting and registry key | Default | Description | |------------------------------------------|------------|---------------| -| Interactive logon: Require smart card

**scforceoption** | Disabled | This security policy setting requires users to sign in to a computer by using a smart card.

**Enabled** Users can sign in to the computer only by using a smart card.
**Disabled** Users can sign in to the computer by using any method. | +| Interactive logon: Require smart card

**scforceoption** | Disabled | This security policy setting requires users to sign in to a computer by using a smart card.

**Enabled** Users can sign in to the computer only by using a smart card.
**Disabled** Users can sign in to the computer by using any method.

NOTE: the Windows LAPS-managed local account is exempted from this policy when Enabled. For more information see [Windows LAPS integration with smart card policy](/windows-server/identity/laps/laps-concepts#windows-laps-integration-with-smart-card-policy).
| | Interactive logon: Smart card removal behavior

**scremoveoption** | This policy setting isn't defined, which means that the system treats it as **No Action**. | This setting determines what happens when the smart card for a signed-in user is removed from the smart card reader. The options are:
**No Action**
**Lock Workstation**: The workstation is locked when the smart card is removed, so users can leave the area, take their smart card with them, and still maintain a protected session.
**Force Logoff**: The user is automatically signed out when the smart card is removed.
**Disconnect if a Remote Desktop Services session**: Removal of the smart card disconnects the session without signing out the user. The user can reinsert the smart card and resume the session later, or at another computer that's equipped with a smart card reader, without having to sign in again. If the session is local, this policy setting functions identically to the **Lock Workstation** option.

**Note**: In earlier versions of Windows Server, Remote Desktop Services was called Terminal Services. | From the Local Security Policy Editor (secpol.msc), you can edit and apply system policies to manage credential delegation for local or domain computers. From 3a9a8672be771d922a9a7ea72681a4b0c1152d77 Mon Sep 17 00:00:00 2001 From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com> Date: Fri, 27 Oct 2023 14:02:27 +0530 Subject: [PATCH 13/26] Update customize-boot-image.md replaced windows10.0-kb5028166-x64_fe3aa2fef685c0e76e1f5d34d529624294273f41.msu with windows11.0-kb5029263-x64_4f5fe19bbec786f5e445d3e71bcdf234fe2cbbec.msu replaced SSU-19041.3205-x64.cab with SSU-22621.2061-x64 corrected grammatical errors --- windows/deployment/customize-boot-image.md | 54 +++++++++++----------- 1 file changed, 27 insertions(+), 27 deletions(-) diff --git a/windows/deployment/customize-boot-image.md b/windows/deployment/customize-boot-image.md index 1e160b35dd..a35ba81cb1 100644 --- a/windows/deployment/customize-boot-image.md +++ b/windows/deployment/customize-boot-image.md @@ -56,9 +56,9 @@ This walkthrough describes how to customize a Windows PE boot image including up For this walk-through, when the Windows ADK is installed, it's only necessary to install the **Deployment Tools**. Other products, such as Microsoft Configuration Manager and Microsoft Deployment Toolkit (MDT), may require additional features installed, such as the **User State Migration Tool (USMT)**. - One of the tools installed when installing the the **Deployment Tools** feature is the **Deployment and Imaging Tools Environment** command prompt. When using the **Command Line** option to run the commands in this walk-through, make sure to run the commands from an elevated **Deployment and Imaging Tools Environment** command prompt. The **Deployment and Imaging Tools Environment** command prompt can be found in the Start Menu under **Windows Kits** > **Deployment and Imaging Tools Environment**. + One of the tools installed when installing the **Deployment Tools** feature is the **Deployment and Imaging Tools Environment** command prompt. When using the **Command Line** option to run the commands in this walk-through, make sure to run the commands from an elevated **Deployment and Imaging Tools Environment** command prompt. The **Deployment and Imaging Tools Environment** command prompt can be found in the Start Menu under **Windows Kits** > **Deployment and Imaging Tools Environment**. - The paths in this article assume the Windows ADK was installed at the default location of `C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit`. If the Windows ADK was installed to a different location, then adjust the paths during the walk-through accordingly. + The paths in this article assume the Windows ADK was installed at the default location of `C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit`. If the Windows ADK was installed in a different location, then adjust the paths during the walk-through accordingly. 1. Download and install the **Windows PE add-on for the Windows ADK** from [Download and install the Windows ADK](/windows-hardware/get-started/adk-install). The **Windows PE add-on for the Windows ADK** is a separate download and install from the **Windows Assessment and Deployment Kit (Windows ADK)**. Make sure to individually download and install both. @@ -70,13 +70,13 @@ This walkthrough describes how to customize a Windows PE boot image including up > > - Microsoft Deployment Toolkit (MDT) doesn't support versions of Windows or the Windows ADK beyond Windows 10. If using MDT, the recommendation is to instead use the [ADK for Windows 10, version 2004](/windows-hardware/get-started/adk-install#other-adk-downloads). This version was the last version of the Windows ADK supported by MDT. > -> - The latest versions of the **Windows PE add-on for the Windows ADK** only includes 64-bit boot images. If a 32-bit boot image is required, then the recommendation in this scenario is to also use the [ADK for Windows 10, version 2004](/windows-hardware/get-started/adk-install#other-adk-downloads). This version of the Windows ADK was the last version to include both 32-bit and 64-bit boot images. +> - The latest versions of the **Windows PE add-on for the Windows ADK** only include 64-bit boot images. If a 32-bit boot image is required, then the recommendation in this scenario is to also use the [ADK for Windows 10, version 2004](/windows-hardware/get-started/adk-install#other-adk-downloads). This version of the Windows ADK was the last version to include both 32-bit and 64-bit boot images. ## Step 2: Download cumulative update (CU) 1. Go to the [Microsoft Update Catalog](https://catalog.update.microsoft.com/) site and search for the latest cumulative update. The Windows version of the cumulative update should match the version of the Windows PE boot image that is being updated. -1. When searching the [Microsoft Update Catalog](https://catalog.update.microsoft.com/) site, use the search term `"- cumulative update for windows "` where `year` is the four digit current year, `` is the two digit current month, and `` is the version of Windows that Windows PE is based on. Make sure to include the quotes (`"`). For example, to search for the latest cumulative update for Windows 11 in August 2023, use the search term `"2023-08 cumulative update for windows 11"`, again making sure to include the quotes. If the cumulative update hasn't been released yet for the current month, then search on the previous month. +1. When searching the [Microsoft Update Catalog](https://catalog.update.microsoft.com/) site, use the search term `"- cumulative update for windows "` where `year` is the four-digit current year, `` is the two-digit current month, and `` is the version of Windows that Windows PE is based on. Make sure to include the quotes (`"`). For example, to search for the latest cumulative update for Windows 11 in August 2023, use the search term `"2023-08 cumulative update for Windows 11"`, again making sure to include the quotes. If the cumulative update hasn't been released yet for the current month, then search for the previous month. 