tag:blogger.com,1999:blog-73964810533597035192024-03-14T03:40:06.609+01:00Henk's blogHenk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.comBlogger644125tag:blogger.com,1999:blog-7396481053359703519.post-18337961611500439752016-11-15T17:13:00.000+01:002016-11-15T17:13:51.512+01:00Failed to Install Software Updates during Build and Capture (Error: 87D00272)<span style="font-family: "verdana" , sans-serif;">Recently I created several Windows 10 1607 images, where Offline Servicing put all Windows 10 updates needed on the image. Besides of that I created Build and Captures task sequences, with an Office 2016 package in it. Because those updates cannot be injected with Offline Servicing, I decided to add an additional Install Software Updates step in the task sequence. Nothing wrong about that :-)</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-jZ0lHUq5R6E/WAnp-13R2sI/AAAAAAAAFE0/9XBGWQnrvNkxG6kMPAL1hwyXNv6XLnPiwCLcB/s1600/Capture01.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="130" src="https://4.bp.blogspot.com/-jZ0lHUq5R6E/WAnp-13R2sI/AAAAAAAAFE0/9XBGWQnrvNkxG6kMPAL1hwyXNv6XLnPiwCLcB/s320/Capture01.PNG" width="320" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;">During the Software Update installation step however, the following error message was displayed:</span><br />
<span style="font-family: "verdana" , sans-serif;">-Refreshing Updates<br />-Failed to RefreshUpdates, hr=0x87d00272<br />-Failed to run the action: Install Software Updates. Component is disabled. (Error: 87D00272)</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-dvgTn9D0bmI/WAnq2I6rNWI/AAAAAAAAFE8/F6hMdGBN5D8uJXI36F_Dw8ThsyMof1JPwCLcB/s1600/Capture06.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="93" src="https://2.bp.blogspot.com/-dvgTn9D0bmI/WAnq2I6rNWI/AAAAAAAAFE8/F6hMdGBN5D8uJXI36F_Dw8ThsyMof1JPwCLcB/s320/Capture06.PNG" width="320" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;">Trick is, someone changed the Default Client Settings policy, and set "Enable software updates on clients" to No. Therefore software update scan, download and install cannot take place. Long story short, change the policy back to Yes, and start build and capture again.</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">Hope it helps!</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-_NNLLOKXPwo/WAnrJe_2NVI/AAAAAAAAFFA/h8-7dN313dYDes7q71ImQJg7j6pAf9PyQCLcB/s1600/Capture03.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="136" src="https://2.bp.blogspot.com/-_NNLLOKXPwo/WAnrJe_2NVI/AAAAAAAAFFA/h8-7dN313dYDes7q71ImQJg7j6pAf9PyQCLcB/s320/Capture03.PNG" width="320" /></span></a></div>
<div style="text-align: center;">
<span style="font-family: "verdana" , sans-serif;">Download software updates working again!</span></div>
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-qt15tIQbTus/WAnrPWwH_2I/AAAAAAAAFFE/zqOik443l4Asc0R2O02MyT86Rt_zhcXIgCLcB/s1600/Capture04.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="134" src="https://2.bp.blogspot.com/-qt15tIQbTus/WAnrPWwH_2I/AAAAAAAAFFE/zqOik443l4Asc0R2O02MyT86Rt_zhcXIgCLcB/s320/Capture04.PNG" width="320" /></span></a></div>
<div style="text-align: center;">
<span style="font-family: "verdana" , sans-serif;">Install software updates working again!</span></div>
Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com3tag:blogger.com,1999:blog-7396481053359703519.post-29120327189741980392016-11-08T20:03:00.002+01:002016-11-08T20:03:31.687+01:00The Report Server WMI provider cannot create the virtual directory (SQL upgrade)<span style="font-family: "verdana" , sans-serif;">Recently I did an in-place upgrade, from SQL 2012 SP1 to 2014 SP2, this for upgrading ConfigMgr 2012 R2 SP1 to Current Branch (1511) afterwards. Nothing wrong here you may think.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://3.bp.blogspot.com/-SpC5gqRnNNE/WCIgGWjC9mI/AAAAAAAAFJA/-FOO6NDgL_kSh6X6B0ysb2_0U1v5lobSACLcB/s1600/Upgrade01.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="89" src="https://3.bp.blogspot.com/-SpC5gqRnNNE/WCIgGWjC9mI/AAAAAAAAFJA/-FOO6NDgL_kSh6X6B0ysb2_0U1v5lobSACLcB/s320/Upgrade01.PNG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">During upgrade the reporting part failed with the following error: "<strong>A Secure Sockets Layer (SSL) certificate is not configured on the Web site.</strong>" Trick is, within Reporting Services Configuration Manager, there may be IP-addresses reserved for both http and https, where the one for https must be connected to an SSL certificate. </span><br />
<br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://3.bp.blogspot.com/-H4n0t1h2HtM/WCIgJ3JsybI/AAAAAAAAFJE/s-S1ReEeO9wPwrTAzSbQ6VOtlXnsOX0xQCLcB/s1600/Upgrade05.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="103" src="https://3.bp.blogspot.com/-H4n0t1h2HtM/WCIgJ3JsybI/AAAAAAAAFJE/s-S1ReEeO9wPwrTAzSbQ6VOtlXnsOX0xQCLcB/s320/Upgrade05.PNG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">After starting upgrade again (with the command: setup.exe /action=repair /instancename=<instance>), there was another error: "<strong>The Report Server WMI provider cannot create the virtual directory.</strong>" This occurs when you call SetVirtualDirectory and the UrlString is already reserved. To continue, clear all URL reservations by calling RemoveURL and then try again."</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">That's another nasty issue if you ask me! I did several installations, with several configurations but it didn't work out for me. With the command: "<strong>netsh http show urlacl</strong>" all registered URL's can be seen. With the command: "<strong>netsh http delete urlacl URL=<url>:<port></strong>" they can be deleted too. </span><span style="font-family: "verdana" , sans-serif;">When lucky removing the Reportserver URL's is enough, but it didn't work out for me. </span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-5ATgYHmwmrI/WCIg0nNUbZI/AAAAAAAAFJI/eDuALN9jWl8MfjP4wBEq8iTiwpSCY5fogCLcB/s1600/Capture.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="119" src="https://2.bp.blogspot.com/-5ATgYHmwmrI/WCIg0nNUbZI/AAAAAAAAFJI/eDuALN9jWl8MfjP4wBEq8iTiwpSCY5fogCLcB/s320/Capture.JPG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">Therefore I removed Reporting Services, and installed it again. After installation you may see this message too: "<strong>The report server installation is not initialized.</strong>" To solve this you need to restore the encryption key created earlier, or delete encrypted content. This can be done in Reporting Services Configuration Manager as well. </span><br />
<br />
<span style="font-family: "verdana" , sans-serif;">After 3 error messages, Reporting is running fine on SQL Server 2014 SP2. </span><span style="font-family: "verdana" , sans-serif;">Now it's time to start the ConfigMgr upgrade finally :-)</span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-59070352985259724752016-11-01T21:58:00.000+01:002016-11-04T09:44:40.604+01:00SMS EXECUTIVE starting SMS OFFLINE SERVICING MANAGER automatically<span style="font-family: "verdana" , sans-serif;">Last days there is something really strange going on with Offline Servicing in ConfigMgr. The task "SMS EXECUTIVE started SMS OFFLINE SERVICING MANAGER" is running multiple times a day normally, with "This Schedule with ID does not have a next run time" as a result. Last days however I saw at two different environments that Offline Servicing is kicking off automatically on multiple images, leaving them in an error message, not cleaning up the ConfigMgr OfflineImageServicing folder afterwards. Let's have a look at some screenshots created.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-uh4EU36AyQI/WBj9nOOBn9I/AAAAAAAAFGc/F8TTIdIwd3E2WPLUW6Pyp2dif7Kd6ZaZQCLcB/s1600/Capture01.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" src="https://4.bp.blogspot.com/-uh4EU36AyQI/WBj9nOOBn9I/AAAAAAAAFGc/F8TTIdIwd3E2WPLUW6Pyp2dif7Kd6ZaZQCLcB/s1600/Capture01.png" /></a></div>
<span style="font-family: "verdana" , sans-serif;">It's all starting with the following messages in the ConfigMgr console! (Failed to apply one or more updates)</span><br />
<span style="font-family: "verdana";"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-5kApFVwWRP4/WBj94-z4hXI/AAAAAAAAFGk/IihEKoj1s_w_cvMsyRVdzKNk1HFdqzdTACEw/s1600/Capture02.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="63" src="https://4.bp.blogspot.com/-5kApFVwWRP4/WBj94-z4hXI/AAAAAAAAFGk/IihEKoj1s_w_cvMsyRVdzKNk1HFdqzdTACEw/s320/Capture02.JPG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">Looking in OfflineServicingMgr.log you see that multiple tasks are scheduled with dates from many months ago. </span><span style="font-family: "verdana";">The schedule with ID will be run now. It's run time is at (some date in past).</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-UIVhEa5IA1Q/WBj9qmL-nII/AAAAAAAAFGg/2hmJEI2J6PwZ5ufeVInbZMBBn4jUSewHgCEw/s1600/Capture01.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="180" src="https://1.bp.blogspot.com/-UIVhEa5IA1Q/WBj9qmL-nII/AAAAAAAAFGg/2hmJEI2J6PwZ5ufeVInbZMBBn4jUSewHgCEw/s320/Capture01.JPG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">In another environment you see the same behavior, where schedules are running multiple times on the same image too. </span><span style="font-family: "verdana";">When you look closely you see a task running six times on the same image.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-TBRcAsLo7zk/WBj-RuyfuLI/AAAAAAAAFGo/BwVoa3svk3gWMWA9NDHve7A7ffR2hAxngCLcB/s1600/Capture02.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="114" src="https://2.bp.blogspot.com/-TBRcAsLo7zk/WBj-RuyfuLI/AAAAAAAAFGo/BwVoa3svk3gWMWA9NDHve7A7ffR2hAxngCLcB/s320/Capture02.png" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">Because of multiple errors during the process, files and folders are not removed, leaving them in a unwanted state afterwards. Where this folder has (in my case) around 73.000 files in 14.000 folders, with almost 12GB in size. (with wrong ownership too)</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-d5BvbRXGKRw/WBj_B3tXCjI/AAAAAAAAFG0/WDCXDkGynz4-X1cLWz_vutz4hx_PT_8hACLcB/s1600/Capture03.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="67" src="https://2.bp.blogspot.com/-d5BvbRXGKRw/WBj_B3tXCjI/AAAAAAAAFG0/WDCXDkGynz4-X1cLWz_vutz4hx_PT_8hACLcB/s320/Capture03.JPG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;"><u>Some of the error messages are:</u></span><br />
<span style="font-family: "verdana" , sans-serif;">-Image UnMount failed with error 31<br />-Deleting file </span><span style="font-family: "verdana" , sans-serif;">\\?\D:\ConfigMgr_OfflineImageServicing\<ID>\ImageMountDir\Program</span><span style="font-family: "verdana" , sans-serif;"> Files\Common Files\microsoft shared\DAO\dao360.dll, FAILED, Win32 Error = 5<br />-Failed to remove previously existing staging folder -D:\ConfigMgr_OfflineImageServicing\<ID>, GLE = 5<br />-Initialization of schedule processing failed<br />-Schedule processing failed</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Hope someone can explain why this is happening on almost same time in totally different environments, where there's no schedule set on OS images? Both environments are running on ConfigMgr Current Branch, version 1606 with all hotfixes available installed. Will be continued.. (and posted at Microsoft bugs or suggestions too)</span><br />
<span style="font-family: Verdana;"></span><br />
<span style="font-family: Verdana;"><strong>Update:</strong> Both tasks mentioned started at Sunday October 30th. One at 5:00 AM, the other at 23:00 AM (both UTC+01:00). Still nothing heard about other issues so far..</span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-52396715837251426282016-10-28T13:51:00.000+02:002016-10-28T13:51:03.103+02:00Highlights from the Microsoft Windows 10 devices event (2016)<span style="font-family: Verdana, sans-serif;">This week (October 26th) the second Windows 10 devices event is shown. Last year it was all about Xbox, Hololens, Band 2, Lumia 950 (XL) and Surface. Where both Surface Pro 4 and Surface Book where shown. Pity Surface Book still isn't available everywhere yet, but hope the product will become at later time (in The Netherlands). </span><br />
<span style="font-family: "verdana";"></span><span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"></span><br /></span>
<span style="font-family: Verdana, sans-serif;">Let's have a look at #Windows10 and #Windows10devices again!</span><br />
<span style="font-family: Verdana;"><br /></span>
<div class="separator" style="clear: both; text-align: center;">
<a href="https://3.bp.blogspot.com/-iRDSWjCLWEA/WBM65WyBxNI/AAAAAAAAFFo/PB-3MB5ZYEIwqohFugoD9nOaTsj4eBiMwCEw/s1600/naamloos.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="213" src="https://3.bp.blogspot.com/-iRDSWjCLWEA/WBM65WyBxNI/AAAAAAAAFFo/PB-3MB5ZYEIwqohFugoD9nOaTsj4eBiMwCEw/s320/naamloos.png" width="320" /></a></div>
<span style="font-family: "verdana";"><div class="separator" style="clear: both; text-align: center;">
<br /></div>
</span><span style="font-family: Verdana, sans-serif;"><u>Windows 10</u></span><br />
<span style="font-family: Verdana, sans-serif;">-Windows 10 Creators Update (coming early 2017)<br />-This week early build release for all Windows insiders<br />-Coming to more then 400M Windows 10 devices<br />-Bringing 3D for everyone & 4K gaming</span><br />
<span style="font-family: Verdana, sans-serif;">-Paint 3D (Within Windows 10 Creators Update)</span><br />
<span style="font-family: Verdana, sans-serif;">-3D animations brings MS PowerPoint to life</span><br />
<span style="font-family: Verdana, sans-serif;">-Connect and share easily with people who matter most</span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"></span><br /></span>
<span style="font-family: Verdana, sans-serif;"><u>Xbox One S</u></span><br />
<span style="font-family: Verdana, sans-serif;">-Game broadcasting for Windows 10<br />-Creating custom tournaments yourself<br />-Dolby Atmos on Xbox One with Windows 10 Creators Update</span><br />
<span style="font-family: Verdana, sans-serif;">-4K gaming and watching movies (Netflix?)</span><br />
<div>
<br /></div>
<div class="separator" style="clear: both; text-align: center;">
<a href="https://3.bp.blogspot.com/-XWi9cut7Juk/WBM61RZ95aI/AAAAAAAAFFk/Y4okxS1yZ_sBNgjdYo25rn1eCy6ZksrFACEw/s1600/SurfaceHome_2_HeroFullBleedPanel_en_V2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="179" src="https://3.bp.blogspot.com/-XWi9cut7Juk/WBM61RZ95aI/AAAAAAAAFFk/Y4okxS1yZ_sBNgjdYo25rn1eCy6ZksrFACEw/s320/SurfaceHome_2_HeroFullBleedPanel_en_V2.jpg" width="320" /></a></div>
<span style="font-family: "verdana";"><div>
<br /></div>
</span><span style="font-family: Verdana, sans-serif;"><u>Surface Book</u></span><br />
<span style="font-family: Verdana, sans-serif;">-Has the highest user satisfaction among any current Windows 10 machine out there or any MacBook, all of them.<br />-The ultimate laptop, but people want even more...<br />-New Surface Book i7 with more power on CPU/GPU and 30% more battery life (16 hours in total)<br />-Available in November for $2,399</span><br />
<div class="separator" style="clear: both; text-align: center;">
</div>
<span style="font-family: "verdana";"><br /></span>
<span style="font-family: Verdana, sans-serif;"><u>Surface Studio</u></span><br />
<span style="font-family: Verdana, sans-serif;">-Thinnest LCD monitor ever built (12.5mm thin touch screen)<br />-28" PixelSense Display, 13.5 million pixels, TrueColor, DCI-P3, 3:2 aspect ratio, 192 PPI, True Scale</span><br />
<span style="font-family: Verdana, sans-serif;">-i5/i7 Intel CPU, Up to 4GB NVIDIA GeForce GPU, Up to 32GB RAM<br />-Mic array, Cortana, HD camera, Windows Hello<br />-Pre-order today $2,999</span><br />
