Skip to content

Commit 99c5d12

Browse files
committed
Merge branch 'main' into release-intune-2207
2 parents 945d985 + 6adc519 commit 99c5d12

9 files changed

Lines changed: 19 additions & 16 deletions

File tree

memdocs/autopilot/known-issues.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ This article describes known issues that can often be resolved by configuration
3030

3131
### Autopilot profile not being applied when assigned
3232

33-
In Windows 10 April (KB5011831) release, there is an issue where the Autopilot profile may fail to apply to the device. As a result, any settings made in the profile may not be configured for the user such as device renaming. To resolve this issue, the May (KB5015020) cumulative update needs to be applied to the device.
33+
In Windows 10 April and some May update releases, there is an issue where the Autopilot profile may fail to apply to the device and the hardware hash may not be harvested. As a result, any settings made in the profile may not be configured for the user such as device renaming. To resolve this issue, the May (KB5015020) cumulative update needs to be applied to the device.
3434

3535
### DefaultuserX profile not deleted
3636

memdocs/configmgr/protect/deploy-use/defender-advanced-threat-protection.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Microsoft Defender for Endpoint
33
titleSuffix: Configuration Manager
44
description: Learn how to manage and monitor Microsoft Defender for Endpoint, a new service that helps enterprises respond to advanced attacks.
5-
ms.date: 12/02/2021
5+
ms.date: 07/18/2022
66
ms.prod: configuration-manager
77
ms.technology: configmgr-protect
88
ms.topic: conceptual
@@ -29,7 +29,7 @@ Microsoft Defender for Endpoint's cloud-based portal is [Microsoft Defender Secu
2929
### <a name="bkmk_os"></a> Supported client operating systems
3030

3131
<!--5229962-->
32-
You can onboard the following operating systems:
32+
You can onboard the following operating systems using Configuration Manager:
3333

3434
- Windows 8.1
3535
- Windows 10, version 1709 or later
@@ -40,6 +40,9 @@ You can onboard the following operating systems:
4040
- Windows Server 2019
4141
- Windows Server 2022<!-- 10200029 -->
4242

43+
> [!IMPORTANT]
44+
> Operating systems that have reached the end of their [product lifecycle](/lifecycle/faq/general-lifecycle) aren't typically supported for onboarding unless they have been enrolled into the [Extended Security Updates (ESU program)](/lifecycle/faq/extended-security-updates). For more information about supported operating systems and capabilities with Microsoft Defender for Endpoint, see [Minimum requirements for Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/minimum-requirements#supported-windows-versions). <!-- MAX 6198973-->
45+
4346
## About onboarding to Microsoft Defender for Endpoint with Configuration Manager
4447

4548
Different operating systems have different needs for onboarding to Microsoft Defender for Endpoint. Windows 8.1 and other down-level operating system devices need the **Workspace key** and **Workspace ID** to onboard. Up-level devices, such as Windows Server version 1803, need the onboarding configuration file. Configuration Manager also installs the Microsoft Monitoring Agent (MMA) when needed by onboarded devices but it doesn't update the agent automatically.

memdocs/configmgr/tenant-attach/atp-onboard.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ Microsoft Endpoint Manager is an integrated solution for managing all of your de
2222

2323
[!INCLUDE [Prerequisites for Configuration Manager tenant attached devices](./includes/configmgr-endpoint-security-prerequisties.md)]
2424
- [Microsoft Intune and Microsoft Defender for Endpoint integration enabled](../../intune/protect/advanced-threat-protection-configure.md#enable-microsoft-defender-for-endpoint-in-intune)
25-
- Client onboarded to [Microsoft Defender for Endpoint](/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements#licensing-requirements).<!--Adding MDE License Requirement-->
25+
- Client which meets the minimum requirements for, and is onboarded to [Microsoft Defender for Endpoint](/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements#licensing-requirements).<!--Adding MDE License Requirement & MAX 6198973-->
2626

