You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/configmgr/comanage/workloads.md
+10-2Lines changed: 10 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,9 +15,9 @@ ms.collection: highpri
15
15
16
16
# Co-management workloads
17
17
18
-
You don't have to switch the workloads, or youcan do them individually when you're ready. Configuration Manager continues to manage all other workloads, including those workloads that you don't switch to Intune, and all other features of Configuration Manager that co-management doesn't support.
18
+
You don't have to switch any of the workloads. When you're ready, you can switch them individually, several at once, or all at the same time. However, until you switch the workloads over to Intune, Configuration Manager continues to manage the workloadsthat you don't switch to Intune, along with all other features of Configuration Manager that co-management doesn't support.
19
19
20
-
If you switch a workload to Intune, but later change your mind, you can switch it back to Configuration Manager.
20
+
If you switch a workload to Intune, but later change your mind, you can switch it back to Configuration Manager, although there might be an impact. For example, Windows and Office versions will remain at a later version if installed by Intune.
21
21
22
22
Co-management supports the following workloads:
23
23
@@ -45,6 +45,9 @@ For more information on the Intune feature, see [Use compliance policies to set
45
45
46
46
Windows Update for Business policies let you configure deferral policies for Windows 10 or later feature updates or quality updates for Windows 10 or later devices managed directly by Windows Update for Business.
47
47
48
+
> [!NOTE]
49
+
> To use Windows Autopatch with these devices, this workload needs to be managed by Intune. For more information, see [Prerequisites for Windows Autopatch](/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites).
50
+
48
51
For more information on the Intune feature, see [Manage Windows software updates in Intune](../../intune/protect/windows-update-for-business-configure.md).
49
52
50
53
## Resource access policies
@@ -96,6 +99,8 @@ The device configuration workload includes settings that you manage for devices
96
99
97
100
You can still deploy settings from Configuration Manager to co-managed devices even though Intune is the device configuration authority. This exception might be used to configure settings that your organization requires but aren't yet available in Intune. Specify this exception on a [Configuration Manager configuration baseline](../compliance/deploy-use/create-configuration-baselines.md). Enable the option to **Always apply this baseline even for co-managed clients** when creating the baseline. You can change it later on the **General** tab of the properties of an existing baseline.
98
101
102
+
To use Windows Autopatch with these devices, this workload needs to be managed by Intune. For more information, see [Prerequisites for Windows Autopatch](/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites).
103
+
99
104
For more information on the Intune feature, see [Create a device profile in Microsoft Intune](../../intune/configuration/device-profile-create.md).
100
105
101
106
> [!NOTE]
@@ -125,6 +130,9 @@ Updates can be managed using either of the following features:
125
130
-[Use Update Channel and Target Version settings to update Microsoft 365 with Microsoft Intune Administrative Templates](../../intune/configuration/administrative-templates-update-office.md)
126
131
-[Manage Microsoft 365 Apps with Configuration Manager](../sum/deploy-use/manage-office-365-proplus-updates.md).
127
132
133
+
> [!NOTE]
134
+
> To use Windows Autopatch with these devices, this workload needs to be managed by Intune. For more information, see [Prerequisites for Windows Autopatch](/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites).
135
+
128
136
For more information on the Intune feature, see [Add Microsoft 365 apps to Windows devices with Microsoft Intune](../../intune/apps/apps-add-office365.md).
Copy file name to clipboardExpand all lines: memdocs/configmgr/hotfix/2207/14840616.md
-2Lines changed: 0 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,8 +40,6 @@ The "Issues that are fixed" list isn't inclusive of all changes. Instead, it hig
40
40
- Computers with updated BIOS may be duplicated in some collections. This happens because of duplicate information stored in the hardware inventory tables.
41
41
<!-- 12554467 -->
42
42
- Clients may generate excessive traffic to the Management point while downloading the WebView2 installation files. This happens after enabling the **Display custom tabs with Microsoft Edge WebView2 runtime** client setting. This update adds randomization to the WebView2 download process to reduce overall management point load.
43
-
<!-- 1261946 -->
44
-
- Discovery data for computers from untrusted domains may be marked as obsolete when they go through the client re-registration process.
45
43
<!-- 13177588 -->
46
44
- The **New-CMFolder** PowerShell cmdlet allows invalid characters as input for folder names. This prevents later modification of the folder name in the Configuration Manager console.
Copy file name to clipboardExpand all lines: memdocs/index.yml
+38-38Lines changed: 38 additions & 38 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
### YamlMime:Hub
2
-
title: Microsoft Intune technologies documentation
3
-
summary: Learn more about the Microsoft Intune technologies to help you secure, deploy, and manage users, apps, and endpoint devices.
