You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/configuration/device-restrictions-android-for-work.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -462,12 +462,12 @@ End of comment -->
462
462
#### Fully managed, dedicated, and corporate-owned work profile devices
463
463
464
464
-**Add new users**: **Block** prevents users from adding new users. Each user has a personal space on the device for custom Home screens, accounts, apps, and settings. When set to **Not configured** (default), Intune doesn't change or update this setting. By default, the OS might allow users to add other users to the device.
465
+
-**User can configure credentials (work profile-level)**: **Block** prevents users from configuring certificates assigned to devices, even devices that aren't associated with a user account. When set to **Not configured** (default), Intune doesn't change or update this setting. By default, the OS might make it possible for users to configure or change their credentials when they access them in the keystore.
465
466
466
467
#### Fully managed and dedicated devices
467
468
468
469
-**User removal**: **Block** prevents users from removing users. When set to **Not configured** (default), Intune doesn't change or update this setting. By default, the OS might allow users to remove other users from the device.
469
470
-**Personal Google Accounts**: **Block** prevents users from adding their personal Google account to the device. When set to **Not configured** (default), Intune doesn't change or update this setting. By default, the OS might allow users to add their personal Google account.
470
-
-**User can configure credentials**: **Block** prevents users from configuring certificates assigned to devices, even devices that aren't associated with a user account. When set to **Not configured** (default), Intune doesn't change or update this setting. By default, the OS might make it possible for users to configure or change their credentials when they access them in the keystore.
Copy file name to clipboardExpand all lines: memdocs/intune/configuration/group-policy-analytics.md
+19-15Lines changed: 19 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,14 +1,14 @@
1
1
---
2
2
# required metadata
3
3
4
-
title: Use group policy analytics to import GPOs in Microsoft Intune
4
+
title: Use group policy analytics to import and analyze GPOs in Microsoft Intune
5
5
description: Import and analyze your group policy objects in Microsoft Intune and Endpoint Manager. See the policies that have the same Configuration Service Provider (CSP) setting in the cloud, and assign to your Windows 10/11 users and devices.
6
6
keywords:
7
7
author: MandiOhlinger
8
8
9
9
ms.author: mandia
10
10
manager: dougeby
11
-
ms.date: 01/19/2022
11
+
ms.date: 02/03/2022
12
12
ms.topic: how-to
13
13
ms.service: microsoft-intune
14
14
ms.subservice: configuration
@@ -33,22 +33,27 @@ ms.collection:
33
33
34
34
# Analyze your on-premises group policy objects (GPO) using Group Policy analytics in Microsoft Endpoint Manager - Preview
35
35
36
-
Group policy objects (GPOs) are used on-premises to configure settings on personal computers, and other on-premises devices. In device management, GPOs help control security and features in the Windows OS, Internet Explorer, Office apps, and more.
36
+
> [!TIP]
37
+
> Looking for information on ADMX templates? See [Use Windows 10/11 Administrative Templates to configure group policy settings in Microsoft Endpoint Manager](administrative-templates-windows.md).
37
38
38
-
Many organizations are looking at cloud solutions to support the growing remote workforce. **Group Policy analytics** is a tool and feature in Microsoft Endpoint Manager that analyzes your on-premises GPOs. It helps you determine how your GPOs translate in the cloud. The output shows which settings are supported in MDM providers, including Microsoft Intune. It also shows any deprecated settings, or settings not available to MDM providers.
39
+
**Group Policy analytics** is a tool and feature in Microsoft Endpoint Manager that analyzes your on-premises GPOs. It helps you determine how your GPOs translate in the cloud. The output shows which settings are supported in MDM providers, including Microsoft Intune. It also shows any deprecated settings, or settings not available to MDM providers.
39
40
40
41
If your organization uses GPOs, and you want to move some workloads to Microsoft Endpoint Manager and Intune, then Group Policy analytics will help.
41
42
43
+
Currently, this feature provides importing and analysis. In a future release (no ETA), you'll be able to create a policy based off your imported GPO, and deploy the policy.
44
+
42
45
This feature applies to:
43
46
44
47
- Windows 11
45
48
- Windows 10
46
49
47
-
This article shows you how export your GPOs, import the GPOs into Endpoint Manager, and review the analysis and results.
50
+
This article shows you how export your GPOs, import the GPOs into Endpoint Manager, and review the analysis and results.
48
51
49
52
## Prerequisites
50
53
51
-
Sign in as the Intune administrator with a role that has the **Security Baselines** permission. For example, the **Endpoint Security Manager** role has the **Security Baselines** permission. For more information on the built-in roles, see [role-based access control](../fundamentals/role-based-access-control.md).
