windows-itpro-docs/education/windows/configure-windows-for-education.md
DocsPreview ce500fde9b
Latest updates for issues content (#379)
* Updated deployment-vdi-windows-defender-antivirus.md

* Updated deployment-vdi-windows-defender-antivirus.md

* Updated deployment-vdi-windows-defender-antivirus.md

* updates for new vdi stuff

* Adding important note to solve #3493

* Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-dir-sync.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Typo "&lt;"→"<", "&gt;"→">"

https://docs.microsoft.com/en-us/windows/application-management/manage-windows-mixed-reality

* Issue #2297

* Update windows/security/identity-protection/hello-for-business/hello-identity-verification.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Clarification

* Update windows/security/identity-protection/hello-for-business/hello-identity-verification.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Update windows/security/identity-protection/hello-for-business/hello-identity-verification.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* update troubleshoot-np.md

* update configure-endpoints-gp.md

* Removing a part which is not supported

* Name change

* update troubleshoot-np.md

* removed on-premises added -hello

* Added link into Domain controller guide

* Line corections

* corrected formatting of xml code samples

When viewing the page in Win 10/Edge, the xml code samples stretched across the page, running into the side menu. The lack of line breaks also made it hard to read.

This update adds line breaks and syntax highlighting, replaces curly double quotes with standard double quotes, and adds a closing tag for <appv:appconnectiongroup>for each code sample

* Update windows/security/identity-protection/hello-for-business/hello-identity-verification.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Update windows/deployment/update/waas-delivery-optimization-reference.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Update windows/deployment/update/waas-delivery-optimization-reference.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* corrected formating of XML examples

The XML samples here present the same formatting problems as in about-the-connection-group-file51.md (see https://github.com/MicrosoftDocs/windows-itpro-docs/pull/3847/)

Perhaps we should open an issue to see if we have more versions of this code sample in the docs

* corrected formatting of XML example section

In the XML example on this page, the whitespace had been stripped out, so there were no spaces between adjacent attribute values or keys.

This made it hard to read, though the original formatting allowed for a scroll bar, so the text was not running into the side of the page (compare to https://github.com/MicrosoftDocs/windows-itpro-docs/pull/3847 and https://github.com/MicrosoftDocs/windows-itpro-docs/pull/3850, where the uncorrected formatting forced the text to run into the side menu).

* update configure-endpoints-gp.md

* Fixed error in registry path and improved description

* Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-dir-sync.md

Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>

* Removing extra line in 25 

Suggested by

* update windows-analytics-azure-portal.md

* re: broken links, credential-guard-considerations

Context:
* #3513, MVA is being retired and producing broken links
* #3860 Microsoft Virtual Academy video links

This page contains two links to deprecated video content on Microsoft Virtual Academy (MVA).

MVA is being retired. 

In addition, the Deep Dive course the two links point to is already retired, and no replacement course exists.

I removed the first link, as I could not find a similar video available describing which credentials are covered by credential guard.

I replaced the second link with a video containing similar material, though it is not a "deep dive".

Suggestions on handling this problem, as many pages contain similar links, would be appreciated,.

* removed link to retired video re: #3867

Context:
* #3513, MVA is being retired and producing broken links
* #3867, Microsoft Virtual Academy video links

This page contains a broken link to deprecated video content on Microsoft Virtual Academy (MVA).

MVA is being retired. 

In addition, the Deep Dive course is already retired, and no replacement course exists.

I removed the whole _See Also_ section, as I could not find a video narrowly or deeply addressing how to protect privelaged users with Credential Guard. The most likely candidate is too short and general: https://www.linkedin.com/learning/cism-cert-prep-1-information-security-governance/privileged-account-management

* addressing broken mva links, #3817

Context:
* #3513, MVA is being retired and producing broken links
* #3817, Another broken link

This page contains two links to deprecated video content on Microsoft Virtual Academy (MVA).

MVA is being retired. 

In addition, the Deep Dive course the two links point to is already retired, and no replacement course exists.

I removed the first link, as we no longer have a video with similar content for a similar audience. The most likely candidate is https://www.linkedin.com/learning/programming-foundations-web-security-2/types-of-credential-attacks, which is more general and for a less technical audience. 

