From 507f1a01495fc8df60be3bd5b0b13653852be93d Mon Sep 17 00:00:00 2001 From: Benjamin Flamm <57767769+beflamm@users.noreply.github.com> Date: Fri, 6 Sep 2024 12:25:15 -0400 Subject: [PATCH 01/12] Learn Editor: Update kernel-extensions-overview-macos.md --- .../intune/configuration/kernel-extensions-overview-macos.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/memdocs/intune/configuration/kernel-extensions-overview-macos.md b/memdocs/intune/configuration/kernel-extensions-overview-macos.md index 11b5b8886a4..8a03407ecef 100644 --- a/memdocs/intune/configuration/kernel-extensions-overview-macos.md +++ b/memdocs/intune/configuration/kernel-extensions-overview-macos.md @@ -114,6 +114,8 @@ For more information on kernel extensions, go to [kernel extensions](https://dev ## Create the kernel extension policy +> [!IMPORTANT] +> The macOS extensions template has been deprecated in the August 2024 service release. Existing policies will remain unchanged; however, you can no longer create new policies using this template and it is recommended to use the settings catalog to create new policies that configure the System Extension payload. Learn more about configuring this payloads using the settings catalog. [insert link] 1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431). 2. Select **Devices** > **Manage devices** > **Configuration** > **Create** > **New policy**. 3. Enter the following properties: From 58adb558427f17ae419f9658bd5e1e9f5e897890 Mon Sep 17 00:00:00 2001 From: Benjamin Flamm <57767769+beflamm@users.noreply.github.com> Date: Wed, 11 Sep 2024 12:30:13 -0400 Subject: [PATCH 02/12] add link --- .../intune/configuration/kernel-extensions-overview-macos.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/memdocs/intune/configuration/kernel-extensions-overview-macos.md b/memdocs/intune/configuration/kernel-extensions-overview-macos.md index 8a03407ecef..03c1efe3172 100644 --- a/memdocs/intune/configuration/kernel-extensions-overview-macos.md +++ b/memdocs/intune/configuration/kernel-extensions-overview-macos.md @@ -115,7 +115,8 @@ For more information on kernel extensions, go to [kernel extensions](https://dev ## Create the kernel extension policy > [!IMPORTANT] -> The macOS extensions template has been deprecated in the August 2024 service release. Existing policies will remain unchanged; however, you can no longer create new policies using this template and it is recommended to use the settings catalog to create new policies that configure the System Extension payload. Learn more about configuring this payloads using the settings catalog. [insert link] +> The macOS extensions template has been deprecated in the August 2024 service release. Existing policies will remain unchanged; however, you can no longer create new policies using this template and it is recommended to use the settings catalog to create new policies that configure the System Extension payload. Learn more about configuring this payloads using the [macOS settings catalog](https://learn.microsoft.com/en-us/mem/intune/configuration/settings-catalog?tabs=sc-search-filter%2Csc-reporting). + 1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431). 2. Select **Devices** > **Manage devices** > **Configuration** > **Create** > **New policy**. 3. Enter the following properties: From cb67f6c7520b64f09620073796c14e74d5fa194a Mon Sep 17 00:00:00 2001 From: Mandi Ohlinger Date: Wed, 11 Sep 2024 13:14:38 -0400 Subject: [PATCH 03/12] text updates --- .../configuration/kernel-extensions-overview-macos.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/memdocs/intune/configuration/kernel-extensions-overview-macos.md b/memdocs/intune/configuration/kernel-extensions-overview-macos.md index 03c1efe3172..adc78b58710 100644 --- a/memdocs/intune/configuration/kernel-extensions-overview-macos.md +++ b/memdocs/intune/configuration/kernel-extensions-overview-macos.md @@ -8,7 +8,7 @@ keywords: macos, kernel extensions, system extensions, microsoft intune, endpoin author: MandiOhlinger ms.author: mandia manager: dougeby -ms.date: 01/11/2024 +ms.date: 09/11/2024 ms.topic: how-to ms.service: microsoft-intune ms.subservice: configuration @@ -115,7 +115,9 @@ For more information on kernel extensions, go to [kernel extensions](https://dev ## Create the kernel extension policy > [!IMPORTANT] -> The macOS extensions template has been deprecated in the August 2024 service release. Existing policies will remain unchanged; however, you can no longer create new policies using this template and it is recommended to use the settings catalog to create new policies that configure the System Extension payload. Learn more about configuring this payloads using the [macOS settings catalog](https://learn.microsoft.com/en-us/mem/intune/configuration/settings-catalog?tabs=sc-search-filter%2Csc-reporting). +> This macOS extensions template is deprecated in the August 2024 service release (2408). Existing policies continue to work. But, you cann't create new policies using this template. +> +> Instead, use the settings catalog to create new policies that configure the System Extension payload. To learn more about the settings catalog, go to [settings catalog](settings-catalog.md). 