1. Once the cumulative update has been found, download the appropriate version for the version and architecture of Windows that matches the Windows PE boot image. For example, if the version of the Windows PE boot image is Windows 11 22H2 64-bit, then download the **Cumulative Update for Windows 11 Version 22H2 for x64-based Systems** version of the update. @@ -249,7 +249,7 @@ The cumulative update installed later in this walkthrough doesn't affect drivers > [!TIP] > -> A full set of drivers is not needed in Windows PE boot images. Only a small subset of drivers is needed that provide basic functionality while in WinPE. In most cases, no drivers need to be added to an out of box Windows ADK boot image since it already has many drivers built in. Don't add drivers to a boot image until it is verified that they are needed. When drivers do need to be added, generally only network (NIC) drivers are needed. Occasionally, mass storage (disk) may also be needed. Some Surface devices may also need keyboard and mouse drivers. +> A full set of drivers is not needed in Windows PE boot images. Only a small subset of drivers is needed that provides basic functionality while in WinPE. In most cases, no drivers need to be added to an out-of-box Windows ADK boot image since it already has many drivers built in. Don't add drivers to a boot image until it is verified that they are needed. When drivers do need to be added, generally only network (NIC) drivers are needed. Occasionally, mass storage (disk) may also be needed. Some Surface devices may also need keyboard and mouse drivers. > [!IMPORTANT] > @@ -304,9 +304,9 @@ The cumulative update installed later in this walkthrough doesn't affect drivers --- -1. After adding an optional component to the boot image, make sure to also add the language specific component for that optional component. +1. After adding an optional component to the boot image, make sure to also add the language-specific component for that optional component. - Not all optional components have the language specific component. However, for optional components that do have a language specific component, make sure that the language specific component is installed. + Not all optional components have the language-specific component. However, for optional components that do have a language-specific component, make sure that the language-specific component is installed. To check if an optional component has a language component, check the `C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Windows Preinstallation Environment\amd64\WinPE_OCs\\` directory to see if there's a matching language component for that optional component. @@ -507,15 +507,15 @@ DISM Package Manager: PID= TID= Failed while processing command add-pa --- -The problem occurs when the WinPE boot image that is being serviced requires installation of a servicing stack update (SSU) before installation of the cumulative update (CU) can occur. The problem usually occurs when using older Windows ADKs and older versions of Windows PE. The suggested fix is to upgrade to the latest version of the Windows ADK and Windows PE. The latest versions of the Windows ADK and Windows PE most likely don't need a servicing stack update (SSU) installed before installing the cumulative update (CU). +The problem occurs when the WinPE boot image that is being serviced requires the installation of a servicing stack update (SSU) before installation of the cumulative update (CU) can occur. The problem usually occurs when using older Windows ADKs and older versions of Windows PE. The suggested fix is to upgrade to the latest version of the Windows ADK and Windows PE. The latest versions of the Windows ADK and Windows PE most likely don't need a servicing stack update (SSU) installed before installing the cumulative update (CU). For scenarios where older versions of the Windows ADK and Windows PE need to be used, for example when using Microsoft Deployment Toolkit (MDT), the servicing stack update needs to be installed before installing the cumulative update. The servicing stack update (SSU) is contained within the cumulative update (CU). To obtain the servicing stack update (SSU) so that it can be applied, it can be extracted from the cumulative update (CU). -The following steps outline how to extract and then install the servicing stack update (SSU) to the boot image. Once the servicing stack update (SSU) has been installed in the boot image, then the cumulative update (CU) should install to the boot image without error: +The following steps outline how to extract and then install the servicing stack update (SSU) to the boot image. Once the servicing stack update (SSU) has been installed in the boot image, then the cumulative update (CU) should be installed in the boot image without error: > [!IMPORTANT] > -> These steps are only necessary if error `0x800f0823` occurs when installing the cumulative update (CU) to the boot image. If error `0x800f0823` didn't occur when installing the cumulative update (CU) to the boot image, then skip to the next step [Step 8: Copy boot files from mounted boot image to ADK installation path](#step-8-copy-boot-files-from-mounted-boot-image-to-adk-installation-path) +> These steps are only necessary if the error `0x800f0823` occurs when installing the cumulative update (CU) to the boot image. If error `0x800f0823` didn't occur when installing the cumulative update (CU) to the boot image, then skip to the next step [Step 8: Copy boot files from mounted boot image to ADK installation path](#step-8-copy-boot-files-from-mounted-boot-image-to-adk-installation-path) 1. Create a folder to extract the servicing stack update (SSU) into. For example, `C:\Updates\Extract`: @@ -530,7 +530,7 @@ The following steps outline how to extract and then install the servicing stack **Example**: ```powershell - Start-Process "expand.exe" -ArgumentList " -f:* `"C:\Updates\windows10.0-kb5028166-x64_fe3aa2fef685c0e76e1f5d34d529624294273f41.msu`" `"C:\Updates\Extract`"" -Wait -LoadUserProfile + Start-Process "expand.exe" -ArgumentList " -f:* `"C:\Updates\windows11.0-kb5029263-x64_4f5fe19bbec786f5e445d3e71bcdf234fe2cbbec.msu`" `"C:\Updates\Extract`"" -Wait -LoadUserProfile ``` For more information, see [Start-Process](/powershell/module/microsoft.powershell.management/start-process) and [expand](/windows-server/administration/windows-commands/expand). @@ -544,7 +544,7 @@ The following steps outline how to extract and then install the servicing stack **Example**: ```cmd - expand.exe -f:* "C:\Updates\windows10.0-kb5028166-x64_fe3aa2fef685c0e76e1f5d34d529624294273f41.msu" "C:\Updates\Extract" + expand.exe -f:* "C:\Updates\windows11.0-kb5029263-x64_4f5fe19bbec786f5e445d3e71bcdf234fe2cbbec.msu" "C:\Updates\Extract" ``` For more information, see [expand](/windows-server/administration/windows-commands/expand). @@ -566,7 +566,7 @@ The following steps outline how to extract and then install the servicing stack **Example**: ```powershell - Add-WindowsPackage -PackagePath "C:\Updates\Extract\SSU-19041.3205-x64.cab" -Path "C:\Mount" -Verbose + Add-WindowsPackage -PackagePath "C:\Updates\Extract\SSU-22621.2061.cab" -Path "C:\Mount" -Verbose ``` For more information, see [Add-WindowsPackage](/powershell/module/dism/add-windowspackage). @@ -582,7 +582,7 @@ The following steps outline how to extract and then install the servicing stack **Example**: ```cmd - DISM.exe /Image:"C:\Mount" /Add-Package /PackagePath:"C:\Updates\Extract\SSU-19041.3205-x64.cab" + DISM.exe /Image:"C:\Mount" /Add-Package /PackagePath:"C:\Updates\Extract\SSU-22621.2061.cab" ``` For more information, see [Add or Remove Packages Offline Using DISM](/windows-hardware/manufacture/desktop/add-or-remove-packages-offline-using-dism) and [DISM Operating System Package (.cab or .msu) Servicing Command-Line Options: /Add-Package](/windows-hardware/manufacture/desktop/dism-operating-system-package-servicing-command-line-options#add-package). @@ -627,7 +627,7 @@ For more information, see [Copy-Item](/powershell/module/microsoft.powershell.ma ### [:::image type="icon" source="images/icons/command-line-18.svg"::: **Command Line**](#tab/command-line) -From an elevated command prompt, run the following command to copy the updated bootmgr boot files from the mounted boot image to the ADK installation path. These commands also back up any existing bootmgr boot files its finds. When applicable, the commands need confirmation to overwrite any existing files: +From an elevated command prompt, run the following command to copy the updated bootmgr boot files from the mounted boot image to the ADK installation path. These commands also back up any existing bootmgr boot files it finds. When applicable, the commands need confirmation to overwrite any existing files: ```cmd copy "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Windows Preinstallation Environment\amd64\Media\bootmgr.efi" "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Windows Preinstallation Environment\amd64\Media\bootmgr.bak.efi" @@ -930,19 +930,19 @@ This process has the following advantages: 1. Keeps `boot.wim` pristine. -1. Makes sure that changes done to a boot image are being done to a pristine unmodified version of the boot image. This process helps avoid corruption when a boot image is updated multiple times. I can also correct issues with existing boot images. +1. Make sure that changes done to a boot image are being done to a pristine unmodified version of the boot image. This process helps avoid corruption when a boot image is updated multiple times. I can also correct issues with existing boot images. 1. Helps manage components in the boot image. The process doesn't need to know what components may need to be removed from the boot image each time the boot image is rebuilt. Instead, it just needs to know what components need to be added to the boot image. -1. It reduces the size of the boot image that can occur when components are repeatedly added to and removed from the boot image. +1. It reduces the size of the boot image which can occur when components are repeatedly added to and removed from the boot image. Configuration Manager updates the `boot.wim` boot image in two scenarios: -1. When Configuration Manager is upgraded between version or a hotfix roll ups (HFRUs) is applied, `boot.wim` may be updated as part of the upgrade process. +1. When Configuration Manager is upgraded between versions or hotfix roll-ups (HFRUs) is applied, `boot.wim` may be updated as part of the upgrade process. 1. When selecting the option **Reload this boot image with the current Windows PE version from the Windows ADK** in the **Update Distribution Points Wizard**. -In theses scenarios, the `boot.wim` boot image is updated using the `winpe.wim` boot image from the Windows ADK as described earlier in this section. This process creates a new pristine copy of the `boot.wim` boot image using the current version of the `winpe.wim` boot image that is part of the Windows ADK. +In these scenarios, the `boot.wim` boot image is updated using the `winpe.wim` boot image from the Windows ADK as described earlier in this section. This process creates a new pristine copy of the `boot.wim` boot image using the current version of the `winpe.wim` boot image that is part of the Windows ADK. ### Which boot image should be updated with the cumulative update? @@ -954,7 +954,7 @@ The `winpe.wim` boot image from the Windows ADK should be updated because if `bo > > Never manually update the `boot..wim` boot image. In addition to facing the same issues when manually updating the `boot.wim` boot image, the `boot..wim` boot image will also face additional issues such as: > -> - Any time any changes are done to the boot image, such as adding drivers, enabling the command prompt. etc, any manual changes done to the boot image, including the cumulative update, will be lost. +> - Any time any changes are done to the boot image, such as adding drivers, and enabling the command prompt. etc, any manual changes done to the boot image, including the cumulative update, will be lost. > > - Manually changing the `boot..wim` boot image changes the hash value of the boot image. A change in the hash value of the boot image can lead to download failures when downloading the boot image from a distribution point. @@ -985,7 +985,7 @@ For Microsoft Configuration Manager boot images to function correctly, it requir | Network/WinPE-WDS-Tools | `WinPE-WDS-Tools.cab` | NA | Yes | | Startup/WinPE-SecureStartup | `WinPE-SecureStartup.cab` | Scripting/WinPE-WMI | Yes | -When adding optional components to any boot image used by Configuration Manager during the [Step 6: Add optional components to boot image](#step-6-add-optional-components-to-boot-image) step, make sure to first add the above required components in the above order to the boot image. After adding the required components to the boot image, add any additional desired optional components to the boot image. +When adding optional components to any boot image used by Configuration Manager during the [Step 6: Add optional components to boot image](#step-6-add-optional-components-to-boot-image) step, make sure to first add the above-required components in the above order to the boot image. After adding the required components to the boot image, add any additional desired optional components to the boot image. For a list of all available WinPE optional components including descriptions for each component, see [WinPE Optional Components (OC) Reference: WinPE Optional Components](/windows-hardware/manufacture/desktop/winpe-add-packages--optional-components-reference#winpe-optional-components). @@ -993,9 +993,9 @@ For a list of all available WinPE optional components including descriptions for After updating the `winpe.wim` boot image from the Windows ADK, generate a new `boot.wim` boot image for Configuration Manager so that it contains the cumulative update. A new `boot.wim` boot image can be generated by using the following steps: -1. Open the Microsoft Configuration manager console. +1. Open the Microsoft Configuration Manager console. -1. In the Microsoft Configuration manager console, navigate to **Software Library** > **Overview** > **Operating Systems** > **Boot Images**. +1. In the Microsoft Configuration Manager console, navigate to **Software Library** > **Overview** > **Operating Systems** > **Boot Images**. 