Skip to content

Commit 8805bca

Browse files
authored
Merge pull request #8238 from Paasin/2207cbfinalreleaseupdate
2207cbfinalreleaseupdate
2 parents 4d7add1 + f119554 commit 8805bca

1 file changed

Lines changed: 40 additions & 22 deletions

File tree

memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2207.md

Lines changed: 40 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -25,31 +25,35 @@ To take full advantage of new Configuration Manager features, after you update t
2525

2626
## Cloud-attached management
2727

28-
### Administration Service Management option
28+
### Enhanced security for Configuration Manager administration service
2929
<!--12952905-->
30-
When configuring Azure Services, a new option called **Administration Service Management** is now added for enhanced security. Selecting this option allows administrators to segment their admin privileges between cloud management gateway (CMG) and administration service. By enabling this option, access is restricted to only administration service endpoints. Configuration Management clients will authenticate to the site using Azure Active Directory.
30+
We're introducing a new cloud application with limited access to the administration service. This feature allows cloud management gateway (CMG) to segment the admin privileges between a management point, and the administration service. This enables CMG to restrict access to the administration service. This feature gives admins granular access controls through which users can have access to the administration service and to enforce MFA if necessary.
3131

3232
For more information, see [Configure Azure services for use with Configuration Manager](../../servers/deploy/configure/azure-services-wizard.md).
3333

34-
### Improvements to cloud management gateway (CMG) workflow
34+
### Simplified application deployment approval
3535
<!--13351390#-->
3636

37-
You can now approve the application workflow through email. For the application approvals through email, manually add the CMG URL in the Azure Active Directory app as single page application redirect URI.
37+
An administrator can now approve or deny the request for deploying an application on a device from anywhere they have internet access by selecting a link in the email notification. This feature requires admins to manually add the CMG URL in the Azure Active Directory app as single page application redirect URI.
3838

39-
For more information, see [Approve applications in Configuration Manager](../../../apps/deploy-use/app-approval.md#to-take-action-from-internet).
39+
For more information, see [Create an app registration in Azure AD for your app service app](../../../apps/deploy-use/app-approval.md#to-take-action-from-internet).
4040

4141
<!--## Site infrastructure-->
4242

43-
### Default site boundary group behavior to support cloud source selection
43+
### Include and prefer a cloud source for a management point in a default boundary group
4444
<!--10674394-->
45-
You can now add options via PowerShell to include and prefer cloud management gateway (CMG) management points for the default site boundary group. When a site is set up, there's a default site boundary group created for each site and all the clients are by default mapped to it until they're assigned to some custom boundary group.
45+
Until 2203 current branch, you didn’t have an option to prefer a CMG as a management point in a default boundary group. The clients falling back to a default boundary group could only communicate to non-cloud-based management points.
46+
47+
When a site is initially installed, there's a default site boundary group created for each site, and all the clients use it by default until they're assigned to a custom boundary group.
48+
49+
Starting in Configuration Manager 2207, you can add options via PowerShell to include and prefer cloud sources. For instance, you can set the CMG as the preferred management point for the clients in the default boundary group.
4650

4751
For more information, see [
4852
Default site boundary group behavior supports cloud source selection](../../../core/servers/deploy/configure/boundary-groups.md#default-site-boundary-group-behavior-supports-cloud-source-selection).
4953

5054
## Client management
5155

52-
### Script execution timeout for compliance settings
56+
### Granular control over compliance settings evaluation
5357
<!--14120481-->
5458
You can now define a **Script Execution Timeout (seconds)** when configuring client settings for compliance settings. The timeout value can be set from a minimum of 60 seconds to a maximum of 600 seconds. This new setting allows you more flexibility for configuration items when you need to run scripts that may exceed the default of 60 seconds.
5559

@@ -63,40 +67,43 @@ For more information, see the [compliance settings group of client settings](../
6367

6468
## Software updates
6569

66-
### Folders for automatic deployment rules (ADRs)
70+
### Improved manageability of automatic deployment rules (ADRs)
6771
<!--13507410-->
6872

69-
Admins can now organize ADRs by using folders. This change allows for better categorization and management of ADRs. Folder management for ADRs is also supported with PowerShell cmdlets.
73+
You'll now be able to organize ADRs with folders. This improvement helps you with better categorization and management of ADRs across your organizational hierarchy by having a structured view across your phased deployments. Folder can also be created with PowerShell cmdlets.
7074

7175
For more information, see [Process to create a folder for automatic deployment rules](../../../sum/deploy-use/automatically-deploy-software-updates.md#process-to-add-a-new-deployment-to-an-existing-adr).
7276

73-
### Offset for reoccuring monthly maintenance window schedules
77+
### Enhanced control over monthly maintenance windows
7478
<!--3601127#-->
7579

