windows-itpro-docs/windows/update/update-compliance-get-started.md
2017-02-14 12:48:04 -08:00

8.0 KiB
Raw Blame History

title, description, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, author
title description ms.prod ms.mktglfcycl ms.sitesec ms.pagetype author
Get started with Update Compliance (Windows 10) Explains how to configure Update Compliance. w10 deploy library deploy greg-lindsay

Get started with Update Compliance

This topic explains the steps necessary to configure your environment for Windows Analytics: Update Compliance.

Steps are provided in sections that follow the recommended setup process:

  1. Ensure that prerequisites are met.
  2. Add Update Compliance to Microsoft Operations Management Suite
  3. Deploy your Commercial ID to your organizations devices

Update Compliance Prerequisites

Update Compliance has the following requirements:

  1. Update Compliance is currently only compatible with Windows 10 devices. The solution is intended to be used with desktop devices (Windows 10 workstations and laptops).

  2. The solution requires that Windows 10 telemetry is enabled on all devices that are intended to be displayed in the solution. These devices must have at least the basic level of telemetry enabled. To learn more about Windows telemetry, see Configure Windows telemetry in your organization.

  3. The telemetry of your organizations Windows devices must be successfully transmitted to Microsoft. Microsoft has specified endpoints for different aspects of telemetry, which must be whitelisted by your organization so the data can be transmitted. The following table is taken from the article on telemetry endpoints and summarizes the use of each endpoint:

    ServiceEndpoint
    Connected User Experience and Telemetry componentv10.vortex-win.data.microsoft.com
    settings-win.data.microsoft.com
    Windows Error Reporting watson.telemetry.microsoft.com
    Online Crash Analysis oca.telemetry.microsoft.com

Add Update Compliance to Microsoft Operations Management Suite

Update Compliance is offered as a solution in the Microsoft Operations Management Suite (OMS), a collection of cloud-based servicing for monitoring and automating your on-premises and cloud environments. For more information about OMS, see Operations Management Suite overview.

If you are already using OMS, youll find Update Compliance in the Solutions Gallery. Select the Update Compliance tile in the gallery and then click Add on the solution's details page. Update Compliance is now visible in your workspace.

If you are not yet using OMS, use the following steps to subscribe to OMS Update Compliance:

  1. Go to Operations Management Suites page on Microsoft.com and click Sign in.

  2. Sign in to Operations Management Suite (OMS). You can use either a Microsoft Account or a Work or School account to create a workspace. If your company is already using Azure Active Directory (Azure AD), use a Work or School account when you sign in to OMS. Using a Work or School account allows you to use identities from your Azure AD to manage permissions in OMS.

  3. Create a new OMS workspace.

  4. Enter a name for the workspace, select the workspace region, and provide the email address that you want associated with this workspace. Click Create.

  5. If your organization already has an Azure subscription, you can link it to your workspace. Note that you may need to request access from your organizations Azure administrator. If your organization does not have an Azure subscription, create a new one or select the default OMS Azure subscription from the list. If you do not yet have an Azure subscription, follow this guide to create and link an Azure subscription to an OMS workspace.

  6. To add the Update Compliance solution to your workspace, go to the Solutions Gallery.

  7. Select the Update Compliance tile in the gallery and then select Add on the solutions details page. You might need to scroll to find Update Compliance. The solution is now visible on your workspace.

  8. Click the Update Compliance tile to configure the solution. The Settings Dashboard opens.

  9. Click Subscribe to subscribe to OMS Update Compliance. You will then need to distribute your Commercial ID across all your organizations devices. More information on the Commercial ID is provided below.

  10. After you are subscribed to OMS Update Compliance and your devices have a Commercial ID, you will begin receiving data. It will typically take 24 hours for the first data to begin appearing. The following section explains how to deploy your Commercial ID to your Windows 10 devices.

    You can unsubscribe from the Update Compliance solution if you no longer want to monitor your organizations devices. User device data will continue to be shared with Microsoft while the opt-in keys are set on user devices and the proxy allows traffic.

    Deploy your Commercial ID to your Windows 10 devices

    In order for your devices to show up in Windows Analytics: Update Compliance, they must be configured with your organizations Commercial ID. This is so that Microsoft knows that a given device is a member of your organization and to feed that devices data back to you. There are two primary methods for widespread deployment of your Commercial ID: Group Policy and Mobile Device Management (MDM).

    • Using Group Policy

      Deploying your Commercial ID using Group Policy can be accomplished by configuring domain Group Policy Objects with the Group Policy Management Editor, or by configuring local Group Policy using the Local Group Policy Editor.

      1. In the console tree, navigate to Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds
      2. Double-click Configure the Commercial ID
      3. In the Options box, under Commercial Id, type the Commercial ID GUID, and then click OK.

    • Using Microsoft Mobile Device Management (MDM)

      Microsofts Mobile Device Management can be used to deploy your Commercial ID to your organizations devices. The Commercial ID is listed under Provider/ProviderID/CommercialID. More information on deployment using MDM can be found here.

    Use Update Compliance to monitor Windows Updates