<div>
<br /></div>
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-JmWY0h9Gm2A/WBM6wcqdaAI/AAAAAAAAFFg/hvs6b-NqbWcf_86bCOT_mYrCPU-f15CJACLcB/s1600/surface-dial_0.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="180" src="https://2.bp.blogspot.com/-JmWY0h9Gm2A/WBM6wcqdaAI/AAAAAAAAFFg/hvs6b-NqbWcf_86bCOT_mYrCPU-f15CJACLcB/s320/surface-dial_0.jpg" width="320" /></a></div>
<span style="font-family: "verdana";"><div class="separator" style="clear: both; text-align: center;">
<br /></div>
</span><span style="font-family: "verdana";"><u><span style="font-family: Verdana, sans-serif;">Surface Dial</span></u><br /><span style="font-family: Verdana, sans-serif;">-A new tool for the creative process</span></span><br />
<span style="font-family: Verdana, sans-serif;">-Available for Surface Pro 3/4 & Surface Book</span><br />
<span style="font-family: Verdana, sans-serif;">-Not included with Surface Studio (additional $100)</span><br />
<div>
<br /></div>
<div>
<span style="font-family: Verdana, sans-serif;">So yes, Windows 10 Creators Update on Surface Book and Surface Studio looks great, but no surprises like last year. No news on Band and Lumia at all, where customers are not sure what Microsoft is doing here. Microsoft will probably pull the plug and ending sales by the end of this year. Instead of Lumia devices, Microsoft will announce Surface Phone for business purpose (expected late 2017).</span></div>
<span style="font-family: "verdana";"><div>
<br /></div>
</span><span style="font-family: Verdana, sans-serif;">No Surface Phone, no Surface Book 2, no Band 3, or anything else. </span><span style="font-family: Verdana, sans-serif;">It's a pity :-)</span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"></span><br /></span>
<span style="font-family: Verdana, sans-serif;"><a href="http://henkhoogendoorn.blogspot.nl/2015/10/highlights-from-microsoft-windows-10.html" target="_blank">Highlights from last year (2015)</a></span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-2650724887221940152016-10-19T21:51:00.000+02:002016-10-24T11:00:13.833+02:00New ConfigMgr Current Branch features from 1511 till now! (part 2)<span style="font-family: Verdana, sans-serif;">Since December 8, 2015 ConfigMgr Current Branch is Generally Available. This based on version 1511, which stands for November 2015 (MMYY). Since this release (and even before that too), there are monthly features added in Technical Preview, which are merged in public release (1602, 1606). Let's have a look at new features so far. When available this blogpost will be updated with new releases.</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;">Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Really love the speed on new builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;">New features in production so far:</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;"><strong>[1610]</strong></span><br />
<span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Deny previously approved application requests:</span></strong><br />As an administrator you can deny a previously approved application request. To install this application later, users must resubmit a request. This does not uninstall the application.</span><br />
<span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Exclude clients from automatic upgrade:</span></strong><br />When you configure settings to control how clients automatically upgrade you can now specify a collection to exclude specific clients from the upgrade. This applies to automatic upgrade as well as other methods such as software update-based upgrade. This can be used for a collection of computers that need greater care when upgrading the client.</span><br />
<span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Filter by content size in automatic deployment rules:</span></strong><br />Use the content size filter in automatic deployment rules to prevent large software updates from automatically downloading to better support simplified Windows down-level servicing when network bandwidth is limited.</span><br />
<span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Improvements to the notification experience for high-impact task sequence and required application deployments:</span></strong><br />Task sequence deployments that have a high-impact to the end user, for example operating system deployments, now display more intrusive notifications. However, end users can dismiss (snooze) these notifications, and control when they reappear. Any relevant client settings for notification frequency are still honored.</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;"><strong>[1609]</strong></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Android, iOS, and Windows Additional Settings:</span></strong><br />New settings have been added for Android, iOS, and Windows.</span></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Boundary Group Improvements:</span></strong><br />Improvements have been made to boundary groups to allow more granular control of fallback behavior, and greater clarity of what distribution points are used.</span></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Deploy Office 365 apps to clients:</span></strong><br />We have added a new Office 365 Servicing node in the Software Library where you can deploy Office 365 apps to clients.</span></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Improvements for BIOS to UEFI conversion:</span></strong><br />An OS deployment task sequence can now be customized with a new variable, TSUEFIDrive, so that the Restart Computer step will prepare the drive for transition to UEFI. See the documentation for additional details on the necessary customizations.</span></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Intune Compliance Charts:</span></strong><br />Administrators can get a quick view of overall compliance, and top reasons for non-compliance using new charts under Monitoring.</span></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Native Connection Types for Windows 10 VPN Profiles:</span></strong><br />You can now create Windows 10 VPN profiles with Microsoft Automatic, IKEv2, and PPTP connection types in the Configuration Manager console without using OMA-URI.</span></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Office 365 Servicing Dashboard:</span></strong><br />Use the Office 365 servicing dashboard to track Office 365 updates and deployments.</span></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">TouchID, ApplePay and Zoom DEP Settings:</span></strong><br />DEP provides the ability for admins to create enrollment profiles to skip initial setup screens for new iOS devices. TouchID, ApplePay and Zoom have now been added as options to configure in the iOS enrollment profiles.</span></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Windows 10 Upgrade Analytics:</span></strong><br />Assess and analyze device readiness and compatibility with Windows 10 to allow smoother upgrades. This is done through integration with Windows Upgrade Analytics. </span></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Windows Store for Business:</span></strong><br />Windows Store for Business allows administrators to obtain applications (purchased or free) and deploy them to users in their organization.</span></span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;"><strong>[1608]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Application Requests from Software Center:</span></strong><br />Users are now able to request approval for applications and view the request history for applications in the Application Details view in Software Center. The Request button in Application Details no longer redirects to the web-based Application Catalog.</span></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Improvements to Asset Intelligence:</span></strong><br />In the Configuration Manager 1608 Technical Preview, we have added a field to the properties for inventoried software that lets you set a parent and child relationship with other software. In the Inventoried Software list, you can view the parent of any software and also hide all child software.</span></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">New Software Indicators in Software Center:</span></strong><br />The Software Center Applications, Updates, and Operating Systems tabs now show what software was recently added. Numbers in the navigation pane show how many new pieces of software are in each tab.</span></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Remote Control Keyboard Translation:</span></strong><br />In a remote control session, keys typed are now mapped by default to the sharer's keyboard when the keyboard languages do not match, so that the viewer is able to type normally. This behavior may be turned off in the Remote Control viewer Action menu.</span></span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<strong><span style="font-family: Verdana, sans-serif;">[1607]</span></strong><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Customizable Branding for End-User Dialogs:</span></strong><br />End-user dialogs that are opened from Software Center or taskbar notifications now show the same organization name, color and icon branding as Software Center. The administrator workflow for specifying branding settings remains unchanged.</span></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Manage duplicate hardware identifiers:</span></strong><br />Add known duplicate MAC addresses or SMBIOS IDs to be ignored hierarchy-wide for PXE boot and client registration.</span></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Microsoft Operations Management Suite (OMS) Connector:</span></strong><br />Sync data such as collections from ConfigMgr to OMS.</span></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: Verdana, sans-serif;"><strong><span style="color: blue;">Windows 10 Edition Upgrade:</span></strong><br />Upgrade Configuration Manager clients running Windows 10 Professional edition to Windows 10 Enterprise edition with just a product key; no reimaging required.</span></span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;">Part 1 of this series can be found </span><a href="http://henkhoogendoorn.blogspot.nl/2016/10/new-configmgr-current-branch-features.html" target="_blank"><strong><span style="font-family: Verdana, sans-serif;">HERE</span></strong></a><span style="font-family: Verdana, sans-serif;">.</span></span><br />
<span style="font-family: Verdana, sans-serif;"><span style="font-family: "verdana";">Will be updated with further 2016 updates!</span> </span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-63819004058037242422016-10-13T19:23:00.000+02:002016-10-13T19:29:47.332+02:00New servicing branch: Long-Term Servicing Branch (LTSB) of Configuration Manager<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">Yesterday a new announcement has been done. There is a new servicing branch called: Long-Term Servicing Branch (LTSB) of Configuration Manager. Where ConfigMgr Current Branch offers new functionality and support for Windows 10 and Windows Server 2016, LTSB of Configuration Manager is not. When Software Assurance (SA) or equivalent subscription rights became expired, customers, per product terms, would have to move back to ConfigMgr 2012 (R2). </span><span style="font-family: "verdana" , sans-serif;">Besides of support for an fixed 10-year lifecycle (and equivalent subscription rights as mentioned), I guess there is no need to use the LTSB version of Configuration Manager.</span></span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">While the LTSB is derived from the current branch of Configuration Manager (version 1606), it is scaled back and reduced in functionality to permit the extended support model. LTSB of Configuration Manager will not receive new functionality or support for new Windows 10 and Windows Server 2016. It will continue to receive security updates only. By design, LTSB of Configuration Manager is intended to be fixed in functionality and very infrequently updated, so any features or components that require continuous updating or are tied to a cloud service have been removed. What's left is ConfigMgr 2012 (R2) with less features and no Hybrid MDM.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><u>These removed features include:</u><br />-Support for Windows 10 Current Branch (CB) and Current Branch for Business (CBB)<br />-Support for the future releases of Windows 10 LTSB and Windows Server<br />-Windows 10 Servicing Dashboard and Servicing Plans<br />-The ability to add a Microsoft Intune Subscription, which prevents the use of Hybrid MDM and on-premises MDM<br />-Asset Intelligence<br />-Cloud-based Distribution Point<br />-Support for Exchange Online as an Exchange Connector<br />-Any pre-release features available in the current branch of Configuration Manager</span><br />
<br />
<span style="font-family: Verdana;">Not my cup of tea :-)</span><br />
<span style="font-family: "verdana";">Source: <a href="https://blogs.technet.microsoft.com/enterprisemobility/2016/10/12/configuration-manager-a-progress-update-on-the-current-branch-and-a-new-servicing-branch/" target="_blank">Enterprise Mobility and Security Blog</a></span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-82207585675617613032016-10-13T12:09:00.001+02:002016-10-13T12:27:58.280+02:00System Center 2016 and Windows Server 2016 available for download now!<span style="font-family: "verdana" , sans-serif;">As for today System Center 2016 and Windows Server 2016 bits are available for download. Strange that Microsoft decided to announce General Availability (GA) during </span><a href="http://henkhoogendoorn.blogspot.nl/2016/10/my-findings-on-microsoft-ignite-2016_4.html" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">Microsoft Ignite</span></strong></a><span style="font-family: "verdana" , sans-serif;">, and publish bits two weeks later for download? </span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-9QsOq0q_u4k/V_9QdKc4VEI/AAAAAAAAFEM/MK3AzoIGrGAE3kYS0Q1_-vASPCujHjkFwCEw/s1600/Capture.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="96" src="https://2.bp.blogspot.com/-9QsOq0q_u4k/V_9QdKc4VEI/AAAAAAAAFEM/MK3AzoIGrGAE3kYS0Q1_-vASPCujHjkFwCEw/s320/Capture.JPG" width="320" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Within System Center 2016, the 1606 version of Configuration Manager is included. Customers still on ConfigMgr 2012 (R2) can upgrade directly to 1606 now. No need to upgrade to 1511 (RTM) first and upgrade to 1606 afterwards.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"><tbody>
<tr><td style="text-align: center;"><a href="https://1.bp.blogspot.com/-ObunEad0gvo/V_9WuU-F9ZI/AAAAAAAAFEY/Wld_b_4loiw3q53nYRSqTm5BLvUbxz1bACLcB/s1600/Capture2.JPG" imageanchor="1" style="margin-left: auto; margin-right: auto;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="297" src="https://1.bp.blogspot.com/-ObunEad0gvo/V_9WuU-F9ZI/AAAAAAAAFEY/Wld_b_4loiw3q53nYRSqTm5BLvUbxz1bACLcB/s320/Capture2.JPG" width="320" /></span></a></td></tr>
<tr><td class="tr-caption" style="text-align: center;"><span style="font-family: "verdana" , sans-serif;">System Center 2016</span></td></tr>
</tbody></table>
<div class="separator" style="clear: both; text-align: center;">
<span style="font-family: "verdana" , sans-serif;"></span> </div>
<table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"><tbody>
<tr><td style="text-align: center;"><a href="https://3.bp.blogspot.com/-uLfTl8b8JE8/V_9Wx7scTJI/AAAAAAAAFEc/Hro_qMy_3v02MUwR1F-l6ngWlNjBwJG7gCLcB/s1600/Capture3.JPG" imageanchor="1" style="margin-left: auto; margin-right: auto;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="224" src="https://3.bp.blogspot.com/-uLfTl8b8JE8/V_9Wx7scTJI/AAAAAAAAFEc/Hro_qMy_3v02MUwR1F-l6ngWlNjBwJG7gCLcB/s320/Capture3.JPG" width="320" /></span></a></td></tr>
