Merge remote-tracking branch 'refs/remotes/origin/master' into atp-securityanalytics

This commit is contained in:
Joey Caparas 2017-06-30 15:21:35 -07:00
commit ffbe992370
16 changed files with 21975 additions and 6203 deletions

View File

@ -11,6 +11,11 @@
"redirect_document_id": true
},
{
"source_path": "windows/client-management/mdm/policy-admx-backed.md",
"redirect_url": "/windows/client-management/mdm/policy-configuration-service-provider",
"redirect_document_id": true
},
{
"source_path": "windows/keep-secure/add-apps-to-protected-list-using-custom-uri.md",
"redirect_url": "/windows/threat-protection/windows-information-protection/create-wip-policy-using-intune",
"redirect_document_id": false

View File

@ -63,9 +63,9 @@ The OMA URI for each setting consists of `./User/Vendor/MSFT/EnterpriseModernApp
| Setting | Details | OMA URI | Supported with<br>Intune? | Supported with<br>Configuration Manager? | Supported with<br>SyncML*? |
| --- | ---- | --- |---- | --- | --- |
| Enable sign-in | Users can sign in and authenticate | EnableSignIn | Yes <br> [Use a custom policy.](#example-intune) | Yes.<br> [Use a custom setting.](#example-sccm) | Yes |
| Disable sign-in | Users are unable to sign in and access collaboration or education features | DisableSignIn | Yes <br> [Use a custom policy.](#example-intune) | Yes.<br> [Use a custom setting.](#example-sccm) | Yes |
| Disable Collaboration | Users can sign in but not create or join collaborative sessions | DisableCollaboration | Yes <br> [Use a custom policy.](#example-intune) | Yes.<br> [Use a custom setting.](#example-sccm) | Yes |
| Enable sign-in | Users can sign in and authenticate | EnableSignIn | Yes <br> [Use a custom policy.](manage-settings-with-mdm-for-surface-hub.md#example-intune) | Yes.<br> [Use a custom setting.](manage-settings-with-mdm-for-surface-hub.md#example-sccm) | Yes |
| Disable sign-in | Users are unable to sign in and access collaboration or education features | DisableSignIn | Yes <br> [Use a custom policy.](manage-settings-with-mdm-for-surface-hub.md#example-intune) | Yes.<br> [Use a custom setting.](manage-settings-with-mdm-for-surface-hub.md#example-sccm) | Yes |
| Disable Collaboration | Users can sign in but not create or join collaborative sessions | DisableCollaboration | Yes <br> [Use a custom policy.](manage-settings-with-mdm-for-surface-hub.md#example-intune) | Yes.<br> [Use a custom setting.](manage-settings-with-mdm-for-surface-hub.md#example-sccm) | Yes |
\*Settings supported with SyncML can also be configured in a Windows Configuration Designer provisioning package.
Whiteboard also has other MDM settings that can be managed and set for defaults, exporting, and sharing. You can see these additional settings in [Manage settings with an MDM provider (Surface Hub)](manage-settings-with-mdm-for-surface-hub.md#whiteboard-collaboration-settings).

