Merge branch 'main' of https://github.com/MicrosoftDocs/windows-docs-pr into nw-issue-7146
@ -17,22 +17,6 @@
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "hololens",
|
||||
"build_source_folder": "devices/hololens",
|
||||
"build_output_subfolder": "hololens",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "internet-explorer",
|
||||
"build_source_folder": "browsers/internet-explorer",
|
||||
@ -49,22 +33,6 @@
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "keep-secure",
|
||||
"build_source_folder": "windows/keep-secure",
|
||||
"build_output_subfolder": "keep-secure",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": false,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "microsoft-edge",
|
||||
"build_source_folder": "browsers/edge",
|
||||
@ -81,22 +49,6 @@
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "release-information",
|
||||
"build_source_folder": "windows/release-information",
|
||||
"build_output_subfolder": "release-information",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": false,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "smb",
|
||||
"build_source_folder": "smb",
|
||||
@ -129,22 +81,6 @@
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "win-access-protection",
|
||||
"build_source_folder": "windows/access-protection",
|
||||
"build_output_subfolder": "win-access-protection",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "win-app-management",
|
||||
"build_source_folder": "windows/application-management",
|
||||
@ -209,54 +145,6 @@
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "win-device-security",
|
||||
"build_source_folder": "windows/device-security",
|
||||
"build_output_subfolder": "win-device-security",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-configure",
|
||||
"build_source_folder": "windows/configure",
|
||||
"build_output_subfolder": "windows-configure",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": false,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-deploy",
|
||||
"build_source_folder": "windows/deploy",
|
||||
"build_output_subfolder": "windows-deploy",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-hub",
|
||||
"build_source_folder": "windows/hub",
|
||||
@ -273,22 +161,6 @@
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-plan",
|
||||
"build_source_folder": "windows/plan",
|
||||
"build_output_subfolder": "windows-plan",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-privacy",
|
||||
"build_source_folder": "windows/privacy",
|
||||
@ -321,38 +193,6 @@
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "windows-update",
|
||||
"build_source_folder": "windows/update",
|
||||
"build_output_subfolder": "windows-update",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "win-threat-protection",
|
||||
"build_source_folder": "windows/threat-protection",
|
||||
"build_output_subfolder": "win-threat-protection",
|
||||
"locale": "en-us",
|
||||
"monikers": [],
|
||||
"moniker_ranges": [],
|
||||
"open_to_public_contributors": true,
|
||||
"type_mapping": {
|
||||
"Conceptual": "Content",
|
||||
"ManagedReference": "Content",
|
||||
"RestApi": "Content"
|
||||
},
|
||||
"build_entry_point": "docs",
|
||||
"template_folder": "_themes"
|
||||
},
|
||||
{
|
||||
"docset_name": "win-whats-new",
|
||||
"build_source_folder": "windows/whats-new",
|
||||
@ -370,9 +210,7 @@
|
||||
"template_folder": "_themes"
|
||||
}
|
||||
],
|
||||
"notification_subscribers": [
|
||||
"elizapo@microsoft.com"
|
||||
],
|
||||
"notification_subscribers": [],
|
||||
"sync_notification_subscribers": [
|
||||
"dstrome@microsoft.com"
|
||||
],
|
||||
@ -408,13 +246,13 @@
|
||||
"Pdf"
|
||||
]
|
||||
},
|
||||
"need_generate_pdf_url_template": true,
|
||||
"targets": {
|
||||
"Pdf": {
|
||||
"template_folder": "_themes.pdf"
|
||||
}
|
||||
},
|
||||
"docs_build_engine": {},
|
||||
"need_generate_pdf_url_template": true,
|
||||
"contribution_branch_mappings": {},
|
||||
"need_generate_pdf": false,
|
||||
"need_generate_intellisense": false
|
||||
|
@ -19559,6 +19559,31 @@
|
||||
"source_path": "windows/deployment/deploy-windows-mdt/deploy-a-windows-11-image-using-mdt.md",
|
||||
"redirect_url": "/windows/deployment/deploy-windows-mdt/deploy-a-windows-10-image-using-mdt",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "education/windows/get-minecraft-device-promotion.md",
|
||||
"redirect_url": "/education/windows/get-minecraft-for-education",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-group-policy.md",
|
||||
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-windows-defender-application-control-policies-using-group-policy",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md",
|
||||
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/deployment/deploy-windows-defender-application-control-policies-using-intune",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "smb/cloud-mode-business-setup.md",
|
||||
"redirect_url": "https://techcommunity.microsoft.com/t5/small-and-medium-business-blog/bg-p/Microsoft365BusinessBlog",
|
||||
"redirect_document_id": false
|
||||
},
|
||||
{
|
||||
"source_path": "smb/index.md",
|
||||
"redirect_url": "https://techcommunity.microsoft.com/t5/small-and-medium-business-blog/bg-p/Microsoft365BusinessBlog",
|
||||
"redirect_document_id": false
|
||||
}
|
||||
]
|
||||
}
|
||||
|
@ -3,3 +3,5 @@ docfx.json @microsoftdocs/officedocs-admin
|
||||
.openpublishing.publish.config.json @microsoftdocs/officedocs-admin
|
||||
CODEOWNERS @microsoftdocs/officedocs-admin
|
||||
.acrolinx-config.edn @microsoftdocs/officedocs-admin
|
||||
|
||||
/windows/privacy/ @DHB-MSFT
|
2
ContentOwners.txt
Normal file
@ -0,0 +1,2 @@
|
||||
/windows/ @aczechowski
|
||||
/windows/privacy/ @DHB-MSFT
|
@ -1,2 +0,0 @@
|
||||
- name: Index
|
||||
href: index.md
|
@ -1,3 +0,0 @@
|
||||
- name: Docs
|
||||
tocHref: /
|
||||
topicHref: /
|
@ -138,7 +138,7 @@ Before you can start to collect your data, you must run the provided PowerShell
|
||||
-OR-
|
||||
- Collect your hardware inventory using the MOF Editor with a .MOF import file.<p>
|
||||
-OR-
|
||||
- Collect your hardware inventory using the SMS\DEF.MOF file (System Center Configuration Manager 2007 only)
|
||||
- Collect your hardware inventory using the SMS\DEF.MOF file (Configuration Manager 2007 only)
|
||||
|
||||
### WMI only: Running the PowerShell script to compile the .MOF file and to update security privileges
|
||||
You need to set up your computers for data collection by running the provided PowerShell script (IETelemetrySetUp.ps1) to compile the .mof file and to update security privileges for the new WMI classes.
|
||||
@ -235,7 +235,7 @@ After you’ve collected your data, you’ll need to get the local files off of
|
||||
-OR-
|
||||
- Collect your hardware inventory using the MOF Editor with a .MOF import file.<p>
|
||||
-OR-
|
||||
- Collect your hardware inventory using the SMS\DEF.MOF file (System Center Configuration Manager 2007 only)
|
||||
- Collect your hardware inventory using the SMS\DEF.MOF file (Configuration Manager 2007 only)
|
||||
|
||||
### Collect your hardware inventory using the MOF Editor while connected to a client device
|
||||
You can collect your hardware inventory using the MOF Editor, while you’re connected to your client devices.
|
||||
@ -277,8 +277,8 @@ You can collect your hardware inventory using the MOF Editor and a .MOF import f
|
||||
4. Click **OK** to close the default windows.<br>
|
||||
Your environment is now ready to collect your hardware inventory and review the sample reports.
|
||||
|
||||
### Collect your hardware inventory using the SMS\DEF.MOF file (System Center Configuration Manager 2007 only)
|
||||
You can collect your hardware inventory using the using the Systems Management Server (SMS\DEF.MOF) file. Editing this file lets you collect your data for System Center Configuration Manager 2007. If you aren’t using this version of Configuration Manager, you won’t want to use this option.
|
||||
### Collect your hardware inventory using the SMS\DEF.MOF file (Configuration Manager 2007 only)
|
||||
You can collect your hardware inventory using the using the Systems Management Server (SMS\DEF.MOF) file. Editing this file lets you collect your data for Configuration Manager 2007. If you aren’t using this version of Configuration Manager, you won’t want to use this option.
|
||||
|
||||
**To collect your inventory**
|
||||
|
||||
@ -352,14 +352,14 @@ You can collect your hardware inventory using the using the Systems Management S
|
||||
Your environment is now ready to collect your hardware inventory and review the sample reports.
|
||||
|
||||
## View the sample reports with your collected data
|
||||
The sample reports, **SCCM Report Sample – ActiveX.rdl** and **SCCM Report Sample – Site Discovery.rdl**, work with System Center 2012, so you can review your collected data.
|
||||
The sample reports, **Configuration Manager Report Sample – ActiveX.rdl** and **Configuration Manager Report Sample – Site Discovery.rdl**, work with System Center 2012, so you can review your collected data.
|
||||
|
||||
### SCCM Report Sample – ActiveX.rdl
|
||||
### Configuration Manager Report Sample – ActiveX.rdl
|
||||
Gives you a list of all of the ActiveX-related sites visited by the client computer.
|
||||
|
||||

|
||||
|
||||
### SCCM Report Sample – Site Discovery.rdl
|
||||
### Configuration Manager Report Sample – Site Discovery.rdl
|
||||
Gives you a list of all of the sites visited by the client computer.
|
||||
|
||||

|
||||
|
@ -29,7 +29,7 @@ Before you install Internet Explorer 11, you should:
|
||||
|
||||
- **Choose how you'll deploy your installation package.** Your deployment method should be based on whether you're installing to computers already running Windows, or if you're deploying IE11 as part of a Windows installation.
|
||||
|
||||
- **Existing computers running Windows.** Use System Center R2 2012 System Center 2012 R2 Configuration Manager, System Center Essentials 2010, Windows Server Updates Services (WSUS), or Microsoft Intune to deploy IE11. For more information about how to use these systems, see [System Center 2012 R2 Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682129(v=technet.10)), [System Center Essentials 2010](https://go.microsoft.com/fwlink/p/?LinkId=395200), [Windows Server Update Services](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/hh852345(v=ws.11)), and [Microsoft Intune Overview](https://www.microsoft.com/cloud-platform/microsoft-intune).
|
||||
- **Existing computers running Windows.** Use Configuration Manager, System Center Essentials 2010, Windows Server Updates Services (WSUS), or Microsoft Intune to deploy IE11. For more information about how to use these systems, see [Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682129(v=technet.10)), [System Center Essentials 2010](https://go.microsoft.com/fwlink/p/?LinkId=395200), [Windows Server Update Services](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/hh852345(v=ws.11)), and [Microsoft Intune Overview](https://www.microsoft.com/cloud-platform/microsoft-intune).
