66 Commits

Author SHA1 Message Date
Alekhya Jupudi
d140fcbf6a Defender App Guard Link text correction-01
Change to Learn more about the [Windows Defender Application Control feature availability](feature-availability.md)
2021-09-30 11:22:51 +05:30
Jordan Geurten
a811de340b Corrected the minversion's since cscript/wscript do not follow typical win10 bin versions 2021-09-21 14:29:35 -07:00
Jordan Geurten
0478c9e056 Updated the recommended blocklist to block un-enlightened versions of cscript/wscript with versions less than 10.0.0.0 2021-09-14 16:16:32 -07:00
Alekhya Jupudi
4467c6631d Merge branch 'master' into aljupudi-w11defender-branch01 2021-08-24 08:39:09 +05:30
denisebmsft
3bd09d2ae2 Update microsoft-recommended-block-rules.md 2021-08-23 10:21:15 -07:00
denisebmsft
1cde0e2127 Update microsoft-recommended-block-rules.md 2021-08-23 10:18:11 -07:00
denisebmsft
b7413430cf Update microsoft-recommended-block-rules.md 2021-08-23 10:17:02 -07:00
denisebmsft
6d34d59f54 Merge branch 'master' into pr/5531 2021-08-23 10:11:44 -07:00
Denise Vangel-MSFT
ca964f9f6b
Update microsoft-recommended-block-rules.md 2021-08-23 10:08:27 -07:00
Alekhya Jupudi
61149771d2 TASK 5358645: Windows 11 Inclusion Update -01
TASK 5358645: First batch of Windows 11 Inclusion updates under Windows-defender-application-control folder. (I've also made some changes to few words as per Acrolinx suggestions to meet the PR criteria).
2021-08-23 14:11:14 +05:30
Jordan Geurten
721dacf612 Added latest security researcher to recommended block rules and sorted them. 2021-08-19 12:49:28 -07:00
Jordan Geurten
c19a697db5 Added cscript and wscript to the Microsoft recommended blocklist 2021-08-05 14:42:03 -07:00
David Coulter
e967b61aa9
Links: Windows (2021-03) 2021-03-25 10:12:36 -07:00
Daniel Simpson
c93d7f2b6c massive prod & technology metadata update 2021-01-21 10:21:50 -08:00
Jordan Geurten
0b0786fd86
Added contributor to the acknowledgements section 2020-10-20 14:32:35 -07:00
Jordan Geurten
bdce156a22
Added mfc40.dll to recommended block list 2020-10-19 15:27:54 -07:00
Gary Moore
3a3bdee19a
Restored original footnote numbering scheme 2020-08-27 17:05:41 -07:00
Gary Moore
375209322e
Replaced CommonMark footnotes with <sup></sup>
It seems we're not using the CommonMark extension that create linked footnote numbers. I've retained the renumbering from my previous change.
2020-08-27 16:48:10 -07:00
Gary Moore
f01afeb588
Removed repeated paragraph, applied footnote functionality
Changed "*" to 1 and incremented the other two footnotes.
2020-08-27 16:41:01 -07:00
isbrahm
853a693904
Add aspnet_compiler to recommended block rules
Also re-alphabetize. Some entries were out of order.
2020-08-27 14:24:14 -07:00
Daniel Simpson
b192690b4b updating blacklist/whitelist to allow/block 2020-06-15 08:51:22 -07:00
brbrahm
7328a258f7 Standardize 'applies to' section 2020-04-15 17:10:55 -07:00
isbrahm
d034371f9b
Minor edits for readability 2020-01-21 09:34:51 -08:00
isbrahm
c6d57cb3d1
Update recommended block list to explain not blocking 1903 files
msxml3.dll, msxml6.dll, and jscript9.dll do not have to be blocked if using 1903, as the previous issue was fixed in this release
2020-01-07 15:21:52 -08:00
martyav
143798dd80 reviewed items through #163 2019-12-26 15:31:03 -05:00
brbrahm
4da03265ac WDAC correct ms.reviewer
Updating to MSFT alias instead of Git username
2019-10-25 11:01:50 -07:00
brbrahm
a996e0cd0a
Update WDAC block rules to fix PR warning 2019-10-24 17:26:56 -07:00
Bella Brahm
40b1776322 Merge branch 'master' of https://github.com/brbrahm/windows-docs-pr 2019-10-24 17:02:37 -07:00
Bella Brahm
4a1f564f36 Update WDAC metadata
Updating WDAC docs metadata to reflect current ownership

author: jsuther1974
ms.reviewer: brbrahm
ms.author: dansimp
manager: dansimp
2019-10-24 16:58:46 -07:00
Bella Brahm
df427631a3 Update WDAC metadata
Updating WDAC docs metadata to reflect current ownership

author: jsuther1974
ms.reviewer: brbrahm
ms.author: dansimp
manager: dansimp
2019-10-24 16:17:47 -07:00
Daniel Simpson
50ca69c5e6
Merge pull request #5112 from illfated/solve_block_rules_ambiguity
WDAC/Recommended block rules: Add notes and link
2019-10-08 13:55:43 -07:00
Trond B. Krokli
09b645765b
Update windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md
- generalized heading text (better phrasing)

