Skip to content

Commit 2409783

Browse files
authored
Merge pull request #6287 from MicrosoftDocs/main
12/3/2021 PM Publish
2 parents aa8494a + cddb2bd commit 2409783

9 files changed

Lines changed: 47 additions & 58 deletions

File tree

memdocs/analytics/proactive-remediations.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ In this tutorial, you learn how to:
3131

3232
Proactive remediations are script packages that can detect and fix common support issues on a user's device before they even realize there's a problem. These remediations can help reduce support calls. You can create your own script package, or deploy one of the script packages we've written and used in our environment for reducing support tickets.
3333

34-
Each script package consists of a detection script, a remediation script, and metadata. Through Intune, you can deploy these script packages and see reports on their effectiveness. We're actively developing new script packages and would like to know your experiences using them.
34+
Each script package consists of a detection script, a remediation script, and metadata. Through Intune, you can deploy these script packages and see reports on their effectiveness.
3535

3636
## <a name="bkmk_prereq"></a> Prerequisites
3737

memdocs/configmgr/apps/deploy-use/packages-and-programs.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -119,9 +119,9 @@ Packages can use some new features of Configuration Manager, including distribut
119119

120120
- **Runs with UNC name**: Specify that the program runs with a Universal Naming Convention (UNC) name. This setting is the default.
121121

122-
- **Requires drive letter**: Specify that the program requires a drive letter to fully qualify its location. For this setting, Configuration Manager can use any available drive letter on the client.
122+
- **Requires drive letter**: Specify that the program requires a drive letter to fully qualify its location. For this setting, Configuration Manager can use any available drive letter on the client. This setting requires the deployment to use the Deployment option **Run program from distribution point** and the package's Data Access option enabled to **Copy the content in this package to a package share on distribution points**.
123123

124-
- **Requires specific drive letter**: Specify that the program requires a specific drive letter that you specify to fully qualify its location. For example, **Z:**. If the client is already using the specified drive letter, the program doesn't run.
124+
- **Requires specific drive letter**: Specify that the program requires a specific drive letter that you specify to fully qualify its location. For example, **Z:**. If the client is already using the specified drive letter, the program doesn't run. This setting requires the deployment to use the Deployment option **Run program from distribution point** and the package's Data Access option enabled to **Copy the content in this package to a package share on distribution points**.
125125

126126
- **Reconnect to distribution point at log on**: Indicate whether the client reconnects to the distribution point when the user signs in. By default, the wizard doesn't enable this option.
127127

memdocs/intune/enrollment/android-enroll.md

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -58,8 +58,10 @@ For Samsung Knox Standard devices, there are [more prerequisites](android-samsun
5858

5959
## Next steps
6060

61-
- [Set up Android Enterprise personally-owned work profile enrollments](android-work-profile-enroll.md)
62-
- [Set up Android Enterprise dedicated device enrollments](android-kiosk-enroll.md)
63-
- [Set up Android Enterprise fully managed enrollments](android-fully-managed-enroll.md)
61+
- [Set up Android Enterprise personally-owned work profile enrollment](android-work-profile-enroll.md)
62+
- [Set up Android Enterprise dedicated device enrollment](android-kiosk-enroll.md)
63+
- [Set up Android Enterprise fully managed enrollment](android-fully-managed-enroll.md)
6464
- [Set up Android device administrator enrollment](android-enroll-device-administrator.md)
6565
- [Set up Android Enterprise corporate-owned work profile](android-corporate-owned-work-profile-enroll.md)
66+
- [Set up Android (AOSP) corporate-owned user-associated enrollment](android-aosp-corporate-owned-user-associated-enroll.md)
67+
- [Set up Android (AOSP) corporate-owned userless enrollment](android-aosp-corporate-owned-userless-enroll.md)

memdocs/intune/enrollment/device-enrollment.md

Lines changed: 13 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ keywords:
88
author: Lenewsad
99
ms.author: lanewsad
1010
manager: dougeby
11-
ms.date: 4/24/2021
11+
ms.date: 12/03/2021
1212
ms.topic: overview
1313
ms.service: microsoft-intune
1414
ms.subservice: enrollment
@@ -43,9 +43,9 @@ By default, devices for all platforms are allowed to enroll in Intune. However,
4343