2727
## <a name="bkmk_onboard"></a> Create Microsoft Defender for Endpoint policies
2828

memdocs/intune/apps/app-protection-policy-settings-android.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ This article describes the app protection policy settings for Android devices. T
3636
There are three categories of policy settings: data protection settings, access requirements, and conditional launch. In this article, the term *policy-managed apps* refers to apps that are configured with app protection policies.
3737

3838
> [!IMPORTANT]
39-
> The Intune Company Portal is required on the device to receive App Protection Policies for Android devices.
39+
> Either the Intune Company Portal or the Microsoft Authenticator is required on the device to receive App Protection Policies for Android devices.
4040
>
4141
> The Intune Managed Browser has been retired. Use [Microsoft Edge](../apps/manage-microsoft-edge.md) for your protected Intune browser experience.
4242

memdocs/intune/apps/intune-management-extension.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -187,7 +187,7 @@ In **PowerShell scripts**, select the script to monitor, choose **Monitor**, and
187187

188188
## Intune management extension logs
189189

190-
Agent logs on the client machine are typically in `\ProgramData\Microsoft\IntuneManagementExtension\Logs`. You can use [CMTrace.exe](/configmgr/core/support/cmtrace) to view these log files.
190+
Agent logs on the client machine are typically in `C:\ProgramData\Microsoft\IntuneManagementExtension\Logs`. You can use [CMTrace.exe](/configmgr/core/support/cmtrace) to view these log files.
191191

192192
![Screenshot or sample cmtrace agent logs in Microsoft Intune](./media/apps-win32-app-management/apps-win32-app-10.png)
193193

memdocs/intune/apps/lob-apps-windows.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,7 @@ A line-of-business (LOB) app is one that you add from an app installation file.
6969
- **Publisher**: Enter the name of the publisher of the app.
7070
- **App Install Context**: Select the install context to be associated with this app. For dual mode apps, select the desired context for this app. For all other apps, this is pre-selected based on the package and cannot be modified.
7171
- **Ignore app version**: Set to **Yes** if the app developer automatically updates the app. This option applies to mobile .msi apps and Windows apps with self-updating installers (such as Google Chrome).
72-
- **Command-line arguments**: Optionally, enter any command-line arguments that you want to apply to the .msi file when it runs. An example is **/q**. Do not include the msiexec command or arguments, such as **/i** or **/x**, as they are automatically used. For more information, see [Command-Line Options](/windows/desktop/Msi/command-line-options). If the .MSI file needs additional command-line options consider using [Win32 app management](app-management.md).
72+
- **Command-line arguments**: Optionally, enter any command-line arguments that you want to apply to the .msi file when it runs. An example is **/q**. Do not include the msiexec command or arguments, such as **/i** or **/x**, as they are automatically used. For more information, see [Command-Line Options](/windows/desktop/Msi/command-line-options). If the .MSI file needs additional command-line options consider using [Win32 app management](apps-win32-app-management.md).
7373
- **Category**: Select one or more of the built-in app categories, or select a category that you created. Categories make it easier for users to find the app when they browse through the company portal.
7474
- **Show this as a featured app in the Company Portal**: Display the app prominently on the main page of the company portal when users browse for apps.
7575
- **Information URL**: Optionally, enter the URL of a website that contains information about this app. The URL appears in the company portal.

memdocs/intune/apps/store-apps-company-portal-autopilot.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
22
# required metadata
33

4-
title: Add and assign the Windows 10 Company Portal app for Autopilot provisioned devices
4+
title: Add and assign the Windows 10 Company Portal app for Intune managed devices
55
titleSuffix: Microsoft Intune
6-
description: Add and assign the Windows 10 Company Portal app to Intune for Autopilot provisioned devices.
6+
description: Add and assign the Windows 10 Company Portal app to Intune managed devices.
77
keywords:
88
author: Erikre
99
ms.author: erikre
@@ -32,15 +32,15 @@ ms.collection:
3232
- highpri
3333
---
3434

35-
# Add and assign the Windows 10 Company Portal app for Autopilot provisioned devices
35+
# Add and assign the Windows 10 Company Portal app for Intune managed devices
3636

