You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/autopilot/enrollment-autopilot.md
+2-3Lines changed: 2 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ author: greg-lindsay
9
9
ms.author: greglin
10
10
ms.reviewer: jubaptis
11
11
manager: dougeby
12
-
ms.date: 03/16/2021
12
+
ms.date: 02/09/2022
13
13
ms.topic: how-to
14
14
ms.service: microsoft-intune
15
15
ms.subservice: enrollment
@@ -80,8 +80,7 @@ For information about formatting and using a CSV file to manually add Windows Au
80
80
## Assign a user to a specific Autopilot device
81
81
82
82
> [!NOTE]
83
-
> This functionality has been removed as of September 30, 2021.
84
-
> While the option to assign user to a device in Autopilot is still available in the GUI portal and PowerShell, it will be ignored by the device during provisioning.
83
+
> Assigning a licensed user to a registered Autopilot device using Microsoft Endpoint Manager no longer pre-fills any user information as described below. Please see [Updates to the Windows Autopilot sign-in and deployment experience](https://techcommunity.microsoft.com/t5/intune-customer-success/updates-to-the-windows-autopilot-sign-in-and-deployment/ba-p/2848452) for details on this change. This change does not impact user assigned policies and apps which are still deployed to the device when a licensed user is assigned. See [Windows Autopilot for pre-provisioned deployment](/mem/autopilot/pre-provision#preparation) for details on this.
85
84
86
85
You can assign a licensed Intune user to a specific Autopilot device. This assignment:
87
86
- Pre-fills a user from Azure Active Directory in the [company-branded](/azure/active-directory/fundamentals/customize-branding) sign-in page during Windows setup.
Copy file name to clipboardExpand all lines: memdocs/autopilot/known-issues.md
+9-1Lines changed: 9 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -28,6 +28,14 @@ This article describes known issues that can often be resolved by configuration
28
28
29
29
## Known issues
30
30
31
+
### Reset button causes pre-provisioning to fail on retry
32
+
33
+
When ESP fails during the pre-provisioning flow and the user selects the reset button, TPM attestation may fail during the retry.
34
+
35
+
### TPM attestation failure on Windows 11 error code 0x81039023
36
+
37
+
Some devices may fail TPM attestation on Windows 11 during the pre-provisioning technician flow or self-deployment mode with the error code 0x81039023. There is no workaround currently for this error code, we are working to resolve this issue.
38
+
31
39
### Duplicate device objects with hybrid Azure AD deployments
32
40
33
41
A device object is pre-created in Azure AD once a device is registered in Autopilot. If a device goes through a hybrid Azure AD deployment, by design, another device object is created resulting in duplicate entries.
@@ -56,7 +64,7 @@ When [customizations are applied to the company branding settings](/azure/active
56
64
57
65
### TPM attestation is not working on Intel Tiger Lake platforms
58
66
59
-
TPM attestation support for Intel firmware TPM Tiger Lake platforms are only supported on devices with Windows 10 version 21H2 or higher.
67
+
TPM attestation support for Intel firmware TPM Tiger Lake platforms are only supported on devices with Windows 10 version 21H2 or higher. This issue should be resolved by applying the November 2021 LCU.
60
68
61
69
### Blocking apps specified in a user-targeted Enrollment Status Profile are ignored during device ESP
Copy file name to clipboardExpand all lines: memdocs/autopilot/troubleshooting.md
+4-1Lines changed: 4 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ author: greg-lindsay
13
13
ms.author: greglin
14
14
ms.reviewer: jubaptis
15
15
manager: dougeby
16
-
ms.date: 12/17/2020
16
+
ms.date: 02/09/2022
17
17
ms.collection: M365-modern-desktop
18
18
ms.topic: troubleshooting
19
19
---
@@ -32,6 +32,9 @@ Windows Autopilot is designed to simplify all parts of the Windows device lifecy
32
32
- How Windows Autopilot [device profiles](#profile-download) are downloaded
33
33
-[Key activities](#key-troubleshooting-activities) to perform during troubleshooting
34
34
35
+
## Windows Autopilot diagnostics page
36
+
On Windows 11, you can open the Autopilot diagnostic page to view additional detailed troubleshooting information about the Autopilot provisioning process. The diagnostics page can be enabled by going to the ESP profile and selecting **Yes** to **Turn on log collection and diagnostics page for end users**. Once it is enabled you can select the **View Diagnostics button** or the keyboard shortcut Ctrl+Shift+D to access any diagnostic information. The diagnostics page is currently supported for commercial OOBE, and Autopilot user-driven mode.