1. In the **Boot Images** pane, select the desired boot image. @@ -1011,11 +1011,11 @@ After updating the `winpe.wim` boot image from the Windows ADK, generate a new ` 1. Once the boot image finishes building, the **The task "Update Distribution Points Wizard" completed successfully**/**Completion** page appears. Select the **Close** button. -This process updates the boot image used by Configuration Manager. It also updates the boot image and the bootmgr boot files used by any PXE enabled distribution points. +This process updates the boot image used by Configuration Manager. It also updates the boot image and the bootmgr boot files used by any PXE-enabled distribution points. > [!IMPORTANT] > -> If there are multiple boot images used in the environment for PXE enabled distribution points, make sure to update all of the PXE enabled boot images with the same cumulative update. This will ensure that the PXE enabled distribution points all use the version of the bootmgr boot files extracted from the boot images (if applicable). +> If there are multiple boot images used in the environment for PXE-enabled distribution points, make sure to update all of the PXE-enabled boot images with the same cumulative update. This will ensure that the PXE-enabled distribution points all use the version of the bootmgr boot files extracted from the boot images (if applicable). ### Updating Configuration Manager boot media @@ -1107,7 +1107,7 @@ For more information, see [wdsutil stop-server](/windows-server/administration/w --- -### WDS boot image is replaced with new updated boot image +### WDS boot image is replaced with the new updated boot image In the following boot image replacement scenario for WDS: @@ -1186,7 +1186,7 @@ then follow these steps to update the boot image in WDS: --- -### Add updated boot image as a new boot image in WDS +### Add the updated boot image as a new boot image in WDS In the following boot image scenario for WDS: From 87cd841d0b115b83c0c605ce43b1129859f20d53 Mon Sep 17 00:00:00 2001 From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com> Date: Fri, 27 Oct 2023 14:14:44 +0530 Subject: [PATCH 14/26] Update customize-boot-image.md --- windows/deployment/customize-boot-image.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/deployment/customize-boot-image.md b/windows/deployment/customize-boot-image.md index a35ba81cb1..490c8bc110 100644 --- a/windows/deployment/customize-boot-image.md +++ b/windows/deployment/customize-boot-image.md @@ -1043,7 +1043,7 @@ For Microsoft Deployment Toolkit (MDT) boot images to function correctly, it req | Startup/WinPE-SecureStartup | `WinPE-SecureStartup.cab` | Scripting/WinPE-WMI | Yes | | HTML/WinPE-HTA | `WinPE-HTA.cab` | Scripting/WinPE-WMI | Yes | -When adding optional components to any boot image used by MDT during the [Step 6: Add optional components to boot image](#step-6-add-optional-components-to-boot-image) step, make sure to first add the above required components in the above order to the boot image. After adding the required components to the boot image, add any additional desired optional components to the boot image. +When adding optional components to any boot image used by MDT during the [Step 6: Add optional components to boot image](#step-6-add-optional-components-to-boot-image) step, make sure to first add the above-required components in the above order to the boot image. After adding the required components to the boot image, add any additional desired optional components to the boot image. For a list of all available WinPE optional components including descriptions for each component, see [WinPE Optional Components (OC) Reference: WinPE Optional Components](/windows-hardware/manufacture/desktop/winpe-add-packages--optional-components-reference#winpe-optional-components). @@ -1107,7 +1107,7 @@ For more information, see [wdsutil stop-server](/windows-server/administration/w --- -### WDS boot image is replaced with the new updated boot image +### WDS boot image is replaced with new updated boot image In the following boot image replacement scenario for WDS: @@ -1186,7 +1186,7 @@ then follow these steps to update the boot image in WDS: --- -### Add the updated boot image as a new boot image in WDS +### Add updated boot image as a new boot image in WDS In the following boot image scenario for WDS: From 5b4aadde70a8e69a4abd138b3c21136e786f0fc1 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Fri, 27 Oct 2023 09:59:55 -0400 Subject: [PATCH 15/26] AAD rebranding fix --- .../identity-protection/hello-for-business/hello-faq.yml | 2 +- .../hello-for-business/hello-how-it-works-authentication.md | 2 +- .../hello-for-business/hello-hybrid-key-trust.md | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-faq.yml b/windows/security/identity-protection/hello-for-business/hello-faq.yml index e289afe305..661971662b 100644 --- a/windows/security/identity-protection/hello-for-business/hello-faq.yml +++ b/windows/security/identity-protection/hello-for-business/hello-faq.yml @@ -190,7 +190,7 @@ sections: Windows Hello for Business is two-factor authentication based on the observed authentication factors of: *something you have*, *something you know*, and *something that's part of you*. Windows Hello for Business incorporates two of these factors: something you have (the user's private key protected by the device's security module) and something you know (your PIN). With the proper hardware, you can enhance the user experience by introducing biometrics. By using biometrics, you can replace the "something you know" authentication factor with the "something that is part of you" factor, with the assurances that users can fall back to the "something you know factor". > [!NOTE] - > The Windows Hello for Business key meets Azure AD multifactor authentication (MFA) requirements and reduces the number of MFA prompts users will see when accessing resources. For more information, see [What is a Primary Refresh Token](/azure/active-directory/devices/concept-primary-refresh-token#when-does-a-prt-get-an-mfa-claim). + > The Windows Hello for Business key meets Microsoft Entra multifactor authentication (MFA) requirements and reduces the number of MFA prompts users will see when accessing resources. For more information, see [What is a Primary Refresh Token](/azure/active-directory/devices/concept-primary-refresh-token#when-does-a-prt-get-an-mfa-claim). - question: Which is a better or more secure for of authentication, key or certificate? answer: | Both types of authentication provide the same security; one is not more secure than the other. diff --git a/windows/security/identity-protection/hello-for-business/hello-how-it-works-authentication.md b/windows/security/identity-protection/hello-for-business/hello-how-it-works-authentication.md index 36755630f0..af0ff0de5a 100644 --- a/windows/security/identity-protection/hello-for-business/hello-how-it-works-authentication.md +++ b/windows/security/identity-protection/hello-for-business/hello-how-it-works-authentication.md @@ -31,7 +31,7 @@ Microsoft Entra joined devices authenticate to Microsoft Entra ID during sign-in ## Microsoft Entra join authentication to Active Directory using cloud Kerberos trust -![Microsoft Entra join authentication to Azure AD.](images/howitworks/auth-aadj-cloudtrust-kerb.png) +![Microsoft Entra join authentication to Active Directory.](images/howitworks/auth-aadj-cloudtrust-kerb.png) | Phase | Description | | :----: | :----------- | diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust.md index d9716ad230..a0a36f2cc0 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust.md @@ -42,7 +42,7 @@ Hybrid Windows Hello for Business needs two directories: - An on-premises Active Directory - A Microsoft Entra tenant -The two directories must be synchronized with [Microsoft Entra Connect Sync][AZ-1], which synchronizes user accounts from the on-premises Active Directory to Azure AD.