37-
To manage devices and install apps, your users can use the Company Portal app. You can assign the Windows 10 Company Portal app directly from Intune.
37+
To manage devices and install apps, your users can optionally use the Company Portal app. You can assign the Windows 10 Company Portal app directly from Intune.
3838

3939
## Prerequisites
4040

41-
For Windows 10 Autopilot provisioned devices, it is recommended that you associate your Microsoft Store for Business account with Intune. For more information, see [How to manage volume purchased apps from the Microsoft Store for Business with Microsoft Intune](windows-store-for-business.md).
41+
You can choose to install the **Company Portal (Offline)** app using the steps below. The Company Portal app will be installed in device context when assigned to the Autopilot group and will be installed on the device before the user logs in. Offline apps are updated using Intune, whereas online apps are updated by the store. Use offline apps when you need to install and maintain a specific app version.
4242

43-
You can choose to install the **Company Portal (Offline)** app using the steps below. The Company Portal app will be installed in device context when assigned to the Autopilot group and will be installed on the device before the user logs in. Offline apps are updated using Intune, whereas online apps are updated by the store. When synced from the Microsoft Store for Business and deployed as a Microsoft Store app, the Company Portal (Offline) updates will occur automatically to any required assignments. If you need to maintain a specific version of the Company Portal app, refer to [Manually add the Windows 10 company portal app](./store-apps-company-portal-app.md) for details.
43+
For Windows 10 Autopilot provisioned devices, it is recommended that you associate your Microsoft Store for Business account with Intune. For more information, see [How to manage volume purchased apps from the Microsoft Store for Business with Microsoft Intune](windows-store-for-business.md).
4444

4545
## Configure the store settings to show the offline app
4646

@@ -71,7 +71,7 @@ You can choose to install the **Company Portal (Offline)** app using the steps b
7171
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) with your admin account.
7272
2. Select **Apps** > **Windows**.
7373
3. From the list of Windows apps, select **Company Portal (Offline)**.
74-
4. To [Assign](apps-deploy.md) the Company Portal app as a required app to your selected autopilot device groups, select **Properties** > **Edit** (next to **Assignments**) > **Add Group** (below **Required**) and then select a device group to assign the app.
74+
4. To [Assign](apps-deploy.md) the Company Portal app as a required app to your selected device groups, select **Properties** > **Edit** (next to **Assignments**) > **Add Group** (below **Required**) and then select a device group to assign the app.
7575
5. As this is an *Offline* app, be sure to change the **License type** to **Device licensing** before selecting **Review + save**. To set the **License type**, click **User** on the row of the group you added (under the **License type** column).
7676
6. Select **Device licensing** > **OK** > **Review + save**.
7777

memdocs/intune/apps/vpp-apps-ios.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -209,7 +209,7 @@ You can renew an Apple Business Manager location token (Apple VPP token) by down
209209
To renew an Apple Business Manager location token (Apple VPP token), use the following steps:
210210

211211
1. Navigate to [Apple Business Manager](https://business.apple.com/) or [Apple School Manager](https://school.apple.com/).
212-
2. Download the existing token in **Apple Business (or School) Manager**, by selecting **Settings** > **Apps and Books** > **My Server Tokens**.
212+
2. Download the existing token in **Apple Business (or School) Manager**, by selecting **Preferences** > **Payments and Billing** > **Apps and Books** > **Server Tokens**.
213213
3. Update the token in [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) by selecting **Tenant administration** > **Connectors and tokens** > **Apple VPP tokens**.
214214
4. Select the VPP token you are renewing, click **Edit** on the Basics category, upload the new token on this page, and then save your changes.
215215

memdocs/intune/protect/windows-hello.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@ END OLD -->
7575

7676
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
7777

78-
2. Go to **Devices** > **Enrollment** > **Enroll devices** > **Windows enrollment** > **Windows Hello for Business**. The Windows Hello for Business pane opens.
78+
2. Go to **Devices** > **Enroll devices** > **Windows enrollment** > **Windows Hello for Business**. The Windows Hello for Business pane opens.
7979

8080
3. Select from the following options for **Configure Windows Hello for Business**:
8181

0 commit comments

Comments
 (0)