Skip to content

Commit 50cbb73

Browse files
committed
Merge branch 'main' into release-cm2208-tp
2 parents 736c1e0 + 66f86b3 commit 50cbb73

4 files changed

Lines changed: 91 additions & 8 deletions

File tree

Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
---
2+
title: Connected cache update for Microsoft Endpoint Configuration Manager version 2203
3+
titleSuffix: Configuration Manager
4+
description: Console update for 2203
5+
ms.date: 8/29/2022
6+
ms.prod: configuration-manager
7+
ms.technology: configmgr-core
8+
ms.topic: reference
9+
ms.assetid: 006f3396-a9d0-44f8-9db1-6408259e405ef
10+
author: bhuney
11+
ms.author: brianhun
12+
manager: dougeby
13+
---
14+
15+
# Connected cache update for Microsoft Endpoint Configuration Manager versions 2103 - 2207
16+
17+
*Applies to: Configuration Manager (current branch, versions 2103 - 2207)*
18+
## Summary of KB14978429
19+
20+
An update is available that fixes the following issues with the Microsoft Connected Cache feature in Configuration Manager current branch, versions 2103 - 2207.
21+
22+
- Incorrect access control list (ACL) set on the cache folder prevents installations from completing in some environments.
23+
- Uninstall race condition that prevents a scheduled task from being cleaned up as expected.
24+
- An incorrect failure state can persist after installation in some cases.
25+
26+
In addition, the following enhancements are included in this release.
27+
28+
- Added general supportability enhancements to improve logging, troubleshooting, and discoverability of error conditions.
29+
- Added support for the latest Office Click-to-Run (C2R) host.
30+
- Decreased installation time by approximately 30 percent.
31+
32+
## Update information for Microsoft Endpoint Configuration Manager
33+
The following hotfix to resolve this problem is available for download from the Microsoft Download Center:
34+
35+
[Download this hotfix now](https://download.microsoft.com/download/8/e/d/8ed826e2-0a9d-4160-a1a0-725efa0d0971/1.5.5.14088/DoincInstall.exe).
36+
37+
After you download this hotfix, refer to the following installation instructions.
38+
39+
## Installation instructions
40+
1. Confirm there is not currently an installation of the MCC component in progress. This is done by checking for status message **9522**, generated by the `SMS_DISTRIBUTION_MANAGER` component. The 9522 message indicates that installation is no longer being retried.
41+
2. Copy the new version of `DoincInstall.exe`, version **1.5.5.14088**, to the `{SMSInstallDir}\bin\x64` folder on all site servers, including the Central Administration Site (CAS) if present, and any passive sites.
42+
3. Uncheck the **Enable this distribution point to be used as Microsoft Connected Cache server** option in the affected distribution point’s properties.
43+
4. Wait for the uninstall of MCC to complete on the distribution point. This can be confirmed by looking for a **9152** success status message, combined with the following entry in `distmgr.log`.
44+
```text
45+
Finished waiting for DoincInstall. InvocationState: UninstallCompleted. InvocationExitCode: 0. InvocationMessage: .
46+
```
47+
5. Recheck the **Enable this distribution point to be used as Microsoft Connected Cache server** option for the affected distribution point.
48+
49+
> [!TIP]
50+
> For sites with a large number of distribution points, replace steps 3 - 5 above with the following.
51+
> - Create an empty file named `resetdps.trn` and place it in the `{SMSInstallDir}\inboxes\distmgr.box` folder. This will reinstall all distribution points for that site using the latest version of `DoincInstall.exe` copied in step 2. above.
52+
53+
## Prerequisites
54+
To apply this hotfix, you must be using Microsoft Endpoint Configuration Manager, versions 2103 through versions 2203.
55+
56+
## Restart information
57+
You don't have to restart the computer after you apply this hotfix.
58+
59+
## Hotfix replacement information
60+
This hotfix replaces the following previously released hotfix.
61+
62+
[KB12819689 Connected cache update for Microsoft Endpoint Configuration Manager version 2111](../../hotfix/2111/12819689.md)
63+
64+
## File information
65+
File information is available in the downloadable [KB14978429_FileList.txt](https://aka.ms/KB14978429_FileList) text file.
66+
67+
## Release history
68+
- August 29, 2022: Initial hotfix release

memdocs/configmgr/hotfix/TOC.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
11
items:
22
- name: Hotfix documentation
33
href: index.yml
4+
- name: Version 2207
5+
items:
6+
- name: KB 14978429 Connected cache update for Microsoft Endpoint Configuration Manager version 2207
7+
href: 2207/14978429.md
48
- name: Version 2203
59
items:
610
- name: KB 13174460 Summary of changes in 2203

memdocs/intune/fundamentals/azure-virtual-desktop-multi-session.md

Lines changed: 14 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ ms.collection:
3333

3434
Azure Virtual Desktop multi-session with Microsoft Intune is now generally available.
3535

36-
You can now use Microsoft Intune to manage Windows 10 or Windows 11 Enterprise multi-session remote desktops in the Microsoft Endpoint Manager admin center just as you can manage a shared Windows 10 or Windows 11 client device. When managing such virtual machines (VMs), you'll be able to use both device-based and user configuration.
36+
You can now use Microsoft Intune to manage Windows 10 or Windows 11 Enterprise multi-session remote desktops in the Microsoft Endpoint Manager admin center just as you can manage a shared Windows 10 or Windows 11 client device. When managing such virtual machines (VMs), you'll be able to use both device-based configuration targeted to devices or user-based configuration targeted to users.
3737

