From eb3165f758e2afec7c7676370e5135b9c3edd641 Mon Sep 17 00:00:00 2001 From: LizRoss Date: Thu, 4 Aug 2016 08:07:20 -0700 Subject: [PATCH 1/5] Added tables about the returned reason codes --- ...ct-data-using-enterprise-site-discovery.md | 64 +++++++++++++++---- 1 file changed, 52 insertions(+), 12 deletions(-) diff --git a/browsers/internet-explorer/ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md b/browsers/internet-explorer/ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md index 86fa6692fe..b9796882f3 100644 --- a/browsers/internet-explorer/ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md +++ b/browsers/internet-explorer/ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md @@ -64,9 +64,50 @@ Data is collected on the configuration characteristics of IE and the sites it br |Number of visits | X | X | X | X |Number of times a site has been visited. | |Zone | X | X | X | X |Zone used by IE to browse sites, based on browser settings. | -

**Important**
By default, IE doesn’t collect this data; you have to turn this feature on if you want to use it. After you turn on this feature, data is collected on all sites visited by IE, except during InPrivate sessions. -The data collection process is silent, so there’s no notification to the employee. Therefore, you must get consent from the employee before you start collecting info. You must also make sure that using this feature complies with all applicable local laws and regulatory requirements. +**Important**
By default, IE doesn’t collect this data; you have to turn this feature on if you want to use it. After you turn on this feature, data is collected on all sites visited by IE, except during InPrivate sessions. Additionally, the data collection process is silent, so there’s no notification to the employee. Therefore, you must get consent from the employee before you start collecting info. You must also make sure that using this feature complies with all applicable local laws and regulatory requirements. + +### Understanding the returned reason codes +The following tables provide more info about the Document mode reason, Browser state reason, and the Zone codes that are returned as part of your data collection. + +#### DocMode reason +The codes in this table can tell you what document mode was set by IE for a webpage. These codes only apply to Internet Explorer 10 and Internet Explorer 11. + +|Code |Description | +|-----|------------| +|3 |Page state is set by the `FEATURE_DOCUMENT_COMPATIBLE_MODE` feature control key.| +|4 |Page is using an X-UA-compatible meta tag. | +|5 |Page is using an X-UA-compatible HTTP header. | +|6 |Page appears on an active **Compatibility View** list. | +|7 |Page is using native XML parsing. | +|8 |Page is using the mode set by the top-level QME FCK. | + +#### Browser state reason +The codes in this table can tell you why the browser is in its current state. Also called “browser mode”. These codes only apply to Internet Explorer 10 and Internet Explorer 11. + +|Code |Description | +|-----|------------| +|1 |Site is on the intranet, with the **Display intranet sites in Compatibility View** box checked. | +|2 |Site appears on an active **Compatibility View** list, created in Group Policy. | +|3 |Site appears on an active **Compatibility View** list, created by the user. | +|4 |Page is using an X-UA-compatible tag. | +|5 |Page state is set by the **Developer** toolbar. | +|6 |Page state is set by the `FEATURE_BROWSER_EMULATION` feature control key. | +|7 |Site appears on the Microsoft **Compatibility View (CV)** list. | +|8 |Site appears on the **Quirks** list, created in Group Policy. | +|11 |Site is using the default browser. | + +#### Zone +The codes in this table can tell you what zone is being used by IE to browse sites, based on browser settings. These codes apply to Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11. + +|Code |Description | +|-----|------------| +|-1 |Internet Explorer is using an invalid zone. | +|0 |Internet Explorer is using the Local machine zone. | +|1 |Internet Explorer is using the Local intranet zone. | +|2 |Internet Explorer is using the Trusted sites zone. | +|3 |Internet Explorer is using the Internet zone. | +|4 |Internet Explorer is using the Restricted sites zone. | ## Where is the data stored and how do I collect it? The data is stored locally, in an industry-standard WMI class, .MOF file or in an XML file, depending on your configuration. This file remains on the client computer until it’s collected. To collect the files, we recommend: @@ -94,14 +135,14 @@ Before you can start to collect your data, you must run the provided PowerShell You need to set up your computers for data collection by running the provided PowerShell script (IETelemetrySetUp.ps1) to compile the .mof file and to update security privileges for the new WMI classes.

