Skip to content

Commit a93ebef

Browse files
author
Angela Fleischmann
authored
Merge pull request #7468 from MicrosoftDocs/Erikre-patch-1
erikre-docs-14191454a
2 parents c1d29eb + 850412e commit a93ebef

1 file changed

Lines changed: 2 additions & 335 deletions

File tree

memdocs/intune/fundamentals/in-development.md

Lines changed: 2 additions & 335 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ keywords:
88
author: dougeby
99
ms.author: dougeby
1010
manager: dougeby
11-
ms.date: 04/19/2022
11+
ms.date: 04/27/2022
1212
ms.topic: conceptual
1313
ms.service: microsoft-intune
1414
ms.subservice: fundamentals
@@ -66,70 +66,12 @@ You can use RSS to be notified when this article is updated. For more informatio
6666
## App management
6767

6868
### iOS Company Portal minimum required version<!-- 13016075 -->
69-
With an upcoming release of the MS Authenticator app, users will be required to update to v5.2204 of the iOS Company Portal. If you have enabled the **[Block installing apps using App Store](../configuration/device-restrictions-ios.md#settings-apply-to-automated-device-enrollment-supervised)** device restriction setting, you will likely need to push an update to the related devices that use this setting. Otherwise, no action is needed. If you have a helpdesk, you may want to make them aware of the prompt to update the Company Portal app. In most cases, users have app updates set to automatic, so they receive the updated Company Portal app without taking any action. Users that have an earlier app version will be prompted to update to the latest Company Portal app.
70-
71-
### Password complexity for Android devices<!-- 9321870 -->
72-
The **Require device lock** setting in Intune will be extended to include values (**Low Complexity**, **Medium Complexity**, and **High Complexity**). If the device lock doesn't meet the minimum password requirement, you'll be able to **warn**, **wipe data**, or **block** the end user from accessing a managed account in a managed app.
73-
74-
This feature targets devices that operate on Android 11+. For devices that operate on Android 10 and earlier, setting a complexity value of **Low**, **Medium**, or **High** will default to the expected behavior for **Low Complexity**. For related information, see [Android app protection policy settings in Microsoft Intune](..\apps\app-protection-policy-settings-android.md).
75-
76-
### Improvements to Win32 App Log collection<!-- 9978316 -->
77-
Win32 App Log collection via Intune Management Extension has moved to the Windows 10 device diagnostic platform, reducing time to collect logs from 1-2 hours to 20 minutes. We've also increased the size from 60mb to 250mb. Along with performance improvements, the app logs will also be available under the **Device diagnostics monitor** action for each device, as well as the managed app monitor. For information about how to collect diagnostics, see [Collect diagnostics from a Windows device](..\remote-actions\collect-diagnostics.md) and [Troubleshooting Win32 app installations with Intune](/troubleshoot/mem/intune/troubleshoot-win32-app-install).
78-
79-
### Update to the App configuration policies list<!-- 13903969 -->
80-
In Intune, the **Assigned** column in the **App configuration policies** list will be removed. To view the assigned groups for an app configuration policy, navigate to [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) > **Apps** > **App configuration policies** > *select a policy* > **Overview**.
81-
82-
<!-- ***********************************************-->
83-
84-
## Device enrollment
85-
86-
### Improvements for enrollment profiles for Apple’s Automated Device Enrollment (Public preview)<!-- 10111795 -->
87-
As a public preview, we’re adding new Setup Assistant screens you can configure when [creating enrollment profiles](../enrollment/device-enrollment-program-enroll-ios.md#create-an-apple-enrollment-profile) for Apple’s Automated Device Enrollment (ADE). The following new screens will be available on the *Setup Assistant* tab for both iOS/iPadOS and macOS as follows:
88-
89-
- iOS/iPadOS 13 and later - **Get Started (preview)**
90-
- Default – Show
91-
- Admin can configure to hide the Get Started pane (Setup Assistant screen) during ADE enrollment.
92-
93-
- macOS 12 and later - **Auto Unlock with Apple Watch (preview)**
94-
- Default – Show
95-
- Admin can configure to hide the Unlock Your Mac with your Apple Watch pane (Setup Assistant screen) during ADE enrollment.
96-
97-
<!-- ***********************************************-->
98-
99-
## Device management
100-
101-
### Device actions available to Android (AOSP) users in Microsoft Intune app<!-- 12645718 -->
102-
AOSP device users will be able to delete, wipe, and rename their enrolled devices in the Microsoft Intune app. This feature will be available on devices enrolled in Intune as user-associated (Android) AOSP devices.
103-
104-
### Support for Audio Alert on Android corporate-owned work- profiles and fully managed (COBO and COPE) devices<!-- 13499471 -->
105-
You'll be able to use the **Play lost device sound** device action to trigger an alarm sound on the device to assist in locating the lost or stolen Android Enterprise corporate owned work profiles and fully managed devices.
106-
107-
For more information, see [Locate lost or stolen devices](../remote-actions/device-locate.md).
69+
With an upcoming release of the MS Authenticator app, users will be required to update to v5.2205 of the iOS Company Portal. If you have enabled the **[Block installing apps using App Store](../configuration/device-restrictions-ios.md#settings-apply-to-automated-device-enrollment-supervised)** device restriction setting, you will likely need to push an update to the related devices that use this setting. Otherwise, no action is needed. If you have a helpdesk, you may want to make them aware of the prompt to update the Company Portal app. In most cases, users have app updates set to automatic, so they receive the updated Company Portal app without taking any action. Users that have an earlier app version will be prompted to update to the latest Company Portal app.
10870

