Skip to content

Commit 093d5f8

Browse files
authored
Merge pull request #6319 from MicrosoftDocs/main
12/7/2021 PM Publish
2 parents 31b070e + e124258 commit 093d5f8

7 files changed

Lines changed: 47 additions & 31 deletions

File tree

memdocs/intune/fundamentals/in-development.md

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -192,10 +192,7 @@ Filters allows you to include or exclude devices in policy or app assignments ba
192192
New assignment filters in Enrollment Restrictions will let you include or exclude restrictions based on device type. For example, you can allow personal devices, while blocking Windows 10 Home devices, by applying the operatingSystemSKU assignment filter. These filters will be released for public preview with a new configuration experience for enrollment restrictions and supported for Windows and Apple devices, with Android support coming at a later date. For more information about how to use filters, see [Create a filter](../fundamentals/filters.md).
193193

194194
<!-- vvvvvvvvvvvvvvvvvvvvvv -->
195-
## Monitor and troubleshoot
196-
197-
### Adding event viewer for Windows 10 diagnostics<!-- 10741116 -->
198-
We're adding a new event viewer to Windows 10 device diagnostics called Microsoft-Windows-Windows Firewall with Advanced Security/Firewall. The event viewer will assist you in troubleshooting issues with the firewall.
195+
## Monitor and troubleshoot
199196

200197
### Account protection policy changes in Endpoint security<!-- 7492116 -->
201198

memdocs/intune/fundamentals/whats-new.md

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: Erikre
88
ms.author: erikre
99
manager: dougeby
10-
ms.date: 12/01/2021
10+
ms.date: 12/07/2021
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: fundamentals
@@ -60,7 +60,15 @@ You can use RSS to be notified when this page is updated. For more information,
6060
### Scripts
6161
-->
6262

63-
## Week of November 22, 2021
63+
64+
## Week of December 6, 2021
65+
66+
### Monitor and troubleshoot
67+
68+
#### New event viewer for Windows 10 diagnostics <!-- 10741116 -->
69+
We've added a new event viewer to Windows device diagnostics called *Microsoft-Windows-Windows Firewall with Advanced Security/Firewall*. The event viewer can assist you in troubleshooting issues with the firewall. For more information about Windows device diagnostics, see [Collect diagnostics from a Windows device](../remote-actions/collect-diagnostics.md).
70+
71+
## Week of November 22, 2021
6472

6573
<!-- vvvvvvvvvvvvvvvvvvvvvv -->
6674

memdocs/intune/protect/certificate-connector-install.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -101,7 +101,7 @@ Use the following procedure to both configure a new connector and modify a previ
101101
- **SYSTEM**
102102
- **Domain user account** – Use any domain user account that is an administrator on the Windows Server.
103103

104-
4. On the *Proxy* page, add details for your proxy server if you require a proxy for internet access. For example, *http://proxy.contoso.com*.
104+
4. On the *Proxy* page, add details for your proxy server if you require a proxy for internet access. For example, `http://proxy.contoso.com`.
105105

106106
5. On the *Prerequisites* page, the wizard runs several checks on the server before the configuration can begin. Review and resolve any errors or warnings before you continue.
107107

memdocs/intune/protect/device-compliance-partners.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -139,7 +139,7 @@ Sign in to the Azure portal and go to **Azure AD** > **Devices** > [**All device
139139

140140
Use additional documentation from your third-party partner to create compliance policies for devices.
141141

142-
- [Blackberry UEM](https://docs.blackberry.com/en/endpoint-management/blackberry-uem/12_15/installation-configuration/cloud-configuration/get15233768326701/Configure-Azure-AD-Conditional-Access)
142+
- [Blackberry UEM](https://docs.blackberry.com/en/id-comm-collab/blackberry-workspaces/blackberry-workspaces-plug-in-for-blackberry-uem/4_9/compatibility-matrix/imm1460398825659/ioz1460399956336)
143143
- [Citrix Endpoint Management - Integrate with Azure AD Conditional Access](https://docs.citrix.com/en-us/citrix-endpoint-management/prepare-to-enroll-devices-and-deliver-resources.html#integrate-with-azure-ad-conditional-access)
144144
- [MobileIron Device Compliance Cloud](https://forums.ivanti.com/s/article/MobileIron-Cloud-Azure-Device-Compliance-for-iOS-and-Android)
145145
- [VMware Workspace ONE UEM](https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/services/Directory_Service_Integration/GUID-800FB831-AA66-4094-8F5A-FA5899A3C70C.html)

