windows-itpro-docs/windows/client-management/mdm/policy-csp-mssecurityguide.md
Chris J. Lin ef1c69b439
Release mcc ent (#1)
* smb adds

* smb adds

* formatting

* private preview and support content

* edit removed and dep

* Fix blocking issues

* Acro-fix

* 24H2 CSP Updates

* Fix link

* fix link in dep page

* edit

* edit index file

* syntax-fix-24h2

* ltsc-edits

* ltsc-edits

* lichris-docs-1

* Acrolinx improvements

* refresh for maxado-8631996

* update link for maxado-8631993

* additional edits, acrolinx

* ltsc-tw

* contentsource-8914508

* contentsource-8914508

* Updates for 1 October release

* Set stale debug to false

* update gp link for 24h2

* additional changes

* Changes to updates, acrolinx changes

* fixes broken links

* Fixed alignment issues

* updates from Rafal

* fixed acrolinx

* so many link fixes

* added release notes and troubleshoot content

* updates

* Update security-compliance-toolkit-10.md

Added Windows 11 24H2

* Update get-support-for-security-baselines.md

Updated for Windows 11 24H2

* bump date

* bump date

* fix pde comment

* fixing broken link

* Fix broken redirections

* fix to rel link

* reset head, fix link

* add cli to deploy, add script to cli

* removing "mcce"

* edits to create page

* Update default and global release policies OS version and dates to latest release values

* emoved e from mcce and other changes

* updated example script

* added important notice to update page

* more update page changes

* clarified how proxy configuration is used

* anonymizing variables in example script

* revise example script

* acrolinx fixes to update page

* changes to other pages and content in overview page

* Update broken link

Update broken link

* Update windows-sandbox-configure-using-wsb-file.md

Update `HostFolder` value description in `MappedFolder`, specifying that the path could be absolute or relative, not only absolute as, instead, is for the `SandboxFolder` value.

* Remove bad link

Removed bad link. There is already a second link referring to content so no need to replace the link.

* docfx update for security book

* Correct TOC entry changing Windows 10 to Windows

* Update whats-new-do.md

- Vpn to VPN
- Minor improvements

* Updated date for freshness reporting

* Add EOS callout

Fix some obvious Acrolinx issues

* Fixed typo added clarity

* Update mcc-ent-deploy-to-windows.md

* Update .openpublishing.redirection.windows-deployment.json

* Update .openpublishing.redirection.windows-deployment.json

* Update policy-csp-localpoliciessecurityoptions.md

* Correct indentation and spacing

* Acrolinx: "Enteprise"

* Update mcc-ent-edu-overview.md

* refresh

* Remove redirection and final bits of store-for-business

store-for-business, AKA /microsoft-store/, is retired, and the content is archived in officearchive-pr. This archival was for ADO task 9268422.

* added support content and other changes

* fixed tabs

* fixed tabs

* Updated device reg policy and group information

* Update delivery-optimization-endpoints.md

Added a line item in MCC table for Outlook *res.cdn.office.net requirement

* freshness review

* Fix broken links

* Minor change

* content for faq

* changes to landing page

* more content to faqs

* pencil edit

* add copilot exps link

* edits and ren cli file temporarily

* ren file back and edit toc to lowercase

* edit

* edit

* edit

* Update windows-autopatch-configure-network.md

Adding a new network endpoint required for the service 'device.autopatch.microsoft.com' @tiaraquan

* Clarify some points and remove data that is confusing to customers.

