You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/configuration/device-restrictions-windows-10.md
+1-3Lines changed: 1 addition & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -445,11 +445,9 @@ This device restrictions profile is directly related to the kiosk profile you cr
445
445
-**Clear browsing data on exit** (desktop only): **Yes** clears the history, and browsing data when users exit Microsoft Edge. **No** (default) uses the OS default, which may cache the browsing data.
446
446
-**Sync browser settings between user's devices**: Choose how you want to sync browser settings between devices. Your options:
447
447
-**Allow**: Allow syncing of Microsoft Edge browser settings between user's devices
448
-
-**Block and enable user override**: Block syncing of Microsoft Edge browser settings between user's devices. Users can override this setting.
448
+
-**Block and enable user override**: Block syncing of Microsoft Edge browser settings between user's devices. Users can override this setting. When this option is selected, users can override the admin designation.
449
449
-**Block**: Block syncing of Microsoft Edge browser setting between users devices. Users can't override this setting.
450
450
451
-
When "block and enable user override" is selected, user can override admin designation.
452
-
453
451
-**Allow Password Manager**: **Yes** (default) allows Microsoft Edge to automatically use Password Manager, which allows users to save and manage passwords on the device. **No** prevents Microsoft Edge from using Password Manager.
454
452
-**Cookies**: Choose how cookies are handled in the web browser. Your options:
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/android-dedicated-devices-fully-managed-enroll.md
+66-13Lines changed: 66 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ keywords:
8
8
author: Lenewsad
9
9
ms.author: lanewsad
10
10
manager: dougeby
11
-
ms.date: 04/21/2022
11
+
ms.date: 08/16/2022
12
12
ms.topic: how-to
13
13
ms.service: microsoft-intune
14
14
ms.subservice: enrollment
@@ -54,7 +54,7 @@ After you've set up your Android Enterprise [dedicated devices](android-kiosk-en
54
54
55
55
## Enroll by using Near Field Communication (NFC)
56
56
57
-
Create a specially-formatted NFC tag to provision NFC-supported devices running Android 8.0 or later. You can use your own app or any NFC tag-creation tool. For more information, see [C-based Android Enterprise device enrollment with Microsoft Intune](/archive/blogs/cbernier/nfc-based-android-enterprise-device-enrollment-with-microsoft-intune) and [Google's Android Management API documentation](https://developers.google.com/android/management/provision-device#nfc_method).
57
+
Create a speciallyformatted NFC tag to provision NFC-supported devices running Android 8.0 or later. You can use your own app or any NFC tag-creation tool. For more information, see [C-based Android Enterprise device enrollment with Microsoft Intune](/archive/blogs/cbernier/nfc-based-android-enterprise-device-enrollment-with-microsoft-intune) and [Google's Android Management API documentation](https://developers.google.com/android/management/provision-device#nfc_method).
58
58
59
59
For corporate-owned work profile (COPE) devices, the NFC enrollment method is only supported on devices running Android versions 8.0 to 10.0. It's not supported with Android 11.0 or later.
60
60
@@ -68,7 +68,7 @@ For corporate-owned work profile (COPE) devices, the NFC enrollment method is on
68
68
69
69
1. Turn on your wiped device.
70
70
2. On the **Welcome** screen, select your language.
71
-
3. Connect to your **Wifi**, and then choose **NEXT**.
71
+
3. Connect to your **Wi-fi**, and then choose **NEXT**.
72
72
4. Accept the Google Terms and conditions, and then choose **NEXT**.
73
73
5. On the Google sign-in screen, enter **afw#setup** instead of a Gmail account, and then choose **NEXT**.
74
74
6. Choose **INSTALL** for the **Android Device Policy** app.
@@ -87,13 +87,68 @@ Scan the QR code from the enrollment profile to enroll devices running Android 8
87
87
2. On devices running Android 8.0, you'll be prompted to install a QR reader. Devices running Android 9 and later are pre-installed with a QR reader.
88
88
3. Use the QR reader to scan the enrollment profile QR code and then follow the on-screen prompts to enroll.
89
89
90
-
## Enroll by using Google Zero Touch
90
+
## Enroll by using Google Zero Touch
91
91
92
-
To use Google's Zero Touch system, the device must support it and be affiliated with a supplier that is part of the service. For more information, see [Google's Zero Touch program website](https://www.android.com/enterprise/management/zero-touch/).
92
+
To use this method, zero-touch enrollment must be supported on devices and affiliated with a supplier that is part of the Android zero-touch enrollment service. For more information, such as prerequisites, where to purchase devices, and how to associate a Google Account with your corporate email, see [Zero-touch enrollment for IT admins](https://support.google.com/work/android/answer/7514005)(opens Android Enterprise Help).
