You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/analytics/app-reliability.md
+3-1Lines changed: 3 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Application reliability in endpoint analytics
3
3
description: Get details about application reliability in endpoint analytics
4
4
titleSuffix: Microsoft Endpoint Manager
5
-
ms.date: 03/01/2021
5
+
ms.date: 03/31/2022
6
6
ms.prod: configuration-manager
7
7
ms.technology: configmgr-analytics
8
8
ms.topic: conceptual
@@ -89,6 +89,8 @@ Selecting a device name opens the **Application reliability** tab for that devic
89
89
90
90
## Known issues
91
91
92
+
[!INCLUDE [Endpoint analytics export to csv value mapping known issue](includes/known-issue-csv-mapping.md)]
93
+
92
94
### Some eligible, enrolled devices aren't appearing in the report due to a client certificate issue
93
95
94
96
**Scenario**: In certain uncommon situations, devices may be missing from the **Application reliability** report. You can determine how many devices are reporting application reliability data by looking at the number of records in the table on the **Device performance** tab of the **Application reliability** report.
<!--Don't apply H2 in this include file since they are context driven by article. Used in startup-performance.md, work-from-anywhere.md, app-reliability.md, and scores.md files -->
11
+
### Exported csv files display numerical values
12
+
13
+
When reporting data is exported to a `.csv` file, the exported data doesn't use the friendly names you're used to seeing in the online reports. Use the information below to map the data in the exported file into the meaning of the value:
14
+
15
+
**Application reliability report** </br>
16
+
17
+
- The `TotalAppUsageDuration` and `MeanTimeToFailure` columns in the `.csv` file are integer values with a unit of **minutes**
18
+
- A `MeanTimeToFailure` value of 2147483647 means `No crash events`
19
+
20
+
**Per device score report** </br>
21
+
22
+
- A value of `-1` or `-2` in the `EndpointAnalyticsScore`, `StartupPerformanceScore`, and `AppReliabilityScore` columns means the associated score is unavailable
23
+
- Health status: </br>
24
+
25
+
|HealthStatus `.csv` value| Report value|
26
+
|---|---|
27
+
|0|Unknown|
28
+
|1|Insufficient data|
29
+
|2|Needs attention|
30
+
|3|Meeting goals|
31
+
32
+
**Startup performance report** </br>
33
+
34
+
The `CoreBootTime`, `GPBootTime`, `CoreLogonTime`, `GPLogonTime`, `DesktopUsableTime`, `Median`, and `TimePerProcess` columns are integer values with a unit of **seconds**.
35
+
36
+
**Work from anywhere report** </br>
37
+
- Column name in `.csv` file: UpgradeEligibility </br>
38
+
Report column name: Windows 11 readiness status </br>
39
+
40
+
|`.csv` value| Report value|
41
+
|---|---|
42
+
|0|Upgraded|
43
+
|1|Unknown|
44
+
|2|Not capable|
45
+
|3|Capable|
46
+
47
+
- Column name in `.csv` file: GraphDeviceIsManaged </br> Report column name: Azure AD registered
Copy file name to clipboardExpand all lines: memdocs/analytics/startup-performance.md
+6-2Lines changed: 6 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Startup performance in Endpoint Analytics
3
3
titleSuffix: Microsoft Endpoint Manager
4
4
description: Get details about device startup performance in Endpoint Analytics
5
-
ms.date: 11/15/2021
5
+
ms.date: 03/31/2022
6
6
ms.prod: configuration-manager
7
7
ms.technology: configmgr-analytics
8
8
ms.topic: conceptual
@@ -47,7 +47,7 @@ The **Startup performance** page also provides a prioritized list of **Insights
47
47
48
48
Startup performance provides an insight on the number of devices on which the boot drive is a hard disk. Hard disk drives typically result in boot times three to four times longer than solid-state drives. We also report the expected improvement to start up performance you would gain by moving to solid-state drives.
49
49
50
-
Click though to see the list of devices that have hard disk drives. The recommended action is to upgrade these devices to solid-state drives.
50
+
Click through to see the list of devices that have hard disk drives. The recommended action is to upgrade these devices to solid-state drives.
51
51
52
52
### <aname="bkmk_gp"></a> Group Policy
53
53
@@ -74,6 +74,10 @@ The **Startup performance** page has reporting tabs that provide support for the
74
74
-**Median delay**: The median delay time of the process for the counted devices.
75
75
-**Total delay**: The sum of the delays for all of the counted devices.
76
76
77
+
## Known issues
78
+
79
+
[!INCLUDE [Endpoint analytics export to csv value mapping known issue](includes/known-issue-csv-mapping.md)]
80
+
77
81
## Next steps
78
82
79
83
- Use the [Work from anywhere report](work-from-anywhere.md).
Copy file name to clipboardExpand all lines: memdocs/intune/configuration/device-firmware-configuration-interface-windows.md
+5-2Lines changed: 5 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: MandiOhlinger
8
8
ms.author: mandia
9
9
manager: dougeby
10
-
ms.date: 01/18/2022
10
+
ms.date: 04/04/2022
11
11
ms.topic: how-to
12
12
ms.service: microsoft-intune
13
13
ms.subservice: configuration
@@ -123,7 +123,10 @@ This profile includes the DFCI settings you configure.
123
123
-**Boot from external media (USB, SD)**: Your options:
124
124
-**Not configured**: Intune doesn't change or update this setting.
125
125
-**Enabled**: UEFI (BIOS) allows booting from non-hard drive storage.
126
-
-**Disabled**: UEFI (BIOS) doesn't allow booting from non-hard drive storage.
