You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/configuration/settings-catalog.md
+21-13Lines changed: 21 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: MandiOhlinger
8
8
ms.author: mandia
9
9
manager: dougeby
10
-
ms.date: 08/15/2022
10
+
ms.date: 09/20/2022
11
11
ms.topic: how-to
12
12
ms.service: microsoft-intune
13
13
ms.subservice: configuration
@@ -79,11 +79,11 @@ For information on some features you can configure using the settings catalog, g
79
79
80
80
For example, select **Windows 10 and later**, then select **Authentication** to see all the settings in this category:
81
81
82
-
:::image type="content" source="./media/settings-catalog/settings-picker-authentication.png" alt-text="In Settings Catalog, select Windows and select Authentication in Microsoft Intune and Endpoint Manager admin center.":::
82
+
:::image type="content" source="./media/settings-catalog/settings-picker-authentication.png" alt-text="Screenshot that shows the Settings Catalog when you select Windows and Authentication in Microsoft Intune and Endpoint Manager admin center.":::
83
83
84
84
For example, select **macOS**. The **Microsoft Edge - All** category lists all the settings you can configure, including any new settings. The other categories include settings that are obsolete, or settings that apply to older versions:
85
85
86
-
:::image type="content" source="./media/settings-catalog/macos-settings-picker-edge-all.png" alt-text="In Settings Catalog, select macOS, and select a feature or category in Microsoft Intune and Endpoint Manager admin center.":::
86
+
:::image type="content" source="./media/settings-catalog/macos-settings-picker-edge-all.png" alt-text="Screenshot that shows the Settings Catalog when you select macOS and select a feature or category in Microsoft Intune and Endpoint Manager admin center.":::
87
87
88
88
> [!TIP]
89
89
>
@@ -93,11 +93,11 @@ For information on some features you can configure using the settings catalog, g
93
93
94
94
8. Select any setting you want to configure. Or, choose **Select all these settings**:
95
95
96
-
:::image type="content" source="./media/settings-catalog/settings-picker-select-all-settings.png" alt-text="In Settings Catalog, select all these settings in Microsoft Intune and Endpoint Manager admin center.":::
96
+
:::image type="content" source="./media/settings-catalog/settings-picker-select-all-settings.png" alt-text="Screenshot that shows the settings when you select all these settings in Microsoft Intune and Endpoint Manager admin center.":::
97
97
98
98
After you add your settings, close the settings picker. All the settings are shown, and configured with a default value, such as **Block** or **Allow**. These defaults values are the same default values in the OS. If you don't want to configure a setting, then select the minus:
99
99
100
-
:::image type="content" source="./media/settings-catalog/default-setting-value-minus-not-configured.png" alt-text="In Settings Catalog, the default value in Microsoft Intune and Endpoint Manager admin center is the same as the OS default value.":::
100
+
:::image type="content" source="./media/settings-catalog/default-setting-value-minus-not-configured.png" alt-text="Screenshot that shows the Settings Catalog and that the default values in Microsoft Intune and Endpoint Manager admin center are the same as the OS default values.":::
101
101
102
102
When you select the minus (`-`):
103
103
@@ -129,15 +129,21 @@ There are thousands of settings available in the settings catalog. To make it ea
129
129
130
130
For example, search for `internet explorer`. All the settings with `internet explorer` are shown. Select a category to see the available settings:
131
131
132
-
:::image type="content" source="./media/settings-catalog/search-internet-explorer.png" alt-text="In Settings Catalog, search for Internet Explorer to see all the settings in Microsoft Intune and Endpoint Manager admin center.":::
132
+
:::image type="content" source="./media/settings-catalog/search-internet-explorer.png" alt-text="Screenshot that shows the Settings Catalog when you search for Internet Explorer to see all the IE settings in Microsoft Intune and Endpoint Manager admin center.":::
133
133
134
-
- In your policy, use **Add settings** > **Add filter**. Select the key, operator, and value. In **value**, you can filter to only show the settings that apply to Holographic for Business, Windows Enterprise, and other editions:
134
+
- In your policy, use **Add settings** > **Add filter**. Select the key, operator, and value.
135
135
136
-
:::image type="content" source="./media/settings-catalog/settings-picker-filter-edition.png" alt-text="In Settings Catalog, filter the settings list by Windows edition in Microsoft Intune and Endpoint Manager admin center.":::
136
+
When you **filter on OS Edition**, you can filter the settings that apply to specific Windows editions:
137
+
138
+
:::image type="content" source="./media/settings-catalog/settings-picker-filter-edition.png" alt-text="Screenshot that shows the Settings Catalog when you filter the settings list by Windows edition in Microsoft Intune and Endpoint Manager admin center.":::
137
139
138
140
> [!NOTE]
139
141
> For the Edge, Office, and OneDrive settings, the OS version or edition doesn't determine if the settings apply. So, if you filter to a specific edition, like Windows Professional, then the Edge, Office, and OneDrive settings aren't shown.