2
+
title: Microsoft Intune product family documentation
3
+
summary: Learn more about the products & services in the Microsoft Intune product family that can help you secure, deploy, and manage users, apps, and endpoint devices.
title: Get started with the Microsoft Intune product family
40
40
items:
41
41
# Card
42
42
- title: Microsoft Intune docs
@@ -49,30 +49,29 @@ productDirectory:
49
49
summary: Configuration Manager is an on-premises and cloud-connected device management solution to manage devices, deploy apps and software updates, etc.
50
50
url: ./configmgr/index.yml
51
51
# Card
52
-
- title: Endpoint Analytics docs
53
-
imageSrc: ./media/endpoint-analytics.svg
54
-
summary: Endpoint analytics can help identify policies or hardware issues that may be slowing down devices and help you proactively make improvements before end-users generate a help desk ticket.
55
-
url: ./analytics/index.yml
56
-
# Card
57
52
- title: Windows Autopilot docs
58
53
imageSrc: ./media/autopilot.svg
59
54
summary: Windows Autopilot is a collection of technologies used to set up and pre-configure new devices, getting them ready for productive use, and to reset, repurpose, and recover devices.
60
55
url: ./autopilot/index.yml
61
56
# Card
62
-
- title: Endpoint Privilege Management docs
63
-
imageSrc: ./media/privilege.svg
64
-
summary: Remove barriers to end-user and IT productivity by elevating end-user permissions to perform specific admin actions only when needed on Windows devices.
65
-
url: ./autopilot/index.yml
57
+
- title: Windows Autopatch docs
58
+
imageSrc: ./media/autopatch.png
59
+
summary: Windows Autopatch is a cloud service that automates Windows, Microsoft 365 Apps for enterprise, Microsoft Edge, and Microsoft Teams updates to improve security and productivity across your organization.
summary: Azure Active Directory (Azure AD) is a cloud-based identity and access management service.
70
-
url: /azure/active-directory/index.yml
62
+
- title: Endpoint Analytics docs
63
+
imageSrc: ./media/endpoint-analytics.svg
64
+
summary: Endpoint analytics can help identify policies or hardware issues that may be slowing down devices and help you proactively make improvements before end-users generate a help desk ticket.
65
+
url: ./analytics/index.yml
66
+
67
+
# Card
68
+
# Card
69
+
#- title: Azure Active Directory
70
+
# imageSrc: ./media/active-directory.svg
71
+
# summary: Azure Active Directory (Azure AD) is a cloud-based identity and access management service.
72
+
# url: /azure/active-directory/index.yml
71
73
# Card
72
-
- title: Training on Microsoft Learn
73
-
imageSrc: ./media/learn.svg
74
-
summary: Learn more about Microsoft Intune, including setting up Intune, managing apps & devices, securing your endpoints, and more.
summary: Microsoft Managed Desktop is a unique ITaaS solution that combines endpoint management and security monitoring in a way that gives users a secure and productive device experience that IT pros can trust.
112
-
url: /managed-desktop/index.yml
113
-
- title: Microsoft 365 docs
114
-
summary: Find the solutions, scenarios, and resources you need to get started with Microsoft 365 for your business or organization. Microsoft 365 includes services such as Teams and SharePoint, and Microsoft 365 Apps such as Outlook, Word, Excel, and PowerPoint.
115
-
url: /microsoft-365/index.yml
116
-
- title: Office deployment docs
117
-
summary: Deploy and manage Microsoft 365 Apps or other versions of Office.
118
-
url: /deployoffice/index.yml
119
115
120
116
- title: Microsoft Intune community & support
121
117
items:
122
118
# Card
119
+
- title: Microsoft Endpoint Manager Blog
120
+
summary: Read Microsoft Endpoint Manager blog posts, including announcements, support tips, troubleshooting tips, and more.
Intune **discovered apps** is a list of detected apps on the Intune enrolled devices in your tenant. It acts as a software inventory for your tenant. **Discovered apps** is a separate report from the [app installation](apps-monitor.md) reports. For personal devices, Intune never collects information on applications that are unmanaged. On corporate devices, any app whether it is a managed app or not is collected for this report. Below is the table mapping the expected behavior. In general, the report refreshes every 7 days from the time of enrollment (not a weekly refresh for the entire tenant). The only exception to this refresh period is application information collected through the Intune Management Extension for Win32 Apps, which is collected every 24 hours.
34
+
Intune **discovered apps** is a list of detected apps on the Intune enrolled devices in your tenant. It acts as a software inventory for your tenant. **Discovered apps** is a separate report from the [app installation](apps-monitor.md) reports. For personal devices, Intune never collects information on applications that are unmanaged. On corporate devices, any app whether it is a managed app or not is collected for this report. Below is the table mapping the expected behavior. In general, the report refreshes every 7 days from the time of enrollment (not a weekly refresh for the entire tenant). The only exception to this refresh cycle for the **Discovered apps** report is application information collected through the Intune Management Extension for Win32 Apps, which is collected every 24 hours.