<tr><td class="tr-caption" style="text-align: center;"><span style="font-family: "verdana" , sans-serif;">Windows Server 2016</span></td></tr>
</tbody></table>
<a href="https://4.bp.blogspot.com/-9QsOq0q_u4k/V_9QdKc4VEI/AAAAAAAAFEI/4Nlm2zrOkPYzQYq0w6aYkYhD07Fnq68rwCLcB/s1600/Capture.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"></span></a><br />
<span style="font-family: "verdana" , sans-serif;">Just download the bits and happy upgrade! :-)</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<u><span style="font-family: "verdana" , sans-serif;">Microsoft Hybrid Cloud (12-10):</span></u><br />
<a href="https://blogs.technet.microsoft.com/hybridcloud/2016/10/12/another-big-step-in-hybrid-cloud-windows-server-2016-general-availability/" target="_blank"><span style="font-family: "verdana" , sans-serif;">Another big step in Hybrid Cloud – Windows Server 2016 general availability</span></a><br />
<span style="font-family: "verdana" , sans-serif;"><a href="https://blogs.technet.microsoft.com/hybridcloud/2016/10/12/managing-the-software-defined-datacenter-with-system-center-2016/" target="_blank">Managing the software-defined datacenter with System Center 2016</a></span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-2019526868650308812016-10-12T12:11:00.001+02:002016-10-12T12:44:13.445+02:00New ConfigMgr Current Branch features from 1511 till now! (part 1)<span style="font-family: "verdana" , sans-serif;">Since December 8, 2015 ConfigMgr Current Branch is Generally Available. This based on version 1511, which stands for November 2015 (MMYY). Since this release (and even before that too), there are monthly features added in Technical Preview, which are merged in public release (1602, 1606). Let's have a look at new features so far. When available this blogpost will be updated with new releases.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Really love the speed on new builds and update experience. </span><span style="font-family: "verdana" , sans-serif;">Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">New features in production so far:</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1606]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Cloud Proxy Service:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The Cloud Proxy Service provides a simple way to manage ConfigMgr clients on the Internet. The service, which is deployed to Microsoft Azure and requires an Azure subscription, connects to your on-premises ConfigMgr infrastructure using a new role called the cloud proxy connector point. You use the ConfigMgr console to deploy the service and configure the supported roles to allow cloud proxy traffic. Cloud Proxy Service currently only supports the management point, distribution point, and software update point roles.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Device Categories:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can create device categories, which can be used to automatically place devices in device collections when used in hybrid environments. Users are then required to choose a device category when they enroll a device in Intune.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Device Guard: ConfigMgr as a managed installer with manual client configuration:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Administrators can use the new Managed Installer AppLocker rules to configure clients so that ConfigMgr-deployed software is automatically trusted, but software from other sources is not. You cannot currently configure this functionality from the ConfigMgr console. Use the instructions at this blog post to manually configure client computers to use this functionality.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Enforcement grace period for application and software update deployments:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Give users a grace period to install required application or software updates beyond any deadlines you configured after their computers are offline for an extended period of time.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Multiple device management points available for enrolled Windows 10 Anniversary Edition devices:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">On-premises Mobile Device Management (MDM) supports a new capability in Windows 10 Anniversary Edition (Redstone 1) that automatically configures an enrolled device to have more than one device management point available for use. This capability allows the device to fallback to another device management point when the one it was using is not available.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">You can deploy offline-licensed applications to a Windows 10 desktop PC managed by on-premises MDM:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can deploy an app with an offline license from the Windows Store for Business to a Windows 10 PC managed by on-premises MDM.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1605]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Auto-Connect App List in Windows 10 VPN Profiles:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Admins can specify desktop and universal applications in Windows 10 VPN profiles that automatically establish a connection with the VPN when launched on the client. Admins can decide whether or not to limit VPN traffic to the apps in the list.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Improvements to the Install Software Updates task sequence step:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">This release includes improvements to smsts.log to help you troubleshoot, and a new task sequence variable, SMSTSSoftwareUpdateScanTimeout, to control the timeout on the software updates scan during the Install Software Updates task sequence step.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">New tabs for Updates and Operating Systems in Software Center:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Software Updates and Operating Systems now have their own respective tabs in Software Center, rather than being accessible via the categories dropdown in the Applications tab.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">On-premises Health Attestation Service integration:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Collect Health Attestation information via on-premises Health Attestation Service with a few critical bug fixes from 1604 Technical Preview.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Pre-Declare Corporate Owned Devices:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can now identify corporate-owned devices by importing their international station mobile equipment identity (IMEI) numbers. You can upload a comma-separated values (.csv) file containing device IMEI numbers or you can manually enter device information. You can also import serial numbers for iOS devices. Imported information will set ownership of the devices that enroll as “Corporate”. An Intune license is still required for each user that accesses the service. View a video walkthrough of the Pre-declare Corporate Owned Devices feature.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Remote Device Actions Experience Update:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The admin experience for wiping, resetting the passcode, remote locking, and bypassing iOS Activation Lock on mobile devices has been adjusted. The states of these actions are now part of the devices' details and properties.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Remote Full Wipe for Windows 10 desktop devices:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Support for remotely wiping and resetting Windows 10 desktop devices to factory settings.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Server groups:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Control settings for software updates in server groups, including the order and percentage of devices that can be updated at any one time. These capabilities introduce some enhancements over our pre-release "Servicing a cluster aware collection" feature, including the ability to control the order and better monitoring.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Enterprise Data Protection policies:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Enterprise data protection (EDP) policy settings - with this technical preview, you can create and deploy EDP policies for Windows devices running Windows 10 Insider Preview and Windows 10 Mobile Preview builds, including specifying apps, defining network boundaries, choosing the restriction modes and other EDP settings.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows Defender Advanced Threat Protection:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Manage Windows Defender Advanced Threat Protection policies for onboarding and offboarding Windows 10 clients to the cloud service, and view agent health in the monitoring dashboard. (Requires a Windows Defender ATP tenant in Azure.)</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows Store for Business Integration:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">ConfigMgr can manage and deploy applications purchased through the Windows Store for Business portal for both online and offline licensed apps. The 1605 Technical Preview adds the ability to create both online and offline apps with the ability to deploy offline apps to Intune and ConfigrMgr managed devices. View video walkthroughs of how to set up and deploy Windows Store for Business apps.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1604]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Client cache size:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">We added a new item to Client Settings called "Client Cache Settings". Use this to configure the client cache size as a percentage of overall disk space and megabytes.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Client Peer Cache:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">A built-in ConfigMgr solution for clients to share content with other clients, directly from their local Cache with monitoring and troubleshooting capabilities.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Passport for Work:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Administrators can now deploy Passport for Work policies to domain-joined Windows 10 devices managed by the ConfigMgr client.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Policy Setting to Disable Smart Lock and other Trust Agents:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Hybrid administrators can now deploy a policy in the ConfigMgr console that disables Smart Lock and other trust agents from being used to circumvent passcode policy on devices running Android 5.0 or higher.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Software Updates Compliance Dashboard:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The Software Updates Dashboard continues our commitment to helping you keep your devices up to date with the latest security updates and Windows features. The dashboard allows you to view the current compliance status of devices in your organization and quickly analyze the data to see which devices are at risk.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Switch Software Update Point:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Administrators will be able to switch Software Update Points for clients when there are multiple SUPs available on a primary site. Administrators should use this option when clients are failing SUM scenarios due to SUP/WSUS issues on their assigned SUP. When administrators switch SUPs for a collection of clients, the selected clients will look for another SUP at the next scan interval. To try out this change go to the Asset and Compliance tab -> Device Collections -> and in the context menu of a device collection click on "Switch to Next Software Update Point".</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">VPN for Windows 10:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can use 3rd party VPN providers for computers with the ConfigMgr client. These include Pulse Secure, F5 Edge, Dell SonicWall and Checkpoint.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1603]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">List View for Applications in Software Center:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">In the Software Center Applications tab, users now have the option to switch between the default tile view and a new list view by clicking on the view selection icons underneath the search bar.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Install Selected Updates in Software Center:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">In the new Updates tab in Software Center, click on the select mode button at the top left of the list of updates. In select mode, multiple updates may be selected and then simultaneously installed using the Install Selected button.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Content Status links in the Admin Console:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The Content Status links for objects like applications, packages, task sequences or software updates, now go directly to the related Content Status object node.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">PXE Provider TFTP Window Size:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The administrator can now configure the TFTP window size (RamDiskTFTPWindowSize) via a registry setting on the PXE-enabled distribution point.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Limit access to the Clipboard in Remote Control Sessions:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can now enable the remote tools client setting "Prompt user for shared clipboard file transfer permission" to limit access to the shared clipboard in a remote control session. When enabled, the end-user who is sharing a remote session must grant permissions to the viewer of that session before they can transfer files from the shared clipboard.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1602]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Support for in-place upgrade of ConfigMgr Site Server's operating system:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">In-place upgrade of the ConfigMgr's Site Server's operating system from Windows Server 2008 R2 to Windows Server 2012 R2 is now supported.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Sync Policy button in Software Center:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The new Sync Policy button helps you keep machine and user policies in sync. The button is available through the Software Center options tab, under Computer Maintenance.</span><br />
<span style="font-family: "verdana" , sans-serif;"><strong><span style="font-family: "verdana" , sans-serif;"><span style="color: blue;">Automatic creation of Microsoft Office mobile apps for iOS and Android:</span> </span></strong></span><br />