View File

@ -0,0 +1,72 @@
---
title: Get Minecraft Education Edition with your Windows 10 device promotion
description: Windows 10 device promotion for Minecraft Education Edition licenses
keywords: school, Minecraft, education edition
ms.prod: W10
ms.mktglfcycl: plan
ms.sitesec: library
localizationpriority: high
author: trudyha
ms.author: trudyha
ms.date: 06/29/2017
---
# Get Minecraft: Education Edition with Windows 10 device promotion
**Applies to:**
- Windows 10
For qualifying customers, receive a one-year, single-user subscription for Minecraft: Education Edition for each Windows 10 device you purchase for your K-12 school. Youll need your invoice or receipt, so be sure to keep track of that. For more information including terms of use, see [Minecraft: Education Edition promotion](https://info.microsoft.com/Minecraft-Education-Edition-Signup.html).
## Requirements
- Qualified Educational Users in K-12 education institutions
- Windows 10 devices purchased from May 2, 2017 - January 31, 2018
- Redeem Minecraft: Education Edition licenses from July 1, 2017 - March 17, 2018
- Microsoft Store for Education admin must submit request for Minecraft: Education Edition licenses
- Proof of device purchase is required (invoice required)
Full details available at [Minecraft: Education Edition promotion](https://info.microsoft.com/Minecraft-Education-Edition-Signup.html).
## Redeem Minecraft: Education Edition licenses
Redeeming your licenses takes just a few steps:
- Visit the device promotion page
- Submit a device purchase statement
- Provide proof of your device purchase
After that, well add the appropriate number of Minecraft: Education Edition licenses to your product inventory in **Microsoft Store for Education** as **Minecraft: Education Edition [subscription]**.
**To redeem Minecraft: Education Edition licenses**
1. Visit [Minecraft: Education Edition and Windows 10 device promotion](https://educationstore.microsoft.com/store/mee-device-promo?setflight=wsfb_devicepromo) in **Microsoft Store for Education**.
![Minecraft: Education Edition page in Microsoft Store for Education. ](images/get-mcee-promo.png)
2. Sign in to **Microsoft Store for Education** using a school account. If you dont have one, well help you set one up. <br>
-or-
If you're already signed in to Microsoft Store for Education, the device special offer is available on **Benefits**. </br>
Click **Manage**, **Benefits**, and then click **Minecraft: Education Edition Device Promotion**.
3. **On Minecraft Windows 10 device special offer**, click **Submit a device purchase**.
![Windows 10 device special offer page for Minecraft: Education Edition. Submit a device purchase is highlighted to show customers how to submit info about the devices you purchased. ](images/mcee-benefits.png)
4. Provide info for **Proof of Purchase**. Be sure to include a .pdf or .jpg of your invoice, and then click **Next**.
> [!NOTE]
> Your one-year subscription starts when you submit your proof-of-purchase info. Be sure to submit your request when you'll be using licenses in the classroom.
![Proof of purchase page with Invoice area highlighted.](images/proof-of-purchase.png)
5. Accept the **Promotion Terms of use**, and then click **Submit**. </br>
Success look like this!
![Proof of purchase page with Invoice area highlighted.](images/msfe-device-promo-success.png)
6. Click **Actions** and then click **Manage** to go to the management page for **Minecraft: Education Edition** and distribute licenses.
## Distribute Minecraft: Education Edition licenses
Teachers or admins can distribute the licenses:
- [Learn how teachers can distribute **Minecraft: Education Edition**](teacher-get-minecraft.md#distribute-minecraft)
- [Learn how IT administrators can distribute **Minecraft: Education Edition**](school-get-minecraft.md#distribute-minecraft)

Binary file not shown.

After

Width:  |  Height:  |  Size: 240 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 60 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 36 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 16 KiB

View File

@ -2305,6 +2305,37 @@ Footnotes:
<!--EndCSP-->
<!--StartCSP-->
<!--StartCSP-->
[WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)
<!--StartSKU-->
<table>
<tr>
<th>Home</th>
<th>Pro</th>
<th>Business</th>
<th>Enterprise</th>
<th>Education</th>
<th>Mobile</th>
<th>Mobile Enterprise</th>
</tr>
<tr>
<td><img src="images/crossmark.png" alt="cross mark" /></td>
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
<td><img src="images/crossmark.png" alt="cross mark" /></td>
<td><img src="images/crossmark.png" alt="cross mark" /></td>
</tr>
</table>
<!--EndSKU-->
<!--EndCSP-->
<!--StartCSP-->
[WindowsLicensing CSP](windowslicensing-csp.md)
<!--StartSKU-->

File diff suppressed because it is too large Load Diff

View File

@ -1215,7 +1215,7 @@ Servers
<Target>
<LocURI>./Vendor/MSFT/VPNv2/VPNProfileName/NativeProfile/Authentication/CryptographySuite/EncryptionMethod</LocURI>
</Target>
<Data>PFS2048</Data>
<Data>AES128</Data>
</Item>
</Add>
<Add>
@ -1224,7 +1224,7 @@ Servers
<Target>
<LocURI>./Vendor/MSFT/VPNv2/VPNProfileName/NativeProfile/Authentication/CryptographySuite/IntegrityCheckMethod</LocURI>
</Target>
<Data>Eap</Data>
<Data>SHA256</Data>
</Item>
</Add>
<Add>
@ -1233,7 +1233,7 @@ Servers
<Target>
<LocURI>./Vendor/MSFT/VPNv2/VPNProfileName/NativeProfile/Authentication/CryptographySuite/DHGroup</LocURI>
</Target>
<Data>SHA256</Data>
<Data>Group2</Data>
</Item>
</Add>
<Add>
@ -1242,7 +1242,7 @@ Servers
<Target>
<LocURI>./Vendor/MSFT/VPNv2/VPNProfileName/NativeProfile/Authentication/CryptographySuite/PfsGroup</LocURI>
</Target>
<Data>AES128</Data>
<Data>PFS2048</Data>
</Item>
</Add>