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
2019-10-08 20:50:52 +02:00
Trond B. Krokli
eb926209ff
Update windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md
- improved phrasing

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
2019-10-08 20:49:54 +02:00
illfated
2651aab85e WDAC/Recommended block rules: Add notes and link
Description:

As agreed on in issue ticket #3642 (Ambiguity), this PR adds a note
about creating two diff policies or merging them in a broad policy,
as well as adding a link to how to merge WDAC policies.

As recommended by Justin Hall, Windows Server 2019 is also added to the
"Applies to" list at the top of this document.

Also, thanks to Air-Git for requesting this clarification.

issue ticket closure or reference:

Closes #3642
2019-10-05 02:46:44 +02:00
brbrahm
deb3e55d9d
Update windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md
Accepting wording change suggestion

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
2019-09-23 13:18:06 -07:00
brbrahm
41be8ac8df
Comment out msxml3, msxml6, jscript9 in signing scenarios
These three dlls are commented out in the rule definition section, so should also be commented out in the signing scenarios section in case people do not uncomment the first.
2019-09-20 08:58:34 -07:00
John Liu
a8680be7fe
CAT Auto Pulish for Windows Release Messages - 20190910123725 (#1079)
* Update waas-servicing-differences.md

Added two clarifications regarding Windows 10 preview updates.  I have consistently fielded questions about why they are 'missing' in people's enterprise environments.  It almost always boils down to one of these two notes: they either weren't published to WSUS or they are looking for the word 'Preview' in the title.

* Update windows/deployment/update/waas-servicing-differences.md

Looks great, thanks Johan!

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update waas-servicing-differences.md

Implement the MarkDown standard of using 1 space between the indent marker > and the [!Note] markers

* Update windows/deployment/update/waas-servicing-differences.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Update windows/deployment/update/waas-servicing-differences.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Update windows/deployment/update/waas-servicing-differences.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* Updated the document

Updated the steps in the document related to Windows Analytics Solutions.

Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/4392

* Update windows/deployment/update/windows-analytics-FAQ-troubleshooting.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* Update windows/deployment/update/windows-analytics-FAQ-troubleshooting.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Update autopilot-support.md

Remove redundant line (PFE was the old term for an Ecosystem PM).  And added new alias for Ecosystem PMs (after discussing all this with the Ecosystem PM managers).

* Terminology Correction

Terminology Correction

* Incorrect Command Line Arguments

According to this doc https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/windows-setup-command-line-options the correct command line argument for ignoring dismissable warnings is /Compat IgnoreWarning not /compat /ignore warning as specified here in the docs. Also, the same incorrect message is included in the setupdiag.exe, so when the report is generated, it is providing incorrect guidance.

* Update mbam-25-server-prerequisites-for-stand-alone-and-configuration-manager-integration-topologies.md

* Enterprise Mode schema: duplicate https usage

- Resolve duplicate use of https where both http and https was intended
- MarkDown code fence XML tag corrections
- Replace HTML `<br>` codes with NewLine
- Remove redundant space at the end of the version 2 file

Resolves #4769

* Update: NewLine changes

- Remove extraneous NewLine breaks
- Remove missed HTML `<br>` code

* Update credential-guard-manage.md

* Update event-5155.md

* Update windows-autopilot-requirements.md

Separated the Windows Autopilot deployment service and Windows Activation items into two separate rows to make it easier to read.

* Update upgrade-mbam2.5-sp1.md

* finish

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* Update windows/security/threat-protection/auditing/event-5155.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* Update kiosk-mdm-bridge.md

* Windows Update resources: add MD code block

Description:

The list of manual regsvr32.exe commands becomes translated in other
languages, to the extent that extra words appear among the commands.
This is an attempt to mitigate this behavior in the machine translation,
by adding a MarkDown code block around the list of commands.