\ +The two directories must be synchronized with [Microsoft Entra Connect Sync][AZ-1], which synchronizes user accounts from the on-premises Active Directory to Microsoft Entra ID.\ During the Window Hello for Business provisioning process, users register the public portion of their Windows Hello for Business credential with Microsoft Entra ID. *Microsoft Entra Connect Sync* synchronizes the Windows Hello for Business public key to Active Directory. > [!NOTE] From e036b4101eaa3f81c8edd1ce4e025d4e479479d6 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Fri, 27 Oct 2023 10:28:34 -0400 Subject: [PATCH 16/26] Entra join link --- windows/security/identity-protection/web-sign-in/index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/web-sign-in/index.md b/windows/security/identity-protection/web-sign-in/index.md index edd4b03647..f13acff6dd 100644 --- a/windows/security/identity-protection/web-sign-in/index.md +++ b/windows/security/identity-protection/web-sign-in/index.md @@ -25,7 +25,7 @@ This article describes how to configure Web sign-in and the supported key scenar To use web sign-in, the clients must meet the following prerequisites: - Windows 11, version 22H2 with [5030310][KB-1], or later -- Must be Microsoft Entra joined +- Must be [Microsoft Entra joined](/entra/identity/devices/concept-directory-join) - Must have Internet connectivity, as the authentication is done over the Internet [!INCLUDE [federated-sign-in](../../../../includes/licensing/web-sign-in.md)] From dbfde3376f31688ba59ba461c50e5d8c21eb2d59 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Fri, 27 Oct 2023 11:42:43 -0400 Subject: [PATCH 17/26] EDU landing page --- education/windows/index.yml | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/education/windows/index.yml b/education/windows/index.yml index 542b61300f..ebb7366333 100644 --- a/education/windows/index.yml +++ b/education/windows/index.yml @@ -40,14 +40,17 @@ productDirectory: links: - url: /education/windows/tutorial-school-deployment/ text: "Tutorial: deploy and manage Windows devices in a school" + - url: /education/windows/tutorial-school-deployment/enroll-autopilot + text: Enrollment in Intune with Windows Autopilot - url: use-set-up-school-pcs-app.md text: Deploy devices with Set up School PCs - url: /windows/deployment text: Learn more about Windows deployment > - - title: Learn how to secure Windows imageSrc: /media/common/i_security-management.svg links: + - url: federated-sign-in.md + text: Configure federated sign-in for Windows devices - url: /windows/security text: Learn more about Windows security > @@ -60,16 +63,18 @@ productDirectory: text: Management functionalities for Surface devices - url: /education/windows/get-minecraft-for-education text: Get and deploy Minecraft Education - - url: get-minecraft-for-education.md - text: Configure settings and applications with Microsoft Intune - url: /windows/client-management text: Learn more about Windows management > - title: Learn how to configure Windows imageSrc: /media/common/i_config-tools.svg links: - - url: federated-sign-in.md - text: Configure federated sign-in for Windows devices + - url: /education/windows/tutorial-school-deployment/configure-devices-overview + text: Configure settings and applications with Microsoft Intune + - url: /windows/configuration/set-up-shared-or-guest-pc + text: Set up a shared or guest Windows device + - url: /education/windows/take-tests-in-windows + text: Take tests and assessments in Windows - url: set-up-school-pcs-provisioning-package.md text: Provisioning package settings - url: https://www.youtube.com/watch?v=2ZLup_-PhkA From f366be74bf524272a99b57a8e49998709b9385cd Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Fri, 27 Oct 2023 11:56:09 -0400 Subject: [PATCH 18/26] EDU landing page --- education/windows/index.yml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/education/windows/index.yml b/education/windows/index.yml index ebb7366333..a78beaa537 100644 --- a/education/windows/index.yml +++ b/education/windows/index.yml @@ -51,6 +51,14 @@ productDirectory: links: - url: federated-sign-in.md text: Configure federated sign-in for Windows devices + - url: /windows/security/application-security/application-control/user-account-control + text: User Account Control (UAC) + - url: /mem/intune/protect/security-baselines + text: Security baselines with Intune + - url: /windows/deployment/windows-autopatch + text: Windows Autopatch + - url: /universal-print + text: Universal Print - url: /windows/security text: Learn more about Windows security > From 00bfd66f96a5c2a560fa56722da5e3ec8a416c03 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Fri, 27 Oct 2023 12:06:45 -0400 Subject: [PATCH 19/26] EDU landing page --- store-for-business/sfb-change-history.md | 86 ++++++++++++++++++++++++ 1 file changed, 86 insertions(+) create mode 100644 store-for-business/sfb-change-history.md diff --git a/store-for-business/sfb-change-history.md b/store-for-business/sfb-change-history.md new file mode 100644 index 0000000000..0bd887f0d4 --- /dev/null +++ b/store-for-business/sfb-change-history.md @@ -0,0 +1,86 @@ +--- +title: Change history for Microsoft Store for Business and Education +description: Summary of topic changes for Microsoft Store for Business and Microsoft Store for Education. +ms.mktglfcycl: manage +ms.sitesec: library +ms.pagetype: store +author: TrudyHa +ms.author: TrudyHa +ms.topic: conceptual +ms.date: 3/2/2019 +ms.reviewer: +manager: dansimp +ms.localizationpriority: medium +--- + +# Change history for Microsoft Store for Business and Microsoft Store for Education + +## March 2019 + +| New or changed topic | Description | +| --- | --- | +| [Understand your Microsoft Customer Agreement invoice](billing-understand-your-invoice-msfb.md) | New topic | +| [Understand billing profiles](billing-profile.md) | New topic | +| [Payment methods](payment-methods.md) | New topic | +| [Update Microsoft Store for Business and Microsoft Store for Education account settings](update-microsoft-store-for-business-account-settings.md) | Update with information on billing accounts. | +| [Roles and permissions in Microsoft Store for Business and Education](roles-and-permissions-microsoft-store-for-business.md) | Add info for purchasing roles and permissions. | + +## April 2018 + +| New or changed topic | Description | +| --- | --- | +| [Configure access to Microsoft Store](/windows/configuration/stop-employees-from-using-microsoft-store#a-href-idblock-store-group-policyablock-microsoft-store-using-group-policy) | Update on app updates when Microsoft Store is blocked. | +| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | + +## March 2018 + +| New or changed topic | Description | +| --- | --- | +| [Manage software purchased with Microsoft Products and Services agreement in Microsoft Store for Business](manage-mpsa-software-microsoft-store-for-business.md) | New | +| [Manage private store settings](manage-private-store-settings.md) | Update for adding private store performance improvements. | +| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | +| [Roles and permissions in Microsoft Store for Business](roles-and-permissions-microsoft-store-for-business.md) | Update | + +## February 2018 + +| New or changed topic | Description | +| --- | --- | +| [Manage private store settings](manage-private-store-settings.md) | Update for adding private store collections. | +| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | + +## November 2017 + +| New or changed topic | Description | +| --- | --- | +| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | + +## October 2017 + +| New or changed topic | Description | +| --- | --- | +| [Manage Windows device deployment with Windows Autopilot Deployment](add-profile-to-devices.md) | Update. Add profile settings with supported build info. | +| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | + +## September 2017 + +| New or changed topic | Description | +| --- | --- | +| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | New | +| [Acquire apps](acquire-apps-microsoft-store-for-business.md#acquire-apps) | New | +| [Settings reference: Microsoft Store for Business and Education](manage-settings-microsoft-store-for-business.md)
and