<span style="font-family: "verdana" , sans-serif;">Microsoft Office mobile apps for iOS and Android are pre-created for users using ConfigMgr integrated with Microsoft Intune.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">iOS Activation Lock management:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">iOS Activation Lock management capabilities include: enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1601]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Team configuration settings:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">New configuration settings added and supported for Windows 10 Team when using either Intune managed (hybrid) devices, or ConfigMgr full client devices.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Microsoft Edge configuration settings:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Specify Windows 10 Edge settings and assign them to users or devices in their organization.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Conditional Access new compliance checks:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Set 3 new compliance checks: require a password to unlock an idle device, time until the device is locked, and require automatic updates with minimum classification. These policy rules are evaluated as part of overall device compliance.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Conditional Access with Health Attestation service:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">For Intune managed devices, Windows 10 Health Attestation data can be used as part of device compliance when used with Conditional Access.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Device Compliance report:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Device Compliance report provides you the number and percentage of devices and their compliance state for each compliance policy.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Health Attestation service reports:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Users can view reports on Windows 10 Health Attestation data collected by Intune. Windows 10 device Health Attestation helps evaluate the vulnerability of Windows 10 desktop and mobile devices.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Kiosk mode for Samsung KNOX devices:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">ConfigMgr kiosk mode allows you to lock a managed mobile device only to allow certain features. For example, you can allow a device only to run a specific managed app, or you can disable the device's volume buttons.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Client Online Status:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">View the online status of devices in Assets and Compliance. New icons indicate the status of a device as online or offline.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Conditional Access for ConfigMgr Managed PCs:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">To help secure Office 365 access and other services on PCs enrolled with ConfigMgr, use Conditional Access. Conditions that can be used to control access include: Workplace Join, BitLocker, Antimalware, and Software Updates.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">On-Premises Exchange Default Rule Override:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Set a default on-premises Exchange rule to block mobile devices from accessing email. You can allow Intune-enrolled and compliant mobile devices to access mail. You can also choose to override the default Exchange rule to allow Intune-enrolled and compliant devices to access email, even when the default rule is set to Block or Quarantine.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">iOS App Configuration:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Create and deploy iOS app configuration policies to dynamically change settings such as server name or port for iOS applications that support configuration.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Apple Volume Purchase Program:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">ConfigMgr can manage and deploy applications purchased through the Apple Volume Purchase Program for Business portal.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1512]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">New antimalware policy settings:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Added settings for protection against Potentially Unwanted Applications, user control of automatic sample submission, and scanning of network drives during a full scan.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Device Health Attestation:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Users are able to view the status of Windows 10 Device Health Attestation in the ConfigMgr console, to ensure that client computers have trustworthy BIOS, TPM, and boot software.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">User acceptance of Terms and Conditions:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Users who use ConfigMgr integrated with Intune (hybrid) can view which users have accepted the Terms and Conditions configured by IT and which users have not, right from the ConfigMgr console.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Will be continued in a next blogpost!</span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-34930338541156945722016-10-12T12:11:00.000+02:002016-10-12T12:43:01.080+02:00New ConfigMgr Current Branch features from 1511 till now! (part 1)<span style="font-family: "verdana" , sans-serif;">Since December 8, 2015 ConfigMgr Current Branch is Generally Available. This based on version 1511, which stands for November 2015 (MMYY). Since this release (and even before that too), there are monthly features added in Technical Preview, which are merged in public release (1602, 1606). Let's have a look at new features so far. When available this blogpost will be updated with new releases.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Really love the speed on new (Windows and ConfigMgr) builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Let's have a look at new features (in production) so far:</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1606]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Cloud Proxy Service:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The Cloud Proxy Service provides a simple way to manage ConfigMgr clients on the Internet. The service, which is deployed to Microsoft Azure and requires an Azure subscription, connects to your on-premises ConfigMgr infrastructure using a new role called the cloud proxy connector point. You use the ConfigMgr console to deploy the service and configure the supported roles to allow cloud proxy traffic. Cloud Proxy Service currently only supports the management point, distribution point, and software update point roles.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Device Categories:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can create device categories, which can be used to automatically place devices in device collections when used in hybrid environments. Users are then required to choose a device category when they enroll a device in Intune.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Device Guard: ConfigMgr as a managed installer with manual client configuration:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Administrators can use the new Managed Installer AppLocker rules to configure clients so that ConfigMgr-deployed software is automatically trusted, but software from other sources is not. You cannot currently configure this functionality from the ConfigMgr console. Use the instructions at this blog post to manually configure client computers to use this functionality.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Enforcement grace period for application and software update deployments:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Give users a grace period to install required application or software updates beyond any deadlines you configured after their computers are offline for an extended period of time.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Multiple device management points available for enrolled Windows 10 Anniversary Edition devices:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">On-premises Mobile Device Management (MDM) supports a new capability in Windows 10 Anniversary Edition (Redstone 1) that automatically configures an enrolled device to have more than one device management point available for use. This capability allows the device to fallback to another device management point when the one it was using is not available.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">You can deploy offline-licensed applications to a Windows 10 desktop PC managed by on-premises MDM:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can deploy an app with an offline license from the Windows Store for Business to a Windows 10 PC managed by on-premises MDM.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1605]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Auto-Connect App List in Windows 10 VPN Profiles:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Admins can specify desktop and universal applications in Windows 10 VPN profiles that automatically establish a connection with the VPN when launched on the client. Admins can decide whether or not to limit VPN traffic to the apps in the list.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Improvements to the Install Software Updates task sequence step:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">This release includes improvements to smsts.log to help you troubleshoot, and a new task sequence variable, SMSTSSoftwareUpdateScanTimeout, to control the timeout on the software updates scan during the Install Software Updates task sequence step.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">New tabs for Updates and Operating Systems in Software Center:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Software Updates and Operating Systems now have their own respective tabs in Software Center, rather than being accessible via the categories dropdown in the Applications tab.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">On-premises Health Attestation Service integration:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Collect Health Attestation information via on-premises Health Attestation Service with a few critical bug fixes from 1604 Technical Preview.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Pre-Declare Corporate Owned Devices:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can now identify corporate-owned devices by importing their international station mobile equipment identity (IMEI) numbers. You can upload a comma-separated values (.csv) file containing device IMEI numbers or you can manually enter device information. You can also import serial numbers for iOS devices. Imported information will set ownership of the devices that enroll as “Corporate”. An Intune license is still required for each user that accesses the service. View a video walkthrough of the Pre-declare Corporate Owned Devices feature.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Remote Device Actions Experience Update:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The admin experience for wiping, resetting the passcode, remote locking, and bypassing iOS Activation Lock on mobile devices has been adjusted. The states of these actions are now part of the devices' details and properties.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Remote Full Wipe for Windows 10 desktop devices:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Support for remotely wiping and resetting Windows 10 desktop devices to factory settings.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Server groups:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Control settings for software updates in server groups, including the order and percentage of devices that can be updated at any one time. These capabilities introduce some enhancements over our pre-release "Servicing a cluster aware collection" feature, including the ability to control the order and better monitoring.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Enterprise Data Protection policies:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Enterprise data protection (EDP) policy settings - with this technical preview, you can create and deploy EDP policies for Windows devices running Windows 10 Insider Preview and Windows 10 Mobile Preview builds, including specifying apps, defining network boundaries, choosing the restriction modes and other EDP settings.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows Defender Advanced Threat Protection:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Manage Windows Defender Advanced Threat Protection policies for onboarding and offboarding Windows 10 clients to the cloud service, and view agent health in the monitoring dashboard. (Requires a Windows Defender ATP tenant in Azure.)</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows Store for Business Integration:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">ConfigMgr can manage and deploy applications purchased through the Windows Store for Business portal for both online and offline licensed apps. The 1605 Technical Preview adds the ability to create both online and offline apps with the ability to deploy offline apps to Intune and ConfigrMgr managed devices. View video walkthroughs of how to set up and deploy Windows Store for Business apps.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1604]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Client cache size:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">We added a new item to Client Settings called "Client Cache Settings". Use this to configure the client cache size as a percentage of overall disk space and megabytes.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Client Peer Cache:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">A built-in ConfigMgr solution for clients to share content with other clients, directly from their local Cache with monitoring and troubleshooting capabilities.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Passport for Work:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Administrators can now deploy Passport for Work policies to domain-joined Windows 10 devices managed by the ConfigMgr client.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Policy Setting to Disable Smart Lock and other Trust Agents:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Hybrid administrators can now deploy a policy in the ConfigMgr console that disables Smart Lock and other trust agents from being used to circumvent passcode policy on devices running Android 5.0 or higher.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Software Updates Compliance Dashboard:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The Software Updates Dashboard continues our commitment to helping you keep your devices up to date with the latest security updates and Windows features. The dashboard allows you to view the current compliance status of devices in your organization and quickly analyze the data to see which devices are at risk.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Switch Software Update Point:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Administrators will be able to switch Software Update Points for clients when there are multiple SUPs available on a primary site. Administrators should use this option when clients are failing SUM scenarios due to SUP/WSUS issues on their assigned SUP. When administrators switch SUPs for a collection of clients, the selected clients will look for another SUP at the next scan interval. To try out this change go to the Asset and Compliance tab -> Device Collections -> and in the context menu of a device collection click on "Switch to Next Software Update Point".</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">VPN for Windows 10:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can use 3rd party VPN providers for computers with the ConfigMgr client. These include Pulse Secure, F5 Edge, Dell SonicWall and Checkpoint.