* fix syntax

* Sentence correction

* Update windows/deployment/do/waas-delivery-optimization-faq.yml

Co-authored-by: Meghan Stewart <33289333+mestew@users.noreply.github.com>

* Update windows/deployment/do/waas-delivery-optimization-faq.yml

Co-authored-by: Meghan Stewart <33289333+mestew@users.noreply.github.com>

* moved shortcuts under policy settings article

---------

Co-authored-by: Alma Jenks <v-alje@microsoft.com>
Co-authored-by: Meghan Stewart <33289333+mestew@users.noreply.github.com>
Co-authored-by: Stacyrch140 <102548089+Stacyrch140@users.noreply.github.com>
Co-authored-by: Nidhi Doshi <77081571+doshnid@users.noreply.github.com>
Co-authored-by: Gary Moore <5432776+garycentric@users.noreply.github.com>
Co-authored-by: Vinay Pamnani (from Dev Box) <vinpa@microsoft.com>
Co-authored-by: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com>
Co-authored-by: Aaron Czechowski <aczechowski@users.noreply.github.com>
Co-authored-by: Aditi Srivastava <133841950+aditisrivastava07@users.noreply.github.com>
Co-authored-by: Daniel H. Brown <32883970+DHB-MSFT@users.noreply.github.com>
Co-authored-by: David Strome <21028455+dstrome@users.noreply.github.com>
Co-authored-by: Padma Jayaraman <v-padmaj@microsoft.com>
Co-authored-by: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com>
Co-authored-by: Rebecca Agiewich <16087112+rjagiewich@users.noreply.github.com>
Co-authored-by: Rick Munck <33725928+jmunck@users.noreply.github.com>
Co-authored-by: Tanaka <Huios@users.noreply.github.com>
Co-authored-by: Tiara Quan <95256667+tiaraquan@users.noreply.github.com>
Co-authored-by: Frank Rojas <45807133+frankroj@users.noreply.github.com>
Co-authored-by: Davide Piccinini <davide.piccinini.95@gmail.com>
Co-authored-by: Phil Garcia <phil@thinkedge.com>
Co-authored-by: Learn Build Service GitHub App <Learn Build Service LearnBuild@microsoft.com>
Co-authored-by: tiaraquan <tiaraquan@microsoft.com>
Co-authored-by: Caitlin Hart <caithart@microsoft.com>
Co-authored-by: Harman Thind <63820404+hathin@users.noreply.github.com>
Co-authored-by: [cmknox] <[cmknox@gmail.com]>
Co-authored-by: Carmen Forsmann <cmforsmann@live.com>
2024-10-17 11:34:07 -07:00