140
142
143
+
You can also **filter the settings by device or user scope**. For more information on user scope and device scope, go to [Device scope vs. user scope settings](#device-scope-vs-user-scope-settings) (in this article):
144
+
145
+
:::image type="content" source="./media/settings-catalog/settings-picker-filter-scope.png" alt-text="Screenshot that shows the user and device scope filter in the settings catalog in Microsoft Intune and Endpoint Manager admin center.":::
146
+
141
147
## Copy a profile
142
148
143
149
Select **Duplicate** to create a copy of an existing profile. Duplicating is useful when you need a profile that's similar yet distinct from the original one. The copy contains the same setting configurations and scope tags as the original profile, but doesn't have assignments attached to it. After you give the new profile a name, you can edit the profile to adjust the settings and add assignments.
@@ -154,15 +160,15 @@ You create the policy, and assign it to your groups. In the Endpoint Manager adm
154
160
155
161
1. In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Devices** > **Device configuration profiles**. In the list, select the policy you created using the Settings Catalog. The **Profile type** column shows **Settings Catalog**:
156
162
157
-
:::image type="content" source="./media/settings-catalog/profile-type-shows-settings-catalog.png" alt-text="In Microsoft Intune and Endpoint Manager admin center, the profile type shows Settings Catalog.":::
163
+
:::image type="content" source="./media/settings-catalog/profile-type-shows-settings-catalog.png" alt-text="Screenshot that shows how to open the settings catalog in Microsoft Intune and Endpoint Manager admin center.":::
158
164
159
165
2. When you select the policy, the device status shows. It shows a summary of your policy state and the policy properties. You can also change or update your policy in the **Configuration settings** section:
160
166
161
-
:::image type="content" source="./media/settings-catalog/settings-catalog-policy-device-status-report.png" alt-text="Select the settings catalog policy to see the device status, policy state, and properties in Microsoft Intune and Endpoint Manager admin center.":::
167
+
:::image type="content" source="./media/settings-catalog/settings-catalog-policy-device-status-report.png" alt-text="Screenshot that shows how to select the settings catalog policy to see the device status, policy state, and properties in Microsoft Intune and Endpoint Manager admin center.":::
162
168
163
169
3. Select **View report**. The report shows detailed information, including the device name, the policy status, and more. You can also filter on the deployment status, and **Export** the report to a `.csv` file:
164
170
165
-
:::image type="content" source="./media/settings-catalog/settings-catalog-policy-view-report.png" alt-text="See detailed report information in Microsoft Intune and Endpoint Manager admin center, including device name, policy status, and more.":::
171
+
:::image type="content" source="./media/settings-catalog/settings-catalog-policy-view-report.png" alt-text="Screenshot that shows how to see detailed report information in Microsoft Intune and Endpoint Manager admin center, including device name, policy status, and more." lightbox="./media/settings-catalog/settings-catalog-policy-view-report.png":::
166
172
167
173
4. You can also look at the states of each setting using the **per-setting status**. This status shows the total number of devices affected by each setting in the policy.
168
174
@@ -190,9 +196,9 @@ Conflicts happen when the same setting is updated to different values. Conflicts
190
196
191
197
When you create the policy, you have two policy types: **Settings catalog** and **Templates**:
192
198
193
-
:::image type="content" source="./media/settings-catalog/select-windows-policy-type.png" alt-text="When you create a Windows or macOS policy, select settings catalog or templates in Microsoft Intune and Endpoint Manager admin center.":::
199
+
:::image type="content" source="./media/settings-catalog/select-windows-policy-type.png" alt-text="Screenshot that shows when you create a Windows or macOS policy, select settings catalog or templates in Microsoft Intune and Endpoint Manager admin center.":::
194
200
195
-
The **Templates** include a logical group of settings, such as device restrictions, kiosk, and more. Use this option if you want to use these groupings to configure your settings.
201
+
The **Templates** include a logical group of settings, such as kiosk, VPN, Wi-Fi, and more. Use this option if you want to use these groupings to configure your settings.
196
202
197
203
The **Settings catalog** lists all the available settings. If you want to see all the available Firewall settings, or all the available BitLocker settings, then use this option. Also, use this option if you're looking for specific settings.
198
204
@@ -204,6 +210,8 @@ For more information on user scope and device scope, see the [Policy CSP](/windo
204
210
205
211
Device and user groups are used when you assign your policies. Device and user scopes describe how a policy is enforced.
206
212
213
+
### Scope assignment behavior
214
+
207
215
When deploying policy from Intune, you can assign user scope or device scope to any type of target group. Behavior of the policy per user depends on the scope of the setting:
208
216
209
217
- User scoped policy writes to `HKEY_CURRENT_USER (HKCU)`.