|
||||
|
||||
- **As part of a Windows deployment.** Update your Windows images to include IE11, and then add the update to your MDT deployment share or to your Windows image. For instructions about how to create and use Windows images, see [Create and Manage a Windows Image Using DISM](/previous-versions/windows/it-pro/windows-8.1-and-8/hh825251(v=win.10)). For general information about deploying IE, see [Microsoft Deployment Toolkit (MDT)](/mem/configmgr/mdt/), [Windows ADK Overview](/previous-versions/windows/it-pro/windows-8.1-and-8/hh825486(v=win.10)).
|
||||
|
||||
|
@ -142,7 +142,7 @@ Before you can start to collect your data, you must run the provided PowerShell
|
||||
-OR-
|
||||
- Collect your hardware inventory using the MOF Editor with a .MOF import file.<p>
|
||||
-OR-
|
||||
- Collect your hardware inventory using the SMS\DEF.MOF file (System Center Configuration Manager 2007 only)
|
||||
- Collect your hardware inventory using the SMS\DEF.MOF file (Configuration Manager 2007 only)
|
||||
|
||||
### WMI only: Running the PowerShell script to compile the .MOF file and to update security privileges
|
||||
You need to set up your computers for data collection by running the provided PowerShell script (IETelemetrySetUp.ps1) to compile the .mof file and to update security privileges for the new WMI classes.
|
||||
@ -239,7 +239,7 @@ After you’ve collected your data, you’ll need to get the local files off of
|
||||
-OR-
|
||||
- Collect your hardware inventory using the MOF Editor with a .MOF import file.<p>
|
||||
-OR-
|
||||
- Collect your hardware inventory using the SMS\DEF.MOF file (System Center Configuration Manager 2007 only)
|
||||
- Collect your hardware inventory using the SMS\DEF.MOF file (Configuration Manager 2007 only)
|
||||
|
||||
### Collect your hardware inventory using the MOF Editor while connected to a client device
|
||||
You can collect your hardware inventory using the MOF Editor, while you’re connected to your client devices.
|
||||
@ -281,8 +281,8 @@ You can collect your hardware inventory using the MOF Editor and a .MOF import f
|
||||
4. Click **OK** to close the default windows.<br>
|
||||
Your environment is now ready to collect your hardware inventory and review the sample reports.
|
||||
|
||||
### Collect your hardware inventory using the SMS\DEF.MOF file (System Center Configuration Manager 2007 only)
|
||||
You can collect your hardware inventory using the using the Systems Management Server (SMS\DEF.MOF) file. Editing this file lets you collect your data for System Center Configuration Manager 2007. If you aren’t using this version of Configuration Manager, you won’t want to use this option.
|
||||
### Collect your hardware inventory using the SMS\DEF.MOF file (Configuration Manager 2007 only)
|
||||
You can collect your hardware inventory using the using the Systems Management Server (SMS\DEF.MOF) file. Editing this file lets you collect your data for Configuration Manager 2007. If you aren’t using this version of Configuration Manager, you won’t want to use this option.
|
||||
|
||||
**To collect your inventory**
|
||||
|
||||
@ -356,14 +356,14 @@ You can collect your hardware inventory using the using the Systems Management S
|
||||
Your environment is now ready to collect your hardware inventory and review the sample reports.
|
||||
|
||||
## View the sample reports with your collected data
|
||||
The sample reports, **SCCM Report Sample – ActiveX.rdl** and **SCCM Report Sample – Site Discovery.rdl**, work with System Center 2012, so you can review your collected data.
|
||||
The sample reports, **Configuration Manager Report Sample – ActiveX.rdl** and **Configuration Manager Report Sample – Site Discovery.rdl**, work with System Center 2012, so you can review your collected data.
|
||||
|
||||
### SCCM Report Sample – ActiveX.rdl
|
||||
### Configuration Manager Report Sample – ActiveX.rdl
|
||||
Gives you a list of all of the ActiveX-related sites visited by the client computer.
|
||||
|
||||

|
||||
|
||||
### SCCM Report Sample – Site Discovery.rdl
|
||||
### Configuration Manager Report Sample – Site Discovery.rdl
|
||||
Gives you a list of all of the sites visited by the client computer.
|
||||
|
||||

|
||||
|
@ -21,7 +21,7 @@ ms.date: 07/27/2017
|
||||
|
||||
If you already manage software distribution and updates on your network through software distribution tools, you can also use these tools for ongoing deployments of Internet Explorer. Software distribution tools include:
|
||||
|
||||
- **System Center R2 2012 System Center 2012 R2 Configuration Manager.** Deploy and install Internet Explorer 11 on your user's computers through a software distribution package. For more information about using this tool, see [System Center R2 2012 Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682129(v=technet.10)).
|
||||
- **Configuration Manager** Deploy and install Internet Explorer 11 on your user's computers through a software distribution package. For more information about using this tool, see [Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682129(v=technet.10)).
|
||||
|
||||
- **Windows Server Update Services (WSUS).** Download a single copy of the IE11 updates, caching them to local servers so your users' computers can receive the updates directly from the WSUS servers, instead of through Windows Update. For more information about using this tool, see [Windows Server Update Services](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/hh852345(v=ws.11)).
|
||||
|
||||
|
@ -75,7 +75,7 @@ If you use Automatic Updates in your company, but want to stop your users from a
|
||||
> [!NOTE]
|
||||
>The toolkit won't stop users with local administrator accounts from manually installing Internet Explorer 11. Using this toolkit also prevents your users from receiving automatic upgrades from Internet Explorer 8, Internet Explorer 9, or Internet Explorer 10 to Internet Explorer 11. For more information, see the [Internet Explorer 11 Blocker Toolkit frequently asked questions](../ie11-faq/faq-for-it-pros-ie11.yml).
|
||||
|
||||
- **Use an update management solution to control update deployment.** If you already use an update management solution, like [Windows Server Update Services (WSUS)](/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus) or the more advanced [System Center 2012 Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682129(v=technet.10)), you should use that instead of the Internet Explorer Blocker Toolkit.
|
||||
- **Use an update management solution to control update deployment.** If you already use an update management solution, like [Windows Server Update Services (WSUS)](/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus) or the more advanced [Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682129(v=technet.10)), you should use that instead of the Internet Explorer Blocker Toolkit.
|
||||
|
||||
> [!NOTE]
|
||||
> If you use WSUS to manage updates, and Update Rollups are configured for automatic installation, Internet Explorer will automatically install throughout your company.
|
||||
|
@ -22,7 +22,7 @@ summary: |
|
||||
Get answers to commonly asked questions about the Internet Explorer 11 Blocker Toolkit.
|
||||
|
||||
> [!Important]
|
||||
> If you administer your company’s environment using an update management solution, such as Windows Server Update Services (WSUS) or System Center 2012 Configuration Manager, you don’t need to use the Internet Explorer 11 Blocker Toolkit. Update management solutions let you completely manage your Windows Updates and Microsoft Updates, including your Internet Explorer 11 deployment.
|
||||
> If you administer your company’s environment using an update management solution, such as Windows Server Update Services (WSUS) or Configuration Manager, you don’t need to use the Internet Explorer 11 Blocker Toolkit. Update management solutions let you completely manage your Windows Updates and Microsoft Updates, including your Internet Explorer 11 deployment.
|
||||
|
||||
- [Automatic updates delivery process](/internet-explorer/ie11-faq/faq-ie11-blocker-toolkit#automatic-updates-delivery-process)
|
||||
|
||||
@ -47,7 +47,7 @@ sections:
|
||||
- question: |
|
||||
Whtools cI use to manage Windows Updates and Microsoft Updates in my company?
|
||||
answer: |
|
||||
We encourage anyone who wants full control over their company’s deployment of Windows Updates and Microsoft Updates, to use [Windows Server Update Services (WSUS)](/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus), a free tool for users of Windows Server. You calso use the more advanced configuration management tool, [System Center 2012 Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682041(v=technet.10)).
|
||||
We encourage anyone who wants full control over their company’s deployment of Windows Updates and Microsoft Updates, to use [Windows Server Update Services (WSUS)](/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus), a free tool for users of Windows Server. You calso use the more advanced configuration management tool, [Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682041(v=technet.10)).
|
||||
|
||||
- question: |
|
||||
How long does the blocker mechanism work?