**Important**
You must run this script if you’re using WMI as your data output. It's not necessary if you're using XML as your data output. -![](images/wedge.gif) **To set up Enterprise Site Discovery** +**To set up Enterprise Site Discovery** - Start PowerShell in elevated mode (using admin privileges) and run IETElemetrySetUp.ps1 by by-passing the PowerShell execution policy, using this command: `powershell -ExecutionPolicy Bypass .\IETElemetrySetUp.ps1`. For more info, see [about Execution Policies](http://go.microsoft.com/fwlink/p/?linkid=517460). ### WMI only: Set up your firewall for WMI data If you choose to use WMI as your data output, you need to make sure that your WMI data can travel through your firewall for the domain. If you’re sure, you can skip this section; otherwise, follow these steps: -![](images/wedge.gif) **To set up your firewall** +**To set up your firewall** 1. In **Control Panel**, click **System and Security**, and then click **Windows Firewall**. @@ -117,13 +158,13 @@ You can determine which zones or domains are used for data collection, using Pow - **Zone allow list.** If you have a zone allow list, a comma-separated list of zones that should have this feature turned on, you should use this process. - ![](images/wedge.gif) **To set up data collection using a domain allow list** +**To set up data collection using a domain allow list** - Start PowerShell in elevated mode (using admin privileges) and run IETElemetrySetUp.ps1, using this command: `.\IETElemetrySetUp.ps1 [other args] -SiteAllowList sharepoint.com,outlook.com,onedrive.com`. **Important**
Wildcards, like \*.microsoft.com, aren’t supported. - ![](images/wedge.gif) **To set up data collection using a zone allow list** +**To set up data collection using a zone allow list** - Start PowerShell in elevated mode (using admin privileges) and run IETElemetrySetUp.ps1, using this command: `.\IETElemetrySetUp.ps1 [other args] -ZoneAllowList Computer,Intranet,TrustedSites,Internet,RestrictedSites`. @@ -223,7 +264,7 @@ Your environment is now ready to collect your hardware inventory and review the ### Collect your hardware inventory using the SMS\DEF.MOF file (System Center Configuration Manager 2007 only) You can collect your hardware inventory using the using the Systems Management Server (SMS\DEF.MOF) file. Editing this file lets you collect your data for System Center Configuration Manager 2007. If you aren’t using this version of Configuration Manager, you won’t want to use this option. - ![](images/wedge.gif) **To collect your inventory** +**To collect your inventory** 1. Using a text editor like Notepad, open the SMS\DEF.MOF file, located in your `\inboxes\clifiles.src\hinv` directory. @@ -339,7 +380,7 @@ After the XML files are created, you can use your own solutions to extract and p ``` You can import this XML data into the correct version of the Enterprise Mode Site List Manager, automatically adding the included sites to your Enterprise Mode site list. - ![](images/wedge.gif) **To add your XML data to your Enterprise Mode site list** +**To add your XML data to your Enterprise Mode site list** 1. Open the Enterprise Mode Site List Manager, click **File**, and then click **Bulk add from file**. ![Enterprise Mode Site List Manager with Bulk add from file option](images/bulkadd-emiesitelistmgr.png) @@ -352,13 +393,12 @@ Each site is validated and if successful, added to the global site list when you ## Turn off data collection on your client devices After you’ve collected your data, you’ll need to turn Enterprise Site Discovery off. - ![](images/wedge.gif) **To stop collecting data, using PowerShell** +**To stop collecting data, using PowerShell** - On your client computer, start Windows PowerShell in elevated mode (using admin privileges) and run `IETelemetrySetUp.ps1`, using this command: `powershell -ExecutionPolicy Bypass .\IETElemetrySetUp.ps1 –IEFeatureOff`.