35
35
36
36
## Monitor discovered apps with Intune
37
37
@@ -71,6 +71,7 @@ The following list provides the app platform type, the apps that are monitored f
71
71
> - Windows 10/11 co-managed devices, as shown in the [client apps](../../configmgr/comanage/workloads.md#client-apps) workload in Configuration Manager, do not currently collect app inventory through the Intune Management Extension (IME) as per the above schedule. To mitigate this issue, the [client apps](../../configmgr/comanage/workloads.md#client-apps) workload in Configuration Manager should be switched to Intune for the IME to be installed on the device (IME is required for Win32 inventory and PowerShell deployment). Note that any changes or updates on this behavior are announced in [in development](../fundamentals/in-development.md) and/or [what's new](../fundamentals/whats-new.md).
72
72
> - Personally-owned macOS devices enrolled before November 2019 may continue to show all apps installed on the device until the devices are enrolled again.
73
73
> - Android Enterprise Fully Managed, Dedicated, and Corporate-Owned Work Profile devices do not display discovered apps.
74
+
> - For customers using a Mobile Threat Defense partner with Intune, [App Sync data](../protect/mtd-connector-enable.md) is sent to Mobile Threat Defense partners at an interval based on device check-in, and should not be confused with the refresh interval for the Discovered Apps report.
74
75
75
76
The number of discovered apps may not match the app install status count. Possibilities for inconsistencies include:
Copy file name to clipboardExpand all lines: memdocs/intune/apps/app-protection-policy-settings-android.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -57,7 +57,7 @@ There are three categories of policy settings: data protection settings, access
57
57
|<ul><b><ul><b>**Allow users to open data from selected services**|Select the application storage services that users can open data from. All other services are blocked. Selecting no services will prevent users from opening data.<br><br>Supported services:<ul><li>OneDrive for Business</li><li>SharePoint Online</li><li>Camera</li><li>Photo Library</li></ul>**Note:** Camera does not include Photos or Photo Gallery access. When selecting **Photo Library** in the **Allow users to open data from selected services** setting within Intune, you can allow managed accounts to allow *incoming* data from their device's photo library to their managed apps. |**All selected**|
58
58
|**Restrict cut, copy and paste between other apps**|Specify when cut, copy, and paste actions can be used with this app. Choose from: <ul><li>**Blocked**: Do not allow cut, copy, and paste actions between this app and any other app.</li><li>**Policy managed apps**: Allow cut, copy, and paste actions between this app and other policy-managed apps.</li><li>**Policy managed with paste in**: Allow cut or copy between this app and other policy-managed apps. Allow data from any app to be pasted into this app.</li><li>**Any app**: No restrictions for cut, copy, and paste to and from this app. |**Any app**|
59
59
|<ul><b>**Cut and copy character limit for any app**|Specify the number of characters that may be cut or copied from org data and accounts. This will allow sharing of the specified number of characters when it would be otherwise blocked by the "Restrict cut, copy, and paste with other apps" setting.<p>Default Value = 0<p>**Note**: Requires Intune Company Portal version 5.0.4364.0 or later. |**0**|
60
-
|**Screen capture and Google Assistant**|Select **Block** to block screen capture and the**Google Assistant**capabilities of the device when using this app. Choosing **Block** will also blur the App-switcher preview image when using this app with a work or school account.|**Block**|
60
+
|**Screen capture and Google Assistant**|Select **Block** to block screen capture and block**Google Assistant**accessing org data on the device when using this app. Choosing **Block** will also blur the App-switcher preview image when using this app with a work or school account.<p>**Note**: Google Assistant may be accessible to users for scenarios that do not access org data. |**Block**|
61
61
|**Approved keyboards**|Select *Require* and then specify a list of approved keyboards for this policy. <p>Users who aren't using an approved keyboard receive a prompt to download and install an approved keyboard before they can use the protected app. This setting requires the app to have the Intune SDK for Android version 6.2.0 or later. |**Not required**|
62
62
|<ul><b>**Select keyboards to approve** |This option is available when you select *Require* for the previous option. Choose *Select* to manage the list of keyboards and input methods that can be used with apps protected by this policy. You can add additional keyboards to the list, and remove any of the default options. You must have at least one approved keyboard to save the setting. Over time, Microsoft may add additional keyboards to the list for new App Protection Policies, which will require administrators to review and update existing policies as needed.<p>To add a keyboard, specify: <ul><li>**Name**: A friendly name that that identifies the keyboard, and is visible to the user. </li><li>**Package ID**: The Package ID of the app in the Google Play store. For example, if the URL for the app in the Play store is `https://play.google.com/store/details?id=com.contoskeyboard.android.prod`, then the Package ID is `com.contosokeyboard.android.prod`. This package ID is presented to the user as a simple link to download the keyboard from Google Play.</li></ul></p> <p>**Note:** A user assigned multiple App Protection Policies will be allowed to use only the approved keyboards common to all policies.</p> ||
0 commit comments