10971
<!-- ***********************************************-->
11072

11173
## Device configuration
11274

113-
### New wired networks device configuration profile for Windows devices<!-- 1746923 -->
114-
There will be a new **Wired Networks** device configuration profile (**Devices** > **Configuration profiles** > **Create profile** > **Windows 10 and later** for platform > **Templates** > **Wired networks** for profile type).
115-
116-
Use this profile to configure common wired network settings, including authentication, EAP type, server trust, and more.
117-
118-
Applies to:
119-
- Windows 11
120-
- Windows 10
121-
122-
### Create a Settings Catalog policy using your imported GPOs with Group Policy analytics (public preview)<!-- 6379751 -->
123-
Using Group Policy analytics, you can import your on-premises GPO, and see the settings that are supported in Microsoft Intune. It also shows any deprecated settings, or settings not available to MDM providers.
124-
125-
When the analysis runs, you'll see the settings that are ready for migration. There will be a **Migrate** option (public preview) that creates a Settings Catalog profile using these settings. Then, you can assign the profile to your groups.
126-
127-
For more information on what you can do now, see [Analyze your on-premises group policy objects (GPO) using Group Policy analytics in Microsoft Endpoint Manager](../configuration/group-policy-analytics.md).
128-
129-
Applies to:
130-
- Windows 11
131-
- Windows 10
132-
13375
### Use the Settings Catalog to create a Universal Print policy on Windows 11 devices<!-- 5513123 -->
13476
Many organizations are moving their printer infrastructure to the cloud. [Universal Print](/universal-print/fundamentals/universal-print-whatis) is a cloud-based printing solution for Microsoft 365 customers. It uses built-in cloud printers, built-in legacy printers, and runs entirely in Microsoft Azure. When Universal Print is deployed with Universal Print-compatible printers, it doesn't require any on-premises infrastructure.
13577

@@ -140,281 +82,6 @@ Currently, you must use the [Universal Print printer provisioning tool](/univers
14082
Applies to:
14183
- Windows 11
14284

