Skip to content

Commit 89f4962

Browse files
author
Angela Fleischmann
authored
Merge pull request #7135 from Erikre/erikre-doc-13947563-ID
Erikre-docs-13947563-ID
2 parents edbc1cf + 38414f3 commit 89f4962

1 file changed

Lines changed: 350 additions & 2 deletions

File tree

memdocs/intune/fundamentals/in-development.md

Lines changed: 350 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ keywords:
88
author: dougeby
99
ms.author: dougeby
1010
manager: dougeby
11-
ms.date: 03/24/2022
11+
ms.date: 03/31/2022
1212
ms.topic: conceptual
1313
ms.service: microsoft-intune
1414
ms.subservice: fundamentals
@@ -65,6 +65,9 @@ You can use RSS to be notified when this article is updated. For more informatio
6565

6666
## App management
6767

68+
### Enterprise feedback policies for Web Company Portal<!-- 9846764 -->
69+
Feedback settings will be provided to address M365 enterprise feedback policies for the currently logged in user via the Microsoft 365 Apps Admin Center. The settings are used to determine whether feedback can be enabled or must be disabled for a user in the Web Company Portal.
70+
6871
### iOS Company Portal minimum required version<!-- 13016075 -->
6972
With an upcoming release of the MS Authenticator app, users will be required to update to v5.2204 of the iOS Company Portal. If you have enabled the **[Block installing apps using App Store](../configuration/device-restrictions-ios.md#settings-apply-to-automated-device-enrollment-supervised)** device restriction setting, you will likely need to push an update to the related devices that use this setting. Otherwise, no action is needed. If you have a helpdesk, you may want to make them aware of the prompt to update the Company Portal app. In most cases, users have app updates set to automatic, so they receive the updated Company Portal app without taking any action. Users that have an earlier app version will be prompted to update to the latest Company Portal app.
7073

@@ -77,12 +80,71 @@ This feature targets devices that operate on Android 11+. For devices that opera
7780
Win32 App Log collection via Intune Management Extension has moved to the Windows 10 device diagnostic platform, reducing time to collect logs from 1-2 hours to 20 minutes. We've also increased the size from 60mb to 250mb. Along with performance improvements, the app logs will also be available under the **Device diagnostics monitor** action for each device, as well as the managed app monitor. For information about how to collect diagnostics, see [Collect diagnostics from a Windows device](..\remote-actions\collect-diagnostics.md) and [Troubleshooting Win32 app installations with Intune](/troubleshoot/mem/intune/troubleshoot-win32-app-install).
7881

7982
### Uninstall DMG-type applications on managed macOS devices (Public preview)<!-- 13155022 -->
80-
You will be able to use the Uninstall assignment type to remove DMG-type applications on managed macOS devices from Microsoft Endpoint Manager. You can find macOS DMG apps in [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) by selecting **Apps** > **macOS** > **macOS app (.DMG)**. For related information, [Add a macOS DMG app to Microsoft Intune](../apps/lob-apps-macos-dmg.md).
83+
You will be able to use the Uninstall assignment type to remove DMG-type applications on managed macOS devices from Microsoft Endpoint Manager. You can find macOS DMG apps in [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) by selecting **Apps** > **macOS** > **macOS app (.DMG)**. For related information, [Add a macOS DMG app to Microsoft Intune](../apps/lob-apps-macos-dmg.md).
84+
85+
### Update to the App configuration policies list<!-- 13903969 -->
86+
In Intune, the **Assigned** column in the **App configuration policies** list will be removed. To view the assigned groups for an app configuration policy, navigate to [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) > **Apps** > **App configuration policies** > *select a policy* > **Overview**.
87+
88+
<!-- ***********************************************-->
89+
90+
## Device enrollment
91+
92+
### Improvements for enrollment profiles for Apple’s Automated Device Enrollment (Public preview)<!-- 10111795 -->
93+
As a public preview, we’re adding new Setup Assistant screens you can configure when [creating enrollment profiles](../enrollment/device-enrollment-program-enroll-ios.md#create-an-apple-enrollment-profile) for Apple’s Automated Device Enrollment (ADE). The following new screens will be available on the *Setup Assistant* tab for both iOS/iPadOS and macOS as follows:
94+
95+
- iOS/iPadOS 13 and later - **Get Started (preview)**
96+
- Default – Show
97+
- Admin can configure to hide the Get Started pane (Setup Assistant screen) during ADE enrollment.
98+
99+
- macOS 12 and later - **Auto Unlock with Apple Watch (preview)**
100+
- Default – Show
101+
- Admin can configure to hide the Unlock Your Mac with your Apple Watch pane (Setup Assistant screen) during ADE enrollment.
102+
103+
<!-- ***********************************************-->
104+
105+
## Device management
106+
107+
### Device actions available to Android (AOSP) users in Microsoft Intune app<!-- 12645718 -->
108+
AOSP device users will be able to delete, wipe, and rename their enrolled devices in the Microsoft Intune app. This feature will be available on devices enrolled in Intune as user-associated (Android) AOSP devices.
109+
110+
### Updating the device diagnostics folder structure<!-- 8504019 -->
111+
We’re updating how Intune exports [Windows Device Diagnostic data](../remote-actions/collect-diagnostics.md). Today, the zip file is flat structure of numbered folders that doesn’t identify their contents. Once updated, the logs collected will be named to match the data that was collected, and if multiple files are collected a folder will be created.
112+
113+
To take advantage of this diagnostic logging update, devices must install one of the following updates:
114+
- Windows 11 - KB5011563
115+
- Windows 10 - KB5011543
116+
117+
These updates are expected to be made available through Windows Updates on April 12, 2022.
118+
119+
### Support for Audio Alert on Android corporate-owned work- profiles and fully managed (COBO and COPE) devices<!-- 13499471 -->
120+
You'll be able to use the **Play lost device sound** device action to trigger an alarm sound on the device to assist in locating the lost or stolen Android Enterprise corporate owned work profiles and fully managed devices.
121+
122+
For more information, see [Locate lost or stolen devices](../remote-actions/device-locate.md).
81123