Copy file name to clipboardExpand all lines: memdocs/intune/protect/certificates-profile-scep.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -131,7 +131,7 @@ Devices that run Android Enterprise might require a PIN before SCEP can provisio
131
131
-**CN={{UserName}}**: The user name of the user, such as janedoe.
132
132
-**CN={{UserPrincipalName}}**: The user principal name of the user, such as [email protected].
133
133
-**CN={{AAD_Device_ID}}**: An ID assigned when you register a device in Azure Active Directory (AD). This ID is typically used to authenticate with Azure AD.
134
-
-**CN={{DeviceId}}**: An ID assigned when you enroll a device in Intune.*(not supported on Android Enterprise for Fully Managed, Dedicated, and Corporate-Owned Work Profile)*
134
+
-**CN={{DeviceId}}**: An ID assigned when you enroll a device in Intune.
135
135
-**CN={{SERIALNUMBER}}**: The unique serial number (SN) typically used by the manufacturer to identify a device.
136
136
-**CN={{IMEINumber}}**: The International Mobile Equipment Identity (IMEI) unique number used to identify a mobile phone.
137
137
-**CN={{OnPrem_Distinguished_Name}}**: A sequence of relative distinguished names separated by comma, such as *CN=Jane Doe,OU=UserAccounts,DC=corp,DC=contoso,DC=com*.
@@ -157,7 +157,7 @@ Devices that run Android Enterprise might require a PIN before SCEP can provisio
157
157
Format options for the Subject name format include the following variables:
158
158
159
159
-**{{AAD_Device_ID}}** or **{{AzureADDeviceId}}** - Either variable can be used to identify a device by its Azure AD ID.
160
-
-**{{DeviceId}}** - The Intune device ID*(not supported on Android Enterprise for Fully Managed, Dedicated, and Corporate-Owned Work Profile)*
Copy file name to clipboardExpand all lines: memdocs/intune/protect/includes/security-config-mgt-prerequisites.md
+2-7Lines changed: 2 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: include file
4
4
author: brenduns
5
5
ms.service: microsoft-intune
6
6
ms.author: brenduns
7
-
ms.date: 05/12/2022
7
+
ms.date: 09/12/2022
8
8
ms.topic: include
9
9
---
10
10
## Prerequisites
@@ -123,13 +123,8 @@ To support Microsoft Defender for Endpoint security configuration management thr
123
123
> [!TIP]
124
124
> Use pilot mode and the proper device tags to test and validate your rollout on a small number of devices. Without using pilot mode, any device that falls into the scope configured will automatically be enrolled.
125
125
126
-
1. Make sure the relevant users have permissions to manage endpoint security settings in Microsoft Endpoint Manager or grant those permissions by configuring a role in the Microsoft 365 Defender portal. Go to **Settings** > **Roles** > **Add item**:
127
-
:::image type="content" source="../media/mde-security-integration/add-role-in-mde.png" alt-text="Create a new role in the Defender portal.":::
128
-
> [!TIP]
129
-
> You can modify existing roles and add the necessary permissions versus creating additional roles in Microsoft Defender for Endpoint
130
-
1. When configuring the role, add users and be sure to select **Manage endpoint security settings in Microsoft Endpoint Manager**:
126
+
1. Make sure the relevant users have permissions to manage endpoint security settings in Microsoft Endpoint Manager. If not already provided, request for your IT administrator to grant applicable users the Microsoft Endpoint Manager’s **Endpoint Security Manager**[built-in RBAC role](/mem/intune/fundamentals/role-based-access-control).
131
127
132
-
:::image type="content" source="../media/mde-security-integration/add-role.png" alt-text="Grant users permissions to manage settings.":::
133
128
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
134
129
1. Select **Endpoint security** > **Microsoft Defender for Endpoint**, and set **Allow Microsoft Defender for Endpoint to enforce Endpoint Security Configurations** to **On**.
Copy file name to clipboardExpand all lines: windows-365/enterprise/health-checks.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -64,7 +64,7 @@ Every failed ANC or success with warning error state includes the technical deta
64
64
-**First party app permissions exist on Azure virtual network**: Sufficient permissions exist on the Azure vNet.
65
65
-**Environment and configuration is ready**: Underlying infrastructure is ready for provisioning to succeed.
66
66
-**Intune enrollment restrictions allow Windows enrollment**: Verify that Intune enrollment restrictions are configured to allow Windows enrollment.
67
-
-**Localization language package readiness**: Verify that the operating system and Microsoft 365 language packages can install. Also verify that the localization package download link is reachable.
67
+
-**Localization language package readiness**: Verify that the operating system and Microsoft 365 language packages are reachable. Also verify that the localization package download link is reachable.
0 commit comments