|
||||
|
@ -32,7 +32,6 @@
|
||||
"ms.topic": "article",
|
||||
"ms.technology": "windows",
|
||||
"manager": "dansimp",
|
||||
"audience": "ITPro",
|
||||
"breadcrumb_path": "/education/breadcrumb/toc.json",
|
||||
"ms.date": "05/09/2017",
|
||||
"feedback_system": "None",
|
||||
@ -51,6 +50,9 @@
|
||||
"Kellylorenebaker",
|
||||
"jborsecnik",
|
||||
"tiburd",
|
||||
"AngelaMotherofDragons",
|
||||
"dstrome",
|
||||
"v-dihans",
|
||||
"garycentric"
|
||||
]
|
||||
},
|
||||
|
@ -2,39 +2,9 @@
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
## Week of June 27, 2022
|
||||
|
||||
|
||||
| Published On |Topic title | Change |
|
||||
|------|------------|--------|
|
||||
| 5/3/2022 | [Reset devices with Autopilot Reset](/education/windows/autopilot-reset) | modified |
|
||||
| 5/3/2022 | [Change history for Windows 10 for Education (Windows 10)](/education/windows/change-history-edu) | modified |
|
||||
| 5/3/2022 | [Change to Windows 10 Education from Windows 10 Pro](/education/windows/change-to-pro-education) | modified |
|
||||
| 5/3/2022 | [Chromebook migration guide (Windows 10)](/education/windows/chromebook-migration-guide) | modified |
|
||||
| 5/3/2022 | [Windows 10 configuration recommendations for education customers](/education/windows/configure-windows-for-education) | modified |
|
||||
| 5/3/2022 | [Deploy Windows 10 in a school district (Windows 10)](/education/windows/deploy-windows-10-in-a-school-district) | modified |
|
||||
| 5/3/2022 | [Deploy Windows 10 in a school (Windows 10)](/education/windows/deploy-windows-10-in-a-school) | modified |
|
||||
| 5/3/2022 | [Deployment recommendations for school IT administrators](/education/windows/edu-deployment-recommendations) | modified |
|
||||
| 5/3/2022 | [For IT administrators get Minecraft Education Edition](/education/windows/school-get-minecraft) | modified |
|
||||
| 5/3/2022 | [What's in Set up School PCs provisioning package](/education/windows/set-up-school-pcs-provisioning-package) | modified |
|
||||
| 5/3/2022 | [Take a Test app technical reference](/education/windows/take-a-test-app-technical) | modified |
|
||||
| 5/3/2022 | [Set up Take a Test on multiple PCs](/education/windows/take-a-test-multiple-pcs) | modified |
|
||||
| 5/3/2022 | [For teachers get Minecraft Education Edition](/education/windows/teacher-get-minecraft) | modified |
|
||||
| 5/3/2022 | [Test Windows 10 in S mode on existing Windows 10 education devices](/education/windows/test-windows10s-for-edu) | modified |
|
||||
|
||||
|
||||
## Week of April 25, 2022
|
||||
|
||||
|
||||
| Published On |Topic title | Change |
|
||||
|------|------------|--------|
|
||||
| 4/25/2022 | [Deploy Windows 10 in a school district (Windows 10)](/education/windows/deploy-windows-10-in-a-school-district) | modified |
|
||||
| 4/25/2022 | [Deploy Windows 10 in a school district (Windows 10)](/education/windows/deploy-windows-10-in-a-school-district) | modified |
|
||||
|
||||
|
||||
## Week of April 18, 2022
|
||||
|
||||
|
||||
| Published On |Topic title | Change |
|
||||
|------|------------|--------|
|
||||
|------|------------|--------|
|
||||
|
@ -53,8 +53,6 @@
|
||||
href: teacher-get-minecraft.md
|
||||
- name: "For IT administrators: get Minecraft Education Edition"
|
||||
href: school-get-minecraft.md
|
||||
- name: "Get Minecraft: Education Edition with Windows 10 device promotion"
|
||||
href: get-minecraft-device-promotion.md
|
||||
- name: Test Windows 10 in S mode on existing Windows 10 education devices
|
||||
href: test-windows10s-for-edu.md
|
||||
- name: Enable Windows 10 in S mode on Surface Go devices
|
||||
|
@ -135,7 +135,7 @@ The topics in this library have been updated for Windows 10, version 1607 (also
|
||||
| New or changed topic | Description|
|
||||
| --- | --- |
|
||||
| [Windows 10 editions for education customers](windows-editions-for-education-customers.md) | New. Learn about the two editions in Windows 10, version 1607 that's designed for the needs of K-12 institutions. |
|
||||
|[Deploy Windows 10 in a school district](deploy-windows-10-in-a-school-district.md)|New. Learn how to deploy Windows 10 in a school district. Integrate the school environment with Office 365, AD DS, and Microsoft Azure AD, use SCCM, Intune, and Group Policy to manage devices. |
|
||||
|[Deploy Windows 10 in a school district](deploy-windows-10-in-a-school-district.md)|New. Learn how to deploy Windows 10 in a school district. Integrate the school environment with Office 365, AD DS, and Microsoft Azure AD, use Configuration Manager, Intune, and Group Policy to manage devices. |
|
||||
|
||||
## June 2016
|
||||
|
||||
|
@ -485,7 +485,7 @@ Table 9. Management systems and deployment resources
|
||||
|--- |--- |
|
||||
|Windows provisioning packages| <li> [Build and apply a provisioning package](/windows/configuration/provisioning-packages/provisioning-create-package) <li>[Windows Imaging and Configuration Designer](/windows/configuration/provisioning-packages/provisioning-install-icd) <li> [Step-By-Step: Building Windows 10 Provisioning Packages](/archive/blogs/canitpro/step-by-step-building-windows-10-provisioning-packages)|
|
||||
|Group Policy|<li> [Core Network Companion Guide: Group Policy Deployment](/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj899807(v=ws.11)) <li> [Deploying Group Policy](/previous-versions/windows/it-pro/windows-server-2003/cc737330(v=ws.10))"|
|
||||
|Configuration Manager| <li> [Site Administration for System Center 2012 Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg681983(v=technet.10)) <li> [Deploying Clients for System Center 2012 Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg699391(v=technet.10))|
|
||||
|Configuration Manager| <li> [Site Administration for Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg681983(v=technet.10)) <li> [Deploying Clients for Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg699391(v=technet.10))|
|
||||
|Intune| <li> [Set up and manage devices with Microsoft Intune](https://go.microsoft.com/fwlink/p/?LinkId=690262) <li> [System Center 2012 R2 Configuration Manager &amp; Windows Intune](/learn/?l=fCzIjVKy_6404984382)|
|
||||
|MDT| <li> [Step-By-Step: Installing Windows 8.1 From A USB Key](/archive/blogs/canitpro/step-by-step-installing-windows-8-1-from-a-usb-key)|
|
||||
|
||||
|
@ -1,90 +0,0 @@
|
||||
---
|
||||
title: Get Minecraft Education Edition with your Windows 10 device promotion
|
||||
description: Windows 10 device promotion for Minecraft Education Edition licenses
|
||||
keywords: school, Minecraft, education edition
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: medium
|
||||
author: dansimp
|
||||
searchScope:
|
||||
- Store
|
||||
ms.author: dansimp
|
||||
ms.date: 06/05/2018
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
---
|
||||
|
||||
# Get Minecraft: Education Edition with Windows 10 device promotion
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
|
||||
The **Minecraft: Education Edition** with Windows 10 device promotion ended January 31, 2018.
|
||||
|
||||
Qualifying customers that received one-year subscriptions for Minecraft: Education Edition as part of this program and wish to continue using the game in their schools can purchase new subscriptions in Microsoft Store for Education.
|
||||
For more information on purchasing Minecraft: Education Edition, see [Add Minecraft to your Store for Education](./school-get-minecraft.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json).
|
||||
|
||||
>[!Note]
|
||||
>**Minecraft: Education Edition** with Windows 10 device promotion subscriptions are valid for 1 year from the time
|
||||
of redemption. At the end of 1 year, the promotional subscriptions will expire and any people using these subscriptions will be reverted to a trial license of **Minecraft: Education Edition**.
|
||||
|
||||
To prevent being reverted to a trial license, admins or teachers need to purchase new **Minecraft: Education Edition** subscriptions from Store for Education, and assign licenses to users who used a promotional subscription.
|
||||
|
||||
|
||||
<!---
|
||||
For qualifying customers, receive a one-year, single-user subscription for Minecraft: Education Edition for each Windows 10 device you purchase for your K-12 school. You’ll need your invoice or receipt, so be sure to keep track of that. For more information including terms of use, see [Minecraft: Education Edition promotion](https://info.microsoft.com/Minecraft-Education-Edition-Signup.html).
|
||||
|
||||
## Requirements
|
||||
- Qualified Educational Users in K-12 education institutions
|
||||
- Windows 10 devices purchased from May 2, 2017 - January 31, 2018
|
||||
- Redeem Minecraft: Education Edition licenses from July 1, 2017 - March 17, 2018
|
||||
- Microsoft Store for Education admin must submit request for Minecraft: Education Edition licenses
|
||||
- Proof of device purchase is required (invoice required)
|
||||
|
||||
Full details available at [Minecraft: Education Edition promotion](https://info.microsoft.com/Minecraft-Education-Edition-Signup.html).
|
||||
|
||||
## Redeem Minecraft: Education Edition licenses
|
||||
Redeeming your licenses takes just a few steps:
|
||||
- Visit the device promotion page
|
||||
- Submit a device purchase statement
|
||||
- Provide proof of your device purchase
|
||||
|
||||
After that, we’ll add the appropriate number of Minecraft: Education Edition licenses to your product inventory in **Microsoft Store for Education** as **Minecraft: Education Edition [subscription]**.
|
||||
|
||||
**To redeem Minecraft: Education Edition licenses**
|
||||
1. Visit [Minecraft: Education Edition and Windows 10 device promotion](https://educationstore.microsoft.com/store/mee-device-promo?setflight=wsfb_devicepromo) in **Microsoft Store for Education**.
|
||||
|
||||

|
||||
|
||||
2. Sign in to **Microsoft Store for Education** using a school account. If you don’t have one, we’ll help you set one up. <br>
|
||||
-or-
|
||||
|
||||
If you're already signed in to Microsoft Store for Education, the device special offer is available on **Benefits**. </br>
|
||||
Click **Manage**, **Benefits**, and then click **Minecraft: Education Edition Device Promotion**.
|
||||
|
||||
3. **On Minecraft Windows 10 device special offer**, click **Submit a device purchase**.
|
||||
|
||||

|
||||
|
||||
4. Provide info for **Proof of Purchase**. Be sure to include a .pdf or .jpg of your invoice, and then click **Next**.
|
||||
|
||||
> [!NOTE]
|
||||
> Your one-year subscription starts when you submit your proof-of-purchase info. Be sure to submit your request when you'll be using licenses in the classroom.
|
||||
|
||||

|
||||
|
||||
5. Accept the **Promotion Terms of use**, and then click **Submit**. </br>
|
||||
|
||||
Success look like this!
|
||||
|
||||

|
||||
|
||||
6. Click **Actions** and then click **Manage** to go to the management page for **Minecraft: Education Edition** and distribute licenses.
