* Updated deployment-vdi-windows-defender-antivirus.md * Updated deployment-vdi-windows-defender-antivirus.md * Updated deployment-vdi-windows-defender-antivirus.md * updates for new vdi stuff * Adding important note to solve #3493 * Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-dir-sync.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> * Typo "<"→"<", ">"→">" https://docs.microsoft.com/en-us/windows/application-management/manage-windows-mixed-reality * Issue #2297 * Update windows/security/identity-protection/hello-for-business/hello-identity-verification.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> * Clarification * Update windows/security/identity-protection/hello-for-business/hello-identity-verification.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> * Update windows/security/identity-protection/hello-for-business/hello-identity-verification.md Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com> * update troubleshoot-np.md * update configure-endpoints-gp.md * Removing a part which is not supported * Name change * update troubleshoot-np.md * removed on-premises added -hello * Added link into Domain controller guide * Line corections * corrected formatting of xml code samples When viewing the page in Win 10/Edge, the xml code samples stretched across the page, running into the side menu. The lack of line breaks also made it hard to read. This update adds line breaks and syntax highlighting, replaces curly double quotes with standard double quotes, and adds a closing tag for <appv:appconnectiongroup>for each code sample * Update windows/security/identity-protection/hello-for-business/hello-identity-verification.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> * Update windows/deployment/update/waas-delivery-optimization-reference.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> * Update windows/deployment/update/waas-delivery-optimization-reference.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> * corrected formating of XML examples The XML samples here present the same formatting problems as in about-the-connection-group-file51.md (see https://github.com/MicrosoftDocs/windows-itpro-docs/pull/3847/) Perhaps we should open an issue to see if we have more versions of this code sample in the docs * corrected formatting of XML example section In the XML example on this page, the whitespace had been stripped out, so there were no spaces between adjacent attribute values or keys. This made it hard to read, though the original formatting allowed for a scroll bar, so the text was not running into the side of the page (compare to https://github.com/MicrosoftDocs/windows-itpro-docs/pull/3847 and https://github.com/MicrosoftDocs/windows-itpro-docs/pull/3850, where the uncorrected formatting forced the text to run into the side menu). * update configure-endpoints-gp.md * Fixed error in registry path and improved description * Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-dir-sync.md Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com> * Removing extra line in 25 Suggested by * update windows-analytics-azure-portal.md * re: broken links, credential-guard-considerations Context: * #3513, MVA is being retired and producing broken links * #3860 Microsoft Virtual Academy video links This page contains two links to deprecated video content on Microsoft Virtual Academy (MVA). MVA is being retired. In addition, the Deep Dive course the two links point to is already retired, and no replacement course exists. I removed the first link, as I could not find a similar video available describing which credentials are covered by credential guard. I replaced the second link with a video containing similar material, though it is not a "deep dive". Suggestions on handling this problem, as many pages contain similar links, would be appreciated,. * removed link to retired video re: #3867 Context: * #3513, MVA is being retired and producing broken links * #3867, Microsoft Virtual Academy video links This page contains a broken link to deprecated video content on Microsoft Virtual Academy (MVA). MVA is being retired. In addition, the Deep Dive course is already retired, and no replacement course exists. I removed the whole _See Also_ section, as I could not find a video narrowly or deeply addressing how to protect privelaged users with Credential Guard. The most likely candidate is too short and general: https://www.linkedin.com/learning/cism-cert-prep-1-information-security-governance/privileged-account-management * addressing broken mva links, #3817 Context: * #3513, MVA is being retired and producing broken links * #3817, Another broken link This page contains two links to deprecated video content on Microsoft Virtual Academy (MVA). MVA is being retired. In addition, the Deep Dive course the two links point to is already retired, and no replacement course exists. I removed the first link, as we no longer have a video with similar content for a similar audience. The most likely candidate is