Proposed changes:
- Add MD code block around the long list of regsvr32.exe commands
- Remove blank space characters at the end of each line (cosmetic)

issue ticket reference or closure:
Ref. #4800 (Spanish "translation" of commands)
Ref. #3569, #3570, #3571, #3572, #3574, #3575
( [LOC] Back-Translation "regsvr32.exe [...]" )

* MetaData update: convert ^M (2x) to NewLine

- replaced Ctrl-M character with NewLine in MetaData

* Update mdop/mbam-v25/mbam-25-server-prerequisites-for-stand-alone-and-configuration-manager-integration-topologies.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* comment

* Clarify the registry key needed to set tags

* Update microsoft-defender-atp-mac-install-with-intune.md

adding troubleshooting step for common 'no license found' issue

* Add page for Audit Token Right Adjusted

* Windows/What's New: amend broken link in See Also

The first link under "See Also",
"What's New in Windows Server, version 1903" ,
is broken because it points to the wrong directory for the file
'whats-new-in-windows-server-1903' which resides in the new directory
/get-started-19/ instead of the old directory /get-started/.

This directory difference is only present in the docs.microsoft.com
pages, not on Github. The links are therefore pointing directly to the
docs.microsoft.com pages instead of being relative to the Github
directory structure.

Broken link:
https://docs.microsoft.com/windows-server/get-started/whats-new-in-windows-server-1903

Operative link:
https://docs.microsoft.com/windows-server/get-started-19/whats-new-in-windows-server-1903

Closes #4784

* Update TOC.md

* Added multifactor unlock

Added multifactor unlock feature update using Passport for work CSP.

Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/4700

* Added policies for 1803 and 1809 (1903 not out yet)

https://github.com/MicrosoftDocs/windows-itpro-docs/issues/3912

* Fix typo

* Actually fix typos

* Windows Defender Antivirus: amend broken link

From the issue ticket
> Set-mppreference is configured with dead URL. (#4831)

- The link "Use the [Set-MpPreference][]" is broken,
  but without the empty brackets it will work as expected.
- Removing the redundant empty brackets after the next link too.

Closes #4831

* Update windows/client-management/new-policies-for-windows-10.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* Update windows/client-management/new-policies-for-windows-10.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* Update upgrading-to-mbam-25-sp1-from-mbam-25.md

* Update windows/client-management/new-policies-for-windows-10.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/client-management/new-policies-for-windows-10.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/client-management/new-policies-for-windows-10.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update windows/client-management/new-policies-for-windows-10.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* URL addition of OWA

Added URL for OWA attachment protection using WIP

Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/3747

* Update windows/security/identity-protection/hello-for-business/feature-multifactor-unlock.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Fixed text

"Automated investigation" instead of "Alert"

* Update waas-overview.md

Corrected a typo

* Update windows/deployment/update/waas-overview.md

Makes sense.

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* edit

* Update microsoft-recommended-block-rules.md

updated typo in description.

* Update windows/security/threat-protection/auditing/audit-token-right-adjusted.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* note ragarding Company Portal change

https://github.com/MicrosoftDocs/windows-itpro-docs/issues/3843

info found here: https://blogs.technet.microsoft.com/cbernier/2018/03/08/windows-information-protection-adding-the-intune-company-portal-for-windows-as-an-exempt-app/

* Update microsoft-defender-atp-mac-install-with-intune.md

* Microsoft Defender ATP: amend copy-paste error

When using Microsoft Intune as part of the Defender ATP setup,
it will become necessary to configure some controlled folder access.
This bug looks like it could have been transferred from one of the
other pages during editing, but I could not locate it easily enough.

Anyway, the correct part of this step is to refer to
-- Controlled folder access --
exactly as the page name points to.

Thanks to jcampos79 for discovering this text-based bug.

Closes #4854

* Updated how to disable HVCI

Prior guidance to disable HVCI was outdated

* Update windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* update content of upgrade mbam2.5 sp1

* Removed bullet

Removed bullet as it was not making any sense.

* format setting

a minor format setting

* Update windows/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* Update windows/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* sample script syntax error due to ASCII codes for quotes

sample script filter syntax contained ASCII codes for single quotes instead of actual quotes, causing the Get-CimInstance commands to error out.

* Update how-windows-update-works.md: amend typo

Simple typo correction, along with a few MarkDown
codestyle corrections for MD blockquote (`>`) indenting.

- typo correction: initates -> initiates
- codestyle corrections:
  3 MarkDown blockquote indentations amended

Thanks to Jessie Gouw (jessiegouw) for reporting the typo.

Closes #4866

* Moved '.' syntax description to a separate table

* fixes #4760, broken table

The formatting was broken because a pipe character was in the wrong place. There was also an extra row due to double spacing below the table.

