You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: windows-365/enterprise/create-filter.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -75,9 +75,9 @@ In these steps, you’ll use the Enrollment Profile Name and Device Model device
75
75
76
76
## Create a filter for all Cloud PCs with a specific configuration
77
77
78
-
For the example below, we use 2 vCPU and 4GB RAM as the configuration. Anywhere you see "2vCPU/4GB" replace it with the desired configuration. You can also target a specific Cloud PC size by adding the OS storage as part of the configuration. You can follow the below steps and create a filter for any of the configurations that make up Cloud PC sizes.
78
+
For the example below, we use 2 vCPU and 4 GB RAM as the configuration. Anywhere you see "2vCPU/4GB" replace it with the desired configuration. You can also target a specific Cloud PC size by adding the OS storage as part of the configuration. You can follow the below steps and create a filter for any of the configurations that make up Cloud PC sizes.
79
79
80
-
In these steps, you will use the Model device property to create the filter.
80
+
In these steps, you'll use the Model device property to create the filter.
81
81
82
82
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) > **Tenant Administration** > **Filters**.
83
83
2. Select **Create**, then enter the following:
@@ -93,9 +93,9 @@ In these steps, you will use the Model device property to create the filter.
93
93
6. On the **Scope tags** page, select any desired scope tags to apply, then select **Next**.
94
94
7. On the **Review + create** page, select **Create**.
95
95
96
-
Once you have created the filter, you can use the filter in the assignment page in [supported policies](/mem/intune/fundamentals/filters-supported-workloads).
96
+
Once you've created the filter, you can use the filter in the assignment page in [supported policies](/mem/intune/fundamentals/filters-supported-workloads).
97
97
98
-
For additional information on using filters in Intune, see the following how-to guides:
98
+
For more information on using filters in Intune, see the following how-to guides:
99
99
100
100
-[Create a filter (Intune how-to guide)](/mem/intune/fundamentals/filters)
Only an unassigned Azure network connection (ANC) can be deleted. If an ANC is in use by a provisioning policy, then you must do one of the following:
33
+
Only an unassigned Azure network connection (ANC) can be deleted. If an ANC is in use by a provisioning policy, then you must take one of the following steps:
Windows 365 Security Baselines are a set of policy templates built on security best practices and experience from real world implementations. You can use security baselines to get security recommendations that can help lower risks. The Windows 365 baselines enable security configurations for Windows 10, Edge, and Microsoft Defender for Endpoint. They include versioning features and help customers choose when to update user policies to the latest release.
33
+
Windows 365 Security Baselines are a set of policy templates built on security best practices and experience from real world implementations. You can use security baselines to get security recommendations that can help lower risks. The Windows 365 baselines enable security configurations for Windows 10, Microsoft Edge, and Microsoft Defender for Endpoint. They include versioning features and help customers choose when to update user policies to the latest release.
34
34
35
35
Windows 365-branded security baselines are a group of tested and validated recommended settings available in Microsoft Endpoint Manager that apply to the following areas:
36
36
37
37
- Windows 10 settings: 1809
38
38
- MDATP settings: version 4
39
-
- Edge settings: April 2020 (Edge version 80 and later)
39
+
-Microsoft Edge settings: April 2020 (Microsoft Edge version 80 and later)
40
40
41
41
You can optionally apply Windows 365 security baselines to the Azure AD groups containing Cloud PC devices in your tenant.
Copy file name to clipboardExpand all lines: windows-365/enterprise/device-images.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -44,7 +44,7 @@ Both marketplace and custom images must meet the following requirements:
44
44
- Generalized VM image.
45
45
- Single Session VM images (multi-session isn’t supported).
46
46
- No recovery partition. For information about how to remove a recovery partition, see the [Windows Server command: delete partition](/windows-server/administration/windows-commands/delete-partition).
47
-
- Default 64GB OS disk size. The OS disk size will be automatically adjusted to the size specified in SKU description of the Windows 365 license.
47
+
- Default 64-GB OS disk size. The OS disk size will be automatically adjusted to the size specified in SKU description of the Windows 365 license.
48
48
49
49
A custom image must also meet the following extra requirements:
50
50
@@ -55,7 +55,7 @@ Storing a managed image on Azure incurs storage costs. However, customers can de
55
55
56
56
## Gallery images
57
57
58
-
Windows 365 provides a built-in gallery of Windows Enterprise images accessible through the provisioning policy creation flow. They are replicated to all Azure regions to give you a quick provisioning experience. These images are updated monthly with the latest security updates so that end users have a secure and seamless experience.
58
+
Windows 365 provides a built-in gallery of Windows Enterprise images accessible through the provisioning policy creation flow. They're replicated to all Azure regions to give you a quick provisioning experience. These images are updated monthly with the latest security updates so that end users have a secure and seamless experience.
59
59
60
60
There are two sets of images available to choose from across the different versions of Windows Enterprise:
61
61
@@ -64,7 +64,7 @@ There are two sets of images available to choose from across the different versi
64
64
- C++ Runtime (Teams).
65
65
- WebRTC Redirector (Teams).
66
66
- Microsoft Teams (Teams).
