You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/autopilot/enrollment-autopilot.md
+2-3Lines changed: 2 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ author: greg-lindsay
9
9
ms.author: greglin
10
10
ms.reviewer: jubaptis
11
11
manager: dougeby
12
-
ms.date: 03/16/2021
12
+
ms.date: 02/09/2022
13
13
ms.topic: how-to
14
14
ms.service: microsoft-intune
15
15
ms.subservice: enrollment
@@ -80,8 +80,7 @@ For information about formatting and using a CSV file to manually add Windows Au
80
80
## Assign a user to a specific Autopilot device
81
81
82
82
> [!NOTE]
83
-
> This functionality has been removed as of September 30, 2021.
84
-
> While the option to assign user to a device in Autopilot is still available in the GUI portal and PowerShell, it will be ignored by the device during provisioning.
83
+
> Assigning a licensed user to a registered Autopilot device using Microsoft Endpoint Manager no longer pre-fills any user information as described below. Please see [Updates to the Windows Autopilot sign-in and deployment experience](https://techcommunity.microsoft.com/t5/intune-customer-success/updates-to-the-windows-autopilot-sign-in-and-deployment/ba-p/2848452) for details on this change. This change does not impact user assigned policies and apps which are still deployed to the device when a licensed user is assigned. See [Windows Autopilot for pre-provisioned deployment](/mem/autopilot/pre-provision#preparation) for details on this.
85
84
86
85
You can assign a licensed Intune user to a specific Autopilot device. This assignment:
87
86
- Pre-fills a user from Azure Active Directory in the [company-branded](/azure/active-directory/fundamentals/customize-branding) sign-in page during Windows setup.
Copy file name to clipboardExpand all lines: memdocs/autopilot/known-issues.md
+9-1Lines changed: 9 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -28,6 +28,14 @@ This article describes known issues that can often be resolved by configuration
28
28
29
29
## Known issues
30
30
31
+
### Reset button causes pre-provisioning to fail on retry
32
+
33
+
When ESP fails during the pre-provisioning flow and the user selects the reset button, TPM attestation may fail during the retry.
34
+
35
+
### TPM attestation failure on Windows 11 error code 0x81039023
36
+
37
+
Some devices may fail TPM attestation on Windows 11 during the pre-provisioning technician flow or self-deployment mode with the error code 0x81039023. There is no workaround currently for this error code, we are working to resolve this issue.
38
+
31
39
### Duplicate device objects with hybrid Azure AD deployments
32
40
33
41
A device object is pre-created in Azure AD once a device is registered in Autopilot. If a device goes through a hybrid Azure AD deployment, by design, another device object is created resulting in duplicate entries.
@@ -56,7 +64,7 @@ When [customizations are applied to the company branding settings](/azure/active
56
64
57
65
### TPM attestation is not working on Intel Tiger Lake platforms
58
66
59
-
TPM attestation support for Intel firmware TPM Tiger Lake platforms are only supported on devices with Windows 10 version 21H2 or higher.
67
+
TPM attestation support for Intel firmware TPM Tiger Lake platforms are only supported on devices with Windows 10 version 21H2 or higher. This issue should be resolved by applying the November 2021 LCU.
60
68
61
69
### Blocking apps specified in a user-targeted Enrollment Status Profile are ignored during device ESP
Copy file name to clipboardExpand all lines: memdocs/autopilot/troubleshooting.md
+4-1Lines changed: 4 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ author: greg-lindsay
13
13
ms.author: greglin
14
14
ms.reviewer: jubaptis
15
15
manager: dougeby
16
-
ms.date: 12/17/2020
16
+
ms.date: 02/09/2022
17
17
ms.collection: M365-modern-desktop
18
18
ms.topic: troubleshooting
19
19
---
@@ -32,6 +32,9 @@ Windows Autopilot is designed to simplify all parts of the Windows device lifecy
32
32
- How Windows Autopilot [device profiles](#profile-download) are downloaded
33
33
-[Key activities](#key-troubleshooting-activities) to perform during troubleshooting
34
34
35
+
## Windows Autopilot diagnostics page
36
+
On Windows 11, you can open the Autopilot diagnostic page to view additional detailed troubleshooting information about the Autopilot provisioning process. The diagnostics page can be enabled by going to the ESP profile and selecting **Yes** to **Turn on log collection and diagnostics page for end users**. Once it is enabled you can select the **View Diagnostics button** or the keyboard shortcut Ctrl+Shift+D to access any diagnostic information. The diagnostics page is currently supported for commercial OOBE, and Autopilot user-driven mode.
