Skip to content

Commit 121d41f

Browse files
authored
Merge pull request #16214 from MicrosoftDocs/main
Publish main to live, Wednesday 3:30PM PDT, 09/25
2 parents ddcfb87 + f785723 commit 121d41f

File tree

5 files changed

+26
-3
lines changed

5 files changed

+26
-3
lines changed

memdocs/intune/apps/apps-inc-exl-assignments.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,7 @@ To assign an app to groups by using the include and exclude assignment:
8585
> [!NOTE]
8686
> When you add a group, if any other group has already been included for a specific assignment type, the app is preselected and can't be modified for other include assignment types. The group that has been used can't be used as an included group.
8787
88-
When you make group assignments, groups that have already been assigned aren't available to be modified. If you want to select a group that currently isn't available, first remove the app from the app's assigned list.
88+
When you make group assignments, groups that have already been assigned aren't available to be modified. If you want to select a group that currently isn't available, first remove the group from the app's assigned list.
8989

9090
To edit assignments, in the app **Assignments** pane, select the row that contains the specific assignment that you want to change. You can also remove an assignment by selecting the ellipse (****) at the end of a row, and then selecting **Remove**.
9191

memdocs/intune/configuration/oemconfig-managed-home-screen-permissions-android.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -170,7 +170,7 @@ When you use the schema settings in the **Knox Service Plugin** app, the Intune
170170
For guidance on configuring the OEM app schema, use the following links:
171171

172172
- [Blog - Frontline workers get a better experience from Microsoft and Samsung](https://techcommunity.microsoft.com/t5/microsoft-intune-blog/frontline-workers-get-a-better-experience-from-microsoft-and/ba-p/4078801)
173-
- [Knox Service Plugin - Overview](https://docs.samsungknox.com/admin/knox-platform-for-enterprise/knox-service-plugin/welcome/) (opens Samsung's web site)
173+
- [Knox Service Plugin - Grant special permissions for an app](https://docs.samsungknox.com/admin/knox-platform-for-enterprise/knox-service-plugin/kbas/kba-1261-grant-special-permissions-for-an-app/) (opens Samsung's web site)
174174

175175
When you create the Intune policy, you enter the following info:
176176

memdocs/intune/enrollment/corporate-identifiers-add.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -247,7 +247,15 @@ To confirm the reason for an enrollment failure, go to **Devices** > **Enrollmen
247247

248248
## Known issues and limitations
249249

250-
- Windows corporate device identifiers are only supported for devices running Windows 10 version 22H2 and later and Windows 11 version 22H2 and later. Earlier versions can't render the model and manufacturer property. As a result, the property appears in the admin center as **Unknown**. We're working on expanding corporate identifer support to devices running earlier versions of Windows.
250+
- Windows corporate device identifiers are only supported for devices running:
251+
252+
- Windows 10 version 22H2 (OS build 19045.4598) or later.
253+
254+
- Windows 11 version 22H2 (OS build 22621.3374) or later.
255+
256+
- Windows 11 version 23H2 (OS build 22631.3374) or later.
257+
258+
Earlier versions can't render the model and manufacturer property. As a result, the property appears in the admin center as **Unknown**.
251259

252260
- You can upload up to 10 CSV files for Windows corporate identifiers in the admin center. If you need to upload more data, we recommend using PowerShell or the Microsoft Intune Graph API to add corporate identifiers.
253261

memdocs/intune/enrollment/device-enrollment-program-enroll-ios.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,15 @@ The following table shows the features and scenarios supported with automated de
5454
| Devices are managed by another MDM provider. | ❌ <br/><br/> If you want to fully manage a device in Intune, users must unenroll from the current MDM provider, and then enroll in Intune. Or, you can use MAM to manage specifics apps on the device. Since these devices are owned by the organization, we recommend enrolling them in Intune. |
5555
| You use the device enrollment manager (DEM) account. | ❌ <br/><br/> The DEM account isn't supported. |
5656

57+
## Certificates
58+
This enrollment type supports the Automated Certificate Management Environment (ACME) protocol. When new devices enroll, the management profile from Intune receives an ACME certificate. The ACME protocol provides better protection than the SCEP protocol against unauthorized certificate issuance through robust validation mechanisms and automated processes, which helps reduce errors in certificate management.
59+
60+
Devices that are already enrolled do not get an ACME certificate unless they re-enroll into Microsoft Intune. ACME is supported on devices running:
61+
62+
- iOS 16.0 or later
63+
64+
- iPadOS 16.1 or later
65+
5766
## Prerequisites
5867
Before you create the enrollment profile, you must have:
5968

memdocs/intune/enrollment/device-enrollment-program-enroll-macos.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,8 +44,14 @@ This article describes how to set up an automated device enrollment profile for
4444
4. [Assign DEP profile to devices](#assign-an-enrollment-profile-to-devices)
4545
5. [Distribute devices to users](#end-user-experience-with-managed-devices)
4646
-->
47+
## Certificates
48+
49+
This enrollment type supports the Automated Certificate Management Environment (ACME) protocol. When new devices enroll, the management profile from Intune receives an ACME certificate. The ACME protocol provides better protection than the SCEP protocol against unauthorized certificate issuance through robust validation mechanisms and automated processes, which helps reduce errors in certificate management.
50+
51+
Devices that are already enrolled do not get an ACME certificate unless they re-enroll into Microsoft Intune. ACME is supported on devices running macOS 13.1 and later.
4752

4853
## Limitations
54+
4955
Automated device enrollment via Apple Business Manager and Apple School Manager isn't supported with [device enrollment manager accounts](device-enrollment-manager-enroll.md).
5056

5157
## Prerequisites

0 commit comments

Comments
 (0)