|
||||
|
||||
## Distribute Minecraft: Education Edition licenses
|
||||
Teachers or admins can distribute the licenses:
|
||||
- [Learn how teachers can distribute **Minecraft: Education Edition**](teacher-get-minecraft.md#distribute-minecraft)
|
||||
- [Learn how IT administrators can distribute **Minecraft: Education Edition**](school-get-minecraft.md#distribute-minecraft)
|
||||
-->
|
@ -56,11 +56,11 @@ Windows 11 SE comes with some preinstalled apps. The following apps can also run
|
||||
|FortiClient |7.0.1.0083 |Win32 |Fortinet|
|
||||
|Free NaturalReader |16.1.2 |Win32 |Natural Soft|
|
||||
|GoGuardian |1.4.4 |Win32 |GoGuardian|
|
||||
|Google Chrome |100.0.4896.127|Win32 |Google|
|
||||
|Google Chrome |102.0.5005.115|Win32 |Google|
|
||||
|Illuminate Lockdown Browser |2.0.5 |Win32 |Illuminate Education|
|
||||
|Immunet |7.5.0.20795 |Win32 |Immunet|
|
||||
|JAWS for Windows |2022.2112.24 |Win32 |Freedom Scientific|
|
||||
|Kite Student Portal |8.0.1 |Win32 |Dynamic Learning Maps|
|
||||
|Kite Student Portal |8.0.3.0 |Win32 |Dynamic Learning Maps|
|
||||
|Kortext |2.3.433.0 |Store |Kortext|
|
||||
|Kurzweil 3000 Assistive Learning |20.13.0000 |Win32 |Kurzweil Educational Systems|
|
||||
|LanSchool |9.1.0.46 |Win32 |Stoneware|
|
||||
@ -83,7 +83,7 @@ Windows 11 SE comes with some preinstalled apps. The following apps can also run
|
||||
|Safe Exam Browser |3.3.2.413 |Win32 |Safe Exam Browser|
|
||||
|Secure Browser |14.0.0 |Win32 |Cambium Development|
|
||||
|Secure Browser |4.8.3.376 |Win32 |Questar, Inc|
|
||||
|Senso.Cloud |2021.11.15.0 |Win32|Senso.Cloud|
|
||||
|Senso.Cloud |2021.11.15.0 |Win32|Senso.Cloud|
|
||||
|SuperNova Magnifier & Screen Reader |21.02 |Win32 |Dolphin Computer Access|
|
||||
|Zoom |5.9.1 (2581)|Win32 |Zoom|
|
||||
|ZoomText Fusion |2022.2109.10|Win32 |Freedom Scientific|
|
||||
|
@ -30,22 +30,24 @@ The following table lists and describes the settings that can be changed by admi
|
||||
|
||||
| Setting | Description |
|
||||
| --- | --- |
|
||||
| Block manual unenrollment | Default: Blocked<br/><br/>Users can't unenroll their devices from device management services. <br/><br/>[Experience/AllowManualMDMUnenrollment CSP](/windows/client-management/mdm/policy-csp-experience#experience-allowmanualmdmunenrollment)|
|
||||
| Allow option to Show Network | Default: Allowed<br/><br/>Gives users the option to see the **Show Network** folder in File Explorer. |
|
||||
| Allow option to Show This PC | Default: Allowed<br/><br/>Gives user the option to see the **Show This PC** folder in File Explorer. |
|
||||
| Set Allowed Folder location | Default folders: Documents, Desktop, Pictures, and Downloads<br/><br/>Gives user access to these folders. |
|
||||
| Set Allowed Storage Locations | Default: Blocks Local Drives and Network Drives<br/><br/>Blocks user access to these storage locations. |
|
||||
| Allow News and Interests | Default: Hide<br/><br/>Hides Widgets. |
|
||||
| Disable advertising ID | Default: Disabled<br/><br/>Blocks apps from using usage data to tailor advertisements. <br/><br/>[Privacy/DisableAdvertisingId CSP](/windows/client-management/mdm/policy-csp-privacy#privacy-disableadvertisingid) |
|
||||
| Visible settings pages | Default: <br/><br/> |
|
||||
| Enable App Install Control | Default: Turned On<br/><br/>Users can’t download apps from the internet.<br/><br/>[SmartScreen/EnableAppInstallControl CSP](/windows/client-management/mdm/policy-csp-smartscreen#smartscreen-enableappinstallcontrol)|
|
||||
| Configure Storage Sense Cloud Content Dehydration Threshold | Default: 30 days<br/><br/>If a file hasn’t been opened in 30 days, it becomes an online-only file. Online-only files can be opened when there's an internet connection. When an online-only file is opened on a device, it downloads and becomes locally available on that device. The file is available until it's unopened for the specified number of days, and becomes online-only again. <br/><br/>[Storage/ConfigStorageSenseCloudContentDehydrationThreshold CSP](/windows/client-management/mdm/policy-csp-storage#storage-configstoragesensecloudcontentdehydrationthreshold) |
|
||||
| Allow Telemetry | Default: Required Telemetry Only<br/><br/>Sends only basic device info, including quality-related data, app compatibility, and similar data to keep the device secure and up-to-date. <br/><br/>[System/AllowTelemetry CSP](/windows/client-management/mdm/policy-csp-system#system-allowtelemetry) |
|
||||
| Allow Experimentation | Default: Disabled<br/><br/>Microsoft can't experiment with the product to study user preferences or device behavior. <br/><br/>[System/AllowExperimentation CSP](/windows/client-management/mdm/policy-csp-system#system-allowexperimentation) |
|
||||
| Block external extensions | Default: Blocked<br/><br/>In Microsoft Edge, users can't install external extensions. <br/><br/>[BlockExternalExtensions](/DeployEdge/microsoft-edge-policies#blockexternalextensions)|
|
||||
| Configure new tab page | Default: `Office.com`<br/><br/>In Microsoft Edge, the new tab page defaults to `office.com`. <br/><br/>[Configure the new tab page URL](/DeployEdge/microsoft-edge-policies#configure-the-new-tab-page-url)|
|
||||
| Configure homepage | Default: `Office.com`<br/><br/>In Microsoft Edge, the homepage defaults to `office.com`. <br/><br/>[HomepageIsNewTabPage](/DeployEdge/microsoft-edge-policies#homepageisnewtabpage)|
|
||||
| Prevent SmartScreen prompt override | Default: Enabled<br/><br/>In Microsoft Edge, users can't override Windows Defender SmartScreen warnings. <br/><br/>[PreventSmartScreenPromptOverride](/DeployEdge/microsoft-edge-policies#preventsmartscreenpromptoverride)|
|
||||
| Block manual unenrollment | Default: Blocked <br/> <br/> Users can't unenroll their devices from device management services. <br/> <br/> [Experience/AllowManualMDMUnenrollment CSP](/windows/client-management/mdm/policy-csp-experience#experience-allowmanualmdmunenrollment) |
|
||||
| Allow option to Show Network | Default: Allowed <br/> <br/> Gives users the option to see the **Show Network** folder in File Explorer. |
|
||||
| Allow option to Show This PC | Default: Allowed <br/> <br/> Gives user the option to see the **Show This PC** folder in File Explorer. |
|
||||
| Set Allowed Folder location | Default folders: Documents, Desktop, Pictures, and Downloads <br/> <br/> Gives user access to these folders. |
|
||||
| Set Allowed Storage Locations | Default: Blocks local drives and network drives <br/> <br/> Blocks user access to these storage locations. |
|
||||
| Allow News and Interests | Default: Hide <br/> <br/> Hides widgets. |
|
||||
| Disable advertising ID | Default: Disabled <br/> <br/> Blocks apps from using usage data to tailor advertisements. <br/> <br/> [Privacy/DisableAdvertisingId CSP](/windows/client-management/mdm/policy-csp-privacy#privacy-disableadvertisingid) |
|
||||
| Visible settings pages | Default: <br/> <br/> |
|
||||
| Enable App Install Control | Default: Turned On <br/><br/> Users can't download apps from the internet.<br/> <br/> [SmartScreen/EnableAppInstallControl CSP](/windows/client-management/mdm/policy-csp-smartscreen#smartscreen-enableappinstallcontrol)|
|
||||
| Configure Storage Sense Cloud Content Dehydration Threshold | Default: 30 days<br/> <br/> If a file hasn't been opened in 30 days, it becomes an online-only file. Online-only files can be opened when there's an internet connection. When an online-only file is opened on a device, it downloads and becomes locally available on that device. The file is available until it's unopened for the specified number of days, and becomes online-only again. <br/> <br/> [Storage/ConfigStorageSenseCloudContentDehydrationThreshold CSP](/windows/client-management/mdm/policy-csp-storage#storage-configstoragesensecloudcontentdehydrationthreshold) |
|
||||
| Allow Telemetry | Default: Required Telemetry Only <br/> <br/> Sends only basic device info, including quality-related data, app compatibility, and similar data to keep the device secure and up-to-date. <br/> <br/> [System/AllowTelemetry CSP](/windows/client-management/mdm/policy-csp-system#system-allowtelemetry) |
|
||||
| Allow Experimentation | Default: Disabled <br/> <br/> Microsoft can't experiment with the product to study user preferences or device behavior. <br/> <br/>[System/AllowExperimentation CSP](/windows/client-management/mdm/policy-csp-system#system-allowexperimentation) |
|
||||
| Block external extensions | Default: Blocked <br/> <br/> In Microsoft Edge, users can't install external extensions. <br/> <br/> [BlockExternalExtensions](/DeployEdge/microsoft-edge-policies#blockexternalextensions) |
|
||||
| Configure new tab page | Default: `Office.com` <br/> <br/> In Microsoft Edge, the new tab page defaults to `Office.com`. <br/> <br/> [Configure the new tab page URL](/DeployEdge/microsoft-edge-policies#configure-the-new-tab-page-url) |
|
||||
| Configure homepage | Default: `Office.com` <br/> <br/> In Microsoft Edge, the homepage defaults to `Office.com`. <br/> <br/> [HomepageIsNewTabPage](/DeployEdge/microsoft-edge-policies#homepageisnewtabpage) |
|
||||
| Prevent SmartScreen prompt override | Default: Enabled <br/> <br/> In Microsoft Edge, users can't override Windows Defender SmartScreen warnings. <br/> <br/>[PreventSmartScreenPromptOverride](/DeployEdge/microsoft-edge-policies#preventsmartscreenpromptoverride) |
|
||||
| Wallpaper Image Customization | Default: <br/> <br/> Specify a jpg, jpeg, or png image to be used as the desktop image. This setting can take an http or https URL to a remote image to be downloaded, a file URL to a local image. <br/> <br/>[DesktopImageUrl](/windows/client-management/mdm/personalization-csp) |
|
||||
| Lock Screen Image Customization | Default: <br/> <br/> Specify a jpg, jpeg, or png image to be used as lock screen image. This setting can take an http or https URL to a remote image to be downloaded, a file URL to a local image. <br/> <br/>[LockScreenImageUrl](/windows/client-management/mdm/personalization-csp) |
|
||||
|
||||
## Settings that can't be changed
|
||||
|
||||
|
@ -1,2 +0,0 @@
|
||||
- name: Index
|
||||
href: index.md
|
@ -1,4 +0,0 @@
|
||||
---
|
||||
ms.date: 09/21/2017
|
||||
---
|
||||
# placeholder
|
Before Width: | Height: | Size: 15 KiB |
@ -1,5 +0,0 @@
|
||||
- name: Windows 10 for SMB
|
||||
href: index.md
|
||||
items:
|
||||
- name: "Get started: Deploy and manage a full cloud IT solution for your business"
|
||||
href: cloud-mode-business-setup.md
|
@ -1,12 +0,0 @@
|
||||
items:
|
||||
- name: Docs
|
||||
tocHref: /
|
||||
topicHref: /
|
||||
items:
|
||||
- name: Windows
|
||||
tocHref: /windows
|
||||
topicHref: /windows/resources/
|
||||
items:
|
||||
- name: SMB
|
||||
tocHref: /windows/smb
|
||||
topicHref: /windows/smb/index
|
@ -1,590 +0,0 @@
|
||||
---
|
||||
title: Deploy and manage a full cloud IT solution for your business
|
||||
description: Learn how to set up a cloud infrastructure for your business, acquire devices and apps, and configure and deploy policies to your devices.