82124
<!-- ***********************************************-->
83125

84126
## Device configuration
85127

128+
### New wired networks device configuration profile for Windows devices<!-- 1746923 -->
129+
There will be a new **Wired Networks** device configuration profile (**Devices** > **Configuration profiles** > **Create profile** > **Windows 10 and later** for platform > **Templates** > **Wired networks** for profile type).
130+
131+
Use this profile to configure common wired network settings, including authentication, EAP type, server trust, and more.
132+
133+
Applies to:
134+
- Windows 11
135+
- Windows 10
136+
137+
### Create a Settings Catalog policy using your imported GPOs with Group Policy analytics (public preview)<!-- 6379751 -->
138+
Using Group Policy analytics, you can import your on-premises GPO, and see the settings that are supported in Microsoft Intune. It also shows any deprecated settings, or settings not available to MDM providers.
139+
140+
When the analysis runs, you'll see the settings that are ready for migration. There will be a **Migrate** option (public preview) that creates a Settings Catalog profile using these settings. Then, you can assign the profile to your groups.
141+
142+
For more information on what you can do now, see [Analyze your on-premises group policy objects (GPO) using Group Policy analytics in Microsoft Endpoint Manager](../configuration/group-policy-analytics.md).
143+
144+
Applies to:
145+
- Windows 11
146+
- Windows 10
147+
86148
### Use the Settings Catalog to create a Universal Print policy on Windows 11 devices<!-- 5513123 -->
87149
Many organizations are moving their printer infrastructure to the cloud. [Universal Print](/universal-print/fundamentals/universal-print-whatis) is a cloud-based printing solution for Microsoft 365 customers. It uses built-in cloud printers, built-in legacy printers, and runs entirely in Microsoft Azure. When Universal Print is deployed with Universal Print-compatible printers, it doesn't require any on-premises infrastructure.
88150

@@ -93,6 +155,292 @@ Currently, you must use the [Universal Print printer provisioning tool](/univers
93155
Applies to:
94156
- Windows 11
95157