4444
## iOS/iPadOS enrollment methods
4545

46-
| **Method** | **Reset Required** | [**User Affinity**](device-enrollment-program-enroll-ios.md#create-an-apple-enrollment-profile) | **Locked** | **Details** |
46+
| **Method** | **Reset required** | **User affinity** | **Locked** | **Details** |
4747
|:---:|:---:|:---:|:---:|:---:|
48-
| | Devices are wiped during enrollment. | Associates each device with a user.| If yes, users can't unenroll devices. | |
48+
|Method used to enroll devices. |If yes, devices are wiped during enrollment. | If yes, each device is associated with a user.| If yes, users can't unenroll devices. |More information about method. |
4949
|**[BYOD](#bring-your-own-device)** | No| Yes | No | [More information](apple-mdm-push-certificate-get.md)|
5050
|**[DEM](#device-enrollment-manager)**| No |No |No | [More information](device-enrollment-manager-enroll.md)|
5151
|**[ADE](#apple-automated-device-enrollment)**| Yes | Optional | Optional|[More information](device-enrollment-program-enroll-ios.md)|
@@ -54,16 +54,18 @@ By default, devices for all platforms are allowed to enroll in Intune. However,
5454

5555
## macOS enrollment methods
5656

57-
| **Method** | **Reset Required** | **User Affinity** | **Locked** | **Details**|
57+
| **Method** | **Reset required** | **User affinity** | **Locked** | **Details**|
5858
|:---:|:---:|:---:|:---:|:---:|
59+
|Method used to enroll devices. |If yes, devices are wiped during enrollment. | If yes, each device is associated with a user.| If yes, users can't unenroll devices. |More information about method. |
5960
|**[BYOD](#bring-your-own-device)** | No| Yes | No | [More information](macos-enroll.md)|
6061
|**[DEM](#device-enrollment-manager)**| No |No |No | [More information](device-enrollment-manager-enroll.md)|
6162
|**[ADE](#apple-automated-device-enrollment)**| Yes | Optional | Optional|[More information](device-enrollment-program-enroll-macos.md)|
6263

6364
## Windows enrollment methods
6465

65-
| **Method** | **Reset Required** | **User Affinity** | **Locked** | **Details**|
66+
| **Method** | **Reset required** | **User affinity** | **Locked** | **Details**|
6667
|:---:|:---:|:---:|:---:|:---:|
68+
|Method used to enroll devices. | If yes, devices are wiped during enrollment. | If yes, each device is associated with a user.| If yes, users can't unenroll devices. | More information about method. |
6769
|**[BYOD](#bring-your-own-device)** | No | Yes | No | [More information](windows-enroll.md)|
6870
|**[DEM](#device-enrollment-manager)**| No |No |No |[More information](device-enrollment-manager-enroll.md)|
6971
|**Auto-enroll** | No |Yes |No | [More information](windows-enroll.md#enable-windows-automatic-enrollment)|
@@ -76,15 +78,19 @@ By default, devices for all platforms are allowed to enroll in Intune. However,
7678

7779
### Personal enrollment methods
7880

79-
| **Personal** | **Enrollment Methods** | **Reset Required** | **User Affinity** | **Locked** | **Details**|
81+
| **Enrollment type** | **Enrollment method** | **Reset required** | **User affinity** | **Locked** | **Details**|
8082
|:---:|:---:|:---:|:---:|:---:|:---:|
83+
|Name of enrollment type. |Method used to enroll devices.| If yes, devices are wiped during enrollment. | If yes, each device is associated with a user.| If yes, users can't unenroll devices. |More information about method. |
8184
|**Android Device Admin**|**User initiated via Company Portal** | No | Yes | No | [More information](../user-help/enroll-device-android-company-portal.md)|
8285
|**Android Enterprise personally-owned with Work Profile**|**User initiated via Company Portal**| No | Yes | No | [More information](android-work-profile-enroll.md)|
8386