https://www.linkedin.com/learning/programming-foundations-web-security-2/types-of-credential-attacks, which is more general and for a less technical audience. I removed the second link and the _See Also_ section, as I could not find a similar video narrowly focused on which credentials are covered by Credential Guard. Most of the related material available now describes how to perform a task. * Update deployment-vdi-windows-defender-antivirus.md * typo fix re: #3876; DMSA -> DSMA * Addressing dead MVA links, #3818 This page, like its fellows in the mva-links label, contains links to a retired video course on a website that is retiring soon. The links listed by the user in issue #3818 were also on several other pages, related to Credentials Guard. These links were addressed in the pull requests #3875, #3872, and #3871 Credentials threat & lateral threat link: removed (see PR #3875 for reasoning) Virtualization link: replaced (see #3871 for reasoning) Credentials protected link: removed (see #3872 for reasoning) * Adding notes for known issue in script Solves #3869 * Updated the download link admx files Windows 10 Added link for April 2018 and Oct 2018 ADMX files. * added event logs path Referenced : https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard * Update browsers/internet-explorer/ie11-deploy-guide/administrative-templates-and-ie11.md Suggestions applied. Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> * Update browsers/internet-explorer/ie11-deploy-guide/administrative-templates-and-ie11.md Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> * Update deployment-vdi-windows-defender-antivirus.md * screenshot update * Add files via upload * update 4 scrrenshots * Update deployment-vdi-windows-defender-antivirus.md * Update browsers/internet-explorer/ie11-deploy-guide/administrative-templates-and-ie11.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> * Update browsers/internet-explorer/ie11-deploy-guide/administrative-templates-and-ie11.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> * Re: #3909 Top link is broken, #3909 > The link here does not work: > Applies to: Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) The link to the pdf describing MDATP was broken. Thankfully, PR #2897 updated the same link in another page some time ago, so I didn't have to go hunting for an equivalent * CI Update * Updated as per task 3405344 * Updated author * Update windows-analytics-azure-portal.md * added the example query * Updated author fields * Update office-csp.md * update video for testing * update video * Update surface-hub-site-readiness-guide.md line 134 Fixed video link MD formatting * fixing video url * updates from Albert * Bulk replaced author to manikadhiman * Bulk replaced ms.author to v-madhi * Latest content is published (#371) * Added 1903 policy DDF link and fixed a typo * Reverted the DDF version * Latest update (#375) * Update deployment-vdi-windows-defender-antivirus.md * Update deployment-vdi-windows-defender-antivirus.md
14 KiB
title, description, keywords, ms.mktglfcycl, ms.sitesec, ms.prod, ms.pagetype, ms.localizationpriority, author, ms.author, ms.date, ms.reviewer, manager
title | description | keywords | ms.mktglfcycl | ms.sitesec | ms.prod | ms.pagetype | ms.localizationpriority | author | ms.author | ms.date | ms.reviewer | manager |
---|---|---|---|---|---|---|---|---|---|---|---|---|
Windows 10 configuration recommendations for education customers | Provides guidance on ways to configure the OS diagnostic data, consumer experiences, Cortana, search, as well as some of the preinstalled apps, so that Windows is ready for your school. | Windows 10 deployment, recommendations, privacy settings, school, education, configurations, accessibility, assistive technology | plan | library | w10 | edu | medium | levinec | ellevin | 08/31/2017 | dansimp |
Windows 10 configuration recommendations for education customers
Applies to:
- Windows 10
Privacy is important to us, we want to provide you with ways to customize the OS diagnostic data, consumer experiences, Cortana, search, as well as some of the preinstalled apps, for usage with education editions of Windows 10 in education environments. These features work on all Windows 10 editions, but education editions of Windows 10 have the settings preconfigured. We recommend that all Windows 10 devices in an education setting be configured with SetEduPolicies enabled. See the following table for more information. To learn more about Microsoft's commitment to privacy, see Windows 10 and privacy.
We want all students to have the chance to use the apps they need for success in the classroom and all school personnel to have apps they need for their job. Students and school personnel who use assistive technology apps not available in the Microsoft Store for Education, and use devices running Windows 10 S, will be able to configure the device at no additional charge to Windows 10 Pro Education. To learn more about the steps to configure this, see Switch to Windows 10 Pro Education from Windows 10 Pro or Windows 10 S.
