Skip to content

Commit f03f705

Browse files
authored
Merge pull request #16482 from MicrosoftDocs/main
publish main to live, 3:30 pm, 10/29/24
2 parents 3133e0d + a2da8af commit f03f705

File tree

11 files changed

+495
-8
lines changed

11 files changed

+495
-8
lines changed

memdocs/configmgr/comanage/autopilot-enrollment.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -131,6 +131,8 @@ Use these recommendations for a more successful deployment:
131131

132132
## Limitations
133133

134+
- [Windows Autopilot device preparation](/autopilot/device-preparation/overview) policy doesn't support Autopilot into co-management. As a result, attempting to install co-management during the device preparation flow might result in failed deployments.
135+
134136
- For Windows 11 devices in Microsoft Entra hybrid joined scenario, the management authority will be set to Microsoft Intune during the Windows Autopilot process. Installing Configuration Manager client as Win32 app does not change management authority to Configuration Manager and Microsoft Intune will continue to manage all the co-management workloads.
135137

136138
To change the management authority to Configuration Manager, set the following registry key value:<br>

memdocs/intune/fundamentals/in-development.md

Lines changed: 129 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: dougeby
88
ms.author: dougeby
99
manager: dougeby
10-
ms.date: 10/17/2024
10+
ms.date: 10/29/2024
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: fundamentals
@@ -77,6 +77,14 @@ EPM is available as an [Intune Suite add-on-capability](../fundamentals/intune-a
7777

7878
## App management
7979

80+
### Additional reporting details for LOB apps on AOSP devices<!-- 27157460 -->
81+
82+
Additional details will be provided for app installation reporting of Line of Business (LOB) apps on Android Open Source Project (AOSP) devices. You will be able to see error codes and detailed error messages for LOB apps. For information about app status details, see [Monitor app information and assignments with Microsoft Intune](../apps/apps-monitor.md).
83+
84+
Applies to:
85+
86+
- Android Open Source Project (AOSP) devices
87+
8088
### Added protection for iOS/iPadOS app widgets<!-- 14614429 -->
8189

8290
To protect organizational data for MAM managed accounts and apps, Intune app protection policies now provide the capability to block data sync from policy managed app data to app widgets. App widgets can be added to end-user's iOS/iPadOS device lock screen, which can expose data contained by these widgets, such as meeting titles, top sites, and recent notes. In Intune, you'll be able to set the app protection policy setting **Sync policy managed app data with app widgets** to **Block** for iOS/iPadOS apps. This setting will be available as part of the **Data Protection** settings in app protection policies. This new setting will be an app protection feature similar to the **Sync policy managed app data with native app or add-ins** setting.
@@ -87,7 +95,67 @@ Applies to:
8795

8896
<!-- *********************************************** -->
8997

90-
<!-- ## Device configuration -->
98+
## Device configuration
99+
100+
### Device Firmware Configuration Interface (DFCI) support for Samsung devices<!-- 29107197 -->
101+
102+
We're adding support to use DFCI profiles to manage UEFI (BIOS) settings for Samsung devices that run Windows 10 or Windows 11. Not all Samsung devices running Windows are enabled for DFCI. Contact your device vendor or device manufacturer for eligible devices.
103+
104+
You can manage DFCI profiles from within the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431) by going to **Devices** > **Manage devices** > **Configuration** > **Create** > **New policy** > **Windows 10 and later** for platform > **Templates** > **Device Firmware Configuration Interface** for profile type. For more information about DFCI profiles, see:
105+
106+
- [Configure Device Firmware Configuration Interface (DFCI) profiles on Windows devices in Microsoft Intune](../configuration/device-firmware-configuration-interface-windows.md)
107+
- [Device Firmware Configuration Interface (DFCI) management with Windows Autopilot](../../autopilot/dfci-management.md)
108+
109+
Applies to:
110+
111+
- Windows
112+
113+
### New settings for Windows 24H2 in the Windows settings catalog<!-- 29592329 -->
114+
115+
The Settings Catalog lists all the settings you can configure in a device policy, and all in one place. You can view these Windows settings in the Microsoft Intune admin center by going to **Devices** > **Manage devices** > **Configuration** > **Create** > **New policy** > **Windows 10 and later for platform** > **Settings catalog** for profile type.
116+
117+
We're working on the addition of new settings for Window 24H2.
118+
119+
Applies to:
120+
121+
- Windows
122+
123+
### New settings available in the Apple settings catalog <!--29038336 -->
124+
125+
The [Settings Catalog](../configuration/settings-catalog.md) lists all the settings you can configure in a device policy, and all in one place. For more information about configuring Settings Catalog profiles in Intune, see [Create a policy using settings catalog](../configuration/settings-catalog.md).
126+
127+
We're adding new settings to the Settings Catalog. To view available settings, in the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), go to **Devices** > **Manage devices** > **Configuration** > **Create** > **New policy** > **iOS/iPadOS** or **macOS** for platform > **Settings catalog** for profile type.
128+
129+
#### iOS/iPadOS
130+
131+
**Restrictions**:
132+
133+
- Allow Apps To Be Hidden
134+
- Allow Apps To Be Locked
135+
- Allow Call Recording
136+
- Allow Mail Summary
137+
- Allow RCS Messaging
138+
139+
##### macOS
140+
141+
**Declarative Device Management (DDM) > Math Settings**:
142+
143+
- Calculator
144+
- Input Mode - RPN
145+
146+
**Restrictions**:
147+
148+
- Allow Mail Summary
149+
- Allow Media Sharing Modification
150+
151+
The following settings have been deprecated by Apple and will be marked as deprecated in the Settings Catalog:
152+
153+
#### macOS
154+
155+
**Security > Firewall**:
156+
157+
- Enable Logging
158+
- Logging Option
91159

