Skip to content

Commit c4db9d4

Browse files
committed
Merge branch 'main' of https://github.com/microsoftdocs/memdocs-pr into erikre-doc-12965151
2 parents 77b74a8 + b40cdb5 commit c4db9d4

6 files changed

Lines changed: 190 additions & 86 deletions

File tree

memdocs/autopilot/add-devices.md

Lines changed: 109 additions & 81 deletions
Large diffs are not rendered by default.

memdocs/configmgr/core/misc/in-console-documentation.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,6 @@ The complete list of all hotfix and update rollup related articles, starting wit
7979
The short form URL for version 2010 and newer hotfix related articles is `https://aka.ms/KB#######`. For example, [https://aka.ms/KB9210721](https://aka.ms/KB9210721).
8080
Hotfix related articles for version 2006 and prior are still available on support.microsoft.com.
8181

82-
The Microsoft knowledge base articles previously found at support.microsoft.com are published to [Microsoft Endpoint Configuration Manager Troubleshooting](https://docs.microsoft.com/troubleshoot/mem/configmgr/welcome-configuration-manager). Troubleshooting articles created after October 2020 don't have a KB article ID.
82+
The Microsoft knowledge base articles previously found at support.microsoft.com are published to [Microsoft Endpoint Configuration Manager Troubleshooting](/troubleshoot/mem/configmgr/welcome-configuration-manager). Troubleshooting articles created after October 2020 don't have a KB article ID.
8383

84-
To subscribe to Atom or RSS notification of new Configuration Manager support articles, see [Support content updates](https://support.microsoft.com/help/4089498/) and select **Microsoft Endpoint Configuration Manager (current branch)**.
84+
To subscribe to Atom or RSS notification of new Configuration Manager support articles, see [Support content updates](https://support.microsoft.com/help/4089498/) and select **Microsoft Endpoint Configuration Manager (current branch)**.

memdocs/intune/enrollment/android-enterprise-overview.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,11 @@ Android Enterprise doesn't provide a default email app or native email profile o
7070

7171
Intune provides configuration templates for Gmail and Nine Work apps when managed as work apps. Other email apps that support app configuration profiles can be configured with mobile app configuration policies.
7272

73-
If you are using Exchange ActiveSync Conditional Access for an Android Enterprise personally-owned or corporate-owned work profile device, consider using either the Gmail or Nine Work email app. The Microsoft Outlook for Android app, or any other email app that uses modern authentication via ADAL, is also supported. For more information, see [How to configure email settings in Microsoft Intune](../configuration/email-settings-configure.md).
73+
If you are using Exchange ActiveSync Conditional Access for an Android Enterprise personally-owned or corporate-owned work profile device, consider using either the Gmail or Nine Work email app. The Microsoft Outlook for Android app, or any other email app that uses modern authentication via MSAL, is also supported. For more information, see [How to configure email settings in Microsoft Intune](../configuration/email-settings-configure.md).
74+
75+
> [!NOTE]
76+
> Azure Active Directory (Azure AD) Authentication Library (ADAL) will be deprecated, so we recommend updating apps that currently use it to MSAL. For more information, see [Update your applications to use Microsoft Authentication Library (MSAL) and Microsoft Graph API](https://techcommunity.microsoft.com/t5/azure-active-directory-identity/update-your-applications-to-use-microsoft-authentication-library/ba-p/1257363).
77+
7478

7579
## App protection policies
7680

memdocs/intune/fundamentals/filters.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -144,8 +144,9 @@ To use filters, you must enable it in your organization tenant.
144144
> - When you create a rule, it's validated for the correct syntax, and any errors are shown.
145145
> - If you enter syntax that's not supported by the basic rule builder, then the rule builder is disabled. For example, using nested parenthesis disables the basic rule builder.
146146
147-
6. Select **Next**.
148-
7. In **Scope tags** (optional), assign a tag to filter the profile to specific IT groups, such as `US-NC IT Team` or `JohnGlenn_ITDepartment`. For more information about scope tags, see [Use RBAC and scope tags for distributed IT](../fundamentals/scope-tags.md).
147+
6. Optionally, select **Preview devices** to generate a list of enrolled devices that match the filter criteria you defined.
148+
7. Select **Next**.
149+
8. In **Scope tags** (optional), assign a tag to filter the profile to specific IT groups, such as `US-NC IT Team` or `JohnGlenn_ITDepartment`. For more information about scope tags, see [Use RBAC and scope tags for distributed IT](../fundamentals/scope-tags.md).
149150