67
-
- Edge settings like sleeping tabs, startup boost, and first time optimizations based on Azure AD and synchronization.
67
+
-Microsoft Edge settings like sleeping tabs, startup boost, and first time optimizations based on Azure AD and synchronization.
68
68
- Microsoft Outlook first-time configuration settings (auto log-on based on Azure AD profile, support for other profiles).
69
69
-**Images with OS optimizations**: These are Windows Enterprise images optimized for improved performance on virtualized environments and on lower end hardware configurations. The following settings are pre-applied:
70
70
- Services optimized for virtualization.
@@ -73,7 +73,7 @@ There are two sets of images available to choose from across the different versi
73
73
74
74
### Gallery image update cycle
75
75
76
-
All supported Windows 365 gallery images are updated monthly after the security patch release schedule of Windows Servicing & Delivery. This happens around the middle of each month.
76
+
All supported Windows 365 gallery images are updated monthly after the security patch release schedule of Windows Servicing & Delivery. This update happens around the middle of each month.
Copy file name to clipboardExpand all lines: windows-365/enterprise/device-management-overview.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -47,28 +47,28 @@ The **All Cloud PCs** page displays a summary and list view detailing the state
47
47
48
48
The list view lets you search, filter, and sort. It automatically refreshes every five minutes.
49
49
50
-
If a user has multiple Windows 365 SKUs assigned to them, they’ll get multiple Cloud PCs. This results in multiple rows for a single user in the **All Cloud PCs** list view.
50
+
If a user has multiple Windows 365 SKUs assigned to them, they’ll get multiple Cloud PCs. This situation results in multiple rows for a single user in the **All Cloud PCs** list view.
51
51
52
52
### Column details
53
53
54
54
**Name**: The name of the Cloud PC, which is composed of the assigned provisioning policy and the assigned user’s name. For example, My first provisioning policy – Henry Ross.
55
55
56
56
**Device name**: The Windows computer name, which is also used in Intune and Azure AD.
57
57
58
-
**Image**: The image used during provisioning. This might not be the current Cloud PC version. For example, an administrator may have updated Windows using Windows Update for Business and this wouldn’t be reflected in this list view.
58
+
**Image**: The image used during provisioning. This image might not be the current Cloud PC version. For example, an administrator may have updated Windows using Windows Update for Business and this update wouldn’t be reflected in this list view.
59
59
60
60
**PC type**: The Windows 365 SKU assigned to the user. A user may have more than one license/SKU assigned to them. If so, they’ll have two Cloud PCs in this list view.
61
61
62
62
**Status**: The current provisioning status of the Cloud PC. Possible states include:
63
63
64
-
-**Provisioned**: The Cloud PC provisioning was successful and the assigned user can log on.
64
+
-**Provisioned**: The Cloud PC provisioning was successful and the assigned user can sign in.
65
65
-**Provisioning**: Provisioning is currently in progress.
66
-
-**Provisioned with warnings**: If a non-critical step in the provisioning process fails, user access isn’t blocked but a warning is flagged.
66
+
-**Provisioned with warnings**: If a non-critical step in the provisioning process fails, user access isn’t blocked, but a warning is flagged.
67
67
-**Not provisioned**: The user has been assigned a Windows 365 license but no provisioning policy has been targeted. To provision a Cloud PC, assign this user to a provisioning policy.
68
68
69
69
When a user is licensed with a Windows 365 license, a new row is automatically created in the **All Cloud PCs** list. If the user also has a provisioning policy assigned to them, a Cloud PC is automatically provisioned.
70
70
71
-
If they don’t have a provisioning policy assigned to them, no Cloud PC is created. This is indicated by a **Not provisioned** status. This is not a bad state. It’s an informational state and we encourage you to assign a provisioning policy to make the most of your Windows 365 investment.
71
+
If they don’t have a provisioning policy assigned to them, no Cloud PC is created. This situation is indicated by a **Not provisioned** status. This isn't a bad state. It’s an informational state and we encourage you to assign a provisioning policy to make the most of your Windows 365 investment.
72
72
73
73
-**Deprovisioning**: This short-lived status indicates that the 7-day grace period has ended and the Cloud PC is now being actively deprovisioned. Once the deprovisioning is complete, the Cloud PC can’t be restored and a new Cloud PC must be provisioned for the affected user(s).
74
74
-**Failed**: The provisioning process failed for this Cloud PC. Select the link to get a detailed reason for the failure, troubleshoot, and retry provisioning.
@@ -81,7 +81,7 @@ If a user has multiple Windows 365 SKUs assigned to them, they’ll get multiple
81
81
If the grace period was triggered in error, you have seven days to resolve the breaking change to get the Cloud PC switched back to **Provisioned**.
82
82
83
83
You can manually end the grace period by using the [End grace period](end-grace-period.md) option.
84
-
-**Pending**: If there are not enough available licenses in your tenant to process the provisioning request, new Cloud PCs are marked as **Pending**.
84
+
-**Pending**: If there aren't enough available licenses in your tenant to process the provisioning request, new Cloud PCs are marked as **Pending**.
