Skip to content

Commit 90e1f60

Browse files
authored
Merge pull request #7601 from MicrosoftDocs/main
Publish 05/13/2022, 10:30 AM
2 parents dda6b4f + 9f15101 commit 90e1f60

10 files changed

Lines changed: 46 additions & 19 deletions

memdocs/intune/configuration/vpn-settings-configure.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 04/29/2022
10+
ms.date: 05/12/2022
1111
ms.topic: how-to
1212
ms.service: microsoft-intune
1313
ms.subservice: configuration
@@ -155,7 +155,11 @@ You can create VPN profiles using the following connection types:
155155
- iOS/iPadOS
156156

157157
> [!Important]
158-
> Use *Microsoft Tunnel (preview)* instead. On April 29, 2022, the *Microsoft Tunnel (preview)* connection type became generally available and supports Microsoft Defender for Endpoint as a tunnel client app. By the end of June 2022, the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app it supports are deprecated and drop from support. Soon after the June date, this connection type will stop functioning and no longer connect to Microsoft Tunnel.
158+
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel (preview)* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
159+
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
160+
> - On August 1, 2022, the *Microsoft Tunnel (standalone client) (preview)* connection type will cease to connect to Microsoft Tunnel.
161+
>
162+
> To avoid a disruption in service for Microsoft Tunnel, plan to migrate your use of the deprecated tunnel client app and connection type to those that are now generally available.
159163
160164
- NetMotion Mobility
161165
- Android Enterprise personally owned devices with a work profile

memdocs/intune/configuration/vpn-settings-ios.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 04/29/2022
10+
ms.date: 05/12/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: configuration
@@ -87,7 +87,11 @@ Select the VPN connection type from the following list of vendors:
8787
Applies to the Microsoft Tunnel client app.
8888

8989
> [!Important]
90-
> Use *Microsoft Tunnel (preview)* instead. On April 29, 2022, the *Microsoft Tunnel (preview)* connection type became generally available and supports Microsoft Defender for Endpoint as a tunnel client app. By the end of June 2022, the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app it supports are deprecated and drop from support. Soon after the June date, this connection type will stop functioning and no longer connect to Microsoft Tunnel.
90+
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel (preview)* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
91+
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
92+
> - On August 1, 2022, the *Microsoft Tunnel (standalone client) (preview)* connection type will cease to connect to Microsoft Tunnel.
93+
>
94+
> To avoid a disruption in service for Microsoft Tunnel, plan to migrate your use of the deprecated tunnel client app and connection type to those that are now generally available.
9195
9296
- **Microsoft Tunnel (preview)**
9397

memdocs/intune/configuration/vpn-settings-windows-10.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 01/25/2022
10+
ms.date: 05/12/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: configuration
@@ -54,13 +54,12 @@ These settings apply to devices running:
5454
- **Use this VPN profile with a user/device scope**: Apply the profile to the user scope or the device scope:
5555

5656
- **User scope**: The VPN profile is installed within the user's account on the device, such as `[email protected]`. If another user signs in to the device, the VPN profile isn't available.
57-
- **Device scope**: The VPN profile is installed in the device context, and applies to all users on the device.
57+
- **Device scope**: The VPN profile is installed in the device context, and applies to all users on the device. Windows Holographic devices only support device scope.
5858

5959
Existing VPN profiles apply to their existing scope. By default, new VPN profiles are installed in the user scope *except* for the profiles with device tunnel enabled. VPN profiles with device tunnel enabled use the device scope.
6060

6161
## Connection type
6262

63-
6463
- **Connection type**: Select the VPN connection type from the following list of vendors:
6564

6665
- **Check Point Capsule VPN**

memdocs/intune/enrollment/enrollment-restrictions-set.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ ms.assetid: 9691982c-1a03-4ac1-b7c5-73087be8c5f2
2121
#ROBOTS:
2222
#audience:
2323

24-
ms.reviewer: dagerrit
24+
ms.reviewer: maholdaa
2525
ms.suite: ems
2626
search.appverid: MET150
2727
#ms.tgt_pltfrm:

memdocs/intune/fundamentals/windows-holographic-for-business.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ keywords:
66
author: MandiOhlinger
77
ms.author: mandia
88
manager: dougeby
9-
ms.date: 01/24/2022
9+
ms.date: 05/12/2022
1010
ms.topic: conceptual
1111
ms.service: microsoft-intune
1212
ms.subservice: fundamentals
@@ -133,6 +133,9 @@ Device restrictions let you control different settings and features on your devi
133133

134134
Virtual private networks (VPNs) give your users secure remote access to your company network. In Intune, you can create a VPN profile that includes specific settings for your devices running Windows Holographic for Business. For example, you can create a VPN profile so all Windows Holographic for Business devices use Citrix VPN as the connection type.
135135