|
||||
keywords: smb, full cloud IT solution, small to medium business, deploy, setup, manage, Windows, Intune, Office 365
|
||||
ms.prod: w10
|
||||
ms.technology:
|
||||
ms.author: eravena
|
||||
audience: itpro
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: smb
|
||||
author: eavena
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.localizationpriority: medium
|
||||
ms.topic: conceptual
|
||||
---
|
||||
|
||||
# Get started: Deploy and manage a full cloud IT solution for your business
|
||||
|
||||

|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Microsoft 365 Business Standard, Azure AD Premium, Intune, Microsoft Store for Business, Windows 10
|
||||
|
||||
Are you ready to move your business to the cloud or wondering what it takes to make this happen with Microsoft cloud services and tools?
|
||||
|
||||
In this walkthrough, we'll show you how to deploy and manage a full cloud IT solution for your small to medium business using Microsoft 365 Business Standard, Microsoft Azure AD, Intune, Microsoft Store for Business, and Windows 10. We'll show you the basics on how to:
|
||||
- Acquire a Microsoft 365 for business domain
|
||||
- Add Microsoft Intune and Azure Active Directory (AD) Premium licenses to your business tenant
|
||||
- Set up Microsoft Store for Business and manage app deployment and sync with Intune
|
||||
- Add users and groups in Azure AD and Intune
|
||||
- Create policies and app deployment rules
|
||||
- Log in as a user and start using your Windows device
|
||||
|
||||
Go to [Microsoft 365 for business](https://www.microsoft.com/microsoft-365/business) to learn more about pricing and purchasing options for your business.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
Here's a few things to keep in mind before you get started:
|
||||
|
||||
- You'll need a registered domain to successfully go through the walkthrough.
|
||||
- If you already own a domain, you can add this during the Office 365 setup.
|
||||
- If you don't already own a domain, you can purchase a domain from the Microsoft 365 admin center. This walkthrough includes the steps.
|
||||
- You'll need an email address to create your Office 365 tenant.
|
||||
- We recommend that you use Internet Explorer for the entire walkthrough. Right select on Internet Explorer > **Start InPrivate Browsing**.
|
||||
|
||||
## 1. Set up your cloud infrastructure
|
||||
To set up a cloud infrastructure for your organization, follow the steps in this section.
|
||||
|
||||
### 1.1 Set up Office 365 for business
|
||||
|
||||
See [Microsoft 365 admin center for business](/microsoft-365/admin) and [Microsoft 365 resources for nonprofits](https://www.microsoft.com/nonprofits/microsoft-365) to learn more about the setup steps for businesses and nonprofits who have Office 365. You can learn how to:
|
||||
- Plan your setup
|
||||
- Create Office 365 accounts and how to add your domain.
|
||||
- Install Office
|
||||
|
||||
To set up your Microsoft 365 for business tenant, see [Get Started with Microsoft 365 for business](/microsoft-365/business-video/what-is-microsoft-365).
|
||||
|
||||
If you're new at setting up Office 365, and you'd like to see how it's done, you can follow these steps to get started:
|
||||
|
||||
1. Go to [Try or buy a Microsoft 365 for business subscription](/microsoft-365/commerce/try-or-buy-microsoft-365). In this walkthrough, we'll select **Try now**.
|
||||
|
||||
**Figure 1** - Try or buy Office 365
|
||||
|
||||

|
||||
|
||||
2. Fill out the sign up form and provide information about you and your company.
|
||||
3. Create a user ID and password to use to sign into your account.
|
||||
|
||||
This step creates an `onmicrosoft.com` email address. You can use this email address to sign in to the various admin centers. Save your sign-in info so you can use it to sign into [https://portal.office.com](https://portal.office.com) (the admin portal).
|
||||
|
||||
4. Select **Create my account** and then enter the phone number you used in step 2 to verify your identity. You'll be asked to enter your verification code.
|
||||
5. Select **You're ready to go...** which will take you to the Microsoft 365 admin center.
|
||||
|
||||
> [!NOTE]
|
||||
> In the Microsoft 365 admin center, icons that are greyed out are still installing.
|
||||
|
||||
**Figure 2** - Microsoft 365 admin center
|
||||
|
||||
:::image type="content" alt-text="Opens the Microsoft 365 admin center." source="images/office365_portal.png":::
|
||||
|
||||
|
||||
6. Select the **Admin** tile to go to the admin center.
|
||||
7. In the admin center, click **Next** to see the highlights and welcome info for the admin center. When you're done, click **Go to setup** to complete the Office 365 setup.
|
||||
|
||||
This step can take up to a half hour to complete.
|
||||
|
||||
**Figure 3** - Admin center
|
||||
|
||||
:::image type="content" alt-text="Complete the Office 365 setup in the Microsoft 365 admin center." source="images/office365_admin_portal.png":::
|
||||
|
||||
|
||||
8. Go back to the [admin center](https://portal.office.com/adminportal/home#/homepage) to add or buy a domain.
|
||||
1. Select the **Domains** option.
|
||||
|
||||
**Figure 4** - Option to add or buy a domain
|
||||
|
||||
:::image type="content" alt-text="Add or buy a domain in admin center." source="images/office365_buy_domain.png":::
|
||||
|
||||
|
||||
2. In the **Home > Domains** page, you will see the Microsoft-provided domain, such as `fabrikamdesign.onmicrosoft.com`.
|
||||
|
||||
**Figure 5** - Microsoft-provided domain
|
||||
|
||||
:::image type="content" alt-text="Microsoft-provided domain." source="images/office365_ms_provided_domain.png":::
|
||||
|
||||
- If you already have a domain, select **+ Add domain** to add your existing domain. If you select this option, you'll be required to verify that you own the domain. Follow the steps in the wizard to verify your domain.
|
||||
- If you don't already own a domain, select **+ Buy domain**. If you're using a trial plan, you'll be required to upgrade your trial plan in order to buy a domain. Choose the subscription plan to use for your business and provide the details to complete your order.
|
||||
|
||||
Once you've added your domain, you'll see it listed in addition to the Microsoft-provided onmicrosoft.com domain.
|
||||
|
||||
**Figure 6** - Domains
|
||||
|
||||
:::image type="content" alt-text="Verify your domains in the admin center." source="images/office365_additional_domain.png":::
|
||||
|
||||
### 1.2 Add users and assign product licenses
|
||||
Once you've set up Office and added your domain, it's time to add users so they have access to Office 365. People in your organization need an account before they can sign in and access Office 365. The easiest way to add users is to add them one at a time in the Microsoft 365 admin center.
|
||||
|
||||
When adding users, you can also assign admin privileges to certain users in your team. You'll also want to assign **Product licenses** to each user so that subscriptions can be assigned to the person.
|
||||
|
||||
**To add users and assign product licenses**
|
||||
|
||||
1. In the [admin center](https://portal.office.com/adminportal/home#/homepage), select **Users > Active users**.
|
||||
|
||||
**Figure 7** - Add users
|
||||
|
||||
:::image type="content" alt-text="Add Office 365 users." source="images/office365_users.png":::
|
||||
|
||||
2. In the **Home > Active users** page, add users individually or in bulk.
|
||||
- To add users one at a time, select **+ Add a user**.
|
||||
|
||||
If you select this option, you'll see the **New user** screen and you can add details about the new user including their name, user name, role, and so on. You also have the opportunity to assign **Product licenses**. For detailed step-by-step info on adding a user account, see [Add users and assign licenses at the same time](/microsoft-365/admin/add-users/add-users).
|
||||
|
||||
**Figure 8** - Add an individual user
|
||||
|
||||
:::image type="content" alt-text="Add an individual user." source="images/office365_add_individual_user.png":::
|
||||
|
||||
- To add multiple users at once, select **More** and then choose **+ Import multiple users**. If you select this option, you'll need to create and upload a CSV file containing the list of users.
|
||||
|
||||
The **Import multiple users** screen includes a link where you can learn more about importing multiple users and also links for downloading a sample CSV file (one with headers only and another with headers and sample user information). For detailed step-by-step info on adding multiple users to Office 365, see [Add users and assign licenses at the same time](/microsoft-365/admin/add-users/add-users). Once you've added all the users, don't forget to assign **Product licenses** to the new users.
|
||||
|
||||
**Figure 9** - Import multiple users
|
||||
|
||||
:::image type="content" alt-text="Import multiple users." source="images/office365_import_multiple_users.png":::
|
||||
|
||||
3. Verify that all the users you added appear in the list of **Active users**. The **Status** should indicate the product licenses that were assigned to them.
|
||||
|
||||
**Figure 10** - List of active users
|
||||
|
||||
:::image type="content" alt-text="Verify users and assigned product licenses." source="images/o365_active_users.png":::
|
||||
|
||||
### 1.3 Add Microsoft Intune
|
||||
Microsoft Intune provides mobile device management, app management, and PC management capabilities from the cloud. Using Intune, organizations can provide their employees with access to apps, data, and corporate resources from anywhere on almost any device while helping to keep corporate information secure. To learn more, see [Microsoft Intune is an MDM and MAM provider](/mem/intune/fundamentals/what-is-intune).
|
||||
|
||||
**To add Microsoft Intune to your tenant**
|
||||
|
||||
1. In the [admin center](https://portal.office.com/adminportal/home#/homepage), select **Billing > Purchase services**.
|
||||
2. In the **Home > Purchase services** screen, search for **Microsoft Intune**. Hover over **Microsoft Intune** to see the options to start a free 30-day trial or to buy now.
|
||||
3. Confirm your order to enable access to Microsoft Intune.
|
||||
4. In the admin center, the Intune licenses will show as available and ready to be assigned to users. Select **Users > Active users** and then edit the product licenses assigned to the users to turn on **Intune A Direct**.
|
||||
|
||||
**Figure 11** - Assign Intune licenses
|
||||
|
||||
:::image type="content" alt-text="Assign Microsoft Intune licenses to users." source="images/o365_assign_intune_license.png":::
|
||||
|
||||
5. In the admin center, confirm that **Intune** shows up in the list under **Admin centers**. If it doesn't, sign out and then sign back in and then check again.