In Windows 10, version 1703 (Creators Update), it is straightforward to configure Windows to be education ready.
Area | How to configure | What this does | Windows 10 Education | Windows 10 Pro Education | Windows 10 S |
---|---|---|---|---|---|
Diagnostic Data | AllowTelemetry | Sets Diagnostic Data to Basic | This is already set | This is already set | The policy must be set |
Microsoft consumer experiences | SetEduPolicies | Disables suggested content from Windows such as app recommendations | This is already set | This is already set | The policy must be set |
Cortana | AllowCortana | Disables Cortana * Cortana is enabled by default on all editions in Windows 10, version 1703 |
If using Windows 10 Education, upgrading from Windows 10, version 1607 to Windows 10, version 1703 will enable Cortana. See the Recommended configuration section below for recommended Cortana settings. |
If using Windows 10 Pro Education, upgrading from Windows 10, version 1607 to Windows 10, version 1703 will enable Cortana. See the Recommended configuration section below for recommended Cortana settings. |
See the Recommended configuration section below for recommended Cortana settings. |
Safe search | SetEduPolicies | Locks Bing safe search to Strict in Microsoft Edge | This is already set | This is already set | The policy must be set |
Bing search advertising | Ad free search with Bing | Disables ads when searching the internet with Bing in Microsoft Edge | Depending on your specific requirements, there are different ways to configure this as detailed in Ad-free search with Bing | Depending on your specific requirements, there are different ways to configure this as detailed in Ad-free search with Bing | Depending on your specific requirements, there are different ways to configure this as detailed in Ad-free search with Bing |
Apps | SetEduPolicies | Preinstalled apps like Microsoft Edge, Movies & TV, Groove, and Skype become education ready * Any app can detect Windows is running in an education ready configuration through IsEducationEnvironment |
This is already set | This is already set | The policy must be set |
Recommended configuration
It is easy to be education ready when using Microsoft products. We recommend the following configuration:
-
Use an Office 365 Education tenant.
With Office 365, you also have Azure Active Directory (Azure AD). To learn more about Office 365 Education features and pricing, see Office 365 Education plans and pricing.
-
Activate Intune for Education in your tenant.
-
On PCs running Windows 10, version 1703:
- Provision the PC using one of these methods:
- Provision PCs with the Set up School PCs app - This will automatically set both SetEduPolicies to True and AllowCortana to False.
- Provision PCs with a custom package created with Windows Configuration Designer - Make sure to set both SetEduPolicies to True and AllowCortana to False.
- Join the PC to Azure Active Directory.
- Use Set up School PCs or Windows Configuration Designer to bulk enroll to Azure AD.
- Manually Azure AD join the PC during the Windows device setup experience.
- Enroll the PCs in MDM.
- If you have activated Intune for Education in your Azure AD tenant, enrollment will happen automatically when the PC is joined to Azure AD. Intune for Education will automatically set SetEduPolicies to True and AllowCortana to False.
- Ensure that needed assistive technology apps can be used.
- If you have students or school personnel who rely on assistive technology apps that are not available in the Microsoft Store for Education, and who are using a Windows 10 S device, configure their device to Windows 10 Pro Education to allow the download and use of non-Microsoft Store assistive technology apps. See Switch to Windows 10 Pro Education from Windows 10 Pro or Windows 10 S for more info.
- Provision the PC using one of these methods:
-
Distribute the PCs to students.
Students sign in with their Azure AD/Office 365 identity, which enables single sign-on to Bing in Microsoft Edge, enabling an ad-free search experience with Bing in Microsoft Edge.
-
Ongoing management through Intune for Education.
You can set many policies through Intune for Education, including SetEduPolicies and AllowCortana, for ongoing management of the PCs.
Configuring Windows
You can configure Windows through provisioning or management tools including industry standard MDM.
- Provisioning - A one-time setup process.
- Management - A one-time and/or ongoing management of a PC by setting policies.
You can set all the education compliance areas through both provisioning and management tools. Additionally, these Microsoft education tools will ensure PCs that you set up are education ready:
AllowCortana
AllowCortana is a policy that enables or disables Cortana. It is a policy node in the Policy configuration service provider, AllowCortana.