37
+
35
38
## Windows Autopilot flow
36
39
37
40
Whether you're performing user-driven or self-deploying device deployments, the troubleshooting process is about the same. It's useful to understand the flow for a specific device:
Copy file name to clipboardExpand all lines: memdocs/autopilot/windows-autopilot-whats-new.md
+12-1Lines changed: 12 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ author: greg-lindsay
13
13
ms.author: greglin
14
14
manager: dougeby
15
15
ms.reviewer: jubaptis
16
-
ms.date: 10/20/2021
16
+
ms.date: 02/09/2022
17
17
ms.collection:
18
18
- M365-modern-desktop
19
19
- highpri
@@ -28,6 +28,17 @@ ms.topic: article
28
28
- Windows 10
29
29
- Windows Holographic, version 2004
30
30
31
+
## Enrollment Status Page
32
+
33
+
With the 2022 Intune release, functionality has been added to the [Enrollment Status Page](enrollment-status.md) UI. The application picker for selecting blocking apps has additional improvements for admins:
34
+
- A search box has been added for easier selection of apps
35
+
- Fixes issue where store apps could not be differentiated between Online and Offline modes
36
+
- A new column has been added for **Version** to see which version of the application is selected
37
+
38
+
See the following example:
39
+
40
+

41
+
31
42
## Autopilot agility rolling out
32
43
33
44
Autopilot agility is a new feature that allows updates and bug fixes to the OOBE experience. These updates occur before device enrollment, after the AADJ login page and may result in an additional reboot and authentication prompt to the user. This feature is rolling out to Windows 10 1909 and 2004/20H2 with August cumulative update and is not yet available for Windows 11.
Copy file name to clipboardExpand all lines: memdocs/autopilot/windows-autopilot.md
-1Lines changed: 0 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -75,7 +75,6 @@ Windows Autopilot enables you to:
75
75
76
76
- Automatically join devices to Azure Active Directory (Azure AD) or Active Directory (via Hybrid Azure AD Join). For more information about the differences between these two join options, see [Introduction to device management in Azure Active Directory](/azure/active-directory/device-management-introduction).
77
77
- Auto-enroll devices into MDM services, such as Microsoft Intune ([*Requires an Azure AD Premium subscription for configuration*](/windows/client-management/mdm/azure-ad-and-microsoft-intune-automatic-mdm-enrollment-in-the-new-portal)).
78
-
- Restrict the Administrator account creation.
79
78
- Create and auto-assign devices to configuration groups based on a device's profile.
80
79
- Customize OOBE content specific to the organization.
Copy file name to clipboardExpand all lines: memdocs/cloud-native-windows-endpoints.md
+4-3Lines changed: 4 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -404,6 +404,7 @@ Use Endpoint Security in Microsoft Endpoint Manager to configure encryption with
404
404
- Check out our blog series on BitLocker at [Enabling BitLocker with Microsoft Endpoint Manager](https://techcommunity.microsoft.com/t5/intune-customer-success/enabling-bitlocker-with-microsoft-endpoint-manager-microsoft/ba-p/2149784).
405
405
406
406
These settings can be enabled in the [Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com) by going to **Endpoint Security** > **Disk encryption** > **Create Policy** > **Windows and later** > **Profile** = **BitLocker**.
407
+
Configuring the BitLocker settings specified below will result in silenty enabling 128 bit encryption for standard users, which is one of the most common scenarios. However your organisation might have different security requirements, so consult the [BitLocker documentation](./intune/protect/encrypt-devices.md) for additional settings.