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1603]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">List View for Applications in Software Center:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">In the Software Center Applications tab, users now have the option to switch between the default tile view and a new list view by clicking on the view selection icons underneath the search bar.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Install Selected Updates in Software Center:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">In the new Updates tab in Software Center, click on the select mode button at the top left of the list of updates. In select mode, multiple updates may be selected and then simultaneously installed using the Install Selected button.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Content Status links in the Admin Console:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The Content Status links for objects like applications, packages, task sequences or software updates, now go directly to the related Content Status object node.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">PXE Provider TFTP Window Size:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The administrator can now configure the TFTP window size (RamDiskTFTPWindowSize) via a registry setting on the PXE-enabled distribution point.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Limit access to the Clipboard in Remote Control Sessions:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">You can now enable the remote tools client setting "Prompt user for shared clipboard file transfer permission" to limit access to the shared clipboard in a remote control session. When enabled, the end-user who is sharing a remote session must grant permissions to the viewer of that session before they can transfer files from the shared clipboard.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1602]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Support for in-place upgrade of ConfigMgr Site Server's operating system:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">In-place upgrade of the ConfigMgr's Site Server's operating system from Windows Server 2008 R2 to Windows Server 2012 R2 is now supported.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Sync Policy button in Software Center:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">The new Sync Policy button helps you keep machine and user policies in sync. The button is available through the Software Center options tab, under Computer Maintenance.</span><br />
<span style="font-family: "verdana" , sans-serif;"><strong><span style="font-family: "verdana" , sans-serif;"><span style="color: blue;">Automatic creation of Microsoft Office mobile apps for iOS and Android:</span> </span></strong></span><br />
<span style="font-family: "verdana" , sans-serif;">Microsoft Office mobile apps for iOS and Android are pre-created for users using ConfigMgr integrated with Microsoft Intune.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">iOS Activation Lock management:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">iOS Activation Lock management capabilities include: enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1601]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Team configuration settings:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">New configuration settings added and supported for Windows 10 Team when using either Intune managed (hybrid) devices, or ConfigMgr full client devices.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Microsoft Edge configuration settings:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Specify Windows 10 Edge settings and assign them to users or devices in their organization.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Conditional Access new compliance checks:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Set 3 new compliance checks: require a password to unlock an idle device, time until the device is locked, and require automatic updates with minimum classification. These policy rules are evaluated as part of overall device compliance.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Conditional Access with Health Attestation service:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">For Intune managed devices, Windows 10 Health Attestation data can be used as part of device compliance when used with Conditional Access.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Device Compliance report:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Device Compliance report provides you the number and percentage of devices and their compliance state for each compliance policy.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Windows 10 Health Attestation service reports:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Users can view reports on Windows 10 Health Attestation data collected by Intune. Windows 10 device Health Attestation helps evaluate the vulnerability of Windows 10 desktop and mobile devices.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Kiosk mode for Samsung KNOX devices:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">ConfigMgr kiosk mode allows you to lock a managed mobile device only to allow certain features. For example, you can allow a device only to run a specific managed app, or you can disable the device's volume buttons.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Client Online Status:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">View the online status of devices in Assets and Compliance. New icons indicate the status of a device as online or offline.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Conditional Access for ConfigMgr Managed PCs:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">To help secure Office 365 access and other services on PCs enrolled with ConfigMgr, use Conditional Access. Conditions that can be used to control access include: Workplace Join, BitLocker, Antimalware, and Software Updates.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">On-Premises Exchange Default Rule Override:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Set a default on-premises Exchange rule to block mobile devices from accessing email. You can allow Intune-enrolled and compliant mobile devices to access mail. You can also choose to override the default Exchange rule to allow Intune-enrolled and compliant devices to access email, even when the default rule is set to Block or Quarantine.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">iOS App Configuration:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Create and deploy iOS app configuration policies to dynamically change settings such as server name or port for iOS applications that support configuration.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Apple Volume Purchase Program:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">ConfigMgr can manage and deploy applications purchased through the Apple Volume Purchase Program for Business portal.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><strong>[1512]</strong></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">New antimalware policy settings:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Added settings for protection against Potentially Unwanted Applications, user control of automatic sample submission, and scanning of network drives during a full scan.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">Device Health Attestation:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Users are able to view the status of Windows 10 Device Health Attestation in the ConfigMgr console, to ensure that client computers have trustworthy BIOS, TPM, and boot software.</span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><strong><span style="color: blue;">User acceptance of Terms and Conditions:</span></strong> </span></span><br />
<span style="font-family: "verdana" , sans-serif;">Users who use ConfigMgr integrated with Intune (hybrid) can view which users have accepted the Terms and Conditions configured by IT and which users have not, right from the ConfigMgr console.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Will be continued in a next blogpost!</span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-53497574139315237022016-10-10T21:45:00.001+02:002016-10-10T21:45:05.495+02:00What to do if App-V Sequencer is missing from Windows 10 ADK 1607<span style="font-family: Verdana, sans-serif;">When installing Windows 10 ADK 1607, the App-V Sequencer component may be missing. </span><span style="font-family: Verdana, sans-serif;">This depending on the Operating System you're installing Windows ADK on. When you need to install the App-V Sequencer from Windows 10 ADK 1607, make sure you install it on Windows 10 1607 as well. Otherwise use the Microsoft Desktop Optimization Pack (MDOP) Setup Media instead.</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-zD3k129DgM0/V_vuPQVQP3I/AAAAAAAAFDo/qTCMUAzkl-UQN3iz0CG73T2YlMPQF0sygCLcB/s1600/no-app-v-in-adk.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: Verdana, sans-serif;"><img border="0" height="235" src="https://4.bp.blogspot.com/-zD3k129DgM0/V_vuPQVQP3I/AAAAAAAAFDo/qTCMUAzkl-UQN3iz0CG73T2YlMPQF0sygCLcB/s320/no-app-v-in-adk.PNG" width="320" /></span></a></div>
<span style="font-family: Verdana, sans-serif;">When running on Windows 10 1511/1507, Windows 8.x, Windows 7 or Windows Server 2012 R2, App-V Sequencer is missing.</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://3.bp.blogspot.com/-Bp8kIk0JXyg/V_vumFpLbkI/AAAAAAAAFDw/E7UcphbNoIkJxN8wJVsZnMVsZcDNQJDJACLcB/s1600/app-v-in-adk.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: Verdana, sans-serif;"><img border="0" height="235" src="https://3.bp.blogspot.com/-Bp8kIk0JXyg/V_vumFpLbkI/AAAAAAAAFDw/E7UcphbNoIkJxN8wJVsZnMVsZcDNQJDJACLcB/s320/app-v-in-adk.png" width="320" /></span></a></div>
<span style="font-family: Verdana, sans-serif;">When running on Windows 1607, App-V Sequencer will be back again :-) Other components are available then as well.</span><br />
<span style="font-family: Verdana;"></span><br />
<span style="font-family: Verdana;">Hope it helps!</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: "verdana";"><span style="font-family: Verdana, sans-serif;">More on App-V in Windows 10 can be found here: </span><a href="http://henkhoogendoorn.blogspot.nl/2016/08/both-app-v-and-ue-v-integrated-in.html" target="_blank"><span style="color: purple; font-family: Verdana, sans-serif;">Both App-V and UE-V integrated in Windows 10 Enterprise now! </span></a></span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-18590394042926570492016-10-06T10:02:00.000+02:002016-10-06T10:02:24.609+02:00Enable the Upgrades classification in ConfigMgr Current Branch (again)<span style="font-family: "verdana" , sans-serif;">Recently I was troubleshooting an environment where Windows 10 upgrades didn't came in. I did check if hotfixes were installed, which was the situation indeed. </span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="https://support.microsoft.com/en-us/kb/3095113" target="_blank"><strong>KB3095113</strong></a>: Update to enable WSUS support for Windows 10 feature upgrades (Server 2012 and 2012R2)</span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="https://support.microsoft.com/en-us/kb/3127032" target="_blank"><strong>KB3127032</strong></a>: Windows 10 upgrades are not downloaded in System Center Configuration Manager (CM1511 only)</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://3.bp.blogspot.com/-0WoR1xRVVQQ/V9b7PnB78EI/AAAAAAAAE9w/eUK8_QVUD707w-SPh9cXt3YmUlaGOAddACLcB/s1600/2016-09-12_14-58-47.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="200" src="https://3.bp.blogspot.com/-0WoR1xRVVQQ/V9b7PnB78EI/AAAAAAAAE9w/eUK8_QVUD707w-SPh9cXt3YmUlaGOAddACLcB/s320/2016-09-12_14-58-47.png" width="320" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;">I decided to remove the Upgrade checkbox, too put it on at later time. Then a new pop-up was displayed: Additionally, to service Windows 10 Version 1607 and later, you must install and configure <a href="https://support.microsoft.com/en-us/kb/3159706" target="_blank"><strong>KB3159706</strong></a> using the guidance. Oops, I missed that one! Installed it a the WSUS/SUP and other Site server(s) and did have a look at additional steps too. This because of the following post on Microsoft TechNet: </span><a href="https://social.technet.microsoft.com/Forums/windows/en-US/59ad21be-7514-46df-adf3-fdf6ec15e132/wsus-breaks-after-kb3159706-released-552016?forum=winserverwsus" target="_blank"><span style="font-family: "verdana" , sans-serif;"><strong>WSUS Breaks after KB3159706, released 5/5/2016</strong></span></a><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><u>It mentions: Manual steps required to complete the installation of this update:</u></span><br />
<span style="font-family: "verdana" , sans-serif;">1. Install the hotfix and restart the WSUS/SUP server!<br />2. Open an elevated Command Prompt window, and run "C:\Program Files\Update Services\Tools\wsusutil.exe postinstall /servicing" (case sensitive)<br />3. Select HTTP Activation under .NET Framework 4.5 Features in the Server Manager Add Roles and Features wizard.<br />4. Restart the WSUS service.</span><br />
<br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-xgBX1y-QFkI/V9b-AXbyZbI/AAAAAAAAE94/af-AhT_4RVw2pXUz9S-qJ2OrmLsu2ehKACLcB/s1600/2016-09-12_16-13-24.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="27" src="https://1.bp.blogspot.com/-xgBX1y-QFkI/V9b-AXbyZbI/AAAAAAAAE94/af-AhT_4RVw2pXUz9S-qJ2OrmLsu2ehKACLcB/s320/2016-09-12_16-13-24.png" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;"><u>I skipped steps mentioned on "If SSL is enabled on the WSUS server" at first try, but they seems to be needed too!</u></span><br />
<span style="font-family: "verdana" , sans-serif;">1.Open an elevated Command Prompt window, and assign ownership of the Web.Config file to the administrators group</span><br />
<span style="font-family: "verdana";">-takeown /f web.config /a</span><br />
<span style="font-family: "verdana";">-icacls "C:\Program Files\Update Services\WebServices\ClientWebService\Web.config" /grant administrators:f</span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-DDyEXbjIbaI/V9b-YiGZ8iI/AAAAAAAAE98/Xj5RcvB8ZzwexHv1HcSKqJseLZRoC6XfgCLcB/s1600/Capture1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="320" src="https://2.bp.blogspot.com/-DDyEXbjIbaI/V9b-YiGZ8iI/AAAAAAAAE98/Xj5RcvB8ZzwexHv1HcSKqJseLZRoC6XfgCLcB/s320/Capture1.JPG" width="301" /></a></div>
<span style="font-family: "verdana" , sans-serif;">2. Make the following changes in the file > add the lines displayed in bold, don't make the mistake (as me) to replace those lines!</span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-uRekhsUOnHg/V9b-b_A5auI/AAAAAAAAE-A/cA0OmGFonC8eI4CUTdTtowXiFWY0appfgCLcB/s1600/Capture2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="62" src="https://1.bp.blogspot.com/-uRekhsUOnHg/V9b-b_A5auI/AAAAAAAAE-A/cA0OmGFonC8eI4CUTdTtowXiFWY0appfgCLcB/s320/Capture2.JPG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">3. Add the multipleSiteBindingsEnabled="true" attribute to the bottom of the Web.Config file</span><br />
<span style="font-family: "verdana" , sans-serif;">4. Restart the WSUS service.</span><br />
<br />
<span style="font-family: "verdana";">Start a Software Update sync in ConfigMgr and watch wsyncmgr.log and WCM.log closely. Everything should be fine now!</span><br />
<span style="font-family: Verdana;"></span><br />