37
+
35
38
## Windows Autopilot flow
36
39
37
40
Whether you're performing user-driven or self-deploying device deployments, the troubleshooting process is about the same. It's useful to understand the flow for a specific device:
Copy file name to clipboardExpand all lines: memdocs/autopilot/windows-autopilot-whats-new.md
+12-1Lines changed: 12 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ author: greg-lindsay
13
13
ms.author: greglin
14
14
manager: dougeby
15
15
ms.reviewer: jubaptis
16
-
ms.date: 10/20/2021
16
+
ms.date: 02/09/2022
17
17
ms.collection:
18
18
- M365-modern-desktop
19
19
- highpri
@@ -28,6 +28,17 @@ ms.topic: article
28
28
- Windows 10
29
29
- Windows Holographic, version 2004
30
30
31
+
## Enrollment Status Page
32
+
33
+
With the 2022 Intune release, functionality has been added to the [Enrollment Status Page](enrollment-status.md) UI. The application picker for selecting blocking apps has additional improvements for admins:
34
+
- A search box has been added for easier selection of apps
35
+
- Fixes issue where store apps could not be differentiated between Online and Offline modes
36
+
- A new column has been added for **Version** to see which version of the application is selected
37
+
38
+
See the following example:
39
+
40
+

41
+
31
42
## Autopilot agility rolling out
32
43
33
44
Autopilot agility is a new feature that allows updates and bug fixes to the OOBE experience. These updates occur before device enrollment, after the AADJ login page and may result in an additional reboot and authentication prompt to the user. This feature is rolling out to Windows 10 1909 and 2004/20H2 with August cumulative update and is not yet available for Windows 11.
Copy file name to clipboardExpand all lines: memdocs/configmgr/protect/deploy-use/create-deploy-exploit-guard-policy.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -77,7 +77,7 @@ After you create Exploit Guard policies, use the Deploy Exploit Guard Policy wiz
77
77
## Windows Defender Exploit Guard policy settings
78
78
79
79
### <a name="bkmk_ASR"></a> Attack Surface Reduction policies and options
80
-
Attack Surface Reduction can reduce the attack surface of your applications with intelligent rules that stop the vectors used by Office, script, and mail-based malware. Learn more about [Attack Surface Reduction](/windows/security/threat-protection/microsoft-defender-atp/customize-attack-surface-reduction) and the Event IDs used for it.
80
+
Attack Surface Reduction can reduce the attack surface of your applications with intelligent rules that stop the vectors used by Office, script, and mail-based malware. Learn more about [Attack Surface Reduction](/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-deployment-implement) and the Event IDs used for it.
81
81
82
82
- **Files and Folders to exclude from Attack Surface Reduction rules** - Click on **Set** and specify any files or folders to exclude.
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/assign-role.md
+10-5Lines changed: 10 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,15 +40,20 @@ To create, edit, or assign roles, your account must have one of the following pe
40
40
41
41
2. On the **Endpoint Manager roles - All roles** blade, choose the built-in role you want to assign > **Assignments** > **+ Assign**.
42
42
43
-
5. On the **Basics** page, enter an **Assignment name** and optional **Assignment description**, and then choose **Next**.
43
+
3. On the **Basics** page, enter an **Assignment name** and optional **Assignment description**, and then choose **Next**.
44
44
45
-
6. On the **Admin Groups** page, select the group that contains the user you want to give the permissions to. Choose **Next**
45
+
4. On the **Admin Groups** page, select the group that contains the user you want to give the permissions to. Choose **Next**.
46
46
47
-
7. On the **Scope (Groups)** page, choose a group containing the users/devices that the member above will be allowed to manage. You also have the option to choose all users and/or all devices. Choose **Next**.
47
+
5. On the **Scope (Groups)** page, choose a group containing the users/devices that the member above will be allowed to manage. You also have the option to choose all users and/or all devices. Choose **Next**.
48
+
49
+
> [!NOTE]
50
+
> The **All users** and **All devices** are [Intune virtual groups](groups-add.md) and not Azure Active Directory (Azure AD) security groups. As a result, for **Scope (Groups)** assignment purposes you cannot use them as parents of Azure AD security groups. If you need both **All users** and **All devices** and specific Azure AD security groups for **Scope (Groups)** assignments, you must add them separately with separate assignments. Otherwise, even if the **Scope (Groups)** assignment for a role is set to **All Users** the admin in this role won't have access to specific Azure AD user groups.
51
+
>
52
+
> For Azure AD security groups, nesting is supported.
48
53
49
-
8. On the **Scope (Tags)** page, choose tags where this role assignment will be applied. Choose **Next**.
54
+
7. On the **Scope (Tags)** page, choose tags where this role assignment will be applied. Choose **Next**.
50
55
51
-
9. On the **Review + Create** page, when you're done, choose **Create**. The new assignment is displayed in the list of assignments.