93
93
94
-
1. Create a new Configuration in the Zero Touch console.
95
-
2. Choose **Microsoft Intune** from the EMM DPC dropdown.
96
-
3. In Google's Zero Touch console, copy/paste the following JSON into the DPC extras field. Replace the *YourEnrollmentToken* string with the enrollment token you created as part of your enrollment profile. Be sure to surround the enrollment token with double quotes.
94
+
This section describes how to:
95
+
* Create a zero-touch configuration in the admin center
96
+
* Create a zero-touch configuration in the zero-touch enrollment portal
97
+
98
+
### Create zero-touch configuration in admin center
99
+
The zero-touch iframe lets you access the zero-touch enrollment portal in the Microsoft Endpoint Manager admin center. To enable the iframe, you must first add the *update app sync* permission and enable enrollment for corporate-owned, fully managed devices. After those steps are complete, the zero-touch enrollment option becomes visible in the admin center and you can link your account and create zero-touch configurations.
100
+
101
+
Complete the following steps to enable the iframe and create a new zero-touch configuration. To create configurations in the zero-touch enrollment portal instead, skip to [Create configuration in zero-touch enrollment portal](android-dedicated-devices-fully-managed-enroll.md#create-configuration-in-zero-touch-enrollment-portal).
102
+
103
+
#### Step 1: Add required permission
104
+
Add the *update app sync* permission.
105
+
106
+
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431)
107
+
admin.
108
+
2. Select **Tenant administration** > **Roles**.
109
+
3. Select your role from the list.
110
+
4. Select **Properties**.
111
+
5. Go to **Permissions** and then select **Edit**.
112
+
5. Select **Android for Work**.
113
+
6. Next to **Update app sync**, select **Yes**.
114
+
9. Select **Review + save** to review your changes.
115
+
9. Select **Save**.
116
+
117
+
#### Step 2: Enable enrollment for corporate-owned devices
118
+
Verify that enrollment is enabled for corporate-owned, fully managed devices.
119
+
120
+
1. In the admin center, go to **Devices** > **Enroll devices**.
121
+
2. Select **Android enrollment**.
122
+
3. Under **Enrollment profiles**, choose **Corporate-owned, fully managed user devices**.
123
+
4. Verify that the setting for **Allow users to enroll corporate-owned user devices**, is set to **Yes**.
124
+
125
+
#### Step 3: Link zero-touch account to Intune
126
+
Link a zero-touch account with your Microsoft Intune account. Upon linking the account, Intune creates a default zero-touch configuration.
127
+
128
+
1. In the admin center, go to **Devices** > **Enroll devices**.
129
+
2. Select **Android enrollment**.
130
+
2. Under **Bulk enrollment methods**, choose **Zero-touch enrollment**.
131
+
3. The iframe opens. Select **Next** to begin setup.
132
+
4. Sign in with the Google account you provided to your reseller.
133
+
5. Select the zero-touch account you want to link, and then select **Link**.
134
+
6. A default configuration is created. A screen appears with basic information about the new configuration. Intune will automatically apply the default to any zero-touch enabled device that's without an existing configuration. Select **Next** to continue.
135
+
136
+
> [!TIP]
137
+
> The token used for the default configuration is for a fully managed device. If you want to create a zero-touch configuration for a corporate-owned work profile device or a dedicated device, see [Create configuration in zero-touch enrollment portal](android-dedicated-devices-fully-managed-enroll.md#create-configuration-in-zero-touch-enrollment-portal) (in this article).
138
+
6. Add support information to assist device users during setup.
139
+
7. Select **Save**.
140
+
141
+
Once your account is linked with Intune, zero-touch enabled devices are ready to receive the default configuration. You can view existing zero-touch configurations, edit support information, unlink the account, and link other accounts in the admin center.
142
+
143
+
### Create configuration in zero-touch enrollment portal
144
+
145
+
Add a zero-touch configuration in the Google zero-touch enrollment portal. You can use the zero-touch enrollment portal by itself to manage configurations, or you can use it in combination with the zero-touch iframe. The portal supports configurations for fully managed and dedicated devices, and corporate-owned devices with a work profile.
146
+
147
+
1. Sign in to the zero-touch enrollment portal with your Google account.
148
+
2. Select the option to add a new configuration.
149
+
3. Fill out the information in the configuration panel.
150
+
4. Select **Microsoft Intune** as the EMM DPC app.
151
+
5. Copy the following JSON text into the DPC extras field. Replace `YourEnrollmentToken` with the enrollment token you created as part of your enrollment profile. Be sure to surround the enrollment token with double quotes.
97
152
98
153
```json
99
154
{
@@ -105,11 +160,9 @@ To use Google's Zero Touch system, the device must support it and be affiliated
6. Enter your organization's name and support information, which is shown on screen while users set up their devices.
164
+
165
+
For more information about how to assign a default configuration or apply a configuration in the zero-touch portal, see [Zero-touch enrollment for IT admins](https://support.google.com/work/android/answer/7514005)(opens Android Enterprise Help).