<span style="font-family: Verdana;">Didn't see Windows 10 Servicing working yet, but hope too see it in near future. On <a href="http://henkhoogendoorn.blogspot.nl/2016/10/my-findings-on-microsoft-ignite-2016_4.html" target="_blank"><strong>Microsoft Ignite</strong></a> there was no session or demo about it too, given the fact that it may be working.</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">Will be continued in a next blogpost :-)</span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-51476907412114907132016-10-04T14:13:00.002+02:002016-10-04T14:17:11.775+02:00Final findings on Microsoft Ignite 2016 (Event) recap<span style="font-family: "verdana" , sans-serif;">Back from Atlanta again, downloading sessions and slides all night. A good script to do this can be found here: </span><a href="https://gallery.technet.microsoft.com/Ignite-2016-Slidedeck-and-296df316" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">Ignite 2016 Slidedeck and Video downloader</span></strong></a><span style="font-family: "verdana" , sans-serif;">. At the moment I downloaded around 85GB of content so far, and it's not done yet :-) </span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">As mentioned last year also, I don't like the idea of one big event with focus on several products. This because of networking and community, which is hard between 23.000 attendees. And because of in-depth knowledge and deep-dive sessions, most of community members going to IT/Dev Connections and Midwest Management Summit (MMS). That's not funny if you ask me. Hope that Microsoft wil consider a specific device management event in future again. </span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Overall the event was better then last year, where Microsoft did a first try to bring several events together. Therefore focus on Azure/Cloud, Server/Client, System Center/Intune, SQL/Visual Studio, Exchange/ Office 365 and SharePoint could all be found on one event. This year improvement was found on transfer shuttles, food (especially lunch), communication (security people) and Wi-Fi connection. Just picking up a name badge on airport is very pleasant, no need to wait on the event for this. No overbooked sessions this year for me also.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Improvements are still possible on food (more snacks between sessions), technical level on breakouts (more in-depth knowledge and demo's, offering level 300 and 400 sessions), sockets in sessions to load devices, and multiple lunch locations (not having to walk 20 minutes to pick up a lunchbox). As a device management focused person myself, I surely missed content on it. There were many sessions for sure, but still having the idea it wasn't enough to fill-up my schedule. No MMS replacement, if that is possible?</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Big question is what Microsoft is doing next year. Microsoft Ignite will be back in Orlando, on September 2017, with the same capacity I guess. Not sure if I will attend again, or choosing Nordic Infrastructure Conference, IT/Dev Connections or Midwest Management Summit instead. Like to have more networking and community, more in-depth knowledge and deep-dive sessions, more overall tech-feast feeling. When attended Microsoft Ignite yourself, please use comments to describe "your feeling on the event". Thanks!</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><u>More blogposts on Microsoft Ignite:</u><br /><a href="http://henkhoogendoorn.blogspot.nl/2016/10/my-findings-on-microsoft-ignite-2016.html" target="_blank">My findings on Microsoft Ignite 2016 day 4 (Session and Expo) recap</a> </span><br />
<span style="font-family: "verdana" , sans-serif;"><a href="http://henkhoogendoorn.blogspot.com/2016/09/my-findings-on-microsoft-ignite-2016_29.html" target="_blank">My findings on Microsoft Ignite 2016 day 3 (Session) recap</a> <br /><a href="http://henkhoogendoorn.blogspot.com/2016/09/my-findings-on-microsoft-ignite-2016_28.html" target="_blank">My findings on Microsoft Ignite 2016 day 2 (Session) recap</a> <br /><a href="http://henkhoogendoorn.blogspot.com/2016/09/my-findings-on-microsoft-ignite-2016_28.html" target="_blank">My findings on Microsoft Ignite 2016 day 1 (Keynote and Event) recap</a> <br /><a href="http://henkhoogendoorn.blogspot.com/2016/09/my-scheduled-sessions-and-product-focus.html" target="_blank">My scheduled sessions and product focus on Microsoft Ignite 2016</a> </span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-7447639046367058682016-10-03T12:02:00.002+02:002016-10-03T12:02:47.265+02:00My findings on Microsoft Ignite 2016 day 4 (Session and Expo) recap <span style="font-family: "verdana" , sans-serif;">Day 4 in Atlanta was kind of same as day 3 (in a good way). I did breakout sessions for 75 minutes again only, with lot of great stuff. I skipped the session after lunch, because of Expo closing. Instead of the extra session I spoke to several vendors and received information. Let's see which interesting stuff has been mentioned!</span><br />
<span style="font-family: "verdana" , sans-serif;"> </span><br />
<u><span style="font-family: "verdana" , sans-serif;">Implement Windows as a service</span></u><br />
<span style="font-family: "verdana" , sans-serif;">-With LTSB you keep to create big images and update all of your machines every few years (same as old model).<br />-With CB/CBB it's lot easier where smaller packages/downloads are used, which is quicker (requires new planning).<br />-Windows 10 cumulative updates supersedes the older ones to increase fragmentation (one big update).<br />-Only Quality updates (security & critical) and Features updates (optional) are left (new naming scheme).<br />-Microsoft recommends to implement al Windows 10 builds, and not to skip one (for CB/CBB usage only).</span><br />
<span style="font-family: "verdana" , sans-serif;"> </span><br />
<u><span style="font-family: "verdana" , sans-serif;">How to make the most out of Azure, Intune, O365 and W10</span></u><br />
<span style="font-family: "verdana" , sans-serif;">-Have a look at all new Windows 10 cloud services (OneDrive, Windows Update for Business, Windows Store for Business).</span><br />
<span style="font-family: "verdana" , sans-serif;">-Federation services (ADFS) is though to setup but it's worth it. Most people in room uses ADFS in environment!</span><br />
<span style="font-family: "verdana" , sans-serif;">-Secure Productive Enterprise contains of: Office365 + EM/S + Windows10. <a href="https://www.microsoft.com/en-us/secure-productive-enterprise/default.aspx" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">Website</span></strong></a></span><br />
<span style="font-family: "verdana" , sans-serif;">-Secure Productive Enterprise is the most trusted, secure, and productive way to work.</span><br />
<span style="font-family: Verdana;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-3mi79uSlzR4/V_IsUY4LjbI/AAAAAAAAFCc/Nn5wuQAANyo_qys7rmiZmRP1P8wIgINXACLcB/s1600/gp_gwcc_buildingc03.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="213" src="https://1.bp.blogspot.com/-3mi79uSlzR4/V_IsUY4LjbI/AAAAAAAAFCc/Nn5wuQAANyo_qys7rmiZmRP1P8wIgINXACLcB/s320/gp_gwcc_buildingc03.jpg" width="320" /></a><span style="font-family: "verdana" , sans-serif;"> </span></div>
<span style="font-family: "verdana" , sans-serif;">Overall the event was better then last year, where things as Wi-Fi, busses and food were better now. Many people from Microsoft to show you the way. Microsoft did a good job on organization, having a event with 23.000 attendees is not that easy.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><u>Let's have a look at my personal pro's on the event:</u><br />-Picking up name badge and bag before the event is really handy.<br />-Location was great, Atlanta is a good city for an event like this.<br />-Expo hall was really big and a lot of interesting stuff there.<br />-Shuttles between hotel and conference location were easy to use.</span><br />
<span style="font-family: "verdana";">-Food (especially lunch) on the event was better then last year.</span><br />
<span style="font-family: "verdana";">-Security people were nicer then last year, not shouting anymore.</span><br />
<span style="font-family: "verdana";">-No overbook sessions on this event (for me), which is fine.</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";"><u>Now let's have a look at my personal con's on the event:</u></span><br />
<span style="font-family: "verdana";">-Technical level on sessions may be better, with more in-depth knowledge and demo's, offering Level 300 and 400 sessions. Multiple times a Level 200 session was more tech and in-depth then a Level 300 session, which is strange isn't it?</span><br />
<span style="font-family: "verdana";">-No possibility to load devices (tablet, phone) during sessions, where you need to find a place to load them, missing a session at same time. </span><br />
<span style="font-family: "verdana";">-No possibility to have a quick lunch also, where a 20 minutes walk was needed. Therefore missing next session, because 30 minutes time is not enough to have lunch and walk back.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-LbuhzBIygKU/V-3y8Qa8YdI/AAAAAAAAFCE/vD1zYP6E5-0ZKRn0GUbELWtv31QeLkrFACLcB/s1600/Capture.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="58" src="https://2.bp.blogspot.com/-LbuhzBIygKU/V-3y8Qa8YdI/AAAAAAAAFCE/vD1zYP6E5-0ZKRn0GUbELWtv31QeLkrFACLcB/s320/Capture.JPG" width="320" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;">Microsoft Ignite is done for this year. Next year they will be back in Orlando, September 25 - 29, 2017. </span><a href="https://login.microsoftonline.com/ecad005.onmicrosoft.com/oauth2/v2.0/authorize?p=b2c_1_ignite2017_registration_signinup&client_id=308dc09b-37fd-49fe-a6b4-bc9fdd456ae3&redirect_uri=https%3a%2f%2fmsignite2017.eventcore.com%2fauth%2flogin&response_mode=form_post&response_type=id_token&scope=openid&state=OpenIdConnect.AuthenticationProperties%3dtGVu4xFXYLM1GArkxcSjwe6lPPcPnVeM7EqTFCfyHPWRI0hoBaQ7EAk6krpGBG0plGF5SyVdbKc_4HxcPdostBXDiTh8Rl4MlkqM3ruqVHub7J_f_ibvxw4L9YEAir9iqMnZv_D60ND-4msrKNQwTfuq5UIWx81eQ4oNi-0Amsw60dVH96CJr0fQ-cRM5k6hzLrhmdkgxWehwByDWpNNH-vk_kSgrgC4XYXKh-YxMaP0d_S0&nonce=636108084779779840.YjI5Mjg3MWYtNWY1ZS00ZDY2LTljYmUtMGNkZTlkMjhlYTc1MWZiMmI5YzQtYjc2Ni00NzljLWIyODgtZGExNGJmYmVhYzlh" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">Sign-up now for early registration access</span></strong></a><span style="font-family: "verdana" , sans-serif;"> and have first choice of hotels in March. I have done it myself already, just to be on time for registration.</span><br />
<span style="font-family: "verdana" , sans-serif;"> </span><br />
<u><span style="font-family: "verdana" , sans-serif;">More blogposts on Microsoft Ignite:</span></u><br />
<a href="http://henkhoogendoorn.blogspot.com/2016/09/my-findings-on-microsoft-ignite-2016_29.html" target="_blank"><span style="font-family: "verdana" , sans-serif;">My findings on Microsoft Ignite 2016 day 3 (Session) recap</span></a><span style="font-family: "verdana" , sans-serif;"> </span><br />
<a href="http://henkhoogendoorn.blogspot.com/2016/09/my-findings-on-microsoft-ignite-2016_28.html" target="_blank"><span style="font-family: "verdana" , sans-serif;">My findings on Microsoft Ignite 2016 day 2 (Session) recap</span></a><span style="font-family: "verdana" , sans-serif;"> </span><br />
<a href="http://henkhoogendoorn.blogspot.com/2016/09/my-findings-on-microsoft-ignite-2016_28.html" target="_blank"><span style="font-family: "verdana" , sans-serif;">My findings on Microsoft Ignite 2016 day 1 (Keynote and Event) recap</span></a><span style="font-family: "verdana" , sans-serif;"> </span><br />
<a href="http://henkhoogendoorn.blogspot.com/2016/09/my-scheduled-sessions-and-product-focus.html" target="_blank"><span style="font-family: "verdana" , sans-serif;">My scheduled sessions and product focus on Microsoft Ignite 2016</span></a><span style="font-family: "verdana" , sans-serif;"> </span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-19002932886016022362016-09-29T15:10:00.000+02:002016-09-29T15:23:46.252+02:00My findings on Microsoft Ignite 2016 day 3 (Session) recap <span style="font-family: Verdana, sans-serif;">Day 3 in Atlanta was best till now, with lot of great sessions. I did breakout sessions for 75 minutes again only, all on Windows 10 and Microsoft Intune. I skipped the session during lunch, to have some rest and load both Surface and Lumia devices. Two sessions in the morning and two in the afternoon is best for me. Let's see which interesting stuff has been mentioned today!</span><br />
<span style="font-family: "verdana";"></span><span style="font-family: Verdana, sans-serif;"> </span><br />
<u><span style="font-family: Verdana, sans-serif;">Windows 10 deployment experience</span></u><br />
<span style="font-family: Verdana, sans-serif;">-MDM or Microsoft Intune does not replace Group Policy and ConfigMgr. Improvements are coming! </span><br />
<span style="font-family: Verdana, sans-serif;">-Windows Defender team is world class now. Take a look at Defender and you will be surprised :-)</span><br />
<span style="font-family: Verdana, sans-serif;"> </span><br />
<span style="font-family: Verdana, sans-serif;"><u>Securing Android devices and apps with Microsoft Intune</u></span><br />
<span style="font-family: Verdana, sans-serif;">-Android fragmentation challenges: 24.000 distinct devices within 1.294 brands!</span><br />
<span style="font-family: Verdana, sans-serif;"><span style="font-family: Verdana, sans-serif;">-Android for work, Requires Android 6.0+ devices </span><a href="https://play.google.com/work" target="_blank"><strong><span style="font-family: Verdana, sans-serif;">Website</span></strong></a><br /><span style="font-family: Verdana, sans-serif;">-Android is missing some key features, Android security is lacking, Android device fragmentation</span></span><span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;">-Samsung KNOX extends native Android in a number of areas, 28 additional settings exposed by Samsung API's.<br />-Android for Work is Generally Available starting in October service release.<br />-Android for Work is filling the gap with managing Android or Samsung KNOX devices, given new policies and a business store!</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><span style="font-family: Verdana, sans-serif;"> </span><br />
<span style="font-family: Verdana, sans-serif;"><span style="font-family: Verdana, sans-serif;"><u>Manage and secure iOS and Mac devices with Microsoft Intune</u> </span></span><br />
<span style="font-family: Verdana, sans-serif;">-Microsoft Intune with Apple DEP looks great, but it's a pain to get the certificate from resellers sometimes?<br />-Lots of information today on Android and iOS management with Microsoft Intune. It's getting better and better!</span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-8XFGAgZr2DM/V-0N9NCgE_I/AAAAAAAAFBg/1pp8hRDj7Nc49sbMxmlzc_TlrhMpg4fuwCLcB/s1600/Ctdn0zIXEAAXHK6.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: Verdana, sans-serif;"><img border="0" height="180" src="https://4.bp.blogspot.com/-8XFGAgZr2DM/V-0N9NCgE_I/AAAAAAAAFBg/1pp8hRDj7Nc49sbMxmlzc_TlrhMpg4fuwCLcB/s320/Ctdn0zIXEAAXHK6.jpg" width="320" /></span></a></div>
<span style="font-family: Verdana, sans-serif;">-Mac OS management with Microsoft Intune, seems to be a great solution! </span><br />