158+
### New macOS settings in Setting Catalog<!-- 13654614 -->
159+
The Settings Catalog has new macOS settings you can configure (**Devices** > **Configuration profiles** > **Create profile** > **macOS** for platform >**Settings catalog (preview)** for profile type):
160+
161+
**Accounts > Mobile Accounts**:
162+
163+
- Ask For Secure Token Auth Bypass
164+
- Create At Login
165+
- Expiry Delete Disused Seconds
166+
- Warn On Create
167+
- Warn On Create Allow Never
168+
169+
**App Management > Autonomous Single App Mode**:
170+
171+
- Bundle Identifier
172+
- Team Identifier
173+
174+
**App Management > NS Extension Management**:
175+
176+
- Allowed Extensions
177+
- Denied Extension Points
178+
- Denied Extensions
179+
180+
**App Store**:
181+
182+
- Disable Software Update Notifications
183+
- Restrict Store Software Update Only
184+
- restrict-store-disable-app-adoption
185+
186+
**Authentication > Directory Service**:
187+
188+
- AD Allow Multi Domain Auth
189+
- AD Allow Multi Domain Auth Flag
190+
- AD Create Mobile Account At Login
191+
- AD Create Mobile Account At Login Flag
192+
- AD Default User Shell
193+
- AD Default User Shell Flag
194+
- AD Domain Admin Group List
195+
- AD Domain Admin Group List Flag
196+
- AD Force Home Local
197+
- AD Force Home Local Flag
198+
- AD Map GGID Attribute
199+
- AD Map GGID Attribute Flag
200+
- AD Map GID Attribute
201+
- AD Map GID Attribute Flag
202+
- AD Map UID Attribute
203+
- AD Map UID Attribute Flag
204+
- AD Mount Style
205+
- AD Namespace
206+
- AD Namespace Flag
207+
- AD Organizational Unit
208+
- AD Packet Encrypt
209+
- AD Packet Encrypt Flag
210+
- AD Packet Sign
211+
- AD Packet Sign Flag
212+
- AD Preferred DC Server
213+
- AD Preferred DC Server Flag
214+
- AD Restrict DDNS
215+
- AD Restrict DDNS Flag
216+
- AD Trust Change Pass Interval Days
217+
- AD Trust Change Pass Interval Days Flag
218+
- AD Use Windows UNC Path
219+
- AD Use Windows UNC Path Flag
220+
- AD Warn User Before Creating MA Flag
221+
- Client ID
222+
- Description
223+
- Password
224+
- User Name
225+
226+
**Authentication > Identification**:
227+
228+
- Prompt
229+
- Prompt Message
230+
231+
**Login > Login Window Login Items**:
232+
233+
- Disable Login Items Suppression
234+
235+
**Media Management Disc Burning**:
236+
237+
- Burn Support
238+
239+
**Parental Controls > Parental Controls Application Restrictions**:
240+
241+
- Family Controls Enabled
242+
243+
**Parental Controls > Parental Controls Content Filter**:
244+
245+
- Allowlist Enabled
246+
- Filter Allowlist
247+
- Filter Blocklist
248+
- Site Allowlist
249+
- Address
250+
- Page Title
251+
- Use Content Filter
252+
253+
**Parental Controls > Parental Controls Dictionary**:
254+
255+
- Parental Control
256+
257+
**Parental Controls > Parental Controls Game Center**:
258+
259+
- GK Feature Account Modification Allowed
260+
261+
**System Configuration > File Provider**:
262+
263+
- Allow Managed File Providers To Request Attribution
264+
265+
**System Configuration > Screensaver**:
266+
267+
- Ask For Password
268+
- Ask For Password Delay
269+
- Login Window Idle Time
270+
- Login Window Module Path
271+
272+
**User Experience > Finder**:
273+
274+
- Prohibit Burn
275+
- Prohibit Connect To
276+
- Prohibit Eject
277+
- Prohibit Go To Folder
278+
- Show External Hard Drives On Desktop
279+
- Show Hard Drives On Desktop
280+
- Show Mounted Servers On Desktop
281+
- Show Removable Media On Desktop
282+
- Warn On Empty Trash
283+
284+
**User Experience > Managed Menu Extras**:
285+
286+
- AirPort
287+
- Battery
288+
- Bluetooth
289+
- Clock
290+
- CPU
291+
- Delay Seconds
292+
- Displays
293+
- Eject
294+
- Fax
295+
- HomeSync
296+
- iChat
297+
- Ink
298+
- IrDA
299+
- Max Wait Seconds
300+
- PCCard
301+
- PPP
302+
- PPPoE
303+
- Remote Desktop
304+
- Script Menu
305+
- Spaces
306+
- Sync
307+
- Text Input
308+
- TimeMachine
309+
- Universal Access
310+
- User
311+
- Volume
312+
- VPN
313+
- WWAN
314+
315+
**User Experience > Notifications**:
316+
317+
- Alert Type
318+
- Badges Enabled
319+
- Critical Alert Enabled
320+
- Notifications Enabled
321+
- Show In Lock Screen
322+
- Show In Notification Center
323+
- Sounds Enabled
324+
325+
**User Experience > Time Machine**:
326+
327+