* Enterprise Mode schema: convert Important notes

As previously discussed in this PR, I have converted the
**Important** section headings by using their MarkDown equivalent
> [!IMPORTANT] (as well as adding the blockquote for its text content).

* Update text in windows/security/threat-protection/windows-defender-application-guard/configure-wd-app-guard.md

Per review.

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update text in windows/security/threat-protection/windows-defender-application-guard/configure-wd-app-guard.md

Per review.

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Spelled out acronym, fixed typo

* pull from public to private and fix warnings

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190910100213 (#1073)

* pull from public to private and fix warnings

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190910112417 (#1077)

* Cat auto publish 20190910112417 (#1081)

* Merge changes from master to live (#950)

* v 1.6

* removed a known issue

* removed references to CB, CBB

* Latest changes for publish today (#949)

* Merge from master to live (#956)

* safety checkin

* added location for group policy object

* replaced reboot w/ restart

* safety commit for some initial noodlings

* restructured to emphasize new policy; connected to TOC

* adjusting heading levels

* fixing tables

* Latest change for August 20 (#955)

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190823163336 (#980) (#981)

* CAT Auto Pulish for Windows Release Messages - 20190829112356 (#1007)

* Update deploy-the-latest-firmware-and-drivers-for-surface-devices.md

* add table

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190829102107 (#1006)

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190829175859 (#1012) (#1013)

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190830100739 (#1018) (#1019)

* CAT Auto Pulish for Windows Release Messages - 20190903135254 (#1033)

* SIEM connector: change alert notion to Detection

* update casing and redirects

* remove space json file

* fix json

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190903123340 (#1031)

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190906173611 (#1061) (#1062)

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190910100213 (#1073) (#1074)

* CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20190910112417
2019-09-10 13:41:31 -07:00
Alton(ius) Blom
cdaed2d39e
Update microsoft-recommended-block-rules.md
updated typo in description.
2019-09-04 15:08:33 +10:00
huypub
67d39ab200 8/6 AM Publish (#843)
* updated description of how wdav screens apps

* Added new content for auto-enrollment

* Updated format

* revised to emphasize cfa

* Multiple updates

* Updated image

* refined wording per sccm, intune, security center

* corrected link

* moved paragraph about ransomeware lower

* addtl updates to change name from Definition Update to Security Intelligence Update

* More updates

* Fixed typo

* Update microsoft-recommended-block-rules.md (#838)

* Update microsoft-recommended-block-rules.md

adding blocks .NET binaries for WDAC work arounds

* added in missing 'audience' attribute

* pre-release and typos

* linted and rfined wording

* New Anouncement added in august (#842)
2019-08-06 10:20:02 -07:00
andyvdav
7d63d74f76 Update microsoft-recommended-block-rules.md (#838)
* Update microsoft-recommended-block-rules.md

adding blocks .NET binaries for WDAC work arounds

* added in missing 'audience' attribute
2019-08-06 11:28:14 -04:00
Marty Hernandez Avedon
01558dc28b
Fixes #3947, Invalid XML provided
> The XML comment tags between line 60 and 87 of the XML file are malformed. There is a space between "<!" and "--" meaning that this cannot be used programmaticaly.

The spacing in certain comments was removed.

For some reason, neither GitHub nor the Docs Markdown addon for VS Code can provide a preview of the resulting page. However, other comments in the article were already spaced correctly and fully displayable on the published page.
2019-06-06 21:35:52 -04:00
get-itips
90972e598f Several metadata changes
added ms.reviewer and manager using ms.date
2019-05-30 10:01:13 -03:00
get-itips
3ee8450013 several metadata changes 2019-05-30 09:32:38 -03:00
wweibull
006a9dddcb
Update microsoft-recommended-block-rules.md
Added two additional researcher to the acknowledgment section.

Philip Tsukerman (@PhilipTsukerman)
Jimmy Bayne (@bohops)
2019-04-15 11:32:12 -07:00
Justin Hall
f24b38f38b date 2019-04-09 12:01:27 -07:00
Justin Hall
606fd49a8e revised block list 2019-03-15 11:49:12 -07:00
Justin Hall
6cda37d623 edit 2019-03-11 17:29:23 -07:00
Justin Hall
a8616882b4 added new script 2019-03-11 17:28:36 -07:00
Nick Schonning
ebb45e3925 chore: Remove en-us from docs.microsoft.com links 2018-10-26 14:00:08 -04:00
Justin Hall
6650ff599c added kill.exe 2018-08-31 15:04:32 -07:00