54
+
- In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), sign in as the Intune administrator with a role that has the **Security Baselines** permission.
55
+
56
+
For example, the **Endpoint Security Manager** role has the **Security Baselines** permission. For more information on the built-in roles, see [role-based access control](../fundamentals/role-based-access-control.md).
52
57
53
58
## Export GPOs as an XML file
54
59
@@ -62,7 +67,7 @@ Sign in as the Intune administrator with a role that has the **Security Baseline
62
67
63
68
Be sure the file is less than 4 MB and has a proper unicode encoding. If the exported file is greater than 4 MB, then include fewer GPOs when you save your report from the GPMC.msc tool.
64
69
65
-
## Use Group Policy analytics
70
+
## Import GPOs and run analytics
66
71
67
72
1. In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Devices** > **Group Policy analytics (preview)**.
68
73
2. Select **Import**, and then select your saved XML file. When you select the XML file, Intune automatically analyzes the GPO in the XML file.
@@ -76,9 +81,9 @@ Be sure the file is less than 4 MB and has a proper unicode encoding. If the exp
76
81
-**MDM Support**: Shows the percentage of group policy settings in the GPO that have the same setting in Intune.
77
82
78
83
> [!NOTE]
79
-
> Whenever the Microsoft Intune product team makes changes to the mapping in Intune, the percentage under MDM Support automatically updates to reflect those changes.
84
+
> Whenever the Microsoft Intune product team makes changes to the mapping in Intune, the percentage under MDM Support automatically updates to reflect those changes.
80
85
81
-
-**Unknown Settings**: Shows GPO settings that fall outside of the list of the Configuration Service Providers (CSPs) that this tool can parse.
86
+
-**Unknown Settings**: There are some CSPs that can't be analyzed. **Unknown Settings** lists the GPOs that can't be analyzed.
82
87
-**Targeted in AD**: **Yes** means the GPO is linked to an OU in on-premises group policy. **No** means the GPO isn't linked to an on-premises OU.
83
88
-**Last imported**: Shows the date of the last import.
84
89
@@ -96,8 +101,6 @@ Be sure the file is less than 4 MB and has a proper unicode encoding. If the exp
96
101
97
102
**No** means there isn't a matching setting available to MDM providers, including Intune.
98
103
99
-
For more information on device configuration profiles, see [Apply features and settings on your devices using device profiles](device-profiles.md).
100
-
101
104
-**Value**: Shows the value imported from the GPO. It shows different values, such `true`, `900`, `Enabled`, `false`, and so on.
102
105
-**Scope**: Shows if the imported GPO targets users or targets devices.
103
106
-**Min OS Version**: Shows the minimum Windows OS version build numbers that the GPO setting applies. It may show `18362` (1903), `17130` (1803), and other Windows client versions.
@@ -106,7 +109,7 @@ Be sure the file is less than 4 MB and has a proper unicode encoding. If the exp
106
109
107
110
-**CSP Name**: A Configuration Service Provider (CSP) exposes device configuration settings in Windows client. This column shows the CSP that includes the setting. For example, you may see Policy, BitLocker, PassportforWork, and so on.
108
111
109
-
For more information on CSPs, see the [CSP reference](/windows/client-management/mdm/configuration-service-provider-reference).
112
+
The [CSP reference](/windows/client-management/mdm/configuration-service-provider-reference) lists the available CSPs, shows the supported OS editions, and more.
110
113
111
114
-**CSP Mapping**: Shows the OMA-URI path for the on-premises policy. You can use the OMA-URI in a [custom device configuration profile](custom-settings-configure.md). For example, you may see `./Device/Vendor/MSFT/BitLocker/RequireDeviceEnryption`.
112
115
@@ -141,7 +144,7 @@ Currently, the Group Policy analytics (preview) tool only supports non-ADMX sett
141
144
142
145
3. Select the **Reports** tab > **Group policy migration readiness**. In this report, you can:
143
146
144
-
- See the number of settings in your GPO that are available in a device configuration profile, if they can be in a custom profile, aren't supported, or are deprecated.
147
+
- See the number of settings in your GPO that can be configure in a device configuration profile. It also shows if the settings can be in a custom profile, aren't supported, or are deprecated.
145
148
- Filter the report output using the **Migration Readiness**, **Profile type**, and **CSP Name** filters.
146
149
- Select **Generate report** or **Generate again** to get current data.
147
150
- See the list of settings in your GPO.