85
85
86
86
Your Windows 365 tenant can only have as many active Cloud PCs as the license allocation allows. An active Cloud PC can either be in a **Provisioned** or **In grace period** state.
Copy file name to clipboardExpand all lines: windows-365/enterprise/edit-provisioning-policy.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -41,7 +41,7 @@ If you change the network or image in a provisioning policy, no change will occu
41
41
If you edit the name of the provisioning policy in the **General** information, the following will occur:
42
42
43
43
- Any Cloud PC in the All Cloud PCs node will have the new policy name updated in the Provisioning policy column.
44
-
- New Cloud PCs created from the provisioning policy will have the new name registered as the device’s enrollmentProfileName in Azure Active Directory and Microsoft Intune. The enrollmentProfileName property for existing Cloud PCs won't change. If you followed the steps to [create a dynamic device group containing all Cloud PCs](create-dynamic-device-group-all-cloudpcs.md) from a specific provisioning policy, edit the dynamic device group and add a new rule so that the group contains both the existing Cloud PCs and any new Cloud PCs from the provisioning policy:
44
+
- New Cloud PCs created from the provisioning policy will have the new name registered as the device’s enrollmentProfileName in Azure Active Directory and Microsoft Intune. The enrollmentProfileName property for existing Cloud PCs won't change. If you followed the steps to [create a dynamic device group containing all Cloud PCs](create-dynamic-device-group-all-cloudpcs.md) from a specific provisioning policy, edit the dynamic device group, and add a new rule so that the group contains both the existing Cloud PCs and any new Cloud PCs from the provisioning policy:
Copy file name to clipboardExpand all lines: windows-365/enterprise/encryption.md
+6-5Lines changed: 6 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,18 +39,19 @@ To help you protect your organization's data, Windows 365 Enterprise and Busines
39
39
This storage layer encryption provides the following benefits:
40
40
41
41
- When persisting data to the cloud, data at rest on your Microsoft-hosted Cloud PC's disk is automatically encrypted.
42
-
- Windows 365 Cloud PC disks are encrypted transparently using 256-bit Advanced Encryption Standard (AES) encryption, a modern block cipher, and is FIPS 140-2 compliant. The encryption at this layer doesn't impact Cloud PC performance.
42
+
- Windows 365 Cloud PC disks are encrypted transparently using 256-bit Advanced Encryption Standard (AES) encryption, a modern block cipher, and is FIPS 140-2 compliant. The encryption at this layer doesn't affect Cloud PC performance.
43
43
- The encryption is applied to every Cloud PC in every region at no extra cost.
44
44
45
45
The following Windows 365 Enterprise and Business objects are automatically encrypted-at-rest with platform-managed keys:
46
-
- Disks
47
-
- Snapshots
48
-
- Images
46
+
47
+
- Disks
48
+
- Snapshots
49
+
- Images
49
50
50
51
Windows 365 as a service treats all data stored on Windows 365 disks as customer content. For more information, see [Privacy and personal data in Windows 365](./privacy-personal-data.md).
51
52
52
53
>[!NOTE]
53
-
>BitLocker is not supported as an encryption option for Windows 365 Cloud PCs. For additional information, see [using Windows 10 virtual machines in Intune](https://go.microsoft.com/fwlink/?linkid=2188944).
54
+
>BitLocker is not supported as an encryption option for Windows 365 Cloud PCs. For more information, see [using Windows 10 virtual machines in Intune](https://go.microsoft.com/fwlink/?linkid=2188944).
Copy file name to clipboardExpand all lines: windows-365/enterprise/get-cloud-pc-audit-logs-using-powershell.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -80,7 +80,7 @@ To get only the top N events, use the following parameters: ```Get-MgDeviceManag
80
80
81
81
#### Get a single event by event ID
82
82
83
-
You can use the following command to get a single audit event, where you will need to provide the {event ID}: ```Get-MgDeviceManagementVirtualEndpointAuditEvent -CloudPcAuditEventId {event ID}```
83
+
You can use the following command to get a single audit event, where you'll need to provide the {event ID}: ```Get-MgDeviceManagementVirtualEndpointAuditEvent -CloudPcAuditEventId {event ID}```
### Provision Cloud PCs with Secure Boot<!--38012584-->
74
-
75
-
You'll be able to create Cloud PCs that use [Secure boot](/windows-hardware/design/device-experiences/oem-secure-boot) functionality. North American regions will receive this feature within the next few months.
Copy file name to clipboardExpand all lines: windows-365/enterprise/known-issues-enterprise.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -81,7 +81,7 @@ The following device compliance settings report as **Not applicable** when being
81
81
The following device compliance settings may report as **Not Compliant** when being evaluated for a Cloud PC:
82
82
83
83
-**Require BitLocker**
84
-
-**Require Secure Boot to be enabled on the device.** Cloud PC support for [Secure boot](/windows-hardware/design/device-experiences/oem-secure-boot) functionality is now rolling out in Asia Pacific (APAC) regions. This feature will roll out to all customers over the next few months.
84
+
-**Require Secure Boot to be enabled on the device.** Cloud PC support for [Secure boot](/windows-hardware/design/device-experiences/oem-secure-boot) functionality is now available to all customers.
0 commit comments