8487
### Corporate enrollment methods
8588

86-
| **Corporate** | **Enrollment Methods** | **Reset Required** | **User Affinity** | **Locked** | **Details**|
89+
| **Enrollment type** | **Enrollment method** | **Reset required** | **User affinity** | **Locked** | **Details**|
8790
|:---:|:---:|:---:|:---:|:---:|:---:|
91+
|Name of enrollment type. |Method used to enroll devices.| If yes, devices are wiped during enrollment. | If yes, each device is associated with a user.| If yes, users can't unenroll devices. |More information about method. |
92+
|**Android (AOSP) user-associated**|**QR code**|Yes|Yes|Configurable via policy|[More information](../enrollment/android-aosp-corporate-owned-user-associated-enroll.md)
93+
|**Android (AOSP) userless**|**QR code**|Yes|No|Configurable via policy|[More information](../enrollment/android-aosp-corporate-owned-userless-enroll.md)
8894
|**Android Device Admin**|**[DEM](#device-enrollment-manager) initiated via Company Portal**| No | No | No |[More information](device-enrollment-manager-enroll.md)|
8995
|**Android Device Admin**|**(Pre-declared IMEI or SN) User initiated via Company Portal**| No | Yes | No | [More information](corporate-identifiers-add.md)|
9096
|**Android Device Admin with Zebra Mobility Extensions**|**User or [DEM](#device-enrollment-manager) initiated via Company Portal**| No | Yes if user initiated, No if [DEM](#device-enrollment-manager) initiated | No | [More information](../configuration/android-zebra-mx-overview.md)|

memdocs/intune/fundamentals/china.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,7 @@ Because the China services are operated by a partner from inside China, there ar
5555
- To follow local regulations and provide improved functionality, the Intune client experience (Company Portal app) may differ in China.
5656
- Fencing isn't available.
5757
- Mobile Application Management (MAM) availability is conditional on those apps being available in People's Republic of China.
58+
- Intune operated by 21Vianet doesn't support Android (AOSP) management for corporate devices.
5859

5960
## You control customer data
6061

@@ -80,4 +81,4 @@ The Tenant Administrator role for Intune operated by 21Vianet can request data f
8081

8182
## Next steps
8283

83-
[Learn more about Intune supported configurations](supported-devices-browsers.md)
84+
[Learn more about Intune supported configurations](supported-devices-browsers.md)

memdocs/intune/protect/microsoft-tunnel-overview.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ keywords:
55
author: brenduns
66
ms.author: brenduns
77
manager: dougeby
8-
ms.date: 10/25/2021
8+
ms.date: 12/03/2021
99
ms.topic: how-to
1010
ms.service: microsoft-intune
1111
ms.subservice: protect
@@ -34,6 +34,9 @@ This article introduces the tunnel, how it works, and its architecture.
3434

3535
If you're ready to deploy the Microsoft Tunnel, see [Prerequisites for the Microsoft Tunnel](microsoft-tunnel-prerequisites.md), and then [Configure the Microsoft Tunnel](microsoft-tunnel-configure.md).
3636

37+
> [!TIP]
38+
> Download the Microsoft Tunnel Deployment Guide v2 from the [*Microsoft Download Center*](https://www.microsoft.com/download/details.aspx?id=102274).
39+
3740
## Overview of Microsoft Tunnel
3841