|
||||
6. Select **Intune**. This step opens the Endpoint Manager admin center.
|
||||
|
||||
**Figure 12** - Microsoft Intune management portal
|
||||
|
||||
:::image type="content" alt-text="Microsoft Intune management portal." source="images/intune_portal_home.png":::
|
||||
|
||||
Intune should now be added to your tenant. We'll come back to Intune later when we [Configure Microsoft Store for Business for app distribution](#17-configure-microsoft-store-for-business-for-app-distribution).
|
||||
|
||||
### 1.4 Add Azure AD to your domain
|
||||
Microsoft Azure is an open and flexible cloud platform that enables you to quickly build, deploy, and manage apps across a global network of Microsoft-managed datacenters. In this walkthrough, we won't be using the full power of Azure and we'll primarily use it to create groups that we then use for provisioning through Intune.
|
||||
|
||||
**To add Azure AD to your domain**
|
||||
|
||||
1. In the [admin center](https://portal.office.com/adminportal/home#/homepage), select **Admin centers > Azure AD**.
|
||||
|
||||
> [!NOTE]
|
||||
> You will need Azure AD Premium to configure automatic MDM enrollment with Intune.
|
||||
|
||||
2. If you have not signed up for Azure AD before, you will see the following message. To proceed with the rest of the walkthrough, you need to activate an Azure subscription.
|
||||
|
||||
**Figure 13** - Access to Azure AD is not available
|
||||
|
||||
:::image type="content" alt-text="Access to Azure AD not available." source="images/azure_ad_access_not_available.png":::
|
||||
|
||||
3. From the error message, select the country/region for your business. The region should match with the location you specified when you signed up for Office 365.
|
||||
4. Select **Azure subscription**. This step will take you to a free trial sign up screen.
|
||||
|
||||
**Figure 14** - Sign up for Microsoft Azure
|
||||
|
||||
:::image type="content" alt-text="Sign up for Microsoft Azure." source="images/azure_ad_sign_up_screen.png":::
|
||||
|
||||
5. In the **Free trial sign up** screen, fill in the required information and then click **Sign up**.
|
||||
6. After you sign up, you should see the message that your subscription is ready. Click **Start managing my service**.
|
||||
|
||||
**Figure 15** - Start managing your Azure subscription
|
||||
|
||||
:::image type="content" alt-text="Start managing your Azure subscription." source="images/azure_ad_successful_signup.png":::
|
||||
|
||||
This step will take you to the [Microsoft Azure portal](https://portal.azure.com).
|
||||
|
||||
### 1.5 Add groups in Azure AD
|
||||
This section is the walkthrough is optional. However, we recommend that you create groups in Azure AD to manage access to corporate resources, such as apps, policies and settings, and so on. For more information, see [Managing access to resources with Azure Active Directory groups](/azure/active-directory/active-directory-manage-groups.
|
||||
|
||||
To add Azure AD group(s), use the [Microsoft Azure portal](https://portal.azure.com). See [Managing groups in Azure Active Directory](/azure/active-directory/active-directory-accessmanagement-manage-groups) for more information about managing groups.
|
||||
|
||||
**To add groups in Azure AD**
|
||||
|
||||
1. If this is the first time you're setting up your directory, when you navigate to the **Azure Active Directory** node, you will see a screen informing you that your directory is ready for use.
|
||||
|
||||
Afterwards, you should see a list of active directories. In the following example, **Fabrikam Design** is the active directory.
|
||||
|
||||
**Figure 16** - Azure first sign-in screen
|
||||
|
||||
:::image type="content" alt-text="Select Azure AD." source="images/azure_portal_classic_configure_directory.png":::
|
||||
|
||||
2. Select the directory (such as Fabrikam Design) to go to the directory's home page.
|
||||
|
||||
**Figure 17** - Directory home page
|
||||
|
||||
:::image type="content" alt-text="Directory home page." source="images/azure_portal_classic_directory_ready.png":::
|
||||
|
||||
3. From the menu options on top, select **Groups**.
|
||||
|
||||
**Figure 18** - Azure AD groups
|
||||
|
||||
:::image type="content" alt-text="Add groups in Azure AD." source="images/azure_portal_classic_groups.png":::
|
||||
|
||||
4. Select **Add a group** (from the top) or **Add group** at the bottom.
|
||||
5. In the **Add Group** window, add a name, group type, and description for the group and click the checkmark to save your changes. The new group will appear on the groups list.
|
||||
|
||||
**Figure 19** - Newly added group in Azure AD
|
||||
|
||||
:::image type="content" alt-text="Verify the new group appears on the list." source="images/azure_portal_classic_all_users_group.png":::
|
||||
|
||||
6. In the **Groups** tab, select the arrow next to the group (such as **All users**), add members to the group, and then save your changes.
|
||||
|
||||
The members that were added to the group will appear on the list.
|
||||
|
||||
**Figure 20** - Members in the new group
|
||||
|
||||
:::image type="content" alt-text="Members added to the new group." source="images/azure_portal_classic_members_added.png":::
|
||||
|
||||
7. Repeat steps 2-6 to add other groups. You can add groups based on their roles in your company, based on the apps that each group can use, and so on.
|
||||
|
||||
### 1.6 Configure automatic MDM enrollment with Intune
|
||||
Now that you have Azure AD Premium and have it properly configured, you can configure automatic MDM enrollment with Intune, which allows users to enroll their Windows devices into Intune management, join their devices directly to Azure AD, and get access to Office 365 resources after sign in.
|
||||
|
||||
You can read the [Windows 10, Azure AD and Microsoft Intune blog post](https://blogs.technet.microsoft.com/enterprisemobility/2015/08/14/windows-10-azure-ad-and-microsoft-intune-automatic-mdm-enrollment-powered-by-the-cloud/) to learn how you can combine login, Azure AD Join, and Intune MDM enrollment into an easy step so that you can bring your devices into a managed state that complies with the policies for your organization. We will use this blog post as our guide for this part of the walkthrough.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> We will use the classic Azure portal instead of the new portal to configure automatic MDM enrollment with Intune.
|
||||
|
||||
**To enable automatic MDM enrollment**
|
||||
|
||||
1. In the Azure portal, click on your company's Azure Active Directory to go back to the main window. Select **Applications** from the list of directory menu options.
|
||||
|
||||
The list of applications for your company will appear. **Microsoft Intune** will be one of the applications on the list.
|
||||
|
||||
**Figure 21** - List of applications for your company
|
||||
|
||||
:::image type="content" alt-text="List of applications for your company." source="images/azure_portal_classic_applications.png":::
|
||||
|
||||
2. Select **Microsoft Intune** to configure the application.
|
||||
3. In the Microsoft Intune configuration page, click **Configure** to start automatic MDM enrollment configuration with Intune.
|
||||
|
||||
**Figure 22** - Configure Microsoft Intune in Azure
|
||||
|
||||
:::image type="content" alt-text="Configure Microsoft Intune in Azure." source="images/azure_portal_classic_configure_intune_app.png":::
|
||||
|
||||
4. In the Microsoft Intune configuration page:
|
||||
- In the **Properties** section, you should see a list of URLs for MDM discovery, MDM terms of use, and MDM compliance.
|
||||
|
||||
> [!NOTE]
|
||||
> The URLs are automatically configured for your Azure AD tenant so you don't need to change them.
|
||||
|
||||
- In the **Manage devices for these users** section, you can specify which users' devices should be managed by Intune.
|
||||
- **All** will enable all users' Windows 10 devices to be managed by Intune.
|
||||
- **Groups** let you select whether only users that belong to a specific group will have their devices managed by Intune.
|
||||
|
||||
> [!NOTE]
|
||||
> In this step, choose the group that contains all the users in your organization as members. This is the **All** group.
|
||||
|
||||
5. After you've chosen how to manage devices for users, select **Save** to enable automatic MDM enrollment with Intune.
|
||||
|
||||
**Figure 23** - Configure Microsoft Intune
|
||||
|
||||
:::image type="content" alt-text="Configure automatic MDM enrollment with Intune." source="images/azure_portal_classic_configure_intune_mdm_enrollment.png":::
|
||||
|
||||
### 1.7 Configure Microsoft Store for Business for app distribution
|
||||
Next, you'll need to configure Microsoft Store for Business to distribute apps with a management tool such as Intune.
|
||||
|
||||
In this part of the walkthrough, use the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) and [Microsoft Store for Business](https://businessstore.microsoft.com/Store/Apps).
|
||||
|
||||
**To associate your Store account with Intune and configure synchronization**
|
||||
|
||||
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
|
||||
2. In the **Administration** workspace, click **Mobile Device Management**. If this is the first item you're using the portal, click **manage mobile devices** in the **Mobile Device Management** window. The page will refresh and you'll have new options under **Mobile Device Management**.
|
||||
|
||||
**Figure 24** - Mobile device management
|
||||
|
||||
:::image type="content" alt-text="Set up mobile device management in Intune." source="images/intune_admin_mdm_configure.png":::
|
||||
|
||||
3. Sign into [Microsoft Store for Business](https://businessstore.microsoft.com/Store/Apps) using the same tenant account that you used to sign into Intune.
|
||||
4. Accept the EULA.
|
||||
5. In the Store portal, select **Settings > Management tools** to go to the management tools page.
|
||||
6. In the **Management tools** page, find **Microsoft Intune** on the list and click **Activate** to get Intune ready to use with Microsoft Store for Business.
|
||||
|
||||
**Figure 25** - Activate Intune as the Store management tool
|
||||
|
||||
:::image type="content" alt-text="Activate Intune from the Store portal." source="images/wsfb_management_tools_activate.png":::
|
||||
|
||||
7. Go back to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Admin > Mobile Device Management**, expand **Windows**, and then choose **Store for Business**.
|
||||
8. In the **Microsoft Store for Business** page, select **Configure Sync** to sync your Store for Business volume-purchased apps with Intune.
|
||||
|
||||
**Figure 26** - Configure Store for Business sync in Intune
|
||||
|
||||
:::image type="content" alt-text="Configure Store for Business sync in Intune." source="images/intune_admin_mdm_store_sync.png":::
|
||||
|
||||
9. In the **Configure Microsoft Store for Business app sync** dialog box, check **Enable Microsoft Store for Business sync**. In the **Language** dropdown list, choose the language in which you want apps from the Store to be displayed in the Intune console and then click **OK**.
|
||||
|
||||
**Figure 27** - Enable Microsoft Store for Business sync in Intune
|
||||
|
||||
:::image type="content" alt-text="Enable Store for Business sync in Intune." source="images/intune_configure_store_app_sync_dialog.png":::
|
||||
|
||||
The **Microsoft Store for Business** page will refresh and it will show the details from the sync.