<span style="font-family: Verdana, sans-serif;">-It doesn't care which iOS apps are installed by users, you can hide them with Microsoft Intune (in supervised mode)<br />-Coming up: Azure based console, Device based VPP, Multi-token support, iOS education features, Lost mode, More restrictions </span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-8KZNlxBnCjY/V-0N3jOJUsI/AAAAAAAAFBc/m2hKXmt_AWcp55x2I9y6mP8sqYjFTLCkgCLcB/s1600/Ctdpug_WAAAS-7E.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: Verdana, sans-serif;"><img border="0" height="180" src="https://4.bp.blogspot.com/-8KZNlxBnCjY/V-0N3jOJUsI/AAAAAAAAFBc/m2hKXmt_AWcp55x2I9y6mP8sqYjFTLCkgCLcB/s320/Ctdpug_WAAAS-7E.jpg" width="320" /></span></a></div>
<span style="font-family: Verdana, sans-serif;"><span style="font-family: Verdana, sans-serif;">-Azure based Intune console </span><span style="font-family: Verdana, sans-serif;">(looks great to me!)</span></span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;"><span style="font-family: Verdana, sans-serif;"><u>Windows 10 security with ConfigMgr and Microsoft Intune</u> </span></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: Verdana, sans-serif;">-Running your ConfigMgr environment on Azure is an Infrastructures as a Service (IaaS) solution <br />-Windows Store for Business integration in Microsoft Intune or ConfigMgr console is nice add-on for publishing apps!<br />-Google Play for Work looks and works same as Windows Store for Business </span><a href="https://play.google.com/work" target="_blank"><strong><span style="font-family: Verdana, sans-serif;">Website</span></strong></a><br /><span style="font-family: Verdana, sans-serif;">-Lot's of (new) dashboards in ConfigMgr console: Health Attestation, Software Updates and Windows Defender ATP </span></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-c5ZPhBumeX0/V-0O7bsHu0I/AAAAAAAAFBw/pqDI9Iko0L88TdjFv35d1XXzlI60SHAsgCLcB/s1600/Ctd_HxIUsAA5KtD.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: Verdana, sans-serif;"><img border="0" height="180" src="https://2.bp.blogspot.com/-c5ZPhBumeX0/V-0O7bsHu0I/AAAAAAAAFBw/pqDI9Iko0L88TdjFv35d1XXzlI60SHAsgCLcB/s320/Ctd_HxIUsAA5KtD.jpg" width="320" /></span></a></div>
<span style="font-family: Verdana, sans-serif;">-What's new in Windows Update for Business (WUfB)<br />-WUfB Is the way to update devices in ConfigMgr in a controlled way</span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-yBJDgNSYtmw/V-0OiXywvNI/AAAAAAAAFBk/339NOnjI7M8LoCPSXXAIqpEBH-NLyLMfACLcB/s1600/CteDtufUIAAj9D2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: Verdana, sans-serif;"><img border="0" height="180" src="https://4.bp.blogspot.com/-yBJDgNSYtmw/V-0OiXywvNI/AAAAAAAAFBk/339NOnjI7M8LoCPSXXAIqpEBH-NLyLMfACLcB/s320/CteDtufUIAAj9D2.jpg" width="320" /></span></a></div>
<span style="font-family: Verdana, sans-serif;">-Coming soon: Windows Upgrade Analytics in ConfigMgr console </span><br />
<span style="font-family: Verdana, sans-serif;"> </span><br />
<span style="font-family: Verdana, sans-serif;">Hope you like my findings so far! Stay tuned for more session findings later this week. Microsoft Ignite is rocking bigtime!</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;"><u>More blogposts on Microsoft Ignite:</u><br /><a href="http://henkhoogendoorn.blogspot.com/2016/09/my-findings-on-microsoft-ignite-2016_28.html" target="_blank">My findings on Microsoft Ignite 2016 day 2 (Session) recap</a> <br /><a href="http://henkhoogendoorn.blogspot.com/2016/09/my-findings-on-microsoft-ignite-2016.html" target="_blank">My findings on Microsoft Ignite 2016 day 1 (Keynote and Event) recap</a> <br /><a href="http://henkhoogendoorn.blogspot.com/2016/09/my-scheduled-sessions-and-product-focus.html" target="_blank">My scheduled sessions and product focus on Microsoft Ignite 2016</a> </span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-16982174714922335842016-09-28T15:33:00.000+02:002016-09-28T15:33:56.587+02:00My findings on Microsoft Ignite 2016 day 2 (Session) recap <span style="font-family: "verdana" , sans-serif;">Day 2 in Atlanta was better overall, where I did breakout sessions for 75 minutes only. No theater or other short sessions for me. Because of long walk between the sessions, you want to give your legs and feet some rest, and sit for a while. Problem again was the battery load on both Surface and Lumia device. When you use your device a lot for tweeting too (like me), you must load your battery during the day. Unfortunately you must really search for that, where it's not possible to load during the sessions.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Therefore I skipped a session partly during the day, to load both devices. Other point of complaining is lunch, which is a 15-20 minute walk, depends on where you are. Where spare time between sessions is around 30 minutes, you don't have time to walk to food service, eat your lunch, and be on time for the next session. Everything you need to do must be in a rush, which I do not prefer. Today I did 5 breakout sessions, with mixed feelings. Some where great, some moderate. It depends per session, but you can't walk out for another one, because of timeframe between other locations.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><u>The following interesting stuff I heard (in first session):</u></span><br />
<span style="font-family: "verdana" , sans-serif;">-When you need to go fast with Windows 10, you need to go fast with ConfigMgr too.</span><br />
<div class="separator" style="clear: both; text-align: center;">
<img border="0" height="180" src="https://3.bp.blogspot.com/-Tm8StYDaRAQ/V-ujqhnqqrI/AAAAAAAAFAs/UZYpi4wlCroPlQ6tJTNm34f_7hDE7XH0wCLcB/s320/Capture6.JPG" width="320" /></div>
<span style="font-family: "verdana" , sans-serif;">-All Windows 10 deployment methodologies possible, where servicing is advised for future upgrades!</span><br />
<span style="font-family: "verdana" , sans-serif;">-A new Microsoft Deployment Toolkit is coming this year named MDT and not MDT 2016, which is the latest version!<br />-ConfigMgr Technical Preview 1609 is released yesterday with lot of great new features. <a href="https://configurationmanager.uservoice.com/forums/300492-ideas" target="_blank"><strong>Website</strong></a></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-FPfKlHl1CuE/V-ujvyeNRAI/AAAAAAAAFAw/j3ntDO1fqhUIYFz80y4yl1gVw-c1_z5lQCLcB/s1600/Capture.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="181" src="https://4.bp.blogspot.com/-FPfKlHl1CuE/V-ujvyeNRAI/AAAAAAAAFAw/j3ntDO1fqhUIYFz80y4yl1gVw-c1_z5lQCLcB/s320/Capture.JPG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">-How to migrate BIOS to UEFI during OSD task sequence > multiple solutions available.</span><br />
<span style="font-family: "verdana" , sans-serif;">-Nested task sequences are coming in ConfigMgr, which is the most requested feature! </span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-Qb4Wb14Bj3U/V-ukhF3OAQI/AAAAAAAAFBA/P7ieE-K4tSUNkc0k3ym4YxwmOBEdJ79XwCLcB/s1600/Capture7.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="180" src="https://2.bp.blogspot.com/-Qb4Wb14Bj3U/V-ukhF3OAQI/AAAAAAAAFBA/P7ieE-K4tSUNkc0k3ym4YxwmOBEdJ79XwCLcB/s320/Capture7.JPG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">-Language and region support (installing language packs) and customizable end user notifications are coming too!</span><br />
<span style="font-family: "verdana" , sans-serif;">-Coming soon: Clients will fallback to a next distribution point in 2 minutes by default (used to be 2 hours)</span><br />
<span style="font-family: "verdana" , sans-serif;">-User voice: 623 submitted ideas, 60 shipped in ConfigMgr current branch. <a href="https://configurationmanager.uservoice.com/forums/300492-ideas" target="_blank"><strong>Feedback</strong></a></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-zJ7IYPCOeOY/V-uj4RaAaHI/AAAAAAAAFA4/tm_hqBoarecFeEvv0ItPsH1cCftx3dNLACLcB/s1600/Capture3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="180" src="https://1.bp.blogspot.com/-zJ7IYPCOeOY/V-uj4RaAaHI/AAAAAAAAFA4/tm_hqBoarecFeEvv0ItPsH1cCftx3dNLACLcB/s320/Capture3.JPG" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">-What's needed for Windows 10 servicing in ConfigMgr Current Branch?</span><br />
<span style="font-family: "verdana" , sans-serif;">-With Windows Update for Business you delegate updates to Microsoft. Handy or not?</span><br />
<span style="font-family: "verdana" , sans-serif;"><br />
<span style="font-family: "verdana" , sans-serif;"><u>The following interesting stuff I heard (in other sessions):</u></span><br />
</span><span style="font-family: "verdana" , sans-serif;">-The Microsoft Intune portal is moving from Silverlight to Azure platform completely! Really awesome.</span><br />
<span style="font-family: "verdana" , sans-serif;">-The New Microsoft Intune portal in Azure is expected somewhere in Q1 2017.</span><br />
<span style="font-family: "verdana";">-Microsoft Intune Mobile Application Management is the way to go! Really awesome functionality and possibilities </span><br />
<span style="font-family: "verdana";">-Everything is going to the cloud: Identity, Membership, Applications, Policies, you name it.</span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-Wv64DSPQxhk/V-uk89DpgbI/AAAAAAAAFBI/OLTK0TEyZ4sn0P1tbescCVldlGuSpVPuQCLcB/s1600/Capture1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="180" src="https://4.bp.blogspot.com/-Wv64DSPQxhk/V-uk89DpgbI/AAAAAAAAFBI/OLTK0TEyZ4sn0P1tbescCVldlGuSpVPuQCLcB/s320/Capture1.JPG" width="320" /></a></div>
<span style="font-family: "verdana";">-20,533 total tenants on ConfigMgr Current Branch worldwide! With around 50% running on the latest build (1606).</span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-ybzyAjXGzgc/V-ukrAMDYeI/AAAAAAAAFBE/w-OmcdAPGdEyw9-nwShYU6LdOGBRLsmaACLcB/s1600/Capture2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="181" src="https://2.bp.blogspot.com/-ybzyAjXGzgc/V-ukrAMDYeI/AAAAAAAAFBE/w-OmcdAPGdEyw9-nwShYU6LdOGBRLsmaACLcB/s320/Capture2.JPG" width="320" /></a></div>
<span style="font-family: "verdana";">-40,497,142 million total clients managed by ConfigMgr worldwide! With around 75% on latest builds (1602, 1606)</span><br />
<span style="font-family: "verdana";">-New ConfigMgr Current Branch release is called 1610 and offers cloud-based management and peer caching for all content.</span><br />
<span style="font-family: "verdana" , sans-serif;">
-Identity is the new attack surface! Not firewall anymore<br />
<span style="font-family: "verdana";">-Identity challenges today: organizations want greater control, users wants simple passwords, multi-factor is to complex.</span><br />
<br />
Stay tuned for more on new ConfigMgr features, Windows 10 servicing and mobile device & application management.<br />
<br />
<u>More blogposts on Microsoft Ignite:</u></span><br />
<span style="font-family: "verdana" , sans-serif;"><a href="http://henkhoogendoorn.blogspot.nl/2016/09/my-findings-on-microsoft-ignite-2016.html" target="_blank">My findings on Microsoft Ignite 2016 day 1 (Keynote and Event) recap</a> <br /><a href="http://henkhoogendoorn.blogspot.nl/2016/09/my-findings-on-microsoft-ignite-2016.html" target="_blank">My scheduled sessions and product focus on Microsoft Ignite 2016</a></span><span style="font-family: "verdana" , sans-serif;"> </span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-66270811409076099692016-09-28T05:56:00.001+02:002016-09-28T12:32:07.399+02:00Now Available: Update 1609 for ConfigMgr Technical Preview <span style="font-family: "verdana" , sans-serif;">Today (September 27th) the latest ConfigMgr (preview) version is released: Update 1609 for ConfigMgr Technical Preview. Update 1609 for Technical Preview is available directly in the ConfigMgr console. If you want to install ConfigMgr Technical Preview for the first time, the installation bits (currently based on Technical Preview 1603) are available on TechNet Evaluation Center. The new version offers lots of new functionality, with several great new features.</span><br />
<span style="font-family: "verdana" , sans-serif;"> </span><br />
<span style="font-family: "verdana" , sans-serif;"><u>This update includes the following improvements:</u><br />-Windows 10 Upgrade Analytics (assess and analyze device readiness and compatibility with Windows 10 to allow smoother upgrades)<br />-Office 365 Client Management Dashboard (track Office 365 updates and deployments)<br />-Deploy Office 365 apps to clients (Office 365 Servicing node in Software Library, deploy Office 365 apps to clients)<br />-Improvements for BIOS to UEFI conversion (OS deployment task sequence with a new variable, called TSUEFIDrive)<br />-Improvement to Endpoint Protection antimalware policy settings (specify the level to block suspicious files)<br />-Boundary Group Improvements (more granular control of fallback behavior, and greater clarity which DP's are used)</span><br />
<br />
<span style="font-family: "verdana" , sans-serif;"><u>This update also includes new features for customers using ConfigMgr integrated with Intune (hybrid scenario):</u><br />-TouchID, ApplePay and Zoom DEP Settings (create enrollment profiles to skip initial setup screens for new iOS devices)<br />-Windows Store for Business (allows customers to obtain applications, purchased or free, and deploy them to users)<br />-Android, iOS, and Windows Additional Settings (create Windows 10 VPN profiles without using OMA-URI)<br />-Intune Compliance Charts (quick view of overall device compliance, and top reasons for non-compliance using new charts)</span><br />
<br />
<span style="font-family: "verdana" , sans-serif;">And nested task sequences will be available soon too! Just great a new (preview) version is available now! Happy installing :-)</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Source: <a href="https://blogs.technet.microsoft.com/enterprisemobility/2016/09/27/update-1609-for-configuration-manager-technical-preview-available-now/" target="_blank"><strong>Enterprise Mobility and Security Blog</strong></a></span><br />
<span style="font-family: "verdana";">Detailed overview of new features: <a href="https://technet.microsoft.com/en-us/library/mt772349.aspx" target="_blank"><strong>Microsoft TechNet</strong></a></span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-29869847104689954522016-09-27T14:44:00.001+02:002016-09-27T14:47:51.168+02:00My findings on Microsoft Ignite 2016 day 1 (Keynote and Event) recap <span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">Day 1 in Atlanta was somewhat expected but not what I hoped for. The day was starting with the keynote (part 1), where part 2 was presented end of day. With around 23.000 attendees (which is equal as last year) it was full house! Within the </span><a href="https://en.wikipedia.org/wiki/Philips_Arena" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">Philips Arena</span></strong></a><span style="font-family: "verdana" , sans-serif;"> itself there was plenty of space left, which is strange because there is room for 18.000 people as mentioned on Wikipedia. My guess is there were around 10.000-12.000 people at maximum :-)</span></span><br />
<br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">Speakers were Julia White, Satya Nadella, Scott Guthrie, Donovan Brown and Laura Jones. No names like </span></span><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">Joe Belfiore, Gurdeep Singh Pall or Brad Anderson this time. </span><span style="font-family: "verdana" , sans-serif;">Instead of other keynotes before, Wi-Fi was working great this time. Even during the keynote opening, which is very pleasant! </span></span><span style="font-family: "verdana" , sans-serif;">Point is, there were some announcements mentioned, but no technology demo's on them. Instead of that a lot of Microsoft marketing and topics like cloud solutions and artificial intelligence were mentioned. And that's pity if you get what I mean. </span><br />
<span style="font-family: "verdana";"></span><br />