I removed the second link and the _See Also_ section, as I could not find a similar video narrowly focused on which credentials are covered by Credential Guard. Most of the related material available now describes how to perform a task.

* Update deployment-vdi-windows-defender-antivirus.md

* typo fix re: #3876; DMSA -> DSMA

* Addressing dead MVA links, #3818

This page, like its fellows in the mva-links label, contains links to a retired video course on a website that is retiring soon.

The links listed by the user in issue #3818 were also on several other pages, related to Credentials Guard. 

These links were addressed in the pull requests #3875, #3872, and #3871

Credentials threat & lateral threat link: removed (see PR #3875 for reasoning) 
Virtualization link: replaced (see #3871 for reasoning)
Credentials protected link: removed (see #3872 for reasoning)

* Adding notes for known issue in script

Solves #3869

* Updated the download link admx files Windows 10

Added link for April 2018 and Oct 2018 ADMX files.

* added event logs path

Referenced : https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard

* Update browsers/internet-explorer/ie11-deploy-guide/administrative-templates-and-ie11.md

Suggestions applied.

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update browsers/internet-explorer/ie11-deploy-guide/administrative-templates-and-ie11.md

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>

* Update deployment-vdi-windows-defender-antivirus.md

* screenshot update

* Add files via upload

* update 4 scrrenshots

* Update deployment-vdi-windows-defender-antivirus.md

* Update browsers/internet-explorer/ie11-deploy-guide/administrative-templates-and-ie11.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Update browsers/internet-explorer/ie11-deploy-guide/administrative-templates-and-ie11.md

Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com>

* Re: #3909

Top link is broken, #3909 

> The link here does not work:
> Applies to: Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)

The link to the pdf describing MDATP was broken.

Thankfully, PR #2897 updated the same link in another page some time ago, so I didn't have to go hunting for an equivalent

* CI Update

* Updated as per task 3405344

* Updated author

* Update windows-analytics-azure-portal.md

* added the example query

* Updated author fields

* Update office-csp.md

* update video for testing

* update video

* Update surface-hub-site-readiness-guide.md

line 134 Fixed  video link MD formatting

* fixing video url

* updates from Albert

* Bulk replaced author to manikadhiman

* Bulk replaced ms.author to v-madhi

* Latest content is published (#371)

* Added 1903 policy DDF link and fixed a typo

* Reverted the DDF version

* Latest update (#375)

* Update deployment-vdi-windows-defender-antivirus.md

* Update deployment-vdi-windows-defender-antivirus.md
2019-06-06 15:54:17 -07:00

14 KiB
Raw Blame History

title, description, keywords, ms.mktglfcycl, ms.sitesec, ms.prod, ms.pagetype, ms.localizationpriority, author, ms.author, ms.date, ms.reviewer, manager
title description keywords ms.mktglfcycl ms.sitesec ms.prod ms.pagetype ms.localizationpriority author ms.author ms.date ms.reviewer manager
Windows 10 configuration recommendations for education customers Provides guidance on ways to configure the OS diagnostic data, consumer experiences, Cortana, search, as well as some of the preinstalled apps, so that Windows is ready for your school. Windows 10 deployment, recommendations, privacy settings, school, education, configurations, accessibility, assistive technology plan library w10 edu medium levinec ellevin 08/31/2017 dansimp

Windows 10 configuration recommendations for education customers

Applies to:

  • Windows 10

Privacy is important to us, we want to provide you with ways to customize the OS diagnostic data, consumer experiences, Cortana, search, as well as some of the preinstalled apps, for usage with education editions of Windows 10 in education environments. These features work on all Windows 10 editions, but education editions of Windows 10 have the settings preconfigured. We recommend that all Windows 10 devices in an education setting be configured with SetEduPolicies enabled. See the following table for more information. To learn more about Microsoft's commitment to privacy, see Windows 10 and privacy.

We want all students to have the chance to use the apps they need for success in the classroom and all school personnel to have apps they need for their job. Students and school personnel who use assistive technology apps not available in the Microsoft Store for Education, and use devices running Windows 10 S, will be able to configure the device at no additional charge to Windows 10 Pro Education. To learn more about the steps to configure this, see Switch to Windows 10 Pro Education from Windows 10 Pro or Windows 10 S.