memdocs/intune/protect/windows-10-feature-updates.md

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: brenduns
88
ms.author: brenduns
99
manager: dougeby
10-
ms.date: 10/04/2021
10+
ms.date: 12/07/2021
1111
ms.topic: how-to
1212
ms.service: microsoft-intune
1313
ms.subservice: protect
@@ -102,7 +102,17 @@ The following are prerequisites for Intune's Feature updates for Windows 10 and
102102

103103
- If you co-manage devices with Configuration Manager, feature updates policies might not immediately take effect on devices when you newly configure the [Windows Update policies workload](../../configmgr/comanage/workloads.md#windows-update-policies) to Intune. This delay is temporary but can initially result in devices updating to a later feature update version than is configured in the policy.
104104

105-
To prevent this initial delay from impacting your co-managed devices, configure a [Feature updates for Windows 10 and later](../protect/windows-10-feature-updates.md) policy and target the policy to your devices before you configure them for co-management or you shift the Windows Update workload to Intune. You can validate whether a device is enrolled for the feature update profile by checking the [Windows feature update report](../protect/windows-update-compliance-reports.md#use-the-windows-10-and-later-feature-updates-organizational-report) under the Reporting node in the Microsoft Endpoint Management admin console.
105+
To prevent this initial delay from impacting your co-managed devices:
106+
107+
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
108+
2. Go to **Devices** > **Windows** > **Feature updates for Windows 10 and later** > **Create profile**.
109+
3. For **Deployment settings**, enter a meaningful name and a description for the policy. Then, Specify the feature update you want devices to be running.
110+
4. Complete the policy configuration, including assigning the policy to devices. The policy deploys to devices, though any device that already has the version you’ve selected, or a newer version, won’t be offered the update.
111+
112+
Monitor the report for the policy. To do so, go to **Reports** > **Windows Updates** > **Reports** Tab > **Feature Updates report**. Select the policy you created and then generate the report.
113+
114+
5. Devices that have a state of *OfferReady* or later, are enrolled for feature updates and protected from updating to anything newer than the update you specified in step 3. See, [Use the Windows 10 and later feature updates (Organizational) report](../protect/windows-update-compliance-reports.md#use-the-windows-10-and-later-feature-updates-organizational-report).
115+
6. With devices enrolled for updates and protected, you can safely change the *Windows Update policies* workload from Configuration Manager to Intune. See, [Switch workloads to Intune](/configmgr/comanage/how-to-switch-workloads) in the co-management documentation.
106116

107117
- When the device checks in to the Windows Update service, the device's group membership is validated against the security groups assigned to the feature updates policy settings for any feature update holds.
108118

memdocs/intune/remote-actions/collect-diagnostics.md

Lines changed: 19 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ keywords:
88
author: brenduns
99
ms.author: brenduns
1010
manager: dougeby
11-
ms.date: 09/27/2021
11+
ms.date: 12/07/2021
1212
ms.topic: how-to
1313
ms.service: microsoft-intune
1414
ms.subservice: remote-actions
@@ -67,13 +67,13 @@ Registry Keys:
6767

6868
1. HKLM\Software\Microsoft\IntuneManagementExtension
6969
2. HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
70-
3. HKLM\SOFTWARE\Microsoft\Windows Endpoint
70+
3. HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection
7171
4. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI
7272
5. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
7373
6. HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall
7474
7. HKLM\Software\Policies
7575
8. HKLM\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL
76-
9. HKLM\SOFTWARE\Policies\Microsoft\Windows Endpoint
76+
9. HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection
7777
10. HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
7878
11. HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL
7979