377 lines
15 KiB
Markdown

---
title: MSSecurityGuide Policy CSP
description: Learn more about the MSSecurityGuide Area in Policy CSP.
ms.date: 09/27/2024
---
<!-- Auto-Generated CSP Document -->
<!-- MSSecurityGuide-Begin -->
# Policy CSP - MSSecurityGuide
[!INCLUDE [ADMX-backed CSP tip](includes/mdm-admx-csp-note.md)]
<!-- MSSecurityGuide-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- MSSecurityGuide-Editable-End -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-Begin -->
## ApplyUACRestrictionsToLocalAccountsOnNetworkLogon
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-Applicability-Begin -->
| Scope | Editions | Applicable OS |
|:--|:--|:--|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 10, version 1803 [10.0.17134] and later |
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-Applicability-End -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-OmaUri-Begin -->
```Device
./Device/Vendor/MSFT/Policy/Config/MSSecurityGuide/ApplyUACRestrictionsToLocalAccountsOnNetworkLogon
```
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-OmaUri-End -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-Description-Begin -->
<!-- Description-Source-Not-Found -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-Description-End -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-Editable-End -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-DFProperties-Begin -->
**Description framework properties**:
| Property name | Property value |
|:--|:--|
| Format | `chr` (string) |
| Access Type | Add, Delete, Get, Replace |
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-DFProperties-End -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-AdmxBacked-Begin -->
<!-- ADMX-Not-Found -->
[!INCLUDE [ADMX-backed policy note](includes/mdm-admx-policy-note.md)]
**ADMX mapping**:
| Name | Value |
|:--|:--|
| Name | Pol_SecGuide_0201_LATFP |
| ADMX File Name | SecGuide.admx |
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-AdmxBacked-End -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-Examples-Begin -->
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-Examples-End -->
<!-- ApplyUACRestrictionsToLocalAccountsOnNetworkLogon-End -->
<!-- ConfigureSMBV1ClientDriver-Begin -->
## ConfigureSMBV1ClientDriver
<!-- ConfigureSMBV1ClientDriver-Applicability-Begin -->
| Scope | Editions | Applicable OS |
|:--|:--|:--|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 10, version 1803 [10.0.17134] and later |
<!-- ConfigureSMBV1ClientDriver-Applicability-End -->
<!-- ConfigureSMBV1ClientDriver-OmaUri-Begin -->
```Device
./Device/Vendor/MSFT/Policy/Config/MSSecurityGuide/ConfigureSMBV1ClientDriver
```
<!-- ConfigureSMBV1ClientDriver-OmaUri-End -->
<!-- ConfigureSMBV1ClientDriver-Description-Begin -->
<!-- Description-Source-Not-Found -->
<!-- ConfigureSMBV1ClientDriver-Description-End -->
<!-- ConfigureSMBV1ClientDriver-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- ConfigureSMBV1ClientDriver-Editable-End -->
<!-- ConfigureSMBV1ClientDriver-DFProperties-Begin -->
**Description framework properties**:
| Property name | Property value |
|:--|:--|
| Format | `chr` (string) |
| Access Type | Add, Delete, Get, Replace |
<!-- ConfigureSMBV1ClientDriver-DFProperties-End -->
<!-- ConfigureSMBV1ClientDriver-AdmxBacked-Begin -->
<!-- ADMX-Not-Found -->
[!INCLUDE [ADMX-backed policy note](includes/mdm-admx-policy-note.md)]
**ADMX mapping**:
| Name | Value |
|:--|:--|
| Name | Pol_SecGuide_0002_SMBv1_ClientDriver |
| ADMX File Name | SecGuide.admx |
<!-- ConfigureSMBV1ClientDriver-AdmxBacked-End -->
<!-- ConfigureSMBV1ClientDriver-Examples-Begin -->
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
<!-- ConfigureSMBV1ClientDriver-Examples-End -->
<!-- ConfigureSMBV1ClientDriver-End -->
<!-- ConfigureSMBV1Server-Begin -->
## ConfigureSMBV1Server
<!-- ConfigureSMBV1Server-Applicability-Begin -->
| Scope | Editions | Applicable OS |
|:--|:--|:--|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 10, version 1803 [10.0.17134] and later |
<!-- ConfigureSMBV1Server-Applicability-End -->
<!-- ConfigureSMBV1Server-OmaUri-Begin -->
```Device
./Device/Vendor/MSFT/Policy/Config/MSSecurityGuide/ConfigureSMBV1Server
```
<!-- ConfigureSMBV1Server-OmaUri-End -->
<!-- ConfigureSMBV1Server-Description-Begin -->
<!-- Description-Source-Not-Found -->
<!-- ConfigureSMBV1Server-Description-End -->
<!-- ConfigureSMBV1Server-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- ConfigureSMBV1Server-Editable-End -->
<!-- ConfigureSMBV1Server-DFProperties-Begin -->
**Description framework properties**:
| Property name | Property value |
|:--|:--|
| Format | `chr` (string) |
| Access Type | Add, Delete, Get, Replace |
<!-- ConfigureSMBV1Server-DFProperties-End -->
<!-- ConfigureSMBV1Server-AdmxBacked-Begin -->
<!-- ADMX-Not-Found -->
[!INCLUDE [ADMX-backed policy note](includes/mdm-admx-policy-note.md)]
**ADMX mapping**:
| Name | Value |
|:--|:--|
| Name | Pol_SecGuide_0001_SMBv1_Server |
| ADMX File Name | SecGuide.admx |
<!-- ConfigureSMBV1Server-AdmxBacked-End -->
<!-- ConfigureSMBV1Server-Examples-Begin -->
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
<!-- ConfigureSMBV1Server-Examples-End -->
<!-- ConfigureSMBV1Server-End -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-Begin -->
## EnableStructuredExceptionHandlingOverwriteProtection
<!-- EnableStructuredExceptionHandlingOverwriteProtection-Applicability-Begin -->
| Scope | Editions | Applicable OS |
|:--|:--|:--|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 10, version 1803 [10.0.17134] and later |
<!-- EnableStructuredExceptionHandlingOverwriteProtection-Applicability-End -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-OmaUri-Begin -->
```Device
./Device/Vendor/MSFT/Policy/Config/MSSecurityGuide/EnableStructuredExceptionHandlingOverwriteProtection
```
<!-- EnableStructuredExceptionHandlingOverwriteProtection-OmaUri-End -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-Description-Begin -->