92160
<!-- *********************************************** -->
93161

@@ -97,6 +165,14 @@ Applies to:
97165

98166
## Device management
99167

168+
### Store macOS certificates in user keychain<!-- 7824255 -->
169+
170+
Soon you'll have the option to store macOS certificates in the user keychain. Currently, Microsoft Intune automatically stores user and device certificates in the *device* keychain. The enhancement will strengthen system security, and will improve the user experience by reducing certificate prompts.
171+
172+
Applies to:
173+
174+
- macOS
175+
100176
### Device Inventory for Windows<!-- 24853010 -->
101177

102178
Device inventory lets you collect and view additional hardware properties from your managed devices to help you better understand the state of your devices and make business decisions.
@@ -111,6 +187,23 @@ Applies to:
111187

112188
## Device security
113189

190+
### Linux support for Endpoint detection and response exclusion settings<!-- 26549863 -->
191+
192+
We are adding a new Endpoint Security template under Endpoint detection and response (EDR) for the Linux platform, that will be supported through the [Microsoft Defender for Endpoint security settings management](../protect/mde-security-integration.md) scenario.
193+
194+
The template will support settings related to global exclusion settings. Applicable to antivirus and EDR engines on the client, the settings can configure exclusions to stop associated real time protection EDR alerts for the excluded items. Exclusions can be defined by the file path, folder, or process explicitly defined by the admin in the policy.
195+
196+
Applies to:
197+
198+
- Linux
199+
200+
### New Microsoft Tunnel readiness check for auditd package<!-- 28148207 -->
201+
202+
We're updating the [Microsoft Tunnel readiness tool](../protect/microsoft-tunnel-prerequisites.md#run-the-readiness-tool) to detect if the **auditd** package for Linux System Auditing (LSA) is installed on your Linux Server. When this check is in place, the mst-readiness tool will raise a warning if the audit package isn't installed. Auditing isn't a required prerequisite for the Linux Server, but recommended.
203+
204+
For more information on *auditd* and how to install it on your Microsoft Tunnel server, see [Linux system auditing](../protect/microsoft-tunnel-prerequisites.md#linux-system-auditing).
205+
206+
114207
### Support for Intune Device control policy for devices managed by Microsoft Defender for Endpoint<!-- 15466620 -->
115208

116209
You'll be able to use the endpoint security policy for *Device control* (Attack surface reduction policy) from the Microsoft Intune with the devices you manage through the [Microsoft Defender for Endpoint security settings management](../protect/mde-security-integration.md) capability.
@@ -134,7 +227,40 @@ When this change takes effect, devices that are assigned this policy while manag
134227

135228
<!-- *********************************************** -->
136229

137-
<!-- ## Monitor and troubleshoot -->
230+
## Monitor and troubleshoot
231+
232+
### New device actions for single device query<!--25799823 -->
233+
234+
We're adding the Intune remote device actions to Single device query to help you manage your devices remotely. From the device query interface, you'll be able to run device actions based on query results for faster and more efficient troubleshooting.
235+
236+
Applies to:
237+
238+
- Windows
239+
240+
For more information, see:
241+
242+
- [Device query in Microsoft Intune](../../analytics/device-query.md)
243+
- [Run remote actions on devices with Microsoft Intune](../remote-actions/device-management.md)
244+
245+
### Device Query for Multiple Devices<!--25234456 -->
246+
247+
We're adding Device query for multiple devices. This feature allows you to gain comprehensive insights about your entire fleet of devices using Kusto Query Language (KQL) to query across collected inventory data for your devices.
248+
249+
Device query for multiple devices will be supported for devices running Windows 10 or later. This feature will be included as part of Advanced Analytics.
250+
251+
Applies to:
252+
253+
- Windows
254+
255+
### ICCID will be inventoried for Android Enterprise Dedicated and Fully Managed <!-- 12846449 -->
256+
257+
We're adding the ability to view a device's ICCID number for devices enrolled as Android Enterprise Dedicated or Android Fully Managed. Admins can view ICCID numbers in their device inventory.
258+
259+
When available, you can find the ICCID number for Android devices by navigating to **Devices** > **Android**. Select a device of interest. In the side panel, under **Monitor** select **Hardware**. The ICCID number will be in the **Network details** group. The ICCID number isn't supported for Android Corporate-Owned Work Profile devices.
260+
261+
Applies to:
262+
263+
- Android
138264