1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431). 2. Select **Devices** > **Manage devices** > **Configuration** > **Create** > **New policy**. From d240e78c5c3df8c766878815ca58be79991fdcf6 Mon Sep 17 00:00:00 2001 From: Mandi Ohlinger Date: Wed, 11 Sep 2024 13:21:52 -0400 Subject: [PATCH 04/12] typo --- .../intune/configuration/kernel-extensions-overview-macos.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/memdocs/intune/configuration/kernel-extensions-overview-macos.md b/memdocs/intune/configuration/kernel-extensions-overview-macos.md index adc78b58710..9ba602f763b 100644 --- a/memdocs/intune/configuration/kernel-extensions-overview-macos.md +++ b/memdocs/intune/configuration/kernel-extensions-overview-macos.md @@ -115,7 +115,7 @@ For more information on kernel extensions, go to [kernel extensions](https://dev ## Create the kernel extension policy > [!IMPORTANT] -> This macOS extensions template is deprecated in the August 2024 service release (2408). Existing policies continue to work. But, you cann't create new policies using this template. +> This macOS extensions template is deprecated in the August 2024 service release (2408). Existing policies continue to work. But, you can't create new policies using this template. > > Instead, use the settings catalog to create new policies that configure the System Extension payload. To learn more about the settings catalog, go to [settings catalog](settings-catalog.md). From a95f36388a597304714484766b404c74cb12d167 Mon Sep 17 00:00:00 2001 From: Benjamin Flamm <57767769+beflamm@users.noreply.github.com> Date: Thu, 12 Sep 2024 11:05:20 -0400 Subject: [PATCH 05/12] Learn Editor: Update device-profiles.md --- memdocs/intune/configuration/device-profiles.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/memdocs/intune/configuration/device-profiles.md b/memdocs/intune/configuration/device-profiles.md index b32b193043a..6cdc2c70a6e 100644 --- a/memdocs/intune/configuration/device-profiles.md +++ b/memdocs/intune/configuration/device-profiles.md @@ -207,6 +207,8 @@ This feature supports: ## Endpoint protection +> [!IMPORTANT] +> This template has been deprecated in the August 2024 service release. Existing policies will remain unchanged; however, you can no longer create new policies using this template and it is recommended to use the settings catalog to create new policies that configure the FileVault, Firewall, and System Policy Control (Gatekeeper) payloads. Learn more about configuring these payloads using the [macOS settings catalog](/mem/intune/configuration/settings-catalog?tabs=sc-search-filter%2Csc-reporting). [Endpoint protection](../protect/endpoint-protection-configure.md) configures BitLocker and Microsoft Defender settings for Windows client devices. On macOS devices, you can also configure the firewall, gateway, and other resources. To onboard Microsoft Defender for Endpoint with Microsoft Intune, see [Configure endpoints using Mobile Device Management (MDM) tools](/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm). @@ -228,6 +230,8 @@ This feature supports: ## Extensions +> [!IMPORTANT] +> This template has been deprecated in the August 2024 service release. Existing policies will remain unchanged; however, you can no longer create new policies using this template and it is recommended to use the settings catalog to create new policies that configure the System Extensions payload. Learn more about configuring this payload using the [macOS settings catalog](/mem/intune/configuration/settings-catalog?tabs=sc-search-filter%2Csc-reporting). [macOS system extensions and kernel extensions](kernel-extensions-overview-macos.md) allows administrators to add features or programs that extend the native capabilities of the operating system. Configure these settings to trust all extensions from a specific developer or partner, or allow specific extensions. This feature supports: From f98ac0a19a47cb05571c44f0a2afd41a89690f8b Mon Sep 17 00:00:00 2001 From: Benjamin Flamm <57767769+beflamm@users.noreply.github.com> Date: Thu, 12 Sep 2024 11:05:28 -0400 Subject: [PATCH 06/12] Learn Editor: Update device-profiles.md From 11c73bcdc47eeee18f5c3e12ca2c90d8025481d1 Mon Sep 17 00:00:00 2001 From: Liz Cox <45763208+mselcox@users.noreply.github.com> Date: Thu, 12 Sep 2024 14:07:34 -0500 Subject: [PATCH 07/12] Update intune-govt-service-description.md Removed note about device query not being supported in GCC-H because it is now supported. --- memdocs/intune/fundamentals/intune-govt-service-description.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/memdocs/intune/fundamentals/intune-govt-service-description.md b/memdocs/intune/fundamentals/intune-govt-service-description.md index eb9bc28b8b8..b2413559de1 100644 --- a/memdocs/intune/fundamentals/intune-govt-service-description.md +++ b/memdocs/intune/fundamentals/intune-govt-service-description.md @@ -77,7 +77,7 @@ The following features are available and supported in Microsoft GCC High and/or | Remote Help | ✅