3942
Microsoft Tunnel Gateway installs onto a container that runs on a Linux server. The Linux server can be a physical box in your on-premises environment or a virtual machine that runs on-premises or in the cloud. You'll deploy a Microsoft Tunnel client app and Intune VPN profiles to your iOS and Android devices to enable them to use the tunnel to connect to corporate resources. When the tunnel is hosted in the cloud, you’ll need to use a solution like Azure ExpressRoute to extend your on-premises network to the cloud.

memdocs/intune/protect/windows-update-settings.md

Lines changed: 9 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: brenduns
88
ms.author: brenduns
99
manager: dougeby
10-
ms.date: 11/16/2021
10+
ms.date: 12/03/2021
1111
ms.topic: reference
1212
ms.service: microsoft-intune
1313
ms.subservice: protect
@@ -18,7 +18,7 @@ ms.localizationpriority: medium
1818
#ROBOTS:
1919
#audience:
2020

21-
ms.reviewer: davidmeb; bryanke
21+
ms.reviewer: davguy; bryanke
2222
ms.suite: ems
2323
search.appverid: MET150
2424
#ms.tgt_pltfrm:
@@ -29,18 +29,16 @@ ms.collection:
2929
---
3030

3131

32-
# Windows update settings for Intune
32+
# Windows update settings for Intune
3333

3434
View the Windows 10 and Windows 11 Update settings that you can [configure and manage](windows-update-for-business-configure.md) with Microsoft Intune.
3535

3636
When you configure settings for Windows update rings in Intune, you're configuring the Windows Update settings. If a Windows update setting has a Windows 10 or Windows 11 version dependency, the version dependency is noted in the settings details.
3737

38-
## Update settings
38+
## Update settings
3939

4040
Update settings control what bits a device will download, and when. For more information about the behavior of each setting, see the Windows reference documentation.
4141

42-
43-
4442
- **Microsoft product updates**
4543
**Default**: Allow
4644
Windows Update CSP: [Update/AllowMUUpdateService](/windows/client-management/mdm/policy-csp-update#update-allowmuupdateservice)
@@ -141,8 +139,8 @@ User experience settings control the end-user experience for device restart and
141139
**Default**: 5 PM
142140
Windows Update CSP: [Update/ActiveHoursEnd](/windows/client-management/mdm/policy-csp-update#update-activehoursend)
143141

144-
- **Auto install and restart at scheduled time** - Specify an installation day and time. If unspecified, installation runs at 3 AM daily, followed by a 15-minute countdown to a restart. Logged on users can delay countdown and restart.
145-
Windows Update CSP: [Update/AllowAutoUpdate](/windows/client-management/mdm/policy-csp-update#update-allowautoupdate)
142+
- **Auto install and restart at scheduled time** - Specify an installation day and time. If unspecified, installation runs at 3 AM daily, followed by a 15-minute countdown to a restart. Logged on users can delay countdown and restart.
143+
Windows Update CSP: [Update/AllowAutoUpdate](/windows/client-management/mdm/policy-csp-update#update-allowautoupdate)
146144

147145
This option supports additional settings.
148146

@@ -153,7 +151,7 @@ User experience settings control the end-user experience for device restart and
153151
**Default**: Any Day
154152

155153
- **Scheduled install time** - Specify the time of day when you want updates to install.
156-
**Default**: 3 AM
154+
**Default**: 3 AM
157155

158156
> [!IMPORTANT]
159157
> The device might not complete the installation at the specified time because of power policies, user absence, and so on. In this case, it will not attempt installation until the specified time occurs again or until a deadline you have specified is reached.
@@ -162,7 +160,6 @@ User experience settings control the end-user experience for device restart and
162160

163161
- **Reset to default** - Restore the original auto update settings on machines that run the Windows 10 October 2018 Update or later, and that run Windows 11. These original auto update settings allow Windows to use automatically determined active hours to schedule the best time to install updates and restart the system after it installs the updates.
164162

165-
166163
- **Restart checks**
167164
**Default**: Allow
168165
Windows Update CSP: [Update/SetEDURestart](/windows/client-management/mdm/policy-csp-update#update-setedurestart)
@@ -178,34 +175,11 @@ User experience settings control the end-user experience for device restart and
178175