139265
<!-- *********************************************** -->
140266

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
---
2+
title: Common Education iPads Apple Intelligence configuration
3+
description: Learn about common iPads Apple Intelligence configuration used by Education organizations in Intune.
4+
ms.date: 10/16/2024
5+
ms.topic: tutorial
6+
author: yegor-a
7+
ms.author: egorabr
8+
ms.manager: dougeby
9+
no-loc: [Microsoft, Apple]
10+
ms.collection:
11+
- graph-interactive
12+
---
13+
14+
# Apple Intelligence
15+
16+
This article summarizes restrictions for Apple Intelligence introduced in iPadOS 18.
17+
18+
To learn more, see:
19+
20+
- [Use the settings catalog to configure settings on Windows, iOS/iPadOS and macOS devices](/mem/intune/configuration/settings-catalog)
21+
- [Restrictions payload](https://developer.apple.com/documentation/devicemanagement/restrictions)
22+
- [iPadOS 18](https://www.apple.com/ipados/ipados-18)
23+
24+
> [!TIP]
25+
> When creating a settings catalog profile in the Microsoft Intune admin center, you can copy a policy name from this article and paste it into the settings picker search field to find the desired policy.
26+
27+
## [**Settings**](#tab/settings)
28+
29+
| **Category** | **Property** | **Value** | **Notes** | **Payload property** |
30+
|---|---|:---:|---|---|
31+
| Restrictions | **:::no-loc text="Allow Genmoji":::** | False | Prohibits creating new Genmoji. | [:::no-loc text="allowGenmoji":::](https://developer.apple.com/documentation/devicemanagement/restrictions) |
32+
| Restrictions | **:::no-loc text="Allow Image Playground":::** | False | Prohibits the use of image generation. | [:::no-loc text="allowImagePlayground":::](https://developer.apple.com/documentation/devicemanagement/restrictions) |
33+
| Restrictions | **:::no-loc text="Allow Image Wand":::** | False | Prohibits the use of Image Wand. | [:::no-loc text="allowImageWand":::](https://developer.apple.com/documentation/devicemanagement/restrictions) |
34+
| Restrictions | **:::no-loc text="Allow Personalized Handwriting Results":::** | False | | [:::no-loc text="allowPersonalizedHandwritingResults":::](https://developer.apple.com/documentation/devicemanagement/restrictions) |
35+
| Restrictions | **:::no-loc text="Allow Writing Tool":::** | False | Disables Apple Intelligence writing tools. | [:::no-loc text="allowWritingTools":::](https://developer.apple.com/documentation/devicemanagement/restrictions) |
36+
37+
## [:::image type="icon" source="../../../media/icons/graph.svg"::: **Create policy using Graph Explorer**](#tab/graph)
38+
39+
[!INCLUDE [graph-explorer-introduction](../../../includes/graph-explorer-intro.md)]
40+
41+
This will create a policy in your tenant with the name **_MSLearn_Example_CommonEDU - iPads - Appple Intelligence**.
42+
43+
```msgraph-interactive
44+
POST https://graph.microsoft.com/beta/deviceManagement/configurationPolicies
45+
Content-Type: application/json
46+
47+
{"name":"_MSLearn_Example_CommonEDU - iPads - Apple Intelligence","description":"","platforms":"iOS","technologies":"mdm,appleRemoteManagement","roleScopeTagIds":["0"],"settings":[{"@odata.type":"#microsoft.graph.deviceManagementConfigurationSetting","settingInstance":{"@odata.type":"#microsoft.graph.deviceManagementConfigurationGroupSettingCollectionInstance","settingDefinitionId":"com.apple.applicationaccess_com.apple.applicationaccess","groupSettingCollectionValue":[{"children":[{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance","settingDefinitionId":"com.apple.applicationaccess_allowgenmoji","choiceSettingValue":{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingValue","value":"com.apple.applicationaccess_allowgenmoji_false","children":[]}},{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance","settingDefinitionId":"com.apple.applicationaccess_allowimageplayground","choiceSettingValue":{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingValue","value":"com.apple.applicationaccess_allowimageplayground_false","children":[]}},{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance","settingDefinitionId":"com.apple.applicationaccess_allowimagewand","choiceSettingValue":{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingValue","value":"com.apple.applicationaccess_allowimagewand_false","children":[]}},{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance","settingDefinitionId":"com.apple.applicationaccess_allowpersonalizedhandwritingresults","choiceSettingValue":{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingValue","value":"com.apple.applicationaccess_allowpersonalizedhandwritingresults_false","children":[]}},{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance","settingDefinitionId":"com.apple.applicationaccess_allowwritingtools","choiceSettingValue":{"@odata.type":"#microsoft.graph.deviceManagementConfigurationChoiceSettingValue","value":"com.apple.applicationaccess_allowwritingtools_false","children":[]}}]}]}}]}
48+
```
49+
50+
[!INCLUDE [graph-explorer-steps](../../../includes/graph-explorer-steps.md)]
51+
52+
---

0 commit comments

Comments
 (0)