View File

@ -18,6 +18,7 @@ This topic lists new and updated topics in the [Configure Windows 10](index.md)
| New or changed topic | Description |
| --- | --- |
| [Guidelines for choosing an app for assigned access](guidelines-for-assigned-access-app.md) | Added guidelines for using Remote Desktop app as the kiosk app and added a general guideline that apps generated using the Desktop App Converter cannot be used for kiosk apps |
| [Set up a kiosk on Windows 10 Pro, Enterprise, or Education](set-up-a-kiosk-for-windows-10-for-desktop-editions.md) | Added warning about using Shell Launcher to set a custom shell with an application that launches a different process and then exits |
| [Windows Configuration Designer command-line interface (reference)](provisioning-packages/provisioning-command-line.md) | Removed references to imaging |

View File

@ -7,6 +7,8 @@ ms.mktglfcycl: manage
ms.sitesec: library
author: jdeckerms
localizationpriority: high
ms.author: jdecker
ms.date: 06/29/2017
---
# Guidelines for choosing an app for assigned access (kiosk mode)
@ -27,6 +29,14 @@ The following guidelines may help you choose an appropriate Windows app for your
- Updating a Windows app can sometimes change the Application User Model ID (AUMID) of the app. If this happens, you must update the assigned access settings to launch the updated app, because assigned access uses the AUMID to determine which app to launch.
- Apps that are generated using the [Desktop App Converter (Desktop Bridge)](https://docs.microsoft.com/windows/uwp/porting/desktop-to-uwp-run-desktop-app-converter) cannot be used as kiosk apps.
## Guidelines for using Remote Desktop app
Kiosk apps open in full screen. When you assign [Remote Desktop](https://www.microsoft.com/store/apps/9wzdncrfj3ps) as the kiosk app, make sure the **Start connections in full screen** setting in the Remote Desktop app is set to **Off**.
![Toggle Start connections in full screen to off](images/rdc.png)
## Guidelines for Windows apps that launch other apps

Binary file not shown.

After

Width:  |  Height:  |  Size: 15 KiB

View File

@ -9,7 +9,7 @@ ms.sitesec: library
ms.pagetype: deploy
author: DaniHalfin
ms.author: daniha
ms.date: 06/28/2017
ms.date: 06/30/2017
---
# Overview of Windows AutoPilot
@ -86,10 +86,7 @@ Options available for Windows 10, Version 1703:
* Skipping privacy settings
* Preventing the account used to set-up the device from getting local administrator permissions
Additional options we are working on for the next Windows 10 release:
* Skipping EULA
* Personalizing the setup experience
* MDM Support
We are working to add additional options to further personalize and streamline the setup experience in future releases.
To see additional details on how to customize the OOBE experience and how to follow this process, see guidance for Microsoft Store for Business or [Partner Center](https://msdn.microsoft.com/partner-center/autopilot).

View File

@ -46,7 +46,7 @@ The following tools can help you administer the application control policies cre
- **AppLocker PowerShell cmdlets**
The AppLocker Windows PowerShell cmdlets are designed to streamline the administration of AppLocker policy. They can be used to help create, test, maintain, and troubleshoot an AppLocker policy. The cmdlets are intended to be used in conjunction with the AppLocker user interface that is accessed through the Local Security Policy snap-in and the GPMC. For information about the cmdlets, see the [AppLocker PowerShell Command Reference](http://technet.microsoft.com/library/hh847210.aspx).
The AppLocker Windows PowerShell cmdlets are designed to streamline the administration of AppLocker policy. They can be used to help create, test, maintain, and troubleshoot an AppLocker policy. The cmdlets are intended to be used in conjunction with the AppLocker user interface that is accessed through the Local Security Policy snap-in and the GPMC. For information about the cmdlets, see the [AppLocker PowerShell Command Reference](https://technet.microsoft.com/itpro/powershell/windows/applocker/applocker).
## Related topics

View File

@ -21,7 +21,7 @@ Windows Defender Antivirus is a built-in antimalware solution that provides secu
This library of documentation is aimed for enterprise security administrators who are either considering deployment, or have already deployed and are wanting to manage and configure Windows Defender AV on PC endpoints in their network.
For more important information about running Windows Defender on a server platform, see [Windows Defender Overview for Windows Server](https://technet.microsoft.com/library/dn765478.aspx).
For more important information about running Windows Defender AV on a server platform, see [Windows Defender Overview for Windows Server](https://technet.microsoft.com/library/dn765478.aspx).
Windows Defender AV can be managed with:
- System Center Configuration Manager (as System Center Endpoint Protection, or SCEP)