Skip to content

Commit 2694575

Browse files
author
Angela Fleischmann
authored
Merge pull request #7933 from MicrosoftDocs/main
Publish 07/05/2022 3:30 PM PT
2 parents 547a105 + c74da60 commit 2694575

21 files changed

Lines changed: 98 additions & 55 deletions

memdocs/analytics/proactive-remediations.md

Lines changed: 17 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Tutorial - Proactive remediations
33
titleSuffix: Microsoft Endpoint Manager
44
description: A tutorial on using Proactive remediations to enhance the user
5-
ms.date: 03/07/2022
5+
ms.date: 07/05/2022
66
ms.prod: configuration-manager
77
ms.technology: configmgr-analytics
88
ms.topic: tutorial
@@ -120,9 +120,24 @@ Proactive remediation scripts need to be encoded in UTF-8. Uploading these scrip
120120

121121
For information about enforcing script signature checks, see [Script requirements](#bkmk_requirements).
122122
1. Click **Next** then assign any **Scope tags** you need.
123-
1. In the **Assignments** step, select the device groups to which you want to deploy the script package. When you're ready to deploy the packages to your users or devices, you can also use filters. For more information, see [Create filters in Microsoft Intune](../intune/fundamentals/filters.md).
123+
1. In the **Assignments** step, select the device groups to which you want to deploy the script package. When you're ready to deploy the packages to your users or devices, you can also use filters. For more information, see [Create filters in Microsoft Intune](../intune/fundamentals/filters.md).
124124
1. Complete the **Review + Create** step for your deployment.
125125

126+
## <a name="bkmk_prs_policy"></a> Client policy retrieval and client reporting
127+
128+
The client retrieves policy for proactive remediations scripts at the following times:
129+
130+
- After a restart of the device or Intune management extension service
131+
- After a user signs into the client
132+
- Once every 8 hours
133+
- The 8 hour script retrieval schedule is fixed based on when the Intune management extension service starts. The schedule isn't altered by user sign ins.
134+
135+
The client reports proactive remediation information at the following times:
136+
137+
- When a script is set to run once, the results are reported after the script runs.
138+
- Recurring scripts follow a 7 day reporting cycle:
139+
- Within the first 6 days, the client reports only if a change occurs. The first time the script runs would be considered a change.
140+
- Every 7 days the client sends a report even if there wasn't a change.
126141

127142
## <a name="bkmk_prs_monitor"></a> Monitor your script packages
128143

memdocs/analytics/startup-performance.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ For devices enrolled via Intune, Startup performance insights are only available
2929
For devices that do not meet the above criteria, you are able to [enroll via Configuration Manager](enroll-configmgr.md).
3030

3131
> [!Important]
32-
> Client devices require a restart to fully enable all analytics. <!--7698085-->
32+
> Client devices require a restart to fully enable all analytics. <!--7698085--> The retention period for device boot and sign-in events is 29 days. If a device has not uploaded a boot or sign-in event in the past 29 days, it will not appear in the Startup performance report.
3333
## <a name="bkmk_score"></a> Startup score
3434
3535
[!INCLUDE [Endpoint analytics startup score](includes/startup-score.md)]
@@ -55,7 +55,7 @@ Startup performance provides an insight on the number of devices that have delay
5555

5656
If you click through to a particular device, you can see its boot and sign-in history. The history helps you determine if the issue is a regression and when it might have occurred.
5757

58-
While there are many articles on how to optimize Group Policies performance, you may choose to migrate to cloud-management instead. Migrating to cloud-management allows you to use [Intune security baselines](../intune/protect/security-baselines.md) and the soon-to-be-released Policy Analytics tool.
58+
While there are many articles on how to optimize Group Policies performance, you may choose to migrate to cloud-management instead. Migrating to cloud-management allows you to use [Intune security baselines](../intune/protect/security-baselines.md) and [Group Policy analytics](../intune/configuration/group-policy-analytics.md).
5959

6060
### <a name="bkmk_sb"></a> Slow boot and sign-in times
6161

memdocs/configmgr/core/get-started/2022/includes/2204/12952905.md

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -13,9 +13,6 @@ ms.topic : include
1313
<!--12952905-->
1414
When configuring Azure Services, a new option called **Administration Service Management** is now added for enhanced security. Selecting this option allows administrators to segment their admin privileges between [cloud management gateway (CMG)](../../../../clients/manage/cmg/overview.md) and [administration service](../../../../../../configmgr/develop/adminservice/overview.md). By enabling this option, access is restricted to only administration service endpoints. Configuration Management clients will authenticate to the site using Azure Active Directory.
1515

