Skip to content

Commit 01363ed

Browse files
author
Angela Fleischmann
authored
Merge pull request #7189 from ChristianMontoya/patch-4
New FAQ item for device compliance policies and Cloud PCs
2 parents f27354c + b8a8495 commit 01363ed

1 file changed

Lines changed: 20 additions & 2 deletions

File tree

windows-365/enterprise/known-issues-enterprise.md

Lines changed: 20 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ A [resize](resize-cloud-pc.md) of a Cloud PC eliminates all existing [restore](r
4040

4141
## Windows doesn’t scan for software updates until the first time a user signs in<!--38212344-->
4242

43-
While a Windows PC (physical or Cloud PC) sits idle before the first user signs in, Windows Update doesn’t scan for or install monthly quality patches. This means that the PC might miss important security updates. Without the latest security updates, the device is exposed to security vulnerabilities.
43+
While a Windows PC (physical or Cloud PC) sits idle before the first user signs in, Windows Update doesn’t scan for or install monthly quality patches. This means that the PC might miss important security updates. Without the latest security updates, the device is exposed to security vulnerabilities.
4444

4545
**Troubleshooting steps**: Make sure that a user signs in to new Cloud PCs as soon as possible.
4646

@@ -51,7 +51,7 @@ Windows 365 provisioning failures may occur because both:
5151
- the Desired State Configuration (DSC) extension isn't signed and
5252
- the PowerShell Execution policy is set to Allsigned in the Group Policy Object (GPO)
5353

54-
**Troubleshooting steps**: Follow these steps:
54+
**Troubleshooting steps**:
5555

5656
1. Did the on-premises network connection (OPNC) fail with the following error: `"An internal error occurred. The virtual machine deployment timed out."`?
5757
2. If yes, review the related GPO. Is PowerShell Execution set to AllSigned?
@@ -64,6 +64,24 @@ Only the default Enrollment Status Page (ESP) profile is supported for Windows 3
6464

6565
For default ESP profiles, when using hybrid Azure Active Directory (Azure AD) Join, you must set the **Only show page to devices provisioned by out-of-box experience (OOBE)** setting to **No**.
6666

67+
## Cloud PC reports as not compliant for compliance policy
68+
69+
The following device compliance settings report as **Not applicable** when being evaluated for a Cloud PC:
70+
71+
- **Trusted Platform Module (TPM)**
72+
- **Require encryption of data storage on device.**
73+
74+
The following device compliance settings report as **Not Compliant** when being evaluated for a Cloud PC:
75+
76+
- **Require BitLocker**
77+
- **Require Secure Boot to be enabled on the device.**
78+
79+
**Troubleshooting steps**:
80+
81+
1. [Create a filter for all Cloud PCs](create-filter.md#create-a-filter-for-all-cloud-pcs).
82+
2. For any existing device compliance policies that both evaluate to a Cloud PC and contain either of the **Not Compliant** settings, use this new filter to exclude Cloud PCs from the policy assignment.
83+
3. Create a new device compliance policy without either of the **Not Compliant** settings and use this new filter to include Cloud PCs for the policy assignment.
84+
6785
## Next steps
6886

6987
[Troubleshoot Windows 365 Enterprise Cloud PC](troubleshooting.md)

0 commit comments

Comments
 (0)