407
408
408
409
**BitLocker – Base Settings**:
409
410
@@ -432,9 +433,9 @@ These settings can be enabled in the [Microsoft Endpoint Manager admin center](h
432
433
- BitLocker system drive policy: **Configure**
433
434
- Startup authentication required: **Yes**
434
435
- Compatible TPM startup: **Required**
435
-
- Compatible TPM startup PIN: **Not configured**
436
-
- Compatible TPM startup key: **Not configured**
437
-
- Compatible TPM startup key and PIN: **Not configured**
436
+
- Compatible TPM startup PIN: **Block**
437
+
- Compatible TPM startup key: **Block**
438
+
- Compatible TPM startup key and PIN: **Block**
438
439
- Disable BitLocker on devices where TPM is incompatible: **Not configured**
439
440
- Enable preboot recovery message and url: **Not configured**
Copy file name to clipboardExpand all lines: memdocs/configmgr/comanage/how-to-prepare-Win10.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ description: Learn how to prepare your Windows internet-based devices for co-man
5
5
author: mestew
6
6
ms.author: mstewart
7
7
manager: dougeby
8
-
ms.date: 10/05/2021
8
+
ms.date: 02/16/2022
9
9
ms.topic: how-to
10
10
ms.prod: configuration-manager
11
11
ms.technology: configmgr-comanage
@@ -77,26 +77,26 @@ Decide which command-line properties you require for your environment:
77
77
78
78
- The following command-line properties are required in all scenarios:
79
79
80
-
-**CCMHOSTNAME**
80
+
-`CCMHOSTNAME`
81
81
82
-
-**SMSSITECODE**
82
+
-`SMSSITECODE`
83
83
84
84
- If a device uses Azure AD for client authentication and also has a PKI-based client authentication certificate, specify the following properties to use Azure AD:<!-- MEMDocs#1483 -->
85
85
86
-
-**AADCLIENTAPPID**
86
+
-`AADCLIENTAPPID`
87
87
88
-
-**AADRESOURCEURI**
88
+
-`AADRESOURCEURI`
89
89
90
-
- If the client roams back to the intranet, use the **SMSMP** property.
90
+
- If the client roams back to the intranet, use the `SMSMP` property.
91
91
92
-
- If you use your own PKI certificate, and your CRL isn't published to the internet, use the **/NoCRLCheck** parameter. For more information, see [About client installation properties: /NoCRLCheck](../core/clients/deploy/about-client-installation-properties.md#nocrlcheck).
92
+
- If you use your own PKI certificate, and your CRL isn't published to the internet, use the `/NoCRLCheck` parameter. For more information, see [About client installation properties: /NoCRLCheck](../core/clients/deploy/about-client-installation-properties.md#nocrlcheck).
93
93
94
94
> [!IMPORTANT]
95
95
> Microsoft recommends publishing the CRL. For more information, see [Planning for CRLs](../core/plan-design/security/plan-for-certificates.md#pki-certificate-revocation).<!-- memdocs#1942 -->
96
96
97
-
- To bootstrap a task sequence immediately after client registration, use the **PROVISIONTS** property. For more information, see [About client installation properties: PROVISIONTS](../core/clients/deploy/about-client-installation-properties.md#provisionts).
97
+
- To bootstrap a task sequence immediately after client registration, use the `PROVISIONTS` property. For more information, see [About client installation properties: PROVISIONTS](../core/clients/deploy/about-client-installation-properties.md#provisionts).
98
98
99
-
The site publishes other Azure AD information to the cloud management gateway (CMG). An Azure AD-joined client gets this information from the CMG during the ccmsetup process, using the same tenant to which it's joined. This behavior further simplifies enrolling devices to co-management in an environment with more than one Azure AD tenant. The only two required ccmsetup properties are **CCMHOSTNAME** and **SMSSITECODE**.<!--3607731-->
99
+
The site publishes other Azure AD information to the cloud management gateway (CMG). An Azure AD-joined client gets this information from the CMG during the ccmsetup process, using the same tenant to which it's joined. This behavior further simplifies enrolling devices to co-management in an environment with more than one Azure AD tenant. The only two required ccmsetup properties are `CCMHOSTNAME` and `SMSSITECODE`.<!--3607731-->
100
100
101
101
> [!NOTE]
102
102
> If you're already deploying the Configuration Manager client from Intune, update the Intune app with a new command line and new MSI.<!-- SCCMDocs-pr issue 3084 -->
0 commit comments