Remote Help is supported in GCC on Android, macOS, and Windows devices. It's not supported in GCC High or DoD.

For more information on this feature, go to [Remote Help in Microsoft Intune](../fundamentals/remote-help.md). | | Windows Autopilot device preparation | ✅

Some features are available now, such as user-driven deployments, and some are still [in the planning phase](#in-the-planning-phase). For more information on the recent changes to Windows Autopilot device preparation, go to [Blog: Windows deployment with the next generation of Windows Autopilot](https://techcommunity.microsoft.com/t5/microsoft-intune-blog/windows-deployment-with-the-next-generation-of-windows-autopilot/ba-p/4148169).

To get started with Windows Autopilot device preparation, go to [Windows Autopilot Device Preparation overview](/autopilot/device-preparation/overview). | | Log Analytics | ✅

You can send Intune log data to Azure Storage, Event Hubs, or Log Analytics.

For more information on this feature, go to [Send log data to storage, event hubs, or log analytics from Intune](review-logs-using-azure-monitor.md). | -| Microsoft Intune Plan 2
and Microsoft Intune Suite | For more information on these plans, go to [Use Intune Suite add-on capabilities](intune-add-ons.md).

The following Plan 2 features support the GCC High and DoD environements:
- [Microsoft Tunnel for Mobile Application Management](../protect/microsoft-tunnel-mam.md)
- [Firmware-over-the-air update](../protect/fota-updates-android.md)
- [Specialty devices management](../fundamentals/specialty-devices-with-intune.md)

The following Microsoft Intune Suite features support the GCC High and DoD environements:
- [Endpoint Privilege Management](../protect/epm-overview.md)
- [Advanced Analytics](../../analytics/advanced-endpoint-analytics.md) - With this release, GCC High and DoD support for Advanced Endpoint Analytics not include the [*Device query*](../../analytics/device-query.md) functionality.| +| Microsoft Intune Plan 2
and Microsoft Intune Suite | For more information on these plans, go to [Use Intune Suite add-on capabilities](intune-add-ons.md).