56
+
8. On the **Review + Create** page, when you're done, choose **Create**. The new assignment is displayed in the list of assignments.
52
57
53
58
## Next steps
54
59
-[Learn more about role-based access control in Intune](role-based-access-control.md)
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/in-development.md
+4-1Lines changed: 4 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ keywords:
8
8
author: dougeby
9
9
ms.author: dougeby
10
10
manager: dougeby
11
-
ms.date: 02/03/2022
11
+
ms.date: 02/09/2022
12
12
ms.topic: conceptual
13
13
ms.service: microsoft-intune
14
14
ms.subservice: fundamentals
@@ -65,6 +65,9 @@ You can use RSS to be notified when this article is updated. For more informatio
65
65
66
66
## App management
67
67
68
+
### iOS Company Portal minimum required version<!-- 13016075 -->
69
+
With the March 2203 release of the MS Authenticator app, users will be required to update to v5.2203 of the iOS Company Portal. If you have enabled the **[Block installing apps using App Store](../configuration/device-restrictions-ios.md#settings-apply-to-automated-device-enrollment-supervised)** device restriction setting, you will likely need to push an update to the related devices that use this setting. Otherwise, no action is needed. If you have a helpdesk, you may want to make them aware of the prompt to update the Company Portal app. In most cases, users have app updates set to automatic, so they receive the updated Company Portal app without taking any action. Users that have an earlier app version will be prompted to update to the latest Company Portal app.
70
+
68
71
### Password complexity for Android devices<!-- 9321870 -->
69
72
The **Require device lock** setting in Intune will be extended to include values (**Low Complexity**, **Medium Complexity**, and **High Complexity**). If the device lock doesn't meet the minimum password requirement, you'll be able to **warn**, **wipe data**, or **block** the end user from accessing a managed account in a managed app.
Copy file name to clipboardExpand all lines: windows-365/business-enterprise-comparison.md
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -60,6 +60,7 @@ Windows 365 is available in two editions: [Windows 365 Business](./business/inde
60
60
| Monitoring | Not supported. | Endpoint Analytics reporting and monitoring, service health, and operational health alerts. |
61
61
| Troubleshooting | Not supported | Microsoft Endpoint Manager troubleshooting including the Troubleshooting blade, device management actions, and reprovisioning of Cloud PCs to their initial state. |
62
62
| Partner/programmatic access | Not supported | Partners can manage Cloud PCs through Microsoft 365 Lighthouse or restful web APIs (Graph) to support Managed Service Provider tooling for up to 300 seats. |
Copy file name to clipboardExpand all lines: windows-365/business/remotely-manage-business-cloud-pcs.md
+5-3Lines changed: 5 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -56,11 +56,11 @@ To use these remote actions, you must have either of the following Azure Active
56
56
## Remotely manage Cloud PCs by using the Microsoft 365 admin center
57
57
58
58
1. Sign in to [Microsoft 365 admin center](https://admin.microsoft.com).
59
-
2. In the left navigation select **Users** -> **Active users**.
59
+
2. In the left navigation, select **Users** -> **Active users**.
60
60
3. Select the user whose Cloud PC you want to manage.
61
61
4. Select **Devices**.
62
62
5. Select the Cloud PC you want to manage.
63
-
6. Select the action that you want to perform.
63
+
6. Select the action that you want to perform.
64
64
65
65
## Remote management actions
66
66
@@ -76,11 +76,13 @@ The following remote actions are supported on winodws365.microsoft.com and the M
76
76
- Removes all apps and locally stored files.
77
77
- Removes changes made to settings.
78
78
79
+
For Windows 365 Business users, it’s not possible to upgrade their Windows 10 Cloud PC to Windows 11 and retain their data and settings. Instead, to upgrade them to a Windows 11 Cloud PC, you must use the **Reset** remote action and choose Windows 11. Reset is a destructive action that removes all the user's data and settings from their Cloud PC.
80
+
79
81
**Restart**: Restart a user’s Cloud PC on their behalf.
80
82
81
83
## Grant remote action permissions to another user
82
84
83
-
If you want to grant remote action permissions to another user, you can assign the Windows 365 Administrator role to them. This role is scoped to performing actions that can alter the state of a Cloud PC. This role cannot manage users, licenses, or billing.
85
+
If you want to grant remote action permissions to another user, you can assign the Windows 365 Administrator role to them. This role is scoped to performing actions that can alter the state of a Cloud PC. This role can't manage users, licenses, or billing.
84
86
85
87
To assign a Windows 365 Administrator role to a user:
0 commit comments