143-
### New macOS settings in Setting Catalog<!-- 13654614 -->
144-
The Settings Catalog has new macOS settings you can configure (**Devices** > **Configuration profiles** > **Create profile** > **macOS** for platform >**Settings catalog (preview)** for profile type):
145-
146-
**Accounts > Mobile Accounts**:
147-
148-
- Ask For Secure Token Auth Bypass
149-
- Create At Login
150-
- Expiry Delete Disused Seconds
151-
- Warn On Create
152-
- Warn On Create Allow Never
153-
154-
**App Management > Autonomous Single App Mode**:
155-
156-
- Bundle Identifier
157-
- Team Identifier
158-
159-
**App Management > NS Extension Management**:
160-
161-
- Allowed Extensions
162-
- Denied Extension Points
163-
- Denied Extensions
164-
165-
**App Store**:
166-
167-
- Disable Software Update Notifications
168-
- Restrict Store Software Update Only
169-
- restrict-store-disable-app-adoption
170-
171-
**Authentication > Directory Service**:
172-
173-
- AD Allow Multi Domain Auth
174-
- AD Allow Multi Domain Auth Flag
175-
- AD Create Mobile Account At Login
176-
- AD Create Mobile Account At Login Flag
177-
- AD Default User Shell
178-
- AD Default User Shell Flag
179-
- AD Domain Admin Group List
180-
- AD Domain Admin Group List Flag
181-
- AD Force Home Local
182-
- AD Force Home Local Flag
183-
- AD Map GGID Attribute
184-
- AD Map GGID Attribute Flag
185-
- AD Map GID Attribute
186-
- AD Map GID Attribute Flag
187-
- AD Map UID Attribute
188-
- AD Map UID Attribute Flag
189-
- AD Mount Style
190-
- AD Namespace
191-
- AD Namespace Flag
192-
- AD Organizational Unit
193-
- AD Packet Encrypt
194-
- AD Packet Encrypt Flag
195-
- AD Packet Sign
196-
- AD Packet Sign Flag
197-
- AD Preferred DC Server
198-
- AD Preferred DC Server Flag
199-
- AD Restrict DDNS
200-
- AD Restrict DDNS Flag
201-
- AD Trust Change Pass Interval Days
202-
- AD Trust Change Pass Interval Days Flag
203-
- AD Use Windows UNC Path
204-
- AD Use Windows UNC Path Flag
205-
- AD Warn User Before Creating MA Flag
206-
- Client ID
207-
- Description
208-
- Password
209-
- User Name
210-
211-
**Authentication > Identification**:
212-
213-
- Prompt
214-
- Prompt Message
215-
216-
**Login > Login Window Login Items**:
217-
218-
- Disable Login Items Suppression
219-
220-
**Media Management Disc Burning**:
221-
222-
- Burn Support
223-
224-
**Parental Controls > Parental Controls Application Restrictions**:
225-
226-
- Family Controls Enabled
227-
228-
**Parental Controls > Parental Controls Content Filter**:
229-
230-
- Allowlist Enabled
231-
- Filter Allowlist
232-
- Filter Blocklist
233-
- Site Allowlist
234-
- Address
235-
- Page Title
236-
- Use Content Filter
237-
238-
**Parental Controls > Parental Controls Dictionary**:
239-
240-
- Parental Control
241-
242-
**Parental Controls > Parental Controls Game Center**:
243-
244-
- GK Feature Account Modification Allowed
245-
246-
**System Configuration > File Provider**:
247-
248-
- Allow Managed File Providers To Request Attribution
249-
250-
**System Configuration > Screensaver**:
251-
252-
- Ask For Password
253-
- Ask For Password Delay
254-
- Login Window Idle Time
255-
- Login Window Module Path
256-
257-
**User Experience > Finder**:
258-
259-
- Prohibit Burn
260-
- Prohibit Connect To
261-
- Prohibit Eject
262-
- Prohibit Go To Folder
263-
- Show External Hard Drives On Desktop
264-
- Show Hard Drives On Desktop
265-
- Show Mounted Servers On Desktop
266-
- Show Removable Media On Desktop
267-
- Warn On Empty Trash
268-
269-
**User Experience > Managed Menu Extras**:
270-
271-
- AirPort
272-
- Battery
273-
- Bluetooth
274-
- Clock
275-
- CPU
276-
- Delay Seconds
277-
- Displays
278-
- Eject
279-
- Fax
280-
- HomeSync
281-
- iChat
282-
- Ink
283-
- IrDA
284-
- Max Wait Seconds
285-
- PCCard
286-
- PPP
287-
- PPPoE
288-
- Remote Desktop
289-