[Update Microsoft Store for Business and Microsoft Store for Education account settings](update-microsoft-store-for-business-account-settings.md) | Updates for UI changes in **Settings**. | + +## July 2017 + +| New or changed topic | Description | +| --- | --- | +| [Microsoft Store for Business and Education PowerShell module - preview](microsoft-store-for-business-education-powershell-module.md) | New | +| [Microsoft Store for Business and Education overview - supported markets](./microsoft-store-for-business-overview.md#supported-markets) | Updates for added market support. | +| [Manage Windows device deployment with Windows Autopilot Deployment](add-profile-to-devices.md) | New. Information about Windows Autopilot Deployment Program and how it is used in Microsoft Store for Business and Education. | + +## June 2017 + +| New or changed topic | Description | +| -------------------- | ----------- | +| [Notifications in Microsoft Store for Business and Education](notifications-microsoft-store-business.md) | New. Information about notification model in Microsoft Store for Business and Education. | +| [Get Minecraft: Education Edition with Windows 10 device promotion](/education/windows/get-minecraft-device-promotion) | New. Information about redeeming Minecraft: Education Edition licenses with qualifying purchases of Windows 10 devices. | +| [Microsoft Store for Business and Education overview - supported markets](./microsoft-store-for-business-overview.md#supported-markets) | Updates for added market support. | From 5f4ceaef03c324c651661feb10665b849583aa6a Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Fri, 27 Oct 2023 12:09:29 -0400 Subject: [PATCH 20/26] EDU landing page --- education/windows/index.old.txt | 40 --------------------------------- 1 file changed, 40 deletions(-) delete mode 100644 education/windows/index.old.txt diff --git a/education/windows/index.old.txt b/education/windows/index.old.txt deleted file mode 100644 index b2d43e8fe6..0000000000 --- a/education/windows/index.old.txt +++ /dev/null @@ -1,40 +0,0 @@ - - - title: Learn about Windows 11 SE - linkLists: - - linkListType: concept - links: - - text: What is Windows 11 SE? - url: windows-11-se-overview.md - - text: Windows 11 SE settings - url: windows-11-se-settings-list.md - - linkListType: whats-new - links: - - text: Configure federated sign-in - url: federated-sign-in.md - - text: Configure education themes - url: edu-themes.md - - text: Configure Stickers - url: edu-stickers.md - - linkListType: video - links: - - text: Deploy Windows 11 SE using Set up School PCs - url: https://www.youtube.com/watch?v=Ql2fbiOop7c - - - title: Configure devices - linkLists: - - linkListType: concept - links: - - text: Take tests and assessments in Windows - url: take-tests-in-windows.md - - text: Considerations for shared and guest devices - url: /windows/configuration/shared-devices-concepts?context=/education/context/context - - text: Change Windows editions - url: change-home-to-edu.md - - linkListType: how-to-guide - links: - - text: Configure Take a Test in kiosk mode - url: edu-take-a-test-kiosk-mode.md - - text: Configure Shared PC - url: /windows/configuration/set-up-shared-or-guest-pc?context=/education/context/context - - text: Get and deploy Minecraft Education - url: get-minecraft-for-education.md \ No newline at end of file From ce4d41f30f72a62c9a8b1803695fd56fc5d3bd91 Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Fri, 27 Oct 2023 10:05:10 -0700 Subject: [PATCH 21/26] Added information about MEC when set to Allow --- ...indows-autopatch-microsoft-365-apps-enterprise.md | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md b/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md index 06e2e12c09..251e6080a3 100644 --- a/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md +++ b/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md @@ -1,7 +1,7 @@ --- title: Microsoft 365 Apps for enterprise description: This article explains how Windows Autopatch manages Microsoft 365 Apps for enterprise updates -ms.date: 06/23/2023 +ms.date: 10/27/2023 ms.prod: windows-client ms.technology: itpro-updates ms.topic: how-to @@ -81,7 +81,15 @@ Windows Autopatch doesn't allow you to pause or roll back an update in the Micro ## Allow or block Microsoft 365 App updates -For organizations seeking greater control, you can allow or block Microsoft 365 App updates for Windows Autopatch-enrolled devices. When the Microsoft 365 App update setting is set to **Block**, Windows Autopatch doesn't provide Microsoft 365 App updates on your behalf, and your organizations have full control over these updates. For example, you can continue to receive updates from [channels](/deployoffice/overview-update-channels) other than the default [Monthly Enterprise Channel](/deployoffice/overview-update-channels#monthly-enterprise-channel-overview). +> [!IMPORTANT] +> You must be an Intune Administrator to make changes to the setting. + +For organizations seeking greater control, you can allow or block Microsoft 365 App updates for Windows Autopatch-enrolled devices. + +| Microsoft 365 App setting | Description | +| ----- | ----- | +| **Block** | When set to **Block**, Windows Autopatch doesn't provide Microsoft 365 App updates on your behalf, and your organizations have full control over these updates. You can continue to receive updates from [channels](/deployoffice/overview-update-channels) other than the default [Monthly Enterprise Channel](/deployoffice/overview-update-channels#monthly-enterprise-channel-overview). | +| **Allow** | When set to **Allow**, Windows Autopatch moves all Autopatch managed devices to the [Monthly Enterprise Channel](/deployoffice/overview-update-channels#monthly-enterprise-channel-overview) and manages updates automatically. To manage updates manually, the Microsoft 365 App update setting is set to **Block**. | **To allow or block Microsoft 365 App updates:** From 5d189c95a738da19d4f28af74eea46f508cc42fc Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Fri, 27 Oct 2023 10:11:12 -0700 Subject: [PATCH 22/26] Updated Whats new with M365 update --- .../whats-new/windows-autopatch-whats-new-2023.md | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2023.md b/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2023.md index e800c3533c..24650e3a33 100644 --- a/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2023.md +++ b/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2023.md @@ -1,7 +1,7 @@ --- title: What's new 2023 description: This article lists the 2023 feature releases and any corresponding Message center post numbers. -ms.date: 10/19/2023 +ms.date: 10/27/2023 ms.prod: windows-client ms.technology: itpro-updates ms.topic: whats-new @@ -23,6 +23,12 @@ Minor corrections such as typos, style, or formatting issues aren't listed. ## October 2023 +### October feature releases or updates + +| Article | Description | +| ----- | ----- | +| [Microsoft 365 Apps for enterprise](../operate/windows-autopatch-microsoft-365-apps-enterprise.md#microsoft-365-apps-for-enterprise-update-controls) | Added more information about the Allow setting in the [Microsoft 365 Apps for enterprise update controls](../operate/windows-autopatch-microsoft-365-apps-enterprise.md#microsoft-365-apps-for-enterprise-update-controls) section | + ## October service release | Message center post number | Description | From d12c2437bc60d41a2ebc25a48abeec47e0853ec5 Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Fri, 27 Oct 2023 10:14:09 -0700 Subject: [PATCH 23/26] Tweak --- .../operate/windows-autopatch-microsoft-365-apps-enterprise.