16-
> [!NOTE]
17-
> Currently, the administration service management option can’t be used with CMG.
18-
1916
:::image type="content" source="../../media/12952905-administration-service-management-azure-services.png" alt-text="Screenshot of administration service management option in the Azure Service Wizard.":::
2017

2118
### Try it out!

memdocs/configmgr/desktop-analytics/connect-configmgr.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Connect Configuration Manager
33
titleSuffix: Configuration Manager
44
description: A how-to guide for connecting Configuration Manager with Desktop Analytics.
5-
ms.date: 08/24/2021
5+
ms.date: 07/01/2022
66
ms.prod: configuration-manager
77
ms.technology: configmgr-analytics
88
ms.topic: how-to
@@ -126,7 +126,7 @@ Monitor the configuration of your devices for Desktop Analytics. In the Configur
126126

127127
For more information, see [Monitor connection health](monitor-connection-health.md).
128128

129-
Configuration Manager synchronizes your collections within 60 minutes of creating the connection. In the Desktop Analytics portal, go to**Global Pilot**, and see your Configuration Manager device collections.
129+
Configuration Manager synchronizes your collections within 60 minutes of creating the connection. In the Desktop Analytics portal, go to **Global Pilot**, and see your Configuration Manager device collections.
130130

131131
> [!NOTE]
132132
> The Configuration Manager connection to Desktop Analytics relies upon the service connection point. Any changes to this site system role may impact synchronization with the cloud service. For more information, see [About the service connection point](../core/servers/deploy/configure/about-the-service-connection-point.md#bkmk_move).

memdocs/configmgr/tenant-attach/device-sync-actions.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Enable Microsoft Endpoint Manager tenant attach
33
titleSuffix: Configuration Manager
44
description: Upload your Configuration Manager devices to the cloud service and take actions from the admin center.
5-
ms.date: 03/21/2022
5+
ms.date: 07/01/2022
66
ms.topic: conceptual
77
ms.prod: configuration-manager
88
ms.technology: configmgr-core
@@ -65,7 +65,7 @@ When co-management isn't enabled, use the instructions below to enable device up
6565
- Optionally, you can import a previously created Azure AD application during tenant attach onboarding (starting in version 2006). For more information, see the [Import a previously created Azure AD application](#bkmk_aad_app) section.
6666
1. On the **Configure upload** page, select the recommended device upload setting for **All my devices managed by Microsoft Endpoint Configuration Manager**. If needed, you can limit upload to a single device collection.
6767
- Starting in Configuration Manager version 2010, when a single collection is selected, its child collections are also uploaded. <!--8717629-->
68-
1. Check the option to **Enable Endpoint analytics for devices uploaded to Microsoft Endpoint Manager** if you also want to get insights to optimize the end-user experience in [Endpoint Analytics](../../analytics/overview.md)
68+
1. Check the option to **Enable Endpoint analytics for devices uploaded to Microsoft Endpoint Manager** if you also want to get insights to optimize the end-user experience in [Endpoint Analytics](../../analytics/overview.md).
6969
1. Select **Summary** to review your selection, then choose **Next**.
7070
1. When the wizard is complete, select **Close**.
7171

memdocs/configmgr/tenant-attach/includes/import-azure-app.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.prod: configuration-manager
55
ms.technology: configmgr-core
66
ms.topic: include
77
ms.localizationpriority: high
8-
ms.date: 01/06/2022
8+
ms.date: 07/01/2022
99
---
1010
<!-- This include file is currently used by device-sync-actions.md and cloud-attach/enable.md. Note H2/H3s for this include file may be context driven by article. -->
1111

@@ -48,4 +48,4 @@ Using a previously created application during onboarding to tenant attach requir
4848

4949
- The imported application needs to be configured as follows:
5050
- Registered for **Accounts in this organizational directory only**. For more information, see [Change who can access your application](/azure/active-directory/develop/quickstart-modify-supported-accounts#to-change-who-can-access-your-application).
51-
- Has a valid application ID URI and secret
51+
- Has a valid application ID URI and secret.

