Skip to content

Commit 547297f

Browse files
authored
Merge pull request #6648 from MicrosoftDocs/main
Publish 01/28/2022, 10:30 AM
2 parents 1d086b6 + e335dc1 commit 547297f

6 files changed

Lines changed: 76 additions & 11 deletions

File tree

memdocs/autopilot/autopilot-device-guidelines.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,7 @@ The following best practices ensure that devices can easily be provisioned as pa
3636
- Before shipping devices to an Autopilot customer or channel partner, the OEM should upload 4K Hardware Hashes to Microsoft by using the CBR report. The hashes should be collected using the OA3 Tool RS3+ run in Audit mode on full OS.
3737
- Microsoft requires that OEM shipping drivers get published to Windows Update within 30 days of the CBR submission date. System firmware and driver updates are published to Windows Update within 14 days.
3838
- The OEM ensures that the PKID provisioned in the SMBIOS is passed on to the channel.
39+
- When using a VM for Autopilot testing, assign at least 2 processors and 4gb of memory. This will help to prevent application install issues in Windows 10 devices with the [May 11, 2021 cumulative update](https://support.microsoft.com/topic/may-11-2021-kb5003173-os-builds-19041-985-19042-985-and-19043-985-2824ace2-eabe-4c3c-8a49-06e249f52527) installed. *Note: The [minimum system requirements](/windows/whats-new/windows-11-requirements#virtual-machine-support) for Windows 11 are 2 processors and 4gb memory.
3940

4041
## Software best practice guidelines for Windows Autopilot
4142

@@ -47,4 +48,4 @@ The following best practices ensure that devices can easily be provisioned as pa
4748
## Next steps
4849

4950
[Windows Autopilot customer consent](registration-auth.md)<br>
50-
[Motherboard replacement scenario guidance](autopilot-mbr.md)<br>
51+
[Motherboard replacement scenario guidance](autopilot-mbr.md)<br>

memdocs/configmgr/core/clients/manage/cmg/configure-clients.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ Get-WmiObject -Namespace Root\Ccm\LocationServices -Class SMS_ActiveMPCandidate
4848
This command displays any internet-based management points the client knows about. While the CMG isn't technically an internet-based management point, clients view it as one.
4949

5050
> [!NOTE]
51-
> To troubleshoot CMG client traffic, use **CMGHttpHandler.log**, **CMGService.log**, and **SMS_Cloud_ProxyConnector.log**. For more information, see [Log files](../../../plan-design/hierarchy/log-files.md#cloud-management-gateway).
51+
> To troubleshoot CMG client traffic, use **CMGService.log** and **SMS_Cloud_ProxyConnector.log**. For more information, see [Log files](../../../plan-design/hierarchy/log-files.md#cloud-management-gateway).
5252
5353
## Install off-premises clients using a CMG
5454

memdocs/configmgr/core/plan-design/hierarchy/includes/logs-cmg.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ ms.author: aaroncz
44
ms.prod: configuration-manager
55
ms.technology: configmgr-client
66
ms.topic: include
7-
ms.date: 09/17/2020
7+
ms.date: 01/27/2022
88
ms.localizationpriority: medium
99
---
1010

@@ -20,7 +20,7 @@ The following table lists the log files that contain information related to the
2020

2121
- For troubleshooting deployments, use **CloudMgr.log** and **CMGSetup.log**
2222
- For troubleshooting service health, use **CMGService.log** and **SMS_Cloud_ProxyConnector.log**.
23-
- For troubleshooting client traffic, use **CMGHttpHandler.log**, **CMGService.log**, and **SMS_Cloud_ProxyConnector.log**.
23+
- For troubleshooting client traffic, use **CMGService.log** and **SMS_Cloud_ProxyConnector.log**.
2424

2525
#### <a name="bkmk_note1"></a> Note 1: Logs synchronized from Azure
2626

memdocs/configmgr/tenant-attach/client-details.md

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,6 @@ ms.localizationpriority: high
1919