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md b/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md index 251e6080a3..c425246290 100644 --- a/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md +++ b/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md @@ -89,7 +89,7 @@ For organizations seeking greater control, you can allow or block Microsoft 365 | Microsoft 365 App setting | Description | | ----- | ----- | | **Block** | When set to **Block**, Windows Autopatch doesn't provide Microsoft 365 App updates on your behalf, and your organizations have full control over these updates. You can continue to receive updates from [channels](/deployoffice/overview-update-channels) other than the default [Monthly Enterprise Channel](/deployoffice/overview-update-channels#monthly-enterprise-channel-overview). | -| **Allow** | When set to **Allow**, Windows Autopatch moves all Autopatch managed devices to the [Monthly Enterprise Channel](/deployoffice/overview-update-channels#monthly-enterprise-channel-overview) and manages updates automatically. To manage updates manually, the Microsoft 365 App update setting is set to **Block**. | +| **Allow** | When set to **Allow**, Windows Autopatch moves all Autopatch managed devices to the [Monthly Enterprise Channel](/deployoffice/overview-update-channels#monthly-enterprise-channel-overview) and manages updates automatically. To manage updates manually, set the Microsoft 365 App update setting to **Block**. | **To allow or block Microsoft 365 App updates:** From fe4a90447a3976c20a278d3efd3490de9d245083 Mon Sep 17 00:00:00 2001 From: tiaraquan Date: Fri, 27 Oct 2023 10:21:36 -0700 Subject: [PATCH 24/26] Nitpick --- .../operate/windows-autopatch-microsoft-365-apps-enterprise.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md b/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md index c425246290..3120c809f3 100644 --- a/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md +++ b/windows/deployment/windows-autopatch/operate/windows-autopatch-microsoft-365-apps-enterprise.md @@ -88,8 +88,8 @@ For organizations seeking greater control, you can allow or block Microsoft 365 | Microsoft 365 App setting | Description | | ----- | ----- | -| **Block** | When set to **Block**, Windows Autopatch doesn't provide Microsoft 365 App updates on your behalf, and your organizations have full control over these updates. You can continue to receive updates from [channels](/deployoffice/overview-update-channels) other than the default [Monthly Enterprise Channel](/deployoffice/overview-update-channels#monthly-enterprise-channel-overview). | | **Allow** | When set to **Allow**, Windows Autopatch moves all Autopatch managed devices to the [Monthly Enterprise Channel](/deployoffice/overview-update-channels#monthly-enterprise-channel-overview) and manages updates automatically. To manage updates manually, set the Microsoft 365 App update setting to **Block**. | +| **Block** | When set to **Block**, Windows Autopatch doesn't provide Microsoft 365 App updates on your behalf, and your organizations have full control over these updates. You can continue to receive updates from [channels](/deployoffice/overview-update-channels) other than the default [Monthly Enterprise Channel](/deployoffice/overview-update-channels#monthly-enterprise-channel-overview). | **To allow or block Microsoft 365 App updates:** From 25bf695a0f09b04805b35989080f8da726ddbe6b Mon Sep 17 00:00:00 2001 From: Frank Rojas <45807133+frankroj@users.noreply.github.com> Date: Fri, 27 Oct 2023 15:37:25 -0400 Subject: [PATCH 25/26] Revert some changes Most of the changes were ok but there were some that were incorrect or not needed, so I reverted them back --- windows/deployment/customize-boot-image.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/windows/deployment/customize-boot-image.md b/windows/deployment/customize-boot-image.md index 490c8bc110..81a6276297 100644 --- a/windows/deployment/customize-boot-image.md +++ b/windows/deployment/customize-boot-image.md @@ -70,7 +70,7 @@ This walkthrough describes how to customize a Windows PE boot image including up > > - Microsoft Deployment Toolkit (MDT) doesn't support versions of Windows or the Windows ADK beyond Windows 10. If using MDT, the recommendation is to instead use the [ADK for Windows 10, version 2004](/windows-hardware/get-started/adk-install#other-adk-downloads). This version was the last version of the Windows ADK supported by MDT. > -> - The latest versions of the **Windows PE add-on for the Windows ADK** only include 64-bit boot images. If a 32-bit boot image is required, then the recommendation in this scenario is to also use the [ADK for Windows 10, version 2004](/windows-hardware/get-started/adk-install#other-adk-downloads). This version of the Windows ADK was the last version to include both 32-bit and 64-bit boot images. +> - The latest versions of the **Windows PE add-on for the Windows ADK** only includes a 64-bit boot image. If a 32-bit boot image is required, then the recommendation in this scenario is to also use the [ADK for Windows 10, version 2004](/windows-hardware/get-started/adk-install#other-adk-downloads). This version of the Windows ADK was the last version to include both 32-bit and 64-bit boot images. ## Step 2: Download cumulative update (CU) @@ -511,7 +511,7 @@ The problem occurs when the WinPE boot image that is being serviced requires the For scenarios where older versions of the Windows ADK and Windows PE need to be used, for example when using Microsoft Deployment Toolkit (MDT), the servicing stack update needs to be installed before installing the cumulative update. The servicing stack update (SSU) is contained within the cumulative update (CU). To obtain the servicing stack update (SSU) so that it can be applied, it can be extracted from the cumulative update (CU). -The following steps outline how to extract and then install the servicing stack update (SSU) to the boot image. Once the servicing stack update (SSU) has been installed in the boot image, then the cumulative update (CU) should be installed in the boot image without error: +The following steps outline how to extract and then install the servicing stack update (SSU) to the boot image. Once the servicing stack update (SSU) has been installed in the boot image, then the cumulative update (CU) should install to the boot image without error: > [!IMPORTANT] > @@ -530,7 +530,7 @@ The following steps outline how to extract and then install the servicing stack **Example**: ```powershell - Start-Process "expand.exe" -ArgumentList " -f:* `"C:\Updates\windows11.0-kb5029263-x64_4f5fe19bbec786f5e445d3e71bcdf234fe2cbbec.msu`" `"C:\Updates\Extract`"" -Wait -LoadUserProfile + Start-Process "expand.exe" -ArgumentList " -f:* `"C:\Updates\windows10.0-kb5028166-x64_fe3aa2fef685c0e76e1f5d34d529624294273f41.msu`" `"C:\Updates\Extract`"" -Wait -LoadUserProfile ``` For more information, see [Start-Process](/powershell/module/microsoft.powershell.management/start-process) and [expand](/windows-server/administration/windows-commands/expand). @@ -566,7 +566,7 @@ The following steps outline how to extract and then install the servicing stack **Example**: ```powershell - Add-WindowsPackage -PackagePath "C:\Updates\Extract\SSU-22621.2061.cab" -Path "C:\Mount" -Verbose + Add-WindowsPackage -PackagePath "C:\Updates\Extract\SSU-19041.3205-x64" -Path "C:\Mount" -Verbose ``` For more information, see [Add-WindowsPackage](/powershell/module/dism/add-windowspackage). @@ -930,7 +930,7 @@ This process has the following advantages: 1. Keeps `boot.wim` pristine. -1. Make sure that changes done to a boot image are being done to a pristine unmodified version of the boot image. This process helps avoid corruption when a boot image is updated multiple times. I can also correct issues with existing boot images. +1. Makes sure that changes done to a boot image are being done to a pristine unmodified version of the boot image. This process helps avoid corruption when a boot image is updated multiple times. I can also correct issues with existing boot images. 