In Windows 10, version 1703 (Creators Update), it is straightforward to configure Windows to be education ready.

Area How to configure What this does Windows 10 Education Windows 10 Pro Education Windows 10 S
Diagnostic Data AllowTelemetry Sets Diagnostic Data to Basic This is already set This is already set The policy must be set
Microsoft consumer experiences SetEduPolicies Disables suggested content from Windows such as app recommendations This is already set This is already set The policy must be set
Cortana AllowCortana Disables Cortana

* Cortana is enabled by default on all editions in Windows 10, version 1703
If using Windows 10 Education, upgrading from Windows 10, version 1607 to Windows 10, version 1703 will enable Cortana.

See the Recommended configuration section below for recommended Cortana settings.
If using Windows 10 Pro Education, upgrading from Windows 10, version 1607 to Windows 10, version 1703 will enable Cortana.

See the Recommended configuration section below for recommended Cortana settings.
See the Recommended configuration section below for recommended Cortana settings.
Safe search SetEduPolicies Locks Bing safe search to Strict in Microsoft Edge This is already set This is already set The policy must be set
Bing search advertising Ad free search with Bing Disables ads when searching the internet with Bing in Microsoft Edge Depending on your specific requirements, there are different ways to configure this as detailed in Ad-free search with Bing Depending on your specific requirements, there are different ways to configure this as detailed in Ad-free search with Bing Depending on your specific requirements, there are different ways to configure this as detailed in Ad-free search with Bing
Apps SetEduPolicies Preinstalled apps like Microsoft Edge, Movies & TV, Groove, and Skype become education ready

* Any app can detect Windows is running in an education ready configuration through IsEducationEnvironment
This is already set This is already set The policy must be set

It is easy to be education ready when using Microsoft products. We recommend the following configuration:

  1. Use an Office 365 Education tenant.

    With Office 365, you also have Azure Active Directory (Azure AD). To learn more about Office 365 Education features and pricing, see Office 365 Education plans and pricing.

  2. Activate Intune for Education in your tenant.

    You can sign up to learn more about Intune for Education.

  3. On PCs running Windows 10, version 1703:

    1. Provision the PC using one of these methods:
    2. Join the PC to Azure Active Directory.
      • Use Set up School PCs or Windows Configuration Designer to bulk enroll to Azure AD.
      • Manually Azure AD join the PC during the Windows device setup experience.
    3. Enroll the PCs in MDM.
      • If you have activated Intune for Education in your Azure AD tenant, enrollment will happen automatically when the PC is joined to Azure AD. Intune for Education will automatically set SetEduPolicies to True and AllowCortana to False.
    4. Ensure that needed assistive technology apps can be used.
      • If you have students or school personnel who rely on assistive technology apps that are not available in the Microsoft Store for Education, and who are using a Windows 10 S device, configure their device to Windows 10 Pro Education to allow the download and use of non-Microsoft Store assistive technology apps. See Switch to Windows 10 Pro Education from Windows 10 Pro or Windows 10 S for more info.
  4. Distribute the PCs to students.

    Students sign in with their Azure AD/Office 365 identity, which enables single sign-on to Bing in Microsoft Edge, enabling an ad-free search experience with Bing in Microsoft Edge.

  5. Ongoing management through Intune for Education.

    You can set many policies through Intune for Education, including SetEduPolicies and AllowCortana, for ongoing management of the PCs.

Configuring Windows

You can configure Windows through provisioning or management tools including industry standard MDM.

  • Provisioning - A one-time setup process.
  • Management - A one-time and/or ongoing management of a PC by setting policies.

You can set all the education compliance areas through both provisioning and management tools. Additionally, these Microsoft education tools will ensure PCs that you set up are education ready:

AllowCortana

AllowCortana is a policy that enables or disables Cortana. It is a policy node in the Policy configuration service provider, AllowCortana.

Note

See the Recommended configuration section for recommended Cortana settings.

Use one of these methods to set this policy.