@@ -151,10 +154,11 @@ Currently, the Group Policy analytics (preview) tool only supports non-ADMX sett
151
154
> [!NOTE]
152
155
> After you add or remove your imported GPOs, it can take about 20 minutes to update the Migration Readiness reporting data.
153
156
154
-
155
157
## Send product feedback
156
158
157
-
You can provide feedback on Group Policy Analytics when you select **Got feedback**. Examples of feedback areas:
159
+
You can provide feedback on Group Policy Analytics. In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Devices** > **Group Policy analytics (preview)** > **Got feedback**.
160
+
161
+
Examples of feedback areas:
158
162
159
163
- You received errors during GPO import or analytics, and you need more specific information.
160
164
- How easy is it to use Group Policy analytics to find the supported group policies in Microsoft Intune?
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/deployment-guide-enrollment-android.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: MandiOhlinger
8
8
ms.author: mandia
9
9
manager: dougeby
10
-
ms.date: 02/02/2022
10
+
ms.date: 02/03/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: enrollment
@@ -234,13 +234,13 @@ When you create the Intune enrollment profile, you decide if the devices are use
234
234
---
235
235
| Feature | Use this enrollment option when |
236
236
| --- | --- |
237
-
| Use Google Mobile Services (GMS). | ❌ AOSP doesn't use[GMS](https://www.android.com/gms/) (opens Android's web site). For example, some countries don't support GMS. <br/><br/> If your devices will use GMS, then use [dedicated devices](#android-enterprise-dedicated-devices) (in this article) or [fully managed](#android-enterprise-fully-managed) (in this article) enrollment. |
237
+
| Use Google Mobile Services (GMS). | ❌ <br/><br/> Device doesn't support[GMS](https://www.android.com/gms/) (opens Android's web site). Some countries don't support GMS. <br/><br/> If your devices will use GMS, then use [dedicated devices](#android-enterprise-dedicated-devices) (in this article) or [fully managed](#android-enterprise-fully-managed) (in this article) enrollment. |
238
238
| Devices are owned by the organization or school. | ✔️ |
239
239
| You have new or existing devices. | ✔️ |
240
240
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ❌ <br/><br/> Can only enroll one device at a time. |
241
241
| Devices are associated with a single user. | ✔️ |
242
242
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ |
243
-
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
243
+
| Devices are personal or BYOD. | ❌ <br/><br/>[Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article) support [GMS](https://www.android.com/gms/) (opens Android's web site).|
244
244
|Devices are managed by another MDM provider. | ❌ <br/><br/> To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune. |
245
245
| You use the optional device enrollment manager (DEM) account | ❌ <br/><br/> The DEM account isn't supported. |
246
246
@@ -270,7 +270,7 @@ Admins can complete the enrollment themselves, and then give the devices to the
270
270
1. Users turn on the device, and are prompted for information, including the enrollment method: QR Code. If you created a user-associated devices enrollment profile, then they may be asked to sign in with their organization credentials (`[email protected]`).
271
271
2. If you created a userless devices enrollment profile, then wait for the enrollment wizard to complete. When it does, the device is ready to use.
272
272
273
-
If you created a user-associated devices enrollment profile, then users enter the required information, and your enrollment profile applies to the device. For more specific steps, see [enroll the device](../user-help/enroll-device-android-microsoft-intune-app.md).
273
+
If you created a user-associated devices enrollment profile, then users enter the required information. Then, wait for the enrollment wizard to complete. For more specific steps, see [enroll the device](../user-help/enroll-device-android-microsoft-intune-app.md).
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/whats-new.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -495,7 +495,7 @@ We have added 9 [BitLocker settings that were previously only available in Group
495
495
### Monitor and troubleshoot
496
496
497
497
#### MDM support data to refresh automatically in Group Policy analytics tool<!-- 7852080 -->
498
-
Now whenever Microsoft makes changes to the mappings in Intune, the **MDM Support** column in the GP analytics tool automatically updates to reflect the changes. The automation is an improvement over the previous behavior, which required you to reimport your Group Policy object (GPO) to refresh the data. For more information about Group Policy analytics, see [Use Group Policy analytics](../configuration/group-policy-analytics.md#use-group-policy-analytics).
498
+
Now whenever Microsoft makes changes to the mappings in Intune, the **MDM Support** column in the GP analytics tool automatically updates to reflect the changes. The automation is an improvement over the previous behavior, which required you to reimport your Group Policy object (GPO) to refresh the data. For more information about Group Policy analytics, see [Use Group Policy analytics](../configuration/group-policy-analytics.md).
0 commit comments