3838
Windows 10 or Windows 11 Enterprise multi-session is a new Remote Desktop Session Host exclusive to [Azure Virtual Desktop](/azure/virtual-desktop/) on Azure. It provides the following benefits:
3939

@@ -45,7 +45,10 @@ You can manage **Windows 10** and **Windows 11 Enterprise multi-session** VMs cr
4545

4646
## Overview
4747

48-
Device configuration support in Microsoft Intune for Windows 10 or Windows 11 Enterprise multi-session is Generally Available (GA). This means [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs. Additionally, multi-session configurations can be targeted to devices or device groups.
48+
Device configuration support in Microsoft Intune for Windows 10 or Windows 11 Enterprise multi-session is Generally Available (GA). This means [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs when assigned to device groups.
49+
50+
> [!NOTE]
51+
> Device-based configuration cannot be assigned to users and user-based configuration cannot be assigned to devices. It will be reported as **Error** or **Not applicable**.
4952
5053
User configuration support in Microsoft Intune for Windows 11 multi-session VMs is in public preview. With this you'll be able to:
5154

@@ -70,7 +73,7 @@ This feature supports Windows 10 or Windows 11 Enterprise multi-session VMs, whi
7073
- Configured with [Active Directory group policy](/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy), set to use Device credentials, and set to automatically enroll devices that are Hybrid Azure AD-joined.
7174
- [Configuration Manager co-management](/configmgr/comanage/overview).
7275
- Azure AD-joined and enrolled in Microsoft Intune by enabling [Enroll the VM with Intune](/azure/virtual-desktop/deploy-azure-ad-joined-vm#deploy-azure-ad-joined-vms) in the Azure portal.
73-
- Licensing: The appropriate Microsoft Intune license is required if a user or device benefits directly or indirectly from the Microsoft Intune service, including access to the Microsoft Intune service through a Microsoft API. For more information, see Microsoft Intune licensing.
76+
- Licensing: The appropriate Azure Virtual Desktop and Microsoft Intune license is required if a user or device benefits directly or indirectly from the Microsoft Intune service, including access to the Microsoft Intune service through a Microsoft API. For more information, go to [Microsoft Intune licensing](licenses.md).
7477

7578
> [!NOTE]
7679
> If you're joining session hosts to Azure Active Directory Domain Services, you can't manage them using Intune.
@@ -88,9 +91,9 @@ To configure configuration policies for Windows 10 or Windows 11 Enterprise mult
8891

8992
The existing device configuration profile templates aren't supported for Windows 10 or Windows 11 Enterprise multi-session VMs, except for the following templates:
9093

91-
- [Trusted certificate](../protect/certificates-trusted-root.md#create-trusted-certificate-profiles) - Device (machine) only
92-
- [SCEP certificate](../protect/certificates-profile-scep.md#create-a-scep-certificate-profile) - Device (machine) only
93-
- [PKCS certificate](../protect/certificates-pfx-configure.md#create-a-pkcs-certificate-profile) - Device (machine) only
94+
- [Trusted certificate](../protect/certificates-trusted-root.md#create-trusted-certificate-profiles) - Device (machine) when targeting devices and User when targeting users
95+
- [SCEP certificate](../protect/certificates-profile-scep.md#create-a-scep-certificate-profile) - Device (machine) when targeting devices and User when targeting users
96+
- [PKCS certificate](../protect/certificates-pfx-configure.md#create-a-pkcs-certificate-profile) - Device (machine) when targeting devices and User when targeting users
9497
- [VPN](../configuration/vpn-settings-configure.md#create-the-profile) - Device Tunnel only
9598

9699
Microsoft Intune won't deliver unsupported templates to multi-session devices, and those policies appear as *Not applicable* in reports.
@@ -160,14 +163,17 @@ All other policies report as **Not applicable**.
160163
> [Conditional Access for Exchange on-premises](../protect/conditional-access-exchange-create.md) isn't supported for Windows 10 or Windows 11 Enterprise multi-session VMs.
161164
162165
> [!NOTE]
163-
> Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
166+
> Configuration and compliance policies for BitLocker, Secure Boot, and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
164167
165168
## Endpoint security
166169

167-
You can configure profiles under Endpoint security for multi-session VMs by selecting Platform Windows 10, Windows 11, and Windows Server.
170+
You can configure profiles under Endpoint security for multi-session VMs by selecting Platform Windows 10, Windows 11, and Windows Server. If that Platform is not available, the profile is not supported on multi-session VMs.
168171

169172
For more information, see [Manage device security with endpoint security policies in Microsoft Intune](../protect/endpoint-security-policy.md)
170173

174+
> [!NOTE]
175+
> Tamper protection is not supported on Azure Virtual Desktop VMs today. This functionality will be enabled in a future release.
176+
171177
## Application deployment
172178

173179
All Windows 10 or Windows 11 apps can be deployed to Windows 10 or Windows 11 Enterprise multi-session with the following restrictions:

memdocs/intune/includes/mdm-supported-devices.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,11 @@ ms.localizationpriority: high
1414
- Apple iPadOS 13.0 and later
1515
- macOS 10.15 and later
1616

17+
> [!NOTE]
18+
> Intune requires iOS 13.x or later for device enrollment scenarios and app configuration delivered through Managed devices app configuration policies.
19+
>
20+
> For Intune app protection policies and app configuration delivered through Managed apps App configuration policies, Intune requires iOS 14.x or later.
21+
1722
### Google
1823

1924
- Android 8.0 and later (including Samsung KNOX Standard 2.4 and higher: [requirements](https://www.samsungknox.com/en/knox-platform/supported-devices/2.4+))

0 commit comments

Comments
 (0)