- Script Menu
290-
- Spaces
291-
- Sync
292-
- Text Input
293-
- TimeMachine
294-
- Universal Access
295-
- User
296-
- Volume
297-
- VPN
298-
- WWAN
299-
300-
**User Experience > Notifications**:
301-
302-
- Alert Type
303-
- Badges Enabled
304-
- Critical Alert Enabled
305-
- Notifications Enabled
306-
- Show In Lock Screen
307-
- Show In Notification Center
308-
- Sounds Enabled
309-
310-
**User Experience > Time Machine**:
311-
312-
- Auto Backup
313-
- Backup All Volumes
314-
- Backup Size MB
315-
- Backup Skip System
316-
- Base Paths
317-
- Mobile Backups
318-
- Skip Paths
319-
320-
**Xsan**:
321-
322-
- San Auth Method
323-
324-
**Xsan > Xsan Preferences**:
325-
326-
- Deny DLC
327-
- Deny Mount
328-
- Only Mount
329-
- Prefer DLC
330-
- Use DLC
331-
332-
The following settings are also in Settings Catalog. Previously, they were only available in Templates:
333-
334-
**App Management > Associated Domains**:
335-
336-
- Enable Direct Downloads
337-
338-
**Networking > Content Caching**:
339-
340-
- Allow Cache Delete
341-
- Allow Personal Caching
342-
- Allow Shared Caching
343-
- Auto Activation
344-
- Auto Enable Tethered Caching
345-
- Cache Limit
346-
- Data Path
347-
- Deny Tethered Caching
348-
- Display Alerts
349-
- Keep Awake
350-
- Listen Ranges
351-
- Listen Ranges Only
352-
- Listen With Peers And Parents
353-
- Local Subnets Only
354-
- Log Client Identity
355-
- Parent Selection Policy
356-
- Parents
357-
- Peer Filter Ranges
358-
- Peer Listen Ranges
359-
- Peer Local Subnets Only
360-
- Port
361-
- Public Range
362-
363-
**Restrictions**:
364-
365-
- Allow Activity Continuation
366-
- Allow Adding Game Center Friends
367-
- Allow Air Drop
368-
- Allow Auto Unlock
369-
- Allow Camera
370-
- Allow Cloud Address Book
371-
- Allow Cloud Bookmarks
372-
- Allow Cloud Calendar
373-
- Allow Cloud Desktop And Documents
374-
- Allow Cloud Document Sync
375-
- Allow Cloud Keychain Sync
376-
- Allow Cloud Mail
377-
- Allow Cloud Notes
378-
- Allow Cloud Photo Library
379-
- Allow Cloud Private Relay
380-
- Allow Cloud Reminders
381-
- Allow Content Caching
382-
- Allow Diagnostic Submission
383-
- Allow Dictation
384-
- Allow Erase Content And Settings
385-
- Allow Fingerprint For Unlock
386-
- Allow Game Center
387-
- Allow iTunes File Sharing
388-
- Allow Multiplayer Gaming
389-
- Allow Music Service
390-
- Allow Passcode Modification
391-
- Allow Password Auto Fill
392-
- Allow Password Proximity Requests
393-
- Allow Password Sharing
394-
- Allow Remote Screen Observation
395-
- Allow Screen Shot
396-
- Allow Spotlight Internet Results
397-
- Allow Wallpaper Modification
398-
- Enforced Fingerprint Timeout
399-
- Enforced Software Update Delay
400-
- Enforced Software Update Major OS Deferred Install Delay
401-
- Enforced Software Update Minor OS Deferred Install Delay
402-
- Enforced Software Update Non OS Deferred Install Delay
403-
- Force Classroom Automatically Join Classes
404-
- Force Classroom Request Permission To Leave Classes
405-
- Force Classroom Unprompted App And Device Lock
406-
- Force Delayed App Software Updates
407-
- Force Delayed Major Software Updates
408-
- Force Delayed Software Updates
409-
- Safari Allow Autofill
410-
411-
There isn't any conflict resolution between policies created using the Settings catalog and policies created using Templates. When creating new policies in the Settings Catalog, be sure there are no conflicting settings with your current policies.
412-
413-
For more information about configuring Settings catalog profiles in Intune, see [Create a policy using settings catalog in Microsoft Intune](../configuration/settings-catalog.md).
414-
415-
Applies to:
416-
- macOS
417-
41885
<!-- ***********************************************-->
41986

42087
## Device security

0 commit comments

Comments
 (0)