76-
Based upon your feedback, you can now offset monthly maintenance window schedules to better align deployments with the release of monthly security updates. For example, using an offset of two days after the second Tuesday of the month, sets the maintenance window for Thursday.
80+
Based upon your feedback, we have enhanced monthly maintenance windows scheduling. You can now set monthly maintenance window schedules to better align deployments with the release of monthly software updates by configuring offsets. For example, using an offset of two days after the second Tuesday of the month, sets the maintenance window for Thursday.
7781

7882
For more information, see [How to use maintenance windows in Configuration Manager](../../../core/clients/manage/collections/use-maintenance-windows.md).
7983

8084
<!--## OS deployment-->
8185

8286

83-
## Protection
87+
## Endpoint Protection
8488

85-
### Microsoft Defender for Endpoint onboarding for Windows Server 2012 R2 and Windows Server 2016
89+
### Improved Microsoft Defender for Endpoint (MDE) onboarding for Windows Server 2012 R2 and Windows Server 2016
8690
<!--9265511-->
87-
Configuration Manager version 2207 now supports automatic deployment of [modern, unified Microsoft Defender for Endpoint for Windows Server 2012 R2 & 2016](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defending-windows-server-2012-r2-and-2016/bc-p/2904464). Windows Server 2012 and 2016 devices that are targeted with Microsoft Defender for Endpoint onboarding policy will use the unified agent versus the existing Microsoft Monitoring Agent based solution, if you choose to use through Client Settings.
91+
Configuration Manager version 2207 now supports automatic deployment of modern, unified Microsoft Defender for Endpoint for Windows Server 2012 R2 & 2016. Windows Server 2012 and 2016 devices that are targeted with Microsoft Defender for Endpoint onboarding policy will use the unified agent versus the existing Microsoft Monitoring Agent based solution, if configured through Client Settings.
8892

8993
For more information, see [Microsoft Defender for Endpoint onboarding](../../../protect/deploy-use/defender-advanced-threat-protection.md).
9094

91-
### Improvements to Configuration Manager policies for Microsoft Defender Application Guard
95+
### Enhanced protection for untrusted environments
9296
<!-- 14059872 -->
9397

94-
1. Windows Defender Application Guard has been renamed to Microsoft Defender Application Guard in the Configuration Manager console.
95-
1. The **General** settings page allows you to enable for isolated Windows environments and enable for Microsoft Edge and isolated Windows environments.
96-
1. The **Application Behavior** settings page allows you to enable or disable cameras and microphones, along with certificate matching the thumbprints to the isolated container.
98+
1. Windows Defender Application Guard is now called Microsoft Defender Application Guard in the console.
99+
100+
1. The **General** settings page in the Microsoft Defender Application Guard now allows you to create policies within Configuration Manager to protect your employees using Microsoft Edge and isolated Windows environments.
101+
102+
1. The **Application Behavior** settings page allows you to enable or disable cameras and microphones, along with certificate matching of the thumbprints to the isolated container.
103+
97104
1. The following items were removed:
98-
- The Enterprise sites can load non-enterprise content, such as third-party plug-ins setting under the **Host interaction** page.
99-
- The file trust criteria policy in the **File Management** page.
105+
- The Enterprise sites can load non-enterprise content, such as third-party plug-in settings, under the **Host interaction** page.
106+
- The file trust criteria policy, under the **File Management** page.
100107

101108
For more information, see [Create and deploy Microsoft Defender Application Guard policy](../../../protect/deploy-use/create-deploy-application-guard-policy.md#create-a-policy-and-to-browse-the-available-settings).
102109

@@ -112,7 +119,18 @@ For more information, see [Create and deploy Microsoft Defender Application Guar
112119

113120
### Improvements to the console
114121

115-
- When using the search bar, the **Path** criteria is added whenever subfolders are included in the search. <!--14908615-->
122+
- When performing a search on any node in the console, the search bar will now include a **Path** criteria to show that subfolders in the node are included in the search.
123+
124+
- The path criteria is informational and can’t be edited.
125+
126+
- By default, all subfolders will be searched when you perform a search in any node that contains subfolders. You can narrow down the search by selecting the “Current Node” option from the search toolbar.
127+
128+
### Improvements to the dark theme
129+
130+
The dark theme has been available as a pre-release feature since 2203. In this release we've extended the dark theme to additional components such as buttons, context menus, and hyperlinks. Enable this pre-release feature to experience the dark theme.
131+
132+
133+
<!--14908615-->
116134

117135
For more information, see [Console changes and tips](../../servers/manage/admin-console-tips.md#bkmk_2207).
118136

0 commit comments

Comments
 (0)