2020
Microsoft Endpoint Manager is an integrated solution for managing all of your devices. Microsoft brings together Configuration Manager and Intune into a single console called **Microsoft Endpoint Manager admin center**. You can see ConfigMgr client details including collections, boundary group membership, and real-time client information for a specific device in the admin center.
2121

22-
> [!Important]
23-
> The boundary groups tab functions only for stand alone sites. The tab will be empty in the admin center for anything other than a standalone primary site.
24-
2522
## Prerequisites
2623

2724
- All of the prerequisites for [Microsoft Endpoint Manager tenant attach](device-sync-actions.md) and a tenant attached environment.

memdocs/intune/fundamentals/whats-new.md

Lines changed: 70 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: Erikre
88
ms.author: erikre
99
manager: dougeby
10-
ms.date: 01/07/2022
10+
ms.date: 01/28/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: fundamentals
@@ -60,9 +60,76 @@ You can use RSS to be notified when this page is updated. For more information,
6060
### Scripts
6161
-->
6262

63-
## Week of January 3, 2022
63+
## Week of January 24, 2022 (Service release 2201)
6464

65-
### Device management
65+
### App management
66+
67+
#### Deploy DMG-type applications to managed macOS devices<!-- 1171356 -->
68+
You can upload and deploy DMG-type applications to managed Macs from Microsoft Endpoint Manager using the **required** assignment type. DMG is the file extension for Apple disk image files. DMG-type apps are deployed using the [Microsoft Intune MDM agent for macOS](..\apps\lob-apps-macos-agent.md). You can add a DMG app from [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) by selecting **Apps** > **macOS** > **Add** > **macOS app (DMG)**. For more information, see [Add a macOS DMG app to Microsoft Intune](../apps/lob-apps-macos-dmg.md).
69+
70+
### Device management
71+
72+
#### Choose either user or device scope when creating Windows VPN profiles<!-- 10685553 -->
73+
You can create a VPN profile for Windows devices that configures VPN settings (**Devices** > **Configuration profiles** > **Create profile** > **Windows 10 and later** for platform > **Templates** > **VPN** for profile).
74+
75+
When you create a profile, use the **Use this VPN profile with a user/device scope** setting to apply the profile to the user scope or the device scope:
76+
- **User scope**: The VPN profile is installed within the user's account on the device.
77+
- **Device scope**: The VPN profile is installed in the device context and applies to all users on the device.
78+
79+
Existing VPN profiles will apply to their existing scope, and aren't impacted by this change. All VPN profiles are installed in the user scope *except* for the profiles with device tunnel enabled, which requires device scope.
80+
81+
For more information on VPN settings you can currently configure, see [Windows device settings to add VPN connections using Intune](../configuration/vpn-settings-windows-10.md).
82+
83+
Applies to:
84+
- Windows 11
85+
- Windows 10
86+
87+
#### Filters are Generally Available (GA)<!-- 12466893 -->
88+
You can use filters to include or exclude devices in workload assignments (like policies and apps) based on different device properties. Filters is now generally available (GA).
89+
90+
For more information on filters, see [Use filters when assigning your apps, policies, and profiles](../fundamentals/filters.md).
91+
92+
#### Automatic device clean-up rules support for Android Enterprise devices<!-- 9797532 -->
93+
Intune supports the creation of rules to automatically remove devices that appear to be inactive, stale, or unresponsive. You can now use these clean-up rules with Android Enterprise devices that previously did not support them. These rules are now supported for:
94+
- Android Enterprise Fully Managed
95+
- Android Enterprise Dedicated
96+
- Android Enterprise Corporate-Owned with Work Profile
97+
98+
To learn more about clean-up rules, see [Automatically delete devices with cleanup rules](../remote-actions/devices-wipe.md#automatically-delete-devices-with-cleanup-rules).
99+
100+
#### Use Collect diagnostics to collect additional details from Windows 365 devices through Intune remote actions<!-- 12636207 -->
101+
Intune’s remote action to [*Collect diagnostics*](../remote-actions/collect-diagnostics.md) now collects additional details from Windows 365 (Coud-PC) devices. The new details for Windows 365 devices include the following registry data:
102+
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\WebRTC Redirector
103+
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Teams\
104+
105+
For information about remote actions supported for Windows 365 devices, see [Remotely manage Windows 365 devices](/windows-365/enterprise/remotely-manage-cloud-pc).
106+
107+
#### Tenant attach features are Generally Available (GA)<!--12976713 -->
108+
The following [tenant attach](../../configmgr/tenant-attach/index.yml) features are now generally available:
109+
- Client details
110+
- Applications
111+
- Device timeline
112+
- Resource explorer
113+
- CMPivot
114+
- Scripts
115+
- BitLocker Recovery Keys
116+
- Collections
117+
118+
### Device security
119+
120+
#### New Account protection policy to configure users in local groups on devices in public preview<!--5663034 -->
121+
In public preview, you can use a new profile for Intune Account protection policies to manage the membership of the built-in local groups on Windows 10 and 11 devices.
122+
123+
Each Windows device comes with a set of built-in local groups. Each local group contains a set of users that have rights within that group. With the new Local user group membership (preview) profile for endpoint security Account protection policies, you can manage which users are members of those local groups.
124+
125+
To configure local group memberships, you select the built-in local account to modify and then choose the users to add, remove, or replace in the group with other users. Each device that receives the policy the updates the membership of those local groups. Modification of the group membership on each device is done by using the [Policy CSP - LocalUsersAndGroups](/windows/client-management/mdm/policy-csp-localusersandgroups?WT.mc_id=Portal-fx).
126+
127+
To learn more, see [Manage local groups on Windows devices](../protect/endpoint-security-account-protection-policy.md#manage-local-groups-on-windows-devices).
128+
129+
## Week of January 3, 2022
130+
131+
### Device management
132+
66133
#### Preview filtered device list before deployment <!-- 7541587 -->
67134
Now as you create or edit a filter in Microsoft Intune, you can preview the list of filtered devices. The new view eliminates the need to apply test filters, because you can immediately preview the impact a filter has on devices and adjust filter rules to achieve your desired outcome. For more information about using filters in Microsoft Intune, see [Create a filter](../fundamentals/filters.md).
68135