The following Plan 2 features support the GCC High and DoD environements:
- [Microsoft Tunnel for Mobile Application Management](../protect/microsoft-tunnel-mam.md)
- [Firmware-over-the-air update](../protect/fota-updates-android.md)
- [Specialty devices management](../fundamentals/specialty-devices-with-intune.md)

The following Microsoft Intune Suite features support the GCC High and DoD environements:
- [Endpoint Privilege Management](../protect/epm-overview.md)
- [Advanced Analytics](../../analytics/advanced-endpoint-analytics.md) ### In the planning phase From 40a95748a3ee4572221799ee298a02149ad666c9 Mon Sep 17 00:00:00 2001 From: Stacyrch140 <102548089+Stacyrch140@users.noreply.github.com> Date: Mon, 23 Sep 2024 13:59:58 -0400 Subject: [PATCH 08/12] pencil edits --- memdocs/intune/fundamentals/intune-govt-service-description.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/memdocs/intune/fundamentals/intune-govt-service-description.md b/memdocs/intune/fundamentals/intune-govt-service-description.md index b2413559de1..0093e500d02 100644 --- a/memdocs/intune/fundamentals/intune-govt-service-description.md +++ b/memdocs/intune/fundamentals/intune-govt-service-description.md @@ -77,7 +77,7 @@ The following features are available and supported in Microsoft GCC High and/or | Remote Help | ✅

Remote Help is supported in GCC on Android, macOS, and Windows devices. It's not supported in GCC High or DoD.

For more information on this feature, go to [Remote Help in Microsoft Intune](../fundamentals/remote-help.md). | | Windows Autopilot device preparation | ✅

Some features are available now, such as user-driven deployments, and some are still [in the planning phase](#in-the-planning-phase). For more information on the recent changes to Windows Autopilot device preparation, go to [Blog: Windows deployment with the next generation of Windows Autopilot](https://techcommunity.microsoft.com/t5/microsoft-intune-blog/windows-deployment-with-the-next-generation-of-windows-autopilot/ba-p/4148169).

To get started with Windows Autopilot device preparation, go to [Windows Autopilot Device Preparation overview](/autopilot/device-preparation/overview). | | Log Analytics | ✅

You can send Intune log data to Azure Storage, Event Hubs, or Log Analytics.

For more information on this feature, go to [Send log data to storage, event hubs, or log analytics from Intune](review-logs-using-azure-monitor.md). | -| Microsoft Intune Plan 2
and Microsoft Intune Suite | For more information on these plans, go to [Use Intune Suite add-on capabilities](intune-add-ons.md).

The following Plan 2 features support the GCC High and DoD environements:
- [Microsoft Tunnel for Mobile Application Management](../protect/microsoft-tunnel-mam.md)
- [Firmware-over-the-air update](../protect/fota-updates-android.md)
- [Specialty devices management](../fundamentals/specialty-devices-with-intune.md)

The following Microsoft Intune Suite features support the GCC High and DoD environements:
- [Endpoint Privilege Management](../protect/epm-overview.md)
- [Advanced Analytics](../../analytics/advanced-endpoint-analytics.md) +| Microsoft Intune Plan 2
and Microsoft Intune Suite | For more information on these plans, go to [Use Intune Suite add-on capabilities](intune-add-ons.md).

The following Plan 2 features support the GCC High and DoD environments:
- [Microsoft Tunnel for Mobile Application Management](../protect/microsoft-tunnel-mam.md)
- [Firmware-over-the-air update](../protect/fota-updates-android.md)
- [Specialty devices management](../fundamentals/specialty-devices-with-intune.md)