136+
> [!NOTE]
137+
> When assigning a VPN policy to Windows Holographic for Business devices, assign the profile to the device scope. Currently, Windows Holographic only supports the device scope. When the VPN profile is installed in the device context, it applies to all users on the device. If a user profile is deployed, it's treated as a device profile.
138+
136139
### [Configure Wi-Fi](../configuration/wi-fi-settings-configure.md)
137140

138141
You can also create a Wi-Fi profile in Intune to assign wireless network settings to your Windows Holographic for Business devices. When you assign a Wi-Fi profile, your end users get corporate network access, without any network configuration. For example, you can create a Wi-Fi network dedicated to only your Windows Holographic for Business devices.
@@ -163,4 +166,4 @@ Hello for Business is an alternative sign-in method that uses an Azure Active Di
163166

164167
## Next steps
165168

166-
[Set up Intune](setup-steps.md).
169+
[Set up Intune](setup-steps.md).

memdocs/intune/protect/endpoint-security.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ The Endpoint security node groups the tools that are available through Intune th
3535

3636
- **Review the status of all your managed devices**. Use the [All devices](#manage-devices) view where you can view device compliance from a high level. Then, drill-in to specific devices to understand which compliance policies aren't met so you can resolve them.
3737

38-
- **Deploy security baselines that establish best practice security configurations for devices**. Intune includes [security baselines](#manage-security-baselines) for Windows devices and a growing list of applications, like Microsoft Defender for Endpoint and Microsoft Edge. Security baselines are pre-configured groups of Windows settings that help you apply a configuration that's recommended by the relevant security teams recommend.
38+
- **Deploy security baselines that establish best practice security configurations for devices**. Intune includes [security baselines](#manage-security-baselines) for Windows devices and a growing list of applications, like Microsoft Defender for Endpoint and Microsoft Edge. Security baselines are pre-configured groups of Windows settings that help you apply a configuration that's recommended by the relevant security teams.
3939

4040
- **Manage security configurations on devices through tightly focused policies**. Each [Endpoint security policy](#use-policies-to-manage-device-security) focuses on aspects of device security like antivirus, disk encryption, firewalls, and several areas made available through integration with Microsoft Defender for Endpoint.
4141

memdocs/intune/protect/microsoft-tunnel-configure.md

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ keywords:
55
author: brenduns
66
ms.author: brenduns
77
manager: dougeby
8-
ms.date: 04/29/2022
8+
ms.date: 05/12/2022
99
ms.topic: how-to
1010
ms.service: microsoft-intune
1111
ms.subservice: protect
@@ -191,7 +191,12 @@ To use the Microsoft Tunnel, devices need access to a Microsoft Tunnel client ap
191191
- **Microsoft Tunnel** client app - For iOS/iPadOS, download the **Microsoft Tunnel** client app from the Apple **App Store**. See Add iOS store apps to Microsoft Intune.
192192

193193
> [!Important]
194-
> Use *Microsoft Defender for Endpoint* instead. On April 29, 2022, the *Microsoft Tunnel (preview)* connection type became generally available and supports Microsoft Defender for Endpoint as a tunnel client app. By the end of June 2022, the *Microsoft Tunnel (standalone client)(preview)* connection type and the *Microsoft Tunnel client app* it supports are deprecated and drop from support. Soon after the June date, this connection type will stop functioning and no longer connect to Microsoft Tunnel.
194+
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel (preview)* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
195+
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
196+
> - On August 1, 2022, the *Microsoft Tunnel (standalone client) (preview)* connection type will cease to connect to Microsoft Tunnel.
197+
>
198+
> To avoid a disruption in service for Microsoft Tunnel, plan to migrate your use of the deprecated tunnel client app and connection type to those that are now generally available.
199+
195200

196201
For more information on deploying apps with Intune, see [Add apps to Microsoft Intune](../apps/apps-add.md).
197202

@@ -221,7 +226,11 @@ After the Microsoft Tunnel installs and devices install the Microsoft Tunnel cli
221226
- **Microsoft Tunnel (standalone client) (preview)** – Use this connection type when you use the standalone Microsoft Tunnel client app. This connection type doesn’t support Microsoft Defender for Endpoint as the client Tunnel app.
222227