1. Helps manage components in the boot image. The process doesn't need to know what components may need to be removed from the boot image each time the boot image is rebuilt. Instead, it just needs to know what components need to be added to the boot image. @@ -938,7 +938,7 @@ This process has the following advantages: Configuration Manager updates the `boot.wim` boot image in two scenarios: -1. When Configuration Manager is upgraded between versions or hotfix roll-ups (HFRUs) is applied, `boot.wim` may be updated as part of the upgrade process. +1. When Configuration Manager is upgraded between versions or a hotfix roll-up (HFRU) is applied, `boot.wim` may be updated as part of the upgrade process. 1. When selecting the option **Reload this boot image with the current Windows PE version from the Windows ADK** in the **Update Distribution Points Wizard**. @@ -954,7 +954,7 @@ The `winpe.wim` boot image from the Windows ADK should be updated because if `bo > > Never manually update the `boot..wim` boot image. In addition to facing the same issues when manually updating the `boot.wim` boot image, the `boot..wim` boot image will also face additional issues such as: > -> - Any time any changes are done to the boot image, such as adding drivers, and enabling the command prompt. etc, any manual changes done to the boot image, including the cumulative update, will be lost. +> - Any time any changes are done to the boot image (adding drivers, enabling the command prompt, etc.), any manual changes done to the boot image, including the cumulative update, will be lost. > > - Manually changing the `boot..wim` boot image changes the hash value of the boot image. A change in the hash value of the boot image can lead to download failures when downloading the boot image from a distribution point. @@ -985,7 +985,7 @@ For Microsoft Configuration Manager boot images to function correctly, it requir | Network/WinPE-WDS-Tools | `WinPE-WDS-Tools.cab` | NA | Yes | | Startup/WinPE-SecureStartup | `WinPE-SecureStartup.cab` | Scripting/WinPE-WMI | Yes | -When adding optional components to any boot image used by Configuration Manager during the [Step 6: Add optional components to boot image](#step-6-add-optional-components-to-boot-image) step, make sure to first add the above-required components in the above order to the boot image. After adding the required components to the boot image, add any additional desired optional components to the boot image. +When adding optional components to any boot image used by Configuration Manager during the [Step 6: Add optional components to boot image](#step-6-add-optional-components-to-boot-image) step, make sure to first add the above required components in the above order to the boot image. After adding the required components to the boot image, add any additional desired optional components to the boot image. For a list of all available WinPE optional components including descriptions for each component, see [WinPE Optional Components (OC) Reference: WinPE Optional Components](/windows-hardware/manufacture/desktop/winpe-add-packages--optional-components-reference#winpe-optional-components). @@ -1043,7 +1043,7 @@ For Microsoft Deployment Toolkit (MDT) boot images to function correctly, it req | Startup/WinPE-SecureStartup | `WinPE-SecureStartup.cab` | Scripting/WinPE-WMI | Yes | | HTML/WinPE-HTA | `WinPE-HTA.cab` | Scripting/WinPE-WMI | Yes | -When adding optional components to any boot image used by MDT during the [Step 6: Add optional components to boot image](#step-6-add-optional-components-to-boot-image) step, make sure to first add the above-required components in the above order to the boot image. After adding the required components to the boot image, add any additional desired optional components to the boot image. +When adding optional components to any boot image used by MDT during the [Step 6: Add optional components to boot image](#step-6-add-optional-components-to-boot-image) step, make sure to first add the above required components in the above order to the boot image. After adding the required components to the boot image, add any additional desired optional components to the boot image. For a list of all available WinPE optional components including descriptions for each component, see [WinPE Optional Components (OC) Reference: WinPE Optional Components](/windows-hardware/manufacture/desktop/winpe-add-packages--optional-components-reference#winpe-optional-components). From 424931311d5246441fabb21483a5a403db2b4f52 Mon Sep 17 00:00:00 2001 From: Frank Rojas <45807133+frankroj@users.noreply.github.com> Date: Fri, 27 Oct 2023 15:45:38 -0400 Subject: [PATCH 26/26] Reverting more changes Reverting more changes --- windows/deployment/customize-boot-image.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/deployment/customize-boot-image.md b/windows/deployment/customize-boot-image.md index 81a6276297..3b52b209f3 100644 --- a/windows/deployment/customize-boot-image.md +++ b/windows/deployment/customize-boot-image.md @@ -544,7 +544,7 @@ The following steps outline how to extract and then install the servicing stack **Example**: ```cmd - expand.exe -f:* "C:\Updates\windows11.0-kb5029263-x64_4f5fe19bbec786f5e445d3e71bcdf234fe2cbbec.msu" "C:\Updates\Extract" + expand.exe -f:* "C:\Updates\windows10.0-kb5028166-x64_fe3aa2fef685c0e76e1f5d34d529624294273f41.msu" "C:\Updates\Extract" ``` For more information, see [expand](/windows-server/administration/windows-commands/expand). @@ -566,7 +566,7 @@ The following steps outline how to extract and then install the servicing stack **Example**: ```powershell - Add-WindowsPackage -PackagePath "C:\Updates\Extract\SSU-19041.3205-x64" -Path "C:\Mount" -Verbose + Add-WindowsPackage -PackagePath "C:\Updates\Extract\SSU-19041.3205-x64.cab" -Path "C:\Mount" -Verbose ``` For more information, see [Add-WindowsPackage](/powershell/module/dism/add-windowspackage). @@ -582,7 +582,7 @@ The following steps outline how to extract and then install the servicing stack **Example**: ```cmd - DISM.exe /Image:"C:\Mount" /Add-Package /PackagePath:"C:\Updates\Extract\SSU-22621.2061.cab" + DISM.exe /Image:"C:\Mount" /Add-Package /PackagePath:"C:\Updates\Extract\SSU-19041.3205-x64.cab" ``` For more information, see [Add or Remove Packages Offline Using DISM](/windows-hardware/manufacture/desktop/add-or-remove-packages-offline-using-dism) and [DISM Operating System Package (.cab or .msu) Servicing Command-Line Options: /Add-Package](/windows-hardware/manufacture/desktop/dism-operating-system-package-servicing-command-line-options#add-package).