113
166
114
167
## Enroll by using Knox Mobile Enrollment
115
168
To use Samsung's Knox Mobile Enrollment, the device must be running Android OS version 8.0 or later and Samsung Knox 2.8 or higher. For more information, learn [how to automatically enroll your devices with Knox Mobile Enrollment](./android-samsung-knox-mobile-enroll.md).
Copy file name to clipboardExpand all lines: memdocs/intune/protect/encrypt-devices.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -187,7 +187,7 @@ To change the disk encryption type between full disk encryption and used space o
187
187
188
188
#### TPM startup PIN or key
189
189
190
-
A device **must not require** use of a startup PIN or startup key.
190
+
A device **must not be set to require** a startup PIN or startup key.
191
191
192
192
When a TPM startup PIN or startup key is required on a device, BitLocker can't silently enable on the device and instead requires interaction from the end user. Settings to configure the TPM startup PIN or key are available in both the endpoint protection template and the BitLocker policy. By default, these policies do not configure these settings.
193
193
@@ -289,4 +289,4 @@ For information about BitLocker deployments and requirements, see the [BitLocker
289
289
-[Monitor disk encryption](../protect/encryption-monitor.md)
-[Known issues for Enforcing BitLocker policies with Intune](/windows/security/information-protection/bitlocker/ts-bitlocker-intune-issues)
292
-
-[BitLocker management for enterprises](/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises), in the Windows security documentation
292
+
-[BitLocker management for enterprises](/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises), in the Windows security documentation
Copy file name to clipboardExpand all lines: memdocs/intune/protect/microsoft-tunnel-configure.md
+3-1Lines changed: 3 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -365,7 +365,9 @@ For more information about *mst-cli*, see [Reference for Microsoft Tunnel](../pr
365
365
366
366
## Uninstall the Microsoft Tunnel
367
367
368
-
To uninstall the product, run **./mst-cli uninstall** from the Linux server as root.
368
+
To uninstall the product, run **./mst-cli uninstall** from the Linux server as root.
369
+
370
+
After the product is uninstalled, delete the corresponding server record in the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) under **Tenant administration** > **Microsoft Tunnel Gateway** > **Servers**.
Copy file name to clipboardExpand all lines: memdocs/intune/protect/windows-10-feature-updates.md
+3Lines changed: 3 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -224,6 +224,9 @@ Selecting a profile from the list opens the profiles **Overview** pane where you
224
224
- Select **Properties** to modify the deployment. On the *Properties* pane, select **Edit** to open the *Deployment settings or Assignments*, where you can then modify the deployment.
225
225
- Select **End user update status** to view information about the policy.
226
226
227
+
> [!NOTE]
228
+
> The End user update status Last Scanned Time value will return 'Not scanned yet' until an initial user logs on and Update Session Orchestrator (USO) scan is initiated. For more information on the Unified Update Platform (UUP) architecture and related components, see [Get started with Windows Update](/windows/deployment/update/windows-update-overview).
229
+
227
230
## Validation and reporting
228
231
229
232
There are multiple options to get in-depth reporting for Windows 10/11 updates with Intune. Windows update reports show details about your Windows 10 and Windows 11 devices side by side in the same report.
Copy file name to clipboardExpand all lines: windows-365/enterprise/whats-new.md
+19-1Lines changed: 19 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: ErikjeMS
8
8
ms.author: erikje
9
9
manager: dougeby
10
-
ms.date: 08/08/2022
10
+
ms.date: 08/16/2022
11
11
ms.topic: reference
12
12
ms.service: cloudpc
13
13
ms.subservice:
@@ -48,6 +48,24 @@ Learn what new features are available in Windows 365 Enterprise.
48
48
### End user experience
49
49
-->
50
50
51
+
52
+
<!-- ########################## -->
53
+
## Week of August 15, 2022
54
+
55
+
<!-- vvvvvvvvvvvvvvvvvvvvvv -->
56
+
### App management
57
+
58
+
#### Language and region configuration now also applies to Microsoft 365 Apps<!--40673170-->
59
+
60
+
Provisioning policies configured for language now also apply to Microsoft 365 Apps. When a user first signs in, their Microsoft 365 Apps will use the configured language. For more information, see [Provide a localized Windows experience](provide-localized-windows-experience.md).
61
+
62
+
<!-- vvvvvvvvvvvvvvvvvvvvvv -->
63
+
### Monitor and troubleshoot
64
+
65
+
#### Remoting connection report in Endpoint Analytics now generally available<!--38310774 -->
66
+
The remoting connection report in Endpoint Analytics has moved out of preview and into general availability. For more information, see [Remoting connection report](report-remoting-connection.md).
0 commit comments