179176
- **Option to check for Windows updates**
180177
**Default**: Enable
181-
Windows Update CSP: [Update/SetDisableUXWUAccess](/windows/client-management/mdm/policy-csp-update#update-setdisableuxwuaccess)
178+
Windows Update CSP: [Update/SetDisableUXWUAccess](/windows/client-management/mdm/policy-csp-update#update-setdisableuxwuaccess)
182179

183180
- **Enable** - Allow device users to use Windows Update scan to find updates.
184181
- **Disable** - Prevent device users from accessing the Windows Update scan.
185182

186-
- **Require user approval to dismiss restart notification**
187-
**Default**: Not configured
188-
Windows Update CSP: [Update/AutoRestartRequiredNotificationDismissal](/windows/client-management/mdm/policy-csp-update#update-autorestartrequirednotificationdismissal)
189-
190-
- **No** - Automatic Dismissal after 25 seconds.
191-
- **Yes** - Require User Dismissal.
192-
193-
- **Remind user prior to required auto-restart with dismissible reminder (hours)**
194-
**Default**: 4
195-
Windows Update CSP: [Update/ScheduleRestartWarning](/windows/client-management/mdm/policy-csp-update#update-schedulerestartwarning)
196-
197-
Specify how long in advance of an automatic restart to display a dismissible notification to a device user about that restart. Values of **2**, **4**, **8**, **12**, or **24** hours are supported.
198-
199-
When you clear the default value, this setting becomes *Not configured*.
200-
201-
- **Remind user prior to required auto-restart with permanent reminder (minutes)**
202-
**Default**: 15
203-
Windows Update CSP: [Update/ScheduleImminentRestartWarning](/windows/client-management/mdm/policy-csp-update#update-scheduleimminentrestartwarning)
204-
205-
Specify how long in advance of an automatic restart to display a non-dismissible warning to a device user about that restart. Values of **15**, **30** or **60** minutes are supported.
206-
207-
When you clear the default value, this setting becomes *Not configured*.
208-
209183
- **Change notification Update level**
210184
**Default**: Use the default Windows Update notifications
211185
Windows Update CSP: [Update/UpdateNotificationLevel](/windows/client-management/mdm/policy-csp-update#update-updatenotificationlevel)
@@ -220,7 +194,7 @@ User experience settings control the end-user experience for device restart and
220194

221195
- **Use deadline settings**
222196
**Default**: Not configured
223-
197+
224198
Allows user to use deadline settings.
225199

226200
- **Not configured**

memdocs/intune/user-help/install-a-new-version-of-the-company-portal-app.md

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -40,10 +40,12 @@ ms.collection:
4040
- Windows 11
4141

4242

43-
Get the latest version of the Company Portal app on your Android, iOS, macOS, or Windows device. Your organization may require you to update the app on your device when:
43+
Get the latest version of the Microsoft Intune Company Portal app on your Android, iOS, macOS, or Windows device. We recommend using the latest version of the Company Portal app on your device because it contains the latest bug fixes and security updates.
4444

45-
* A newer version of Company Portal becomes available.
46-
* Your version of Company Portal is no longer supported.
45+
Your organization may require you to update the app on your device when:
46+
47+
* A newer version of Company Portal becomes available.
48+
* Your version of Company Portal is no longer supported.
4749

4850
If an update is required, you'll receive a notification from Company Portal.
4951

@@ -97,6 +99,7 @@ To turn on automatic updates:
9799

98100
Organizations may disable app updates. If this option is unavailable on your device, use the first set of Windows 10/11 instructions to update your app.
99101

102+
100103
## Next steps
101104

102105
Still need help? Contact your IT support person. For contact information, check the [Company Portal website](https://go.microsoft.com/fwlink/?linkid=2010980).

0 commit comments

Comments
 (0)