150151
Select **Next**.
151152

windows-365/enterprise/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,8 @@ items:
2525
href: end-of-support.md
2626
- name: Device configuration with MEM
2727
href: device-configuration.md
28+
- name: Encryption
29+
href: encryption.md
2830
- name: Privacy and personal data
2931
href: privacy-personal-data.md
3032
- name: How-to guides
Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
---
2+
# required metadata
3+
title: Data encryption in Windows 365
4+
titleSuffix:
5+
description: Learn about data encryption in Windows 365.
6+
keywords:
7+
author: ErikjeMS
8+
ms.author: erikje
9+
manager: dougeby
10+
ms.date: 01/05/2022
11+
ms.topic: overview
12+
ms.service: cloudpc
13+
ms.subservice:
14+
ms.localizationpriority: high
15+
ms.technology:
16+
ms.assetid:
17+
18+
# optional metadata
19+
20+
#ROBOTS:
21+
#audience:
22+
23+
ms.reviewer: anbiswas
24+
ms.suite: ems
25+
search.appverid: MET150
26+
#ms.tgt_pltfrm:
27+
ms.custom: intune-azure; get-started
28+
ms.collection: M365-identity-device-management
29+
---
30+
31+
# Data encryption in Windows 365
32+
33+
Windows 365 encrypts data at rest and in transit as explained below.
34+
35+
## Encryption of data at rest
36+
37+
To help you protect your organization's data, Windows 365 Enterprise and Business Cloud PC disks are encrypted with [Azure Storage server-side encryption (SSE)](/azure/storage/common/storage-service-encryption).
38+
39+
This storage layer encryption provides the following benefits:
40+
41+
- When persisting data to the cloud, data at rest on your Microsoft-hosted Cloud PC's disk is automatically encrypted.
42+
- Windows 365 Cloud PC disks are encrypted transparently using 256-bit Advanced Encryption Standard (AES) encryption, a modern block cipher, and is FIPS 140-2 compliant. The encryption at this layer doesn't impact Cloud PC performance.
43+
- The encryption is applied to every Cloud PC in every region at no extra cost.
44+
45+
The following Windows 365 Enterprise and Business objects are automatically encrypted-at-rest with platform-managed keys:
46+
- Disks
47+
- Snapshots
48+
- Images
49+
50+
Windows 365 as a service treats all data stored on Windows 365 disks as customer content. For more information, see [Privacy and personal data in Windows 365](/windows-365/enterprise/privacy-personal-data).
51+
52+
## Encryption of data in transit
53+
54+
Windows 365 uses the Transport Layer Security (TLS) protocol to protect data in transit. TLS provides:
55+
56+
- Strong authentication
57+
- Message privacy and integrity (enabling detection of message tampering, interception, and forgery)
58+
- Interoperability
59+
- Algorithm flexibility
60+
- Ease of deployment and use
61+
62+
TLS 1.2 is used for all connections started from Windows 365 to the Azure Virtual Desktop infrastructure components. These components use the same TLS 1.2 ciphers as [Azure Front Door](/azure/frontdoor/concept-end-to-end-tls#supported-cipher-suites).
63+
64+
<!-- ########################## -->
65+
## Next steps
66+
67+
For more information about the cryptographic modules underlying Azure managed disks, see [Cryptography API: Next Generation](/windows/desktop/seccng/cng-portal).
68+
69+
For more information on network connectivity and encryption of the RDP remoting connection, see [Understanding Azure Virtual Desktop network connectivity](/azure/virtual-desktop/network-connectivity).

0 commit comments

Comments
 (0)