**Note**
Turning off data collection only disables the Enterprise Site Discovery feature – all data already written to WMI stays on your employee’s computer. -   - ![](images/wedge.gif) **To stop collecting data, using Group Policy** +**To stop collecting data, using Group Policy** 1. Open your Group Policy editor, go to `Administrative Templates\Windows Components\Internet Explorer\Turn on Site Discovery WMI output`, and click **Off**. @@ -367,7 +407,7 @@ Turning off data collection only disables the Enterprise Site Discovery feature ### Delete already stored data from client computers You can completely remove the data stored on your employee’s computers. - ![](images/wedge.gif) **To delete all existing data** +**To delete all existing data** - On the client computer, start PowerShell in elevated mode (using admin privileges) and run these four commands: From 0d1789d05872a1dfeed1b6c5f3e24acbf960735e Mon Sep 17 00:00:00 2001 From: LizRoss Date: Thu, 4 Aug 2016 08:18:33 -0700 Subject: [PATCH 2/5] Fixed broken formatting --- ...ct-data-using-enterprise-site-discovery.md | 55 ++++++++++--------- 1 file changed, 30 insertions(+), 25 deletions(-) diff --git a/browsers/internet-explorer/ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md b/browsers/internet-explorer/ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md index b9796882f3..1d47983620 100644 --- a/browsers/internet-explorer/ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md +++ b/browsers/internet-explorer/ie11-deploy-guide/collect-data-using-enterprise-site-discovery.md @@ -9,7 +9,6 @@ title: Collect data using Enterprise Site Discovery ms.sitesec: library --- - # Collect data using Enterprise Site Discovery **Applies to:** @@ -65,7 +64,7 @@ Data is collected on the configuration characteristics of IE and the sites it br |Zone | X | X | X | X |Zone used by IE to browse sites, based on browser settings. | -**Important**
By default, IE doesn’t collect this data; you have to turn this feature on if you want to use it. After you turn on this feature, data is collected on all sites visited by IE, except during InPrivate sessions. Additionally, the data collection process is silent, so there’s no notification to the employee. Therefore, you must get consent from the employee before you start collecting info. You must also make sure that using this feature complies with all applicable local laws and regulatory requirements. +>**Important**
By default, IE doesn’t collect this data; you have to turn this feature on if you want to use it. After you turn on this feature, data is collected on all sites visited by IE, except during InPrivate sessions. Additionally, the data collection process is silent, so there’s no notification to the employee. Therefore, you must get consent from the employee before you start collecting info. You must also make sure that using this feature complies with all applicable local laws and regulatory requirements. ### Understanding the returned reason codes The following tables provide more info about the Document mode reason, Browser state reason, and the Zone codes that are returned as part of your data collection. @@ -120,7 +119,8 @@ The data is stored locally, in an industry-standard WMI class, .MOF file or in a We recommend that you collect your data for at most a month at a time, to capture a user’s typical workflow. We don’t recommend collecting data longer than that because the data is stored in a WMI provider and can fill up your computer’s hard drive. You may also want to collect data only for pilot users or a representative sample of people, instead of turning this feature on for everyone in your company. On average, a website generates about 250bytes of data for each visit, causing only a minor impact to Internet Explorer’s performance. Over the course of a month, collecting data from 20 sites per day from 1,000 users, you’ll get about 150MB of data:
\[250bytes (per site visit) \* 20sites/day\* 30days = (approximately) 150KB \*1000users = (approximately) 150MB\]. -

**Important**
The data collection process is silent, so there’s no notification to the employee. Therefore, you must get consent from the employee before you start collecting info. You must also make sure that using this feature complies with all applicable local laws and regulatory requirements. + +>**Important**
The data collection process is silent, so there’s no notification to the employee. Therefore, you must get consent from the employee before you start collecting info. You must also make sure that using this feature complies with all applicable local laws and regulatory requirements. ## Getting ready to use Enterprise Site Discovery Before you can start to collect your data, you must run the provided PowerShell script (IETelemetrySetUp.ps1) on your client devices to start generating the site discovery data and to set up a place to store this data locally. Then, you must start collecting the site discovery data from the client devices, using one of these three options: @@ -133,7 +133,8 @@ Before you can start to collect your data, you must run the provided PowerShell ### WMI only: Running the PowerShell script to compile the .MOF file and to update security privileges You need to set up your computers for data collection by running the provided PowerShell script (IETelemetrySetUp.ps1) to compile the .mof file and to update security privileges for the new WMI classes. -

**Important**
You must run this script if you’re using WMI as your data output. It's not necessary if you're using XML as your data output. + +>**Important**
You must run this script if you’re using WMI as your data output. It's not necessary if you're using XML as your data output. **To set up Enterprise Site Discovery** @@ -152,7 +153,8 @@ If you choose to use WMI as your data output, you need to make sure that your WM ## Use PowerShell to finish setting up Enterprise Site Discovery You can determine which zones or domains are used for data collection, using PowerShell. If you don’t want to use PowerShell, you can do this using Group Policy. For more info, see [Use Group Policy to finish setting up Enterprise Site Discovery](#use-group-policy-to-finish-setting-up-enterprise-site-discovery). -