<!-- Description-Source-Not-Found -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-Description-End -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-Editable-End -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-DFProperties-Begin -->
**Description framework properties**:
| Property name | Property value |
|:--|:--|
| Format | `chr` (string) |
| Access Type | Add, Delete, Get, Replace |
<!-- EnableStructuredExceptionHandlingOverwriteProtection-DFProperties-End -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-AdmxBacked-Begin -->
<!-- ADMX-Not-Found -->
[!INCLUDE [ADMX-backed policy note](includes/mdm-admx-policy-note.md)]
**ADMX mapping**:
| Name | Value |
|:--|:--|
| Name | Pol_SecGuide_0102_SEHOP |
| ADMX File Name | SecGuide.admx |
<!-- EnableStructuredExceptionHandlingOverwriteProtection-AdmxBacked-End -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-Examples-Begin -->
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-Examples-End -->
<!-- EnableStructuredExceptionHandlingOverwriteProtection-End -->
<!-- NetBTNodeTypeConfiguration-Begin -->
## NetBTNodeTypeConfiguration
<!-- NetBTNodeTypeConfiguration-Applicability-Begin -->
| Scope | Editions | Applicable OS |
|:--|:--|:--|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 24H2 [10.0.26100] and later |
<!-- NetBTNodeTypeConfiguration-Applicability-End -->
<!-- NetBTNodeTypeConfiguration-OmaUri-Begin -->
```Device
./Device/Vendor/MSFT/Policy/Config/MSSecurityGuide/NetBTNodeTypeConfiguration
```
<!-- NetBTNodeTypeConfiguration-OmaUri-End -->
<!-- NetBTNodeTypeConfiguration-Description-Begin -->
<!-- Description-Source-Not-Found -->
<!-- NetBTNodeTypeConfiguration-Description-End -->
<!-- NetBTNodeTypeConfiguration-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- NetBTNodeTypeConfiguration-Editable-End -->
<!-- NetBTNodeTypeConfiguration-DFProperties-Begin -->
**Description framework properties**:
| Property name | Property value |
|:--|:--|
| Format | `chr` (string) |
| Access Type | Add, Delete, Get, Replace |
<!-- NetBTNodeTypeConfiguration-DFProperties-End -->
<!-- NetBTNodeTypeConfiguration-AdmxBacked-Begin -->
<!-- ADMX-Not-Found -->
[!INCLUDE [ADMX-backed policy note](includes/mdm-admx-policy-note.md)]
**ADMX mapping**:
| Name | Value |
|:--|:--|
| Name | Pol_SecGuide_0050_NetbtNodeTypeConfig |
| ADMX File Name | SecGuide.admx |
<!-- NetBTNodeTypeConfiguration-AdmxBacked-End -->
<!-- NetBTNodeTypeConfiguration-Examples-Begin -->
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
<!-- NetBTNodeTypeConfiguration-Examples-End -->
<!-- NetBTNodeTypeConfiguration-End -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-Begin -->
## TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-Applicability-Begin -->
| Scope | Editions | Applicable OS |
|:--|:--|:--|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 10, version 1803 [10.0.17134] and later |
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-Applicability-End -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-OmaUri-Begin -->
```Device
./Device/Vendor/MSFT/Policy/Config/MSSecurityGuide/TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications
```
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-OmaUri-End -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-Description-Begin -->
<!-- Description-Source-Not-Found -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-Description-End -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-Editable-End -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-DFProperties-Begin -->
**Description framework properties**:
| Property name | Property value |
|:--|:--|
| Format | `chr` (string) |
| Access Type | Add, Delete, Get, Replace |
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-DFProperties-End -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-AdmxBacked-Begin -->
<!-- ADMX-Not-Found -->
[!INCLUDE [ADMX-backed policy note](includes/mdm-admx-policy-note.md)]
**ADMX mapping**:
| Name | Value |
|:--|:--|
| Name | Pol_SecGuide_0101_WDPUA |
| ADMX File Name | SecGuide.admx |
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-AdmxBacked-End -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-Examples-Begin -->
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-Examples-End -->
<!-- TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications-End -->
<!-- WDigestAuthentication-Begin -->
## WDigestAuthentication
<!-- WDigestAuthentication-Applicability-Begin -->
| Scope | Editions | Applicable OS |
|:--|:--|:--|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 10, version 1803 [10.0.17134] and later |
<!-- WDigestAuthentication-Applicability-End -->
<!-- WDigestAuthentication-OmaUri-Begin -->
```Device
./Device/Vendor/MSFT/Policy/Config/MSSecurityGuide/WDigestAuthentication
```
<!-- WDigestAuthentication-OmaUri-End -->
<!-- WDigestAuthentication-Description-Begin -->
<!-- Description-Source-Not-Found -->
<!-- WDigestAuthentication-Description-End -->
<!-- WDigestAuthentication-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- WDigestAuthentication-Editable-End -->
<!-- WDigestAuthentication-DFProperties-Begin -->
**Description framework properties**:
| Property name | Property value |
|:--|:--|
| Format | `chr` (string) |
| Access Type | Add, Delete, Get, Replace |
<!-- WDigestAuthentication-DFProperties-End -->
<!-- WDigestAuthentication-AdmxBacked-Begin -->
<!-- ADMX-Not-Found -->
[!INCLUDE [ADMX-backed policy note](includes/mdm-admx-policy-note.md)]
**ADMX mapping**:
| Name | Value |
|:--|:--|
| Name | Pol_SecGuide_0202_WDigestAuthn |
| ADMX File Name | SecGuide.admx |
<!-- WDigestAuthentication-AdmxBacked-End -->
<!-- WDigestAuthentication-Examples-Begin -->
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
<!-- WDigestAuthentication-Examples-End -->
<!-- WDigestAuthentication-End -->
<!-- MSSecurityGuide-CspMoreInfo-Begin -->
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
<!-- MSSecurityGuide-CspMoreInfo-End -->
<!-- MSSecurityGuide-End -->
## Related articles
[Policy configuration service provider](policy-configuration-service-provider.md)