windows-365/business-enterprise-comparison.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ Windows 365 is available in two editions: [Windows 365 Business](./business/inde
4444
| --- | --- | --- |
4545
| Purchase channels | Web direct, self-service, Cloud Solution Provider (CSP). | Web direct, Enterprise Agreements (EA), CSP. |
4646
| License assignment | Microsoft 365 Admin Center or the Azure AD portal. | Microsoft 365 Admin Center. |
47-
| Licensing requirements | No licensing pre-requirements to buy and deploy Windows 365 Business. Other features (like device management) can be used if users are licensed for Microsoft Endpoint Management.| Each user must be licensed for Windows 10 or 11 Enterprise (when available), Microsoft Endpoint Manager, and Azure AD P1. |
47+
| Licensing requirements | No licensing pre-requirements to buy and deploy Windows 365 Business. Other features (like device management) can be used if users are licensed for Microsoft Endpoint Management.| Each user must be licensed for Windows 10 or 11 Enterprise, Microsoft Endpoint Manager, and Azure AD P1. |
4848
| Networking costs | Outbound data/month is based on the RAM of the Cloud PC:<br>- 2 GB RAM = 12 GB outbound data<br>- 4 or 8 GB RAM = 20 GB outbound data<br>- 16 GB RAM = 40 GB outbound data<br>- 32 GB RAM = 70 GB outbound data<br>Data bandwidth may be restricted when these levels are exceeded. | Networking goes through the customer's Azure VNet and isn't included in the license. [Azure bandwidth pricing](https://azure.microsoft.com/pricing/details/bandwidth/) applies for these network usage costs.
4949
| Seat limits | Capped to 300 seats per tenant. [Commercial Licensing Terms](https://www.microsoft.com/licensing/terms/productoffering/Windows365/MOSA) | No seat cap per tenant. [Commercial Licensing Terms](https://www.microsoft.com/licensing/terms/productoffering/Windows365/MOSA) |
5050

0 commit comments

Comments
 (0)