|
||||
|
||||
**To buy apps from the Store**
|
||||
|
||||
In your [Microsoft Store for Business portal](https://businessstore.microsoft.com/Store/Apps), you can see the list of apps that you own by going to **Manage > Inventory**. You should see the following apps in your inventory:
|
||||
- Sway
|
||||
- OneNote
|
||||
- PowerPoint Mobile
|
||||
- Excel Mobile
|
||||
- Word Mobile
|
||||
|
||||
In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Apps > Apps > Volume-Purchased Apps** and verify that you can see the same list of apps appear on Intune.
|
||||
|
||||
In the following example, we'll show you how to buy apps through the Microsoft Store for Business and then make sure the apps appear on Intune.
|
||||
|
||||
**Example 1 - Add other apps like Reader and InstaNote**
|
||||
|
||||
1. In the [Microsoft Store for Business portal](https://businessstore.microsoft.com/Store/Apps), click **Shop**, scroll down to the **Made by Microsoft** category, and click **Show all** to see all the Microsoft apps in the list.
|
||||
|
||||
**Figure 28** - Shop for Store apps
|
||||
|
||||
:::image type="content" alt-text="Shop for Store apps." source="images/wsfb_shop_microsoft_apps.png":::
|
||||
|
||||
2. Click to select an app, such as **Reader**. This opens the app page.
|
||||
3. In the app's Store page, click **Get the app**. You should see a dialog that confirms your order. Click **Close**. This will refresh the app's Store page.
|
||||
4. In the app's Store page, click **Add to private store**.
|
||||
5. Next, search for another app by name (such as **InstaNote**) or repeat steps 1-4 for the **InstaNote** app.
|
||||
6. Go to **Manage > Inventory** and verify that the apps you purchased appear in your inventory.
|
||||
|
||||
**Figure 29** - App inventory shows the purchased apps
|
||||
|
||||
:::image type="content" alt-text="Confirm that your inventory shows purchased apps." source="images/wsfb_manage_inventory_newapps.png":::
|
||||
|
||||
> [!NOTE]
|
||||
> Sync happens automatically, but it may take up to 24 hours for your organization's private store and 12 hours for Intune to sync all your purchased apps. You can force a sync to make this process happen faster. For more info, see [To sync recently purchased apps](#forceappsync).
|
||||
|
||||
**<a name="forceappsync"></a>To sync recently purchased apps**
|
||||
|
||||
If you need to sync your most recently purchased apps and have it appear in your catalog, you can do this by forcing a sync.
|
||||
|
||||
1. In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Admin > Mobile Device Management > Windows > Store for Business**.
|
||||
2. In the **Microsoft Store for Business** page, click **Sync now** to force a sync.
|
||||
|
||||
**Figure 30** - Force a sync in Intune
|
||||
|
||||
:::image type="content" alt-text="Force a sync in Intune." source="images/intune_admin_mdm_forcesync.png":::
|
||||
|
||||
**To view purchased apps**
|
||||
- In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Apps > Apps** and then choose **Volume-Purchased Apps** to see the list of available apps. Verify that the apps you purchased were imported correctly.
|
||||
|
||||
**To add more apps**
|
||||
- If you have other apps that you want to deploy or manage, you must add it to Microsoft Intune. To deploy Win32 apps and Web links, see [Add apps to Microsoft Intune](/mem/intune/apps/apps-add) for more info on how to do this.
|
||||
|
||||
## 2. Set up devices
|
||||
|
||||
### 2.1 Set up new devices
|
||||
To set up new Windows devices, go through the Windows initial device setup or first-run experience to configure your device.
|
||||
|
||||
**<a name="usewindowsoobe"></a>To set up a device**
|
||||
1. Go through the Windows device setup experience. On a new or reset device, this starts with the **Hi there** screen on devices running Windows 10, version 1607 (Anniversary Update). The setup lets you:
|
||||
- Fill in the details in the **Hi there** screen including your home country/region, preferred language, keyboard layout, and timezone
|
||||
- Accept the EULA
|
||||
- Customize the setup or use Express settings
|
||||
|
||||
**Figure 31** - First screen in Windows device setup
|
||||
|
||||
:::image type="content" alt-text="First screen in Windows device setup." source="images/win10_hithere.png":::
|
||||
|
||||
> [!NOTE]
|
||||
> During setup, if you don't have a Wi-Fi network configured, make sure you connect the device to the Internet through a wired/Ethernet connection.
|
||||
|
||||
2. In the **Who owns this PC?** screen, select **My work or school owns it** and click **Next**.
|
||||
3. In the **Choose how you'll connect** screen, select **Join Azure Active Directory** and click **Next**.
|
||||
|
||||
**Figure 32** - Choose how you'll connect your Windows device
|
||||
|
||||
:::image type="content" alt-text="Choose how you'll connect the Windows device." source="images/win10_choosehowtoconnect.png":::
|
||||
|
||||
4. In the **Let's get you signed in** screen, sign in using a user account you added in section [1.2 Add users and assign product licenses](#12-add-users-and-assign-product-licenses). We suggest signing in as one of the global administrators. Later, sign in on another device using one of the non-admin accounts.
|
||||
|
||||
**Figure 33** - Sign in using one of the accounts you added
|
||||
|
||||
:::image type="content" alt-text="Sign in using one of the accounts you added." source="images/win10_signin_admin_account.png":::
|
||||
|
||||
5. If this is the first time you're signing in, you will be asked to update your password. Update the password and continue with sign-in and setup.
|
||||
|
||||
Windows will continue with setup and you may be asked to set up a PIN for Windows Hello if your organization has it enabled.
|
||||
|
||||
### 2.2 Verify correct device setup
|
||||
Verify that the device is set up correctly and boots without any issues.
|
||||
|
||||
**To verify that the device was set up correctly**
|
||||
1. Click on the **Start** menu and select some of the options to make sure everything opens properly.
|
||||
2. Confirm that the Store and built-in apps are working.
|
||||
|
||||
### 2.3 Verify the device is Azure AD joined
|
||||
In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), verify that the device is joined to Azure AD and shows up as being managed in Microsoft Intune.
|
||||
|
||||
**To verify if the device is joined to Azure AD**
|
||||
1. Check the device name on your PC. On your Windows PC, select **Settings > System > About** and then check **PC name**.
|
||||
|
||||
**Figure 34** - Check the PC name on your device
|
||||
|
||||
:::image type="content" alt-text="Check the PC name on your device." source="images/win10_settings_pcname.png":::
|
||||
|
||||
2. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
|
||||
3. Select **Groups** and then go to **Devices**.
|
||||
4. In the **All Devices** page, look at the list of devices and select the entry that matches the name of your PC.
|
||||
- Check that the device name appears in the list. Select the device and it will also show the current logged-in user in the **General Information** section.
|
||||
- Check the **Management Channel** column and confirm that it says **Managed by Microsoft Intune**.
|
||||
- Check the **AAD Registered** column and confirm that it says **Yes**.
|
||||
|
||||
**Figure 35** - Check that the device appears in Intune
|
||||
|
||||
:::image type="content" alt-text="Check that the device appears in Intune." source="images/intune_groups_devices_list.png":::
|
||||
|
||||
## 3. Manage device settings and features
|
||||
You can use Microsoft Intune admin settings and policies to manage features on your organization's mobile devices and computers. For more info, see [Manage settings and features on your devices with Microsoft Intune policies](/mem/intune/configuration/device-profiles).
|
||||
|
||||
In this section, we'll show you how to reconfigure app deployment settings and add a new policy that will disable the camera for the Intune-managed devices and turn off Windows Hello and PINs during setup.
|
||||
|
||||
### 3.1 Reconfigure app deployment settings
|
||||
In some cases, if an app is missing from the device, you need to reconfigure the deployment settings for the app and set the app to require installation as soon as possible.
|
||||
|
||||
**To reconfigure app deployment settings**
|
||||
1. In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Apps** and go to **Apps > Volume-Purchased Apps**.
|
||||
2. Select the app, right-click, then select **Manage Deployment...**.
|
||||
3. Select the group(s) whose apps will be managed, and then click **Add** to add the group.
|
||||
4. Click **Next** at the bottom of the app deployment settings window or select **Deployment Action** on the left column to check the deployment settings for the app.
|
||||
5. For each group that you selected, set **Approval** to **Required Install**. This step automatically sets **Deadline** to **As soon as possible**. If **Deadline** is not automatically set, set it to **As soon as possible**.
|
||||
|
||||
**Figure 36** - Reconfigure an app's deployment setting in Intune
|
||||
|
||||
:::image type="content" alt-text="Reconfigure app deployment settings in Intune." source="images/intune_apps_deploymentaction.png":::
|
||||
|
||||
6. Click **Finish**.
|
||||
7. Repeat steps 2-6 for other apps that you want to deploy to the device(s) as soon as possible.
|
||||
8. Verify that the app shows up on the device using the following steps:
|
||||
- Make sure you're logged in to the Windows device.
|
||||
- Click the **Start** button and check the apps that appear in the **Recently added** section. If you don't see the apps that you deployed in Intune, give it a few minutes. Only apps that aren't already deployed on the device will appear in the **Recently added** section.
|
||||
|
||||
**Figure 37** - Confirm that additional apps were deployed to the device
|
||||
|
||||
:::image type="content" alt-text="Confirm that additional apps were deployed to the device." source="images/win10_deploy_apps_immediately.png":::
|
||||
|
||||
### 3.2 Configure other settings in Intune
|
||||
|
||||
**To disable the camera**
|
||||
1. In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Devices > Configuration Policies**.
|
||||
2. In the **Policies** window, click **Add** to create a new policy.
|
||||
3. On the **Create a New Policy** page, click **Windows** to expand the group, select **General Configuration (Windows 10 Desktop and Mobile and later)**, choose **Create and Deploy a Custom Policy**, and then click **Create Policy**.
|
||||
4. On the **Create Policy** page, select **Device Capabilities**.
|
||||
5. In the **General** section, add a name and description for this policy. For example:
|
||||
- **Name**: Test Policy - Disable Camera
|
||||
- **Description**: Disables the camera
|
||||
6. Scroll down to the **Hardware** section, find **Allow camera is not configured**, toggle the button so that it changes to **Allow camera** and choose **No** from the dropdown list.