223228
> [!Important]
224-
> Use *Microsoft Tunnel (preview)* instead. On April 29, 2022, the *Microsoft Tunnel (preview)* connection type became generally available and supports Microsoft Defender for Endpoint as a tunnel client app. By the end of June 2022, the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app it supports are deprecated and drop from support. Soon after the June date, this connection type will stop functioning and no longer connect to Microsoft Tunnel.
229+
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel (preview)* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
230+
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
231+
> - On August 1, 2022, the *Microsoft Tunnel (standalone client) (preview)* connection type will cease to connect to Microsoft Tunnel.
232+
>
233+
> To avoid a disruption in service for Microsoft Tunnel, plan to migrate your use of the deprecated tunnel client app and connection type to those that are now generally available.
225234
226235
The iOS platform supports routing traffic by either a per-app VPN or by split tunneling rules, but not both simultaneously. If you enable a per-app VPN for iOS, your split tunneling rules are ignored.
227236

memdocs/intune/protect/microsoft-tunnel-migrate-app.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ keywords:
55
author: brenduns
66
ms.author: brenduns
77
manager: dougeby
8-
ms.date: 04/29/2022
8+
ms.date: 05/12/2022
99
ms.topic: how-to
1010
ms.service: microsoft-intune
1111
ms.subservice: protect
@@ -52,7 +52,7 @@ The following device platforms support Microsoft Defender for Endpoint as the tu
5252

5353
On April 29, 2022, Microsoft Defender for Endpoint became available as the Microsoft Tunnel client app for iOS/iPadOS devices for use with the Microsoft Tunnel Gateway in Microsoft Intune.
5454

55-
If you've previously configured Microsoft Tunnel for iOS/iPadOS using the standalone Microsoft Tunnel client app, you must migrate your devices to use Microsoft Defender for Endpoint as the Tunnel client app. Support for the iOS standalone Tunnel client app ends by the end of June.
55+
If you've previously configured Microsoft Tunnel for iOS/iPadOS using the standalone Microsoft Tunnel client app, you must migrate your devices to use Microsoft Defender for Endpoint as the Tunnel client app. Support for the iOS standalone Tunnel client app ends on July 29, 2022.
5656

5757
To configure the Microsoft Defender for Endpoint app to connect to Tunnel, you'll need to create a new VPN profile with the *Microsoft Tunnel (preview)* connection type.
5858

memdocs/intune/protect/microsoft-tunnel-overview.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ keywords:
55
author: brenduns
66
ms.author: brenduns
77
manager: dougeby
8-
ms.date: 04/29/2022
8+
ms.date: 05/12/2022
99
ms.topic: how-to
1010
ms.service: microsoft-intune
1111
ms.subservice: protect
@@ -67,7 +67,11 @@ To direct devices to use the tunnel, you create and deploy a VPN policy for Micr
6767
> - As of June 14 2021, both the standalone tunnel app and standalone client connection type are deprecated and drop from support after January 31, 2022.
6868
>
6969
> For iOS/iPadOS:
70-
> - As of April 29, 2022, Microsoft Defender for Endpoint is generally available as the Microsoft Tunnel client app for iOS/iPadOS, and replaces use of the standalone tunnel client app and preview versions of Defender for Endpoint. By the end of June 2022, the standalone client app and its connection type of *Microsoft Tunnel (standalone client)(preview)* are deprecated and drop from support. Soon after the June date, this connection type will stop functioning and no longer connect to Microsoft Tunnel.
70+
> - On April 29, 2022 both the *Microsoft Tunnel (preview)* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
71+
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
72+
> - On August 1, 2022, the *Microsoft Tunnel (standalone client) (preview)* connection type will cease to connect to Microsoft Tunnel.
73+
>
74+
> To avoid a disruption in service for Microsoft Tunnel, plan to migrate your use of the deprecated tunnel client app and connection type to those that are now generally available.
7175
7276
Features of the VPN profiles for the tunnel include:
7377

memdocs/intune/protect/microsoft-tunnel-prerequisites.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,10 @@ The following sections detail the prerequisites for the Microsoft Tunnel, and pr
4949

5050
Set up a Linux based virtual machine or a physical server on which Microsoft Tunnel Gateway will install.
5151

52+
> [!NOTE]
53+
> Only the opearating systems and container versions that are listed in the following table are supported. Versions not listed are not supported. Only after testing and supportability are verified are newer versions added to this list.
54+
55+
5256
- **Supported Linux distributions** - The following table details which versions of Linux are supported for the Tunnel server, and the container they require:
5357

5458
|Distributon version | Container requirements | Considerations |
@@ -116,7 +120,7 @@ Both Podman and Docker containers use a bridge network to forward traffic throug
116120
The default bridge networks are:
117121

118122
- Docker: **172.17.0.0/16**
119-
- Podman: **10.0.88.0.0/16**
123+
- Podman: **10.88.0.0/16**
120124

121125
To avoid conflicts, you can reconfigure both Podman and Docker to use a bridge network that you specify.
122126

0 commit comments

Comments
 (0)