The following Microsoft Intune Suite features support the GCC High and DoD environments:
- [Endpoint Privilege Management](../protect/epm-overview.md)
- [Advanced Analytics](../../analytics/advanced-endpoint-analytics.md) ### In the planning phase From 676e6803b2082adde5d605804a0c67b00d8cdc9c Mon Sep 17 00:00:00 2001 From: Mandi Ohlinger Date: Mon, 23 Sep 2024 14:45:43 -0400 Subject: [PATCH 09/12] formatting --- memdocs/intune/configuration/device-profiles.md | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/memdocs/intune/configuration/device-profiles.md b/memdocs/intune/configuration/device-profiles.md index 6cdc2c70a6e..ace0952e590 100644 --- a/memdocs/intune/configuration/device-profiles.md +++ b/memdocs/intune/configuration/device-profiles.md @@ -8,7 +8,7 @@ author: MandiOhlinger ms.author: mandia manager: dougeby -ms.date: 07/18/2024 +ms.date: 09/23/2024 ms.topic: overview ms.service: microsoft-intune ms.subservice: configuration @@ -208,7 +208,10 @@ This feature supports: ## Endpoint protection > [!IMPORTANT] -> This template has been deprecated in the August 2024 service release. Existing policies will remain unchanged; however, you can no longer create new policies using this template and it is recommended to use the settings catalog to create new policies that configure the FileVault, Firewall, and System Policy Control (Gatekeeper) payloads. Learn more about configuring these payloads using the [macOS settings catalog](/mem/intune/configuration/settings-catalog?tabs=sc-search-filter%2Csc-reporting). +> This template is deprecated in the August 2024 service release (2408). Existing policies continue to work. But, you can't create new policies using this template. +> +> Instead, use the settings catalog to create new policies that configure the FileVault, Firewall, and System Policy Control (Gatekeeper) payloads. To learn more, go to [macOS settings catalog](settings-catalog.md). + [Endpoint protection](../protect/endpoint-protection-configure.md) configures BitLocker and Microsoft Defender settings for Windows client devices. On macOS devices, you can also configure the firewall, gateway, and other resources. To onboard Microsoft Defender for Endpoint with Microsoft Intune, see [Configure endpoints using Mobile Device Management (MDM) tools](/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm). @@ -231,7 +234,10 @@ This feature supports: ## Extensions > [!IMPORTANT] -> This template has been deprecated in the August 2024 service release. Existing policies will remain unchanged; however, you can no longer create new policies using this template and it is recommended to use the settings catalog to create new policies that configure the System Extensions payload. Learn more about configuring this payload using the [macOS settings catalog](/mem/intune/configuration/settings-catalog?tabs=sc-search-filter%2Csc-reporting). +> This template is deprecated in the August 2024 service release (2408). Existing policies continue to work. But, you can't create new policies using this template. +> +> Instead, use the settings catalog to create new policies that configure the System Extensions payload. To learn more, go to [macOS settings catalog](settings-catalog.md). + [macOS system extensions and kernel extensions](kernel-extensions-overview-macos.md) allows administrators to add features or programs that extend the native capabilities of the operating system. Configure these settings to trust all extensions from a specific developer or partner, or allow specific extensions. This feature supports: From 5011585eb10505d31c4a2979001b754370129554 Mon Sep 17 00:00:00 2001 From: ErikjeMS Date: Mon, 23 Sep 2024 13:19:36 -0700 Subject: [PATCH 10/12] add WN --- windows-365/enterprise/whats-new.md | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/windows-365/enterprise/whats-new.md b/windows-365/enterprise/whats-new.md index 08b7ea7a24e..c5f1885954e 100644 --- a/windows-365/enterprise/whats-new.md +++ b/windows-365/enterprise/whats-new.md @@ -7,7 +7,7 @@ keywords: author: ErikjeMS ms.author: erikje manager: dougeby -ms.date: 09/20/2024 +ms.date: 09/23/2024 ms.topic: conceptual ms.service: windows-365 ms.subservice: windows-365-enterprise @@ -55,6 +55,16 @@ For more information about public preview items, see [Public preview in Windows ### Windows 365 app --> + +## Week of September 23, 2024 + + +### Device management + +#### Windows 11 Cloud PCs now support EN-NZ + +Windows 365 Cloud PCs now support EN-NZ for Windows 11. + ## Week of September 16, 2024 From 106dbca8267912689ab399ddee9f4a4db73e9e54 Mon Sep 17 00:00:00 2001 From: DidunAyodeji <98491992+DidunAyodeji@users.noreply.github.com> Date: Mon, 23 Sep 2024 16:24:12 -0400 Subject: [PATCH 11/12] Update sso-dialog-faqs.yml Fixed some duplicate terms and sentences. Device can't be described as "your" in the document because customers might use a shared device. Need them to be aware of implications of adding an account on a device that they do not own. --- memdocs/intune/user-help/sso-dialog-faqs.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/memdocs/intune/user-help/sso-dialog-faqs.yml b/memdocs/intune/user-help/sso-dialog-faqs.yml index 831a1678807..e7a2d28b5ef 100644 --- a/memdocs/intune/user-help/sso-dialog-faqs.yml +++ b/memdocs/intune/user-help/sso-dialog-faqs.yml @@ -36,7 +36,7 @@ sections: On a Windows device, navigate to the **Settings** app > **Accounts** > **Access work or school** > Select your account > **Disconnect**. If you don't have access to the device you signed in to, go to [https://account.microsoft.com/devices](https://account.microsoft.com/devices) to manage your account and sign out. > [!NOTE] - > Signing out of any individual app doesn't remove your account from your device. Signing out of a desktop app doesn't remove your account from the device. You must sign out of all apps via settings or [https://account.microsoft.com/devices](https://account.microsoft.com/devices) to remove your account from the device. + > Signing out of any individual desktop app won't remove your account from the device. You must sign out of all apps via settings or [https://account.microsoft.com/devices](https://account.microsoft.com/devices) to remove your account from the device. - question: | What does selecting "No, this app only" do? @@ -70,7 +70,7 @@ sections: - question: | What happens if I uncheck the device management checkbox but sign in to all apps? answer: | - You're signed in to all native and desktop apps on your device, but your device isn't enrolled in [mobile device management](/windows/client-management/mdm-overview). Your organization might require MDM to access some applications or resources, without it you might not have access. + You're signed in to all desktop apps on the device, but the device isn't enrolled in [mobile device management](/windows/client-management/mdm-overview). Your organization might require MDM to access some applications or resources, without it you might not have access. - question: | What can my administrator do if I enroll in mobile device management? From 66466178c76ffa23dc674767ada5c432f907542b Mon Sep 17 00:00:00 2001 From: DidunAyodeji <98491992+DidunAyodeji@users.noreply.github.com> Date: Mon, 23 Sep 2024 16:27:46 -0400 Subject: [PATCH 12/12] Update sso-dialog-faqs.yml --- memdocs/intune/user-help/sso-dialog-faqs.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/memdocs/intune/user-help/sso-dialog-faqs.yml b/memdocs/intune/user-help/sso-dialog-faqs.yml index e7a2d28b5ef..e8248e87c91 100644 --- a/memdocs/intune/user-help/sso-dialog-faqs.yml +++ b/memdocs/intune/user-help/sso-dialog-faqs.yml @@ -36,7 +36,7 @@ sections: On a Windows device, navigate to the **Settings** app > **Accounts** > **Access work or school** > Select your account > **Disconnect**. If you don't have access to the device you signed in to, go to [https://account.microsoft.com/devices](https://account.microsoft.com/devices) to manage your account and sign out. > [!NOTE] - > Signing out of any individual desktop app won't remove your account from the device. You must sign out of all apps via settings or [https://account.microsoft.com/devices](https://account.microsoft.com/devices) to remove your account from the device. + > Signing out of any individual desktop app doesn't remove your account from the device. You must sign out of all apps via settings or [https://account.microsoft.com/devices](https://account.microsoft.com/devices) to remove your account from the device. - question: | What does selecting "No, this app only" do?