Note
See the Recommended configuration section for recommended Cortana settings.
Use one of these methods to set this policy.
MDM
- Intune for Education automatically sets this policy in the All devices group policy configuration.
- If you're using an MDM provider other than Intune for Education, check your MDM provider documentation on how to set this policy.
-
If your MDM provider doesn't explicitly support this policy, you can manually set this policy if your MDM provider allows specific OMA-URIs to be manually set.
For example, in Intune, create a new configuration policy and add an OMA-URI.
-
Group Policy
Set Computer Configuration > Administrative Templates > Windows Components > Search > AllowCortana to Disabled.
Provisioning tools
- Set up School PCs always sets this policy in provisioning packages it creates.
- Windows Configuration Designer
SetEduPolicies
SetEduPolicies is a policy that applies a set of configuration behaviors to Windows. It is a policy node in the SharedPC configuration service provider.
Use one of these methods to set this policy.
MDM
- Intune for Education automatically sets this policy in the All devices group policy configuration.
- If you're using an MDM provider other than Intune for Education, check your MDM provider documentation on how to set this policy.
-
If your MDM provider doesn't explicitly support this policy, you can manually set this policy if your MDM provider allows specific OMA-URIs to be manually set.
For example, in Intune, create a new configuration policy and add an OMA-URI.
-
Group Policy
SetEduPolicies is not natively supported in Group Policy. Instead, use the MDM Bridge WMI Provider to set the policy in MDM SharedPC.
For example:
-
Open PowerShell as an administrator and enter the following:
$sharedPC = Get-CimInstance -Namespace "root\cimv2\mdm\dmmap" -ClassName "MDM_SharedPC" $sharedPC.SetEduPolicies = $True Set-CimInstance -CimInstance $sharedPC Get-CimInstance -Namespace $namespaceName -ClassName $MDM_SharedPCClass
Provisioning tools
- Set up School PCs always sets this policy in provisioning packages it creates.
- Windows Configuration Designer
Ad-free search with Bing
Provide an ad-free experience that is a safer, more private search option for K–12 education institutions in the United States. Additional information is available at https://www.bing.com/classroom/about-us.
Note
If you enable the guest account in shared PC mode, students using the guest account will not have an ad-free experience searching with Bing in Microsoft Edge unless the PC is connected to your school network and your school network has been configured as described in IP registration for entire school network using Microsoft Edge.
Configurations
IP registration for entire school network using Microsoft Edge
Ad-free searching with Bing in Microsoft Edge can be configured at the network level. To configure this, email bingintheclassroom@microsoft.com with the subject "New Windows 10, version 1703 (Creators Update) Registration: [School District Name]" and the include the following information in the body of the email.
District information
- District or School Name:
- Outbound IP Addresses (IP Range + CIDR):
- Address:
- City:
- State Abbreviation:
- Zip Code:
Registrant information
- First Name:
- Last Name:
- Job Title:
- Email Address:
- Opt-In for Email Announcements?:
- Phone Number:
This will suppress ads when searching with Bing on Microsoft Edge when the PC is connected to the school network.
Azure AD and Office 365 Education tenant
To suppress ads when searching with Bing on Microsoft Edge on any network, follow these steps:
- Ensure your Office 365 tenant is registered as an education tenant. For more information, see Verify your Office 365 domain to prove education status.
- Domain join the Windows 10 PCs to your Azure AD tenant (this is the same as your Office 365 tenant).
- Configure SetEduPolicies according to one of the methods described in the previous sections in this topic.
- Have students sign in with their Azure AD identity, which is the same as your Office 365 identity, to use the PC.
Office 365 sign-in to Bing
To suppress ads only when the student signs into Bing with their Office 365 account in Microsoft Edge, follow these steps:
- Configure SetEduPolicies according to one of the methods described in the previous sections in this topic.
- Have students sign into Bing with their Office 365 account.
More information
For more information on all the possible Bing configuration methods, see https://aka.ms/e4ahor.