@@ -107,24 +107,25 @@ Event Viewers:
107107
34. Microsoft-Windows-HelloForBusiness/Operational
108108
35. Microsoft-Windows-SENSE/Operational
109109
36. Microsoft-Windows-SenseIR/Operational
110-
37. Setup
111-
38. System
110+
37. Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
111+
38. Setup
112+
39. System
112113

113114
Files:
114115

115-
39. %ProgramData%\Microsoft\DiagnosticLogCSP\Collectors\*.etl
116-
40. %ProgramData%\Microsoft\IntuneManagementExtension\Logs\*.*
117-
41. %ProgramData%\Microsoft\Windows Defender\Support\MpSupportFiles.cab
118-
42. %ProgramData%\Microsoft\Windows\WlanReport\wlan-report-latest.html
119-
43. %temp%\MDMDiagnostics\battery-report.html
120-
44. %temp%\MDMDiagnostics\energy-report.html
121-
45. %temp%\MDMDiagnostics\mdmlogs-<Date/Time>.cab
122-
46. %temp%\MDMDiagnostics\msinfo32.log
123-
47. %windir%\ccm\logs\*.log
124-
48. %windir%\ccmsetup\logs\*.log
125-
49. %windir%\logs\CBS\cbs.log
126-
50. %windir%\logs\measuredboot\*.*
127-
51. %windir%\Logs\WindowsUpdate\*.etl
116+
40. %ProgramData%\Microsoft\DiagnosticLogCSP\Collectors\*.etl
117+
41. %ProgramData%\Microsoft\IntuneManagementExtension\Logs\*.*
118+
42. %ProgramData%\Microsoft\Windows Defender\Support\MpSupportFiles.cab
119+
43. %ProgramData%\Microsoft\Windows\WlanReport\wlan-report-latest.html
120+
44. %temp%\MDMDiagnostics\battery-report.html
121+
45. %temp%\MDMDiagnostics\energy-report.html
122+
46. %temp%\MDMDiagnostics\mdmlogs-<Date/Time>.cab
123+
47. %temp%\MDMDiagnostics\msinfo32.log
124+
48. %windir%\ccm\logs\*.log
125+
49. %windir%\ccmsetup\logs\*.log
126+
50. %windir%\logs\CBS\cbs.log
127+
51. %windir%\logs\measuredboot\*.*
128+
52. %windir%\Logs\WindowsUpdate\*.etl
128129

129130
## Disable device diagnostics
130131

memdocs/intune/remote-actions/remote-help.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: brenduns
88
ms.author: brenduns
99
manager: dougeby
10-
ms.date: 12/03/2021
10+
ms.date: 12/07/2021
1111
ms.topic: how-to
1212
ms.service: microsoft-intune
1313
ms.subservice: remote-actions
@@ -181,7 +181,7 @@ To configure your tenant to support remote help, review and complete the followi
181181

182182
2. On the **Settings** tab:
183183
1. Set **Enable remote help** to **Enabled** to allow use of remote help. By default, this setting is *Enabled*.
184-
2. Set **Allow remote help to unenrolled devices** to **Enabled** if you want to allow this option. By default, this setting *Not allowed*.
184+
2. Set **Allow remote help to unenrolled devices** to **Enabled** if you want to allow this option. By default, this setting *Disabled*.
185185

186186
3. Select **Save**.
187187

@@ -232,7 +232,7 @@ To request help, you must reach out to your support staff to request assistance.
232232
233233
As a sharer, when you’ve requested help and both you and the helper are ready to start:
234234

235-
1. Start the remote help app on the device and sign-in to authenticate to your organization. The device might not need to be enrolled to Intune if your administrator allows you to get help on unenrolled devices.
235+
1. Start the remote help app on the device and sign in to authenticate to your organization. The device might not need to be enrolled to Intune if your administrator allows you to get help on unenrolled devices.
236236

237237
2. After signing into the app, get the security code from the individual assisting you and enter that code below *Get Help*, and then select **Submit**.
238238

0 commit comments

Comments
 (0)