MDM

  • Intune for Education automatically sets this policy in the All devices group policy configuration.
  • If you're using an MDM provider other than Intune for Education, check your MDM provider documentation on how to set this policy.
    • If your MDM provider doesn't explicitly support this policy, you can manually set this policy if your MDM provider allows specific OMA-URIs to be manually set.

      For example, in Intune, create a new configuration policy and add an OMA-URI.

      • OMA-URI: ./Vendor/MSFT/Policy/Config/Experience/AllowCortana

      • Data type: Integer

      • Value: 0

        Create an OMA URI for AllowCortana

Group Policy

Set Computer Configuration > Administrative Templates > Windows Components > Search > AllowCortana to Disabled.

Set AllowCortana to disabled through Group Policy

Provisioning tools

SetEduPolicies

SetEduPolicies is a policy that applies a set of configuration behaviors to Windows. It is a policy node in the SharedPC configuration service provider.

Use one of these methods to set this policy.

MDM

  • Intune for Education automatically sets this policy in the All devices group policy configuration.
  • If you're using an MDM provider other than Intune for Education, check your MDM provider documentation on how to set this policy.
    • If your MDM provider doesn't explicitly support this policy, you can manually set this policy if your MDM provider allows specific OMA-URIs to be manually set.

      For example, in Intune, create a new configuration policy and add an OMA-URI.

      • OMA-URI: ./Vendor/MSFT/SharedPC/SetEduPolicies

      • Data type: Boolean

      • Value: true

        Create an OMA URI for SetEduPolices

Group Policy

SetEduPolicies is not natively supported in Group Policy. Instead, use the MDM Bridge WMI Provider to set the policy in MDM SharedPC.

For example:

  • Open PowerShell as an administrator and enter the following:

    $sharedPC = Get-CimInstance -Namespace "root\cimv2\mdm\dmmap" -ClassName "MDM_SharedPC"
    
    $sharedPC.SetEduPolicies = $True
    
    Set-CimInstance -CimInstance $sharedPC
    
    Get-CimInstance -Namespace $namespaceName -ClassName $MDM_SharedPCClass
    

Provisioning tools

Ad-free search with Bing

Provide an ad-free experience that is a safer, more private search option for K12 education institutions in the United States. Additional information is available at https://www.bing.com/classroom/about-us.

Note

If you enable the guest account in shared PC mode, students using the guest account will not have an ad-free experience searching with Bing in Microsoft Edge unless the PC is connected to your school network and your school network has been configured as described in IP registration for entire school network using Microsoft Edge.

Configurations

IP registration for entire school network using Microsoft Edge

Ad-free searching with Bing in Microsoft Edge can be configured at the network level. To configure this, email bingintheclassroom@microsoft.com with the subject "New Windows 10, version 1703 (Creators Update) Registration: [School District Name]" and the include the following information in the body of the email.

District information

  • District or School Name:
  • Outbound IP Addresses (IP Range + CIDR):
  • Address:
  • City:
  • State Abbreviation:
  • Zip Code:

Registrant information

  • First Name:
  • Last Name:
  • Job Title:
  • Email Address:
  • Opt-In for Email Announcements?:
  • Phone Number:

This will suppress ads when searching with Bing on Microsoft Edge when the PC is connected to the school network.

Azure AD and Office 365 Education tenant

To suppress ads when searching with Bing on Microsoft Edge on any network, follow these steps:

  1. Ensure your Office 365 tenant is registered as an education tenant. For more information, see Verify your Office 365 domain to prove education status.
  2. Domain join the Windows 10 PCs to your Azure AD tenant (this is the same as your Office 365 tenant).
  3. Configure SetEduPolicies according to one of the methods described in the previous sections in this topic.
  4. Have students sign in with their Azure AD identity, which is the same as your Office 365 identity, to use the PC.

Office 365 sign-in to Bing

To suppress ads only when the student signs into Bing with their Office 365 account in Microsoft Edge, follow these steps:

  1. Configure SetEduPolicies according to one of the methods described in the previous sections in this topic.
  2. Have students sign into Bing with their Office 365 account.

More information

For more information on all the possible Bing configuration methods, see https://aka.ms/e4ahor.

Deployment recommendations for school IT administrators