- Auto Backup
328+
- Backup All Volumes
329+
- Backup Size MB
330+
- Backup Skip System
331+
- Base Paths
332+
- Mobile Backups
333+
- Skip Paths
334+
335+
**Xsan**:
336+
337+
- San Auth Method
338+
339+
**Xsan > Xsan Preferences**:
340+
341+
- Deny DLC
342+
- Deny Mount
343+
- Only Mount
344+
- Prefer DLC
345+
- Use DLC
346+
347+
The following settings are also in Settings Catalog. Previously, they were only available in Templates:
348+
349+
**App Management > Associated Domains**:
350+
351+
- Enable Direct Downloads
352+
353+
**Networking > Content Caching**:
354+
355+
- Allow Cache Delete
356+
- Allow Personal Caching
357+
- Allow Shared Caching
358+
- Auto Activation
359+
- Auto Enable Tethered Caching
360+
- Cache Limit
361+
- Data Path
362+
- Deny Tethered Caching
363+
- Display Alerts
364+
- Keep Awake
365+
- Listen Ranges
366+
- Listen Ranges Only
367+
- Listen With Peers And Parents
368+
- Local Subnets Only
369+
- Log Client Identity
370+
- Parent Selection Policy
371+
- Parents
372+
- Peer Filter Ranges
373+
- Peer Listen Ranges
374+
- Peer Local Subnets Only
375+
- Port
376+
- Public Range
377+
378+
**Restrictions**:
379+
380+
- Allow Activity Continuation
381+
- Allow Adding Game Center Friends
382+
- Allow Air Drop
383+
- Allow Auto Unlock
384+
- Allow Camera
385+
- Allow Cloud Address Book
386+
- Allow Cloud Bookmarks
387+
- Allow Cloud Calendar
388+
- Allow Cloud Desktop And Documents
389+
- Allow Cloud Document Sync
390+
- Allow Cloud Keychain Sync
391+
- Allow Cloud Mail
392+
- Allow Cloud Notes
393+
- Allow Cloud Photo Library
394+
- Allow Cloud Private Relay
395+
- Allow Cloud Reminders
396+
- Allow Content Caching
397+
- Allow Diagnostic Submission
398+
- Allow Dictation
399+
- Allow Erase Content And Settings
400+
- Allow Fingerprint For Unlock
401+
- Allow Game Center
402+
- Allow iTunes File Sharing
403+
- Allow Multiplayer Gaming
404+
- Allow Music Service
405+
- Allow Passcode Modification
406+
- Allow Password Auto Fill
407+
- Allow Password Proximity Requests
408+
- Allow Password Sharing
409+
- Allow Remote Screen Observation
410+
- Allow Screen Shot
411+
- Allow Spotlight Internet Results
412+
- Allow Wallpaper Modification
413+
- Enforced Fingerprint Timeout
414+
- Enforced Software Update Delay
415+
- Enforced Software Update Major OS Deferred Install Delay
416+
- Enforced Software Update Minor OS Deferred Install Delay
417+
- Enforced Software Update Non OS Deferred Install Delay
418+
- Force Classroom Automatically Join Classes
419+
- Force Classroom Request Permission To Leave Classes
420+
- Force Classroom Unprompted App And Device Lock
421+
- Force Delayed App Software Updates
422+
- Force Delayed Major Software Updates
423+
- Force Delayed Software Updates
424+
- Safari Allow Autofill
425+
426+
There isn't any conflict resolution between policies created using the Settings catalog and policies created using Templates. When creating new policies in the Settings Catalog, be sure there are no conflicting settings with your current policies.
427+
428+
For more information about configuring Settings catalog profiles in Intune, see [Create a policy using settings catalog in Microsoft Intune](../configuration/settings-catalog.md).
429+
430+
Applies to:
431+
- macOS
432+
433+
<!-- ***********************************************-->
434+
435+
## Device security
436+
437+
### Microsoft Defender for Endpoint as the Tunnel client app for iOS will soon be out of Preview<!-- 9849514 -->
438+
The preview version of Microsoft Defender for Endpoint that supports [Microsoft Tunnel](../protect/microsoft-tunnel-overview.md) on iOS/iPadOS will soon be out of preview and become generally available.
439+
440+
When the Microsoft Defender for Endpoint app with support for Microsoft Tunnel becomes generally available for iOS, the standalone tunnel client app for iOS will be deprecated with support ending 60 days later.
441+
442+
If you are using the standalone tunnel app for iOS, prepare for this change by planning to [migrate to the Microsoft Defender for Endpoint app](../protect/microsoft-tunnel-migrate-app.md) before support for the standalone app ends.
443+
96444
<!-- ***********************************************-->
97445

98446
## Notices

0 commit comments

Comments
 (0)