|
||||
|
||||
**Figure 38** - Add a configuration policy
|
||||
|
||||
:::image type="content" alt-text="Add a configuration policy." source="images/intune_policy_disablecamera.png":::
|
||||
|
||||
7. Click **Save Policy**. A confirmation window will pop up.
|
||||
8. On the **Deploy Policy** confirmation window, select **Yes** to deploy the policy now.
|
||||
9. On the **Management Deployment** window, select the user group(s) or device group(s) that you want to apply the policy to (for example, **All Users**), and then click **Add**.
|
||||
10. Click **OK** to close the window.
|
||||
|
||||
**Figure 39** - The new policy should appear in the **Policies** list.
|
||||
|
||||
:::image type="content" alt-text="New policy appears on the list." source="images/intune_policies_newpolicy_deployed.png":::
|
||||
|
||||
**To turn off Windows Hello and PINs during device setup**
|
||||
1. Go to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
|
||||
2. Go to **Mobile Device Management > Windows > Windows Hello for Business**.
|
||||
3. In the **Windows Hello for Business** page, select **Disable Windows Hello for Business on enrolled devices**.
|
||||
|
||||
**Figure 40** - Policy to disable Windows Hello for Business
|
||||
|
||||
:::image type="content" alt-text="Disable Windows Hello for Business." source="images/intune_policy_disable_windowshello.png":::
|
||||
|
||||
4. Click **Save**.
|
||||
|
||||
> [!NOTE]
|
||||
> This policy is a tenant-wide Intune setting. It disables Windows Hello and required PINs during setup for all enrolled devices in a tenant.
|
||||
|
||||
To test whether these policies get successfully deployed to your tenant, go through [4. Add more devices and users](#4-add-more-devices-and-users) and setup another Windows device and login as one of the users.
|
||||
|
||||
## 4. Add more devices and users
|
||||
After your cloud infrastructure is set up and you have a device management strategy in place, you may need to add more devices or users and you want the same policies to apply to these new devices and users. In this section, we'll show you how to do this.
|
||||
|
||||
### 4.1 Connect other devices to your cloud infrastructure
|
||||
Adding a new device to your cloud-based tenant is easy. For new devices, you can follow the steps in [2. Set up devices](#2-set-up-devices).
|
||||
|
||||
For other devices, such as those personally-owned by employees who need to connect to the corporate network to access corporate resources (BYOD), you can follow the steps in this section to get these devices connected.
|
||||
|
||||
> [!NOTE]
|
||||
> These steps enable users to get access to the organization's resources, but it also gives the organization some control over the device.
|
||||
|
||||
**To connect a personal device to your work or school**
|
||||
1. On your Windows device, go to **Settings > Accounts**.
|
||||
2. Select **Access work or school** and then click **Connect** in the **Connect to work or school** page.
|
||||
3. In the **Set up a work or school account** window, click **Join this device to Azure Active Directory** to add an Azure AD account to the device.
|
||||
|
||||
**Figure 41** - Add an Azure AD account to the device
|
||||
|
||||
:::image type="content" alt-text="Add an Azure AD account to the device." source="images/win10_add_new_user_join_aad.png":::
|
||||
|
||||
4. In the **Let's get you signed in** window, enter the work credentials for the account and then click **Sign in** to authenticate the user.
|
||||
|
||||
**Figure 42** - Enter the account details
|
||||
|
||||
:::image type="content" alt-text="Enter the account details." source="images/win10_add_new_user_account_aadwork.png":::
|
||||
|
||||
5. You will be asked to update the password so enter a new password.
|
||||
6. Verify the details to make sure you're connecting to the right organization and then click **Join**.
|
||||
|
||||
**Figure 43** - Make sure this is your organization
|
||||
|
||||
:::image type="content" alt-text="Make sure this is your organization." source="images/win10_confirm_organization_details.png":::
|
||||
|
||||
7. You will see a confirmation window that says the device is now connected to your organization. Click **Done**.
|
||||
|
||||
**Figure 44** - Confirmation that the device is now connected
|
||||
|
||||
:::image type="content" alt-text="Confirmation that the device is now connected." source="images/win10_confirm_device_connected_to_org.png":::
|
||||
|
||||
8. The **Connect to work or school** window will refresh and will now include an entry that shows you're connected to your organization's Azure AD. This means the device is now registered in Azure AD and enrolled in MDM and the account should have access to the organization's resources.
|
||||
|
||||
**Figure 45** - Device is now enrolled in Azure AD
|
||||
|
||||
:::image type="content" alt-text="Device is enrolled in Azure AD." source="images/win10_device_enrolled_in_aad.png":::
|
||||
|
||||
9. You can confirm that the new device and user are showing up as Intune-managed by going to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) and following the steps in [2.3 Verify the device is Azure AD joined](#23-verify-the-device-is-azure-ad-joined). It may take several minutes before the new device shows up so check again later.
|
||||
|
||||
### 4.2 Add a new user
|
||||
You can add new users to your tenant simply by adding them to the Microsoft 365 groups. Adding new users to Microsoft 365 groups automatically adds them to the corresponding groups in Microsoft Intune.
|
||||
|
||||
See [Add users to Office 365](/microsoft-365/admin/add-users/add-users) to learn more. Once you're done adding new users, go to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) and verify that the same users were added to the Intune groups as well.
|
||||
|
||||
## Get more info
|
||||
|
||||
### For IT admins
|
||||
To learn more about the services and tools mentioned in this walkthrough, and learn what other tasks you can do, follow these links:
|
||||
- [Set up Office 365 for business](/microsoft-365/admin/setup)
|
||||
- Common admin tasks in Office 365 including email and OneDrive in [Manage Office 365](/microsoft-365/admin/)
|
||||
- More info about managing devices, apps, data, troubleshooting, and more in the [Intune documentation](/mem/intune/)
|
||||
- Learn more about Windows client in the [Windows client documentation for IT Pros](/windows/resources/).
|
||||
- Info about distributing apps to your employees, managing apps, managing settings, and more in [Microsoft Store for Business](/microsoft-store/)
|
||||
|
||||
### For information workers
|
||||
Whether it's in the classroom, getting the most out of your devices, or learning some of the cool things you can do, we've got teachers covered. Follow these links for more info:
|
||||
|
||||
- [Office Help & Training](https://support.microsoft.com/office)
|
||||
- [Windows help & learning](https://support.microsoft.com/windows)
|
||||
|
||||
## Related topics
|
||||
|
||||
- [Windows for business](https://www.microsoft.com/windows/business)
|
||||
- [Microsoft 365 for business](https://www.microsoft.com/microsoft-365/business)
|
@ -48,6 +48,9 @@
|
||||
"Kellylorenebaker",
|
||||
"jborsecnik",
|
||||
"tiburd",
|
||||
"AngelaMotherofDragons",
|
||||
"dstrome",
|
||||
"v-dihans",
|
||||
"garycentric"
|
||||
],
|
||||
"titleSuffix": "Windows for Small to Midsize Business"
|
||||
|
Before Width: | Height: | Size: 22 KiB |
Before Width: | Height: | Size: 45 KiB |
Before Width: | Height: | Size: 74 KiB |
Before Width: | Height: | Size: 76 KiB |
Before Width: | Height: | Size: 76 KiB |
Before Width: | Height: | Size: 46 KiB |
Before Width: | Height: | Size: 7.7 KiB |
Before Width: | Height: | Size: 26 KiB |
Before Width: | Height: | Size: 66 KiB |
Before Width: | Height: | Size: 46 KiB |
Before Width: | Height: | Size: 50 KiB |
Before Width: | Height: | Size: 51 KiB |
Before Width: | Height: | Size: 60 KiB |
Before Width: | Height: | Size: 74 KiB |
Before Width: | Height: | Size: 41 KiB |
Before Width: | Height: | Size: 30 KiB |
Before Width: | Height: | Size: 70 KiB |
Before Width: | Height: | Size: 70 KiB |
Before Width: | Height: | Size: 24 KiB |
Before Width: | Height: | Size: 31 KiB |
Before Width: | Height: | Size: 921 B |
Before Width: | Height: | Size: 2.1 KiB |
Before Width: | Height: | Size: 41 KiB |
Before Width: | Height: | Size: 44 KiB |
Before Width: | Height: | Size: 60 KiB |
Before Width: | Height: | Size: 37 KiB |
Before Width: | Height: | Size: 58 KiB |
Before Width: | Height: | Size: 18 KiB |
Before Width: | Height: | Size: 85 KiB |
Before Width: | Height: | Size: 61 KiB |
Before Width: | Height: | Size: 81 KiB |
Before Width: | Height: | Size: 130 KiB |
Before Width: | Height: | Size: 65 KiB |
Before Width: | Height: | Size: 388 B |
Before Width: | Height: | Size: 425 B |
Before Width: | Height: | Size: 53 KiB |
Before Width: | Height: | Size: 19 KiB |
Before Width: | Height: | Size: 22 KiB |
Before Width: | Height: | Size: 84 KiB |
Before Width: | Height: | Size: 13 KiB |
Before Width: | Height: | Size: 97 KiB |
Before Width: | Height: | Size: 23 KiB |
Before Width: | Height: | Size: 1.4 MiB |
Before Width: | Height: | Size: 71 KiB |
Before Width: | Height: | Size: 15 KiB |
Before Width: | Height: | Size: 15 KiB |
Before Width: | Height: | Size: 54 KiB |
Before Width: | Height: | Size: 47 KiB |
Before Width: | Height: | Size: 52 KiB |
Before Width: | Height: | Size: 102 KiB |
Before Width: | Height: | Size: 52 KiB |
Before Width: | Height: | Size: 21 KiB |
Before Width: | Height: | Size: 16 KiB |
Before Width: | Height: | Size: 40 KiB |
Before Width: | Height: | Size: 48 KiB |
Before Width: | Height: | Size: 105 KiB |
Before Width: | Height: | Size: 262 KiB |
Before Width: | Height: | Size: 262 KiB |
Before Width: | Height: | Size: 42 KiB |
Before Width: | Height: | Size: 38 KiB |
Before Width: | Height: | Size: 142 KiB |
Before Width: | Height: | Size: 152 KiB |
Before Width: | Height: | Size: 63 KiB |
Before Width: | Height: | Size: 86 KiB |
Before Width: | Height: | Size: 139 KiB |
Before Width: | Height: | Size: 129 KiB |
Before Width: | Height: | Size: 148 KiB |
Before Width: | Height: | Size: 208 KiB |
Before Width: | Height: | Size: 148 KiB |
Before Width: | Height: | Size: 294 KiB |
Before Width: | Height: | Size: 34 KiB |
Before Width: | Height: | Size: 114 KiB |
Before Width: | Height: | Size: 44 KiB |