memdocs/intune/configuration/vpn-settings-configure.md

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -145,17 +145,14 @@ You can create VPN profiles using the following connection types:
145145
> [!Important]
146146
> As of June 14, 2021, both the standalone tunnel app and standalone client connection type for Android are deprecated and drop from support after October 26, 2021.
147147
148-
- Microsoft Tunnel (preview)
148+
- Microsoft Tunnel
149149
- iOS/iPadOS
150-
151-
> [!Important]
152-
> On April 29, 2022, this connection type became generally available and supports Microsoft Defender for Endpoint as a tunnel client app. However, the connection type continues to reflect *preview*.
153150

154151
- Microsoft Tunnel (standalone client)(preview)
155152
- iOS/iPadOS
156153

157154
> [!Important]
158-
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel (preview)* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
155+
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
159156
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
160157
> - On August 1, 2022, the *Microsoft Tunnel (standalone client) (preview)* connection type will cease to connect to Microsoft Tunnel.
161158
>

memdocs/intune/configuration/vpn-settings-ios.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 05/12/2022
10+
ms.date: 07/05/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: configuration
@@ -87,13 +87,13 @@ Select the VPN connection type from the following list of vendors:
8787
Applies to the Microsoft Tunnel client app.
8888

8989
> [!Important]
90-
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel (preview)* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
90+
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
9191
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
9292
> - On August 1, 2022, the *Microsoft Tunnel (standalone client) (preview)* connection type will cease to connect to Microsoft Tunnel.
9393
>
9494
> To avoid a disruption in service for Microsoft Tunnel, plan to migrate your use of the deprecated tunnel client app and connection type to those that are now generally available.
9595
96-
- **Microsoft Tunnel (preview)**
96+
- **Microsoft Tunnel**
9797

9898
Applies to the Microsoft Defender for Endpoint app that includes Tunnel client functionality.
9999

@@ -385,7 +385,7 @@ These settings apply when you choose **Connection type** > **IKEv2**.
385385
These settings apply to the following VPN connection types:
386386

387387
- **Microsoft Tunnel (standalone client) (preview)**
388-
- **Microsoft Tunnel (preview)**
388+
- **Microsoft Tunnel**
389389

390390
**Settings**:
391391

memdocs/intune/fundamentals/scope-tags.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,10 @@ The default scope tag feature is similar to the security scopes feature in Micro
5353
3. On the **Assignments** page, choose the groups containing the devices that you want to assign this scope tag. Choose **Next**.
5454
4. On the **Review + create** page, choose **Create**.
5555

56+
> [!IMPORTANT]
57+
> Auto scope tags assignments will overwrite mannually assigned scope tags.
58+
> You can assign multiple scope tags to a role.
59+
5660
## To assign a scope tag to a role
5761

5862
1. In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), choose **Tenant administration** > **Roles** > **All roles** > choose a role > **Assignments** > **Assign**.

memdocs/intune/fundamentals/whats-new.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -906,7 +906,7 @@ We've added two new Setup Assistant settings that you can use with Apple Automat
906906

907907
Use of Microsoft Defender for Endpoint that supports [Microsoft Tunnel](../protect/microsoft-tunnel-overview.md) on iOS/iPadOS is now out of preview and is generally available. With general availability, a new version of the Defender for Endpoint app for iOS is available from the App store to download and deploy. If you’ve been using the preview version as your Tunnel client app for iOS, we recommend you upgrade to the latest Defender for Endpoint app for iOS soon to gain the benefits of the latest updates and fixes.
908908

909-
For now, even with the general availability of Defender as the tunnel client app, the VPN profile connection type you'll use remains named **Microsoft Tunnel (preview)**. The connection type will be renamed in a future update to **Microsoft Tunnel**.
909+
As of August 30, 2022, the connection type is named **Microsoft Tunnel**.
910910

911911
With this release, by the end of June both the standalone Tunnel client app and the preview version of Defender for Endpoint as the Tunnel client app for iOS will be deprecated and be dropped from support. Soon after that deprecation, the standalone Tunnel client app will no longer function and will no longer support opening connections to Microsoft Tunnel.
912912

0 commit comments

Comments
 (0)