**Important**
The .ps1 file updates turn on Enterprise Site Discovery and WMI collection for all users on a device. + +>**Important**
The .ps1 file updates turn on Enterprise Site Discovery and WMI collection for all users on a device. - **Domain allow list.** If you have a domain allow list, a comma-separated list of domains that should have this feature turned on, you should use this process. @@ -162,51 +164,52 @@ You can determine which zones or domains are used for data collection, using Pow - Start PowerShell in elevated mode (using admin privileges) and run IETElemetrySetUp.ps1, using this command: `.\IETElemetrySetUp.ps1 [other args] -SiteAllowList sharepoint.com,outlook.com,onedrive.com`. - **Important**
Wildcards, like \*.microsoft.com, aren’t supported. + >**Important**
Wildcards, like \*.microsoft.com, aren’t supported. **To set up data collection using a zone allow list** - Start PowerShell in elevated mode (using admin privileges) and run IETElemetrySetUp.ps1, using this command: `.\IETElemetrySetUp.ps1 [other args] -ZoneAllowList Computer,Intranet,TrustedSites,Internet,RestrictedSites`. - **Important**
Only Computer, Intranet, TrustedSites, Internet, and RestrictedSites are supported. + >**Important**
Only Computer, Intranet, TrustedSites, Internet, and RestrictedSites are supported. ## Use Group Policy to finish setting up Enterprise Site Discovery You can use Group Policy to finish setting up Enterprise Site Discovery. If you don’t want to use Group Policy, you can do this using PowerShell. For more info, see [Use Powershell to finish setting up Enterprise Site Discovery](#use-powershell-to-finish-setting-up-enterprise-site-discovery). -

**Note**
 All of the Group Policy settings can be used individually or as a group. - ![](images/wedge.gif) **To set up Enterprise Site Discovery using Group Policy** +>**Note**
 All of the Group Policy settings can be used individually or as a group. + + **To set up Enterprise Site Discovery using Group Policy** - Open your Group Policy editor, and go to these new settings: |Setting name and location |Description |Options | |---------------------------|-------------|---------| |Administrative Templates\Windows Components\Internet Explorer\Turn on Site Discovery WMI output |Writes collected data to a WMI class, which can be aggregated using a client-management solution like Configuration Manager. |

| -|Administrative Templates\Windows Components\Internet Explorer\Turn on Site Discovery XML output |Writes collected data to an XML file, which is stored in your specified location. | | +|Administrative Templates\Windows Components\Internet Explorer\Turn on Site Discovery XML output |Writes collected data to an XML file, which is stored in your specified location. | | |Administrative Templates\Windows Components\Internet Explorer\Limit Site Discovery output by Zone |Manages which zone can collect data. |To specify which zones can collect data, you must include a binary number that represents your selected zones, based on this order:

0 – Restricted Sites zone
0 – Internet zone
0 – Trusted Sites zone
0 – Local Intranet zone
0 – Local Machine zone

**Example 1:** Include only the Local Intranet zone

Binary representation: *00010*, based on:

0 – Restricted Sites zone
0 – Internet zone
0 – Trusted Sites zone
1 – Local Intranet zone
0 – Local Machine zone

**Example 2:** Include only the Restricted Sites, Trusted Sites, and Local Intranet zones

Binary representation: *10110*, based on:

1 – Restricted Sites zone
0 – Internet zone
1 – Trusted Sites zone
1 – Local Intranet zone
1 – Local Machine zone | |Administrative Templates\Windows Components\Internet Explorer\Limit Site Discovery output by domain |Manages which domains can collect data |To specify which domains can collect data, you must include your selected domains, one domain per line, in the provided box. It should look like:

microsoft.sharepoint.com
outlook.com
onedrive.com
timecard.contoso.com
LOBApp.contoso.com | ### Combining WMI and XML Group Policy settings You can use both the WMI and XML settings individually or together, based on: - ![](images/wedge.gif) **To turn off Enterprise Site Discovery** + **To turn off Enterprise Site Discovery**

- ![](images/wedge.gif) **To turn on WMI recording only** + **To turn on WMI recording only** - ![](images/wedge.gif) **To turn on XML recording only** + **To turn on XML recording only** - ![](images/wedge.gif) **To turn on both WMI and XML recording** + **To turn on both WMI and XML recording**