126
+
-**Disabled**: UEFI (BIOS) doesn't allow booting from non-hard drive storage, which also disables booting from network adapters.
127
+
128
+
When set to **Disabled**, don't set the **Boot from network adapters** setting to **Enabled**. It causes the **Boot from external media (USB, SD)** setting or **Boot from network adapters** setting to become not compliant.
129
+
127
130
-**Boot from network adapters**: Your options:
128
131
-**Not configured**: Intune doesn't change or update this setting.
129
132
-**Enabled**: UEFI (BIOS) allows booting from built-in network interfaces.
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/device-enrollment-manager-enroll.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -43,10 +43,9 @@ DEM user accounts and devices that are enrolled with a DEM user account have the
43
43
- Wipe can't be done from the Company Portal. Wiping a device enrolled by a DEM user account can be done from the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
44
44
- Only the local device appears in the Company Portal app or website.
45
45
- DEM user accounts cannot use Apple Volume Purchase Program (VPP) apps with Apple VPP user licenses because of per-user Apple ID requirements for app management.
46
-
-For all platforms, DEM accounts do not support conditional access because conditional access is intended for per-user scenarios.
47
-
- DEM accounts cannot be used when enrolling devices via Apple's Automated Device Enrollment (ADE).
46
+
-Microsoft Intune does not support the use of DEM accounts when enrolling devices via Apple Automated Device Enrollment (ADE).
47
+
- DEM accounts cannot support conditional access because conditional access is intended for per-user scenarios.
48
48
- Devices can install VPP apps if they have Apple VPP device licenses.
49
-
- On Windows 10 1709 and older, conditional access isn't available for Windows devices enrolled using bulk enrollment.
50
49
- Every device enrolled with DEM accounts needs to be properly licensed to be managed by Intune. The license could be an Intune user license or an Intune device license.
51
50
- If you're [enrolling Android Enterprise personally-owned devices with work profile](android-work-profile-enroll.md) using a DEM account, there is a limit of 10 devices that can be enrolled per account.
52
51
-[Enrolling Android Enterprise fully managed devices](android-fully-managed-enroll.md) with DEM accounts isn't supported.
@@ -63,6 +62,7 @@ You can use the following methods to enroll devices using DEM accounts:
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/device-enrollment-program-enroll-ios.md
-9Lines changed: 0 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -234,16 +234,7 @@ Now that you've installed your token, you can create an enrollment profile for A
234
234
- Won’t be evaluated for device compliance.
235
235
- Will be redirected to the Company Portal from other apps if the user tries to open any managed applications that are protected by conditional access.
236
236
237
-
7. If you selected **Company Portal** for your authentication method, you can use a VPP token to automatically install Company Portal on the device. In this case, the user doesn't have to provide an Apple ID. To install Company Portal by using a VPP token, select a token in **Install Company Portal with VPP**. You need to have already added Company Portal to the VPP token. To ensure that Company Portal continues to be updated after enrollment, make sure that you've configured an app deployment in Intune (In Endpoint Manager select **Apps** > **All apps** > **Add**).
238
237
239
-
To ensure that user interaction isn't required, you'll probably want to make Company Portal an iOS/iPadOS VPP app, make it a required app, and use device licensing for the assignment. Make sure that the token doesn't expire and that you have enough device licenses for Company Portal. If the token expires or runs out of licenses, Intune installs the App Store Company Portal instead and prompts for an Apple ID.
240
-
241
-
> [!NOTE]
242
-
> If you set the authentication method to **Company Portal**, make sure that the device enrollment process is completed within the first 24 hours of the Company Portal download to the ADE device. Otherwise enrollment might fail, and a factory reset will be needed to enroll the device.
243
-
244
-
:::image type="content" source="./media/device-enrollment-program-enroll-ios/install-cp-with-vpp.png" alt-text="Screenshot that shows the options for installing the Company Portal app with VPP.":::
245
-
246
-
For more information about connecting Intune to Apple Volume Purchase Program (VPP), see [Manage Apple volume-purchased apps](../apps/vpp-apps-ios.md). After you've connected to VPP, you can add the Company Portal app to your Apple Business Manager/Apple School Manager inventory so it can be assigned through Intune.
247
238
8. If you selected **Setup Assistant (legacy)** for the authentication method but you also want to use Conditional Access or deploy company apps on the devices, you need to install Company Portal on the devices and sign in to complete the Azure AD registration. To do so, select **Yes** for **Install Company Portal**. If you want users to receive Company Portal without having to authenticate in to the App Store, in **Install Company Portal with VPP**, select a VPP token. Make sure the token doesn't expire and that you have enough device licenses for the Company Portal app to deploy correctly.
248
239
249
240
9. If you select a token for **Install Company Portal with VPP**, you can lock the device in Single App Mode (specifically, the Company Portal app) right after the Setup Assistant completes. Select **Yes** for **Run Company Portal in Single App Mode until authentication** to set this option. To use the device, the user must first authenticate by signing in with Company Portal.
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/ios-user-enrollment.md
+3Lines changed: 3 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -54,6 +54,9 @@ For more information about the options available with User Enrollment, see [User
54
54
55
55
## Create a User Enrollment profile in Intune
56
56
57
+
> [!NOTE]
58
+
> An iOS User Enrollment profile overrides an enrollment restriction policy.
59
+
57
60
An enrollment profile defines the settings applied to a group of devices during enrollment.
58
61
59
62
1. Federate your Azure AD instance with Apple Business Manager or Apple School Manager. For more information, see [Intro to federated authentication with Apple Business Manager](https://support.apple.com/en-euro/guide/apple-business-manager/welcome/web).
0 commit comments