<table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"><tbody>
<tr><td style="text-align: center;"><a href="https://3.bp.blogspot.com/-dBNjXXKC8Rw/V-nBh3jadRI/AAAAAAAAE_g/NP25Bja0Np0HEKNo0-iXRbyY_bBtsA3_gCLcB/s1600/WP_20160926_11_08_45_Rich.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"><img border="0" height="180" src="https://3.bp.blogspot.com/-dBNjXXKC8Rw/V-nBh3jadRI/AAAAAAAAE_g/NP25Bja0Np0HEKNo0-iXRbyY_bBtsA3_gCLcB/s320/WP_20160926_11_08_45_Rich.jpg" width="320" /></a></td></tr>
<tr><td class="tr-caption" style="text-align: center;"><span style="font-family: "verdana" , sans-serif;">Julia White on stage</span></td></tr>
</tbody></table>
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Announcements were done on the following products or solutions:</span><br />
<span style="font-family: "verdana" , sans-serif;">-Windows Server 2016 is GA (</span><a href="https://www.microsoft.com/en-us/evalcenter/evaluate-windows-server-2016" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">Download</span></strong></a><span style="font-family: "verdana" , sans-serif;">)</span><br />
<span style="font-family: "verdana" , sans-serif;">-System Center 2016 is GA (</span><a href="https://www.microsoft.com/en-us/evalcenter/evaluate-system-center-2016" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">Download</span></strong></a><span style="font-family: "verdana" , sans-serif;">)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Azure Monitoring dashboard, for overview</span><br />
<span style="font-family: "verdana" , sans-serif;">-Delve Analytics Outlook add-in for email statistics <br />-Surface hub stormboard app, offers new features</span><br />
<span style="font-family: "verdana" , sans-serif;">-Windows Defender Application Guard for Edge browser </span><br />
<br />
<span style="font-family: "verdana" , sans-serif;">Furthermore the following was mentioned during the first keynote:</span><br />
<span style="font-family: "verdana" , sans-serif;">-IT stands for Innovation and Transformation</span><br />
<span style="font-family: "verdana" , sans-serif;">-Azure in 34 regions now, 2 times more as Amazon AWS</span><br />
<span style="font-family: "verdana" , sans-serif;">-Azure platform is growing strong says Gartner</span><br />
<span style="font-family: "verdana" , sans-serif;">-Windows 10 running on 400 million devices now</span><br />
<span style="font-family: "verdana" , sans-serif;">-MS Edge is the most secure browser for enterprises </span><br />
<span style="font-family: "verdana" , sans-serif;">-Cortana has 133 million users, 12 billion questions </span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"><tbody>
<tr><td style="text-align: center;"><a href="https://4.bp.blogspot.com/-nctcPPXhpoU/V-nrMgGanII/AAAAAAAAE_w/VKNtXfZSfFsF6TgVrsSO2LxN5mwIspDagCLcB/s1600/CCapture.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"><img border="0" height="180" src="https://4.bp.blogspot.com/-nctcPPXhpoU/V-nrMgGanII/AAAAAAAAE_w/VKNtXfZSfFsF6TgVrsSO2LxN5mwIspDagCLcB/s320/CCapture.jpg" width="320" /></a></td></tr>
<tr><td class="tr-caption" style="text-align: center;"><span style="font-family: "verdana" , sans-serif;">Small moment of fame</span></td></tr>
</tbody></table>
<br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana";">Besides of that I went to two sessions on Windows 10 functionality and deployment. Both were level 200, which is kind of marketing level with a bit of tech information. More information on that in a next blogpost. No interesting information on Windows Server 2016, System Center 2016, Enterprise Mobility and/or MS Intune at all which is odd.</span></span><span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">The </span><a href="https://en.wikipedia.org/wiki/Georgia_World_Congress_Center" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">Georgia World Congress Center</span></strong></a><span style="font-family: "verdana" , sans-serif;"> itself is a really huge place, with lot's of floors and escalators. Many of them were malfunction for a while too. When moving between sessions, Expo hall or Food service, it is possible that a 20-30 minutes walk is needed. When a session is overbooked, it's almost impossible to be on-time for another one. That's the downside of an event with so many attendees. Back in the days of Microsoft Management Summit (MMS), with around 5.000 attendees this was never a problem at all.</span><br />
<span style="font-family: "verdana";"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-pCUlKkZ11Ck/V-ppY4nIDXI/AAAAAAAAFAA/jSenqoi3HFAYxFbSeSHgkin-gzNI0MsvgCLcB/s1600/microsoft-ignite-app-lumia-640.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="240" src="https://2.bp.blogspot.com/-pCUlKkZ11Ck/V-ppY4nIDXI/AAAAAAAAFAA/jSenqoi3HFAYxFbSeSHgkin-gzNI0MsvgCLcB/s320/microsoft-ignite-app-lumia-640.jpg" width="320" /></a></div>
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">Bus transfers are great, you never have to wait for transfers to Microsoft Ignite conference or hotel. Point of discussion is there is no paper conference guide this time, it's all mobile driven now. When you use your phone a lot for tweeting too (like me), you must load your battery during the day. Unfortunately you must really search for that, where it's not possible to load during the sessions. Between the sessions there is less time in between, which given a (partly)missed session to be battery loaded again.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">My overall feeling after day 1 with two keynotes is somewhat expected but not what I hoped for (as mentioned earlier). Because Microsoft is talking about Mobile-first, Cloud-first and Azure solutions only, there's no feeling with new on-premises solutions and features like Windows Server 2016 and/or System Center 2016. Count that with long walks and bad lunch, and you have a kind of superficial day. Hope that next days (with more tech sessions) will be much better!</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">Stay tuned for more information on this.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><u>More blogposts on Microsoft Ignite:</u></span><br />
<span style="font-family: "verdana" , sans-serif;"><a href="http://henkhoogendoorn.blogspot.nl/2016/09/my-scheduled-sessions-and-product-focus.html" target="_blank">My scheduled sessions and product focus on Microsoft Ignite 2016</a> </span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-77601901907642969762016-09-23T10:47:00.001+02:002016-09-23T10:52:45.803+02:00My scheduled sessions and product focus on Microsoft Ignite 2016<span style="font-family: "verdana" , sans-serif;">Next week Microsoft Ignite is already there! As for many months, the Microsoft Ignite general attendee registration is SOLD OUT! With around 20,000 attendees in attendance (which is same as last year), it will be a great event full off Microsoft announcements and new technology. More about that can be found <strong><a href="http://henkhoogendoorn.blogspot.nl/2016/07/system-center-2016-and-windows-server.html" target="_blank">HERE</a></strong>. In this blogpost I mention my focus on products and sessions scheduled.</span><br />
<br />
<span style="font-family: "verdana" , sans-serif;">When we look on products first, the following have my attention:<br />- Microsoft Azure</span><br />
<span style="font-family: "verdana" , sans-serif;">- Microsoft Intune</span><br />
<span style="font-family: "verdana" , sans-serif;">- System Center 2016</span><br />
<span style="font-family: "verdana" , sans-serif;">- Windows 10</span><br />
<span style="font-family: "verdana" , sans-serif;">- Windows Server 2016</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana";">Most sessions will be on Mobile Device & Application Management and how to keep Windows 10 secure:</span><br />
<span style="font-family: "verdana";">- Conditional Access </span><br />
<span style="font-family: "verdana";">- Credential Guard</span><br />
<span style="font-family: "verdana";">- Device Guard</span><br />
<span style="font-family: "verdana";">- Federation Services</span><br />
<span style="font-family: "verdana";">- Manage Android devices</span><br />
<span style="font-family: "verdana";">- Manage iOS devices</span><br />
<span style="font-family: "verdana";">- Windows Defender ATP<br />- Windows Information Protection</span><br />
<span style="font-family: "verdana";">- Windows Store for Business</span><br />
<span style="font-family: "verdana";">- Windows Update for Business</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">Where Windows 10 is one year old now, there's a business need to keep it secure and safely. Therefore less sessions on OS deployment this year for me, but security it is :-)</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">Expect a lot of tweets and blogposts around Microsoft Ignite from me, and lot's of other people love sharing knowledge.</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">Follow me on Twitter: <a href="https://twitter.com/henkhoogendoorn" target="_blank">@HenkHoogendoorn</a> / </span><span style="font-family: "verdana";"><a href="https://twitter.com/sccm2016" target="_blank">@SCCM2016</a> / <a href="https://twitter.com/server2016" target="_blank">@Server2016</a> / <a href="https://twitter.com/sysctr2016" target="_blank">@SysCtr2016</a></span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-91558692327497432602016-09-21T14:10:00.000+02:002016-09-21T14:10:25.272+02:00Microsoft probably won't release a Band 3 this year (or later)<span style="font-family: Verdana, sans-serif;">Where Windows Phone worldwide sales is dropped to 0.7% market share only, next point of discussion is Microsoft Band. Microsoft probably won't release a Band 3 this year (or later). Didn't find statistics on market share on this, but would be pity if both Windows Phone and Band are end of life. Where other wearables must be used with the same operating system, Microsoft Band can be used in combination with your favorite phone. There are health apps for both Android, iOS and Windows Phone available.</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-flfemh59Lrk/V-J1cgsTFbI/AAAAAAAAE_E/V4YFKk6RMdkJMl4QzfgPkLNVl8Pas11FQCLcB/s1600/Band2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: Verdana, sans-serif;"><img border="0" height="227" src="https://2.bp.blogspot.com/-flfemh59Lrk/V-J1cgsTFbI/AAAAAAAAE_E/V4YFKk6RMdkJMl4QzfgPkLNVl8Pas11FQCLcB/s320/Band2.JPG" width="320" /></span></a></div>
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;">Besides of that current Band is cheaper now, where price is dropped with $75 (temporarily). When looking for wearables market share, Microsoft is not mentioned at all. Maybe sales on Band is as worse as Windows Phone, where Microsoft stepped in to late to make a difference! Time will tell, because Microsoft has planned a device event on October 26th already. Hope that announcements are coming on both expired and future devices.</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;"><u>My personal experience on Windows Phone:</u> </span><br />
<span style="font-family: Verdana, sans-serif;"><a href="http://henkhoogendoorn.blogspot.nl/2016/09/microsoft-lumia-950-experience-after-9.html" target="_blank">Microsoft Lumia 950 experience after 9 months (pro's and cons)</a> <br /><a href="http://henkhoogendoorn.blogspot.nl/2016/09/microsoft-will-be-ending-sales-of-all.html" target="_blank">Microsoft will be ending sales of all Lumia smartphones by end of this year!</a></span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<u><span style="font-family: Verdana, sans-serif;">Other news on Microsoft Band 3:</span></u><br />
<span style="font-family: Verdana, sans-serif;"><a href="https://www.engadget.com/2016/09/14/microsoft-probably-wont-release-a-band-3-this-year/" target="_blank">Microsoft probably won't release a Band 3 this year</a></span><br />
<span style="font-family: Verdana, sans-serif;"><a href="http://www.zdnet.com/article/dont-expect-a-new-microsoft-band-device-this-year-or-maybe-ever/" target="_blank">Don't expect a new Microsoft Band device this year (or maybe ever)</a></span><br />
<span style="font-family: Verdana, sans-serif;"><a href="https://www.wareable.com/wearable-tech/microsoft-band-cancelled-rumour-2016" target="_blank">And finally: Microsoft Band to be dumped and more</a></span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-19988779457796428912016-09-20T13:53:00.000+02:002016-09-20T13:53:03.488+02:00Microsoft will be ending sales of all Lumia smartphones by end of this year!<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">Last weeks sad news is coming from many news sites. Because of bad selling of Microsoft Lumia devices, Microsoft will pull the plug and ending sales of all Lumia smartphones by the end of this year. </span><span style="font-family: "verdana" , sans-serif;">That's not strange with 0,7% market share only in Q1 2016 (Gartner). Probably the Surface Phone fits better, but it will be no consumer device for sure. This news is killing for Lumia owners like me, where devices are half of price after release 9 months ago.</span></span></span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-ydZ2PNjQoIo/V9w38vXf0VI/AAAAAAAAE-g/WqG8_saWp0cIO7sANBt6bdpka-TDaigagCEw/s1600/gartnerchart2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="113" src="https://2.bp.blogspot.com/-ydZ2PNjQoIo/V9w38vXf0VI/AAAAAAAAE-g/WqG8_saWp0cIO7sANBt6bdpka-TDaigagCEw/s400/gartnerchart2.png" width="400" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Where my Lumia 950 was €599 around 9 months ago, with another €99 for a Display Dock (which was included with 950XL only), price has now dropped down to €299 with a free Display Dock instead. That's a €399 price drop within a year, which is frankly outrageous if you ask me! Microsoft is abandon Windows Phone lovers that way really quick. No good residual value for the money here, and no one daring to buy Surface Phone at later time. My 2 cents..</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-cDjT5FaKO-0/V9w98wUvXeI/AAAAAAAAE-o/snZ-EsSKYDUOboidLgNNbKVFlzgb0N5VQCLcB/s1600/Capture1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="156" src="https://4.bp.blogspot.com/-cDjT5FaKO-0/V9w98wUvXeI/AAAAAAAAE-o/snZ-EsSKYDUOboidLgNNbKVFlzgb0N5VQCLcB/s320/Capture1.JPG" width="320" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Where promises were made on Continuum and Appstore support, on both Android (Project Astoria) and iOS (Project Islandwood), nothing has been released so far. Continuum was not as expected, without further app support and possibility to open a single app multiple times. Appstore support on both Android and iOS transfers has never been released, which was another reason for me to buy this flagship. No single reaction from Microsoft so far on this!</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-y3PHoiIqL6s/V9w-Vphn7oI/AAAAAAAAE-s/kF3Y1OQHZGIBgxpQkIKhrmmhnTaMA00DwCLcB/s1600/maxresdefault.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="181" src="https://1.bp.blogspot.com/-y3PHoiIqL6s/V9w-Vphn7oI/AAAAAAAAE-s/kF3Y1OQHZGIBgxpQkIKhrmmhnTaMA00DwCLcB/s320/maxresdefault.jpg" width="320" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">So yes, it's no secret, Microsoft is done with it's Lumia line of devices. Probably Surface Phone will be coming end of 2017, where current Lumia 950 (XL) owners will not try it again. Time will tell if Surface Phone (when released, because currently just a product that's in-development internally), is good value for money after all. Still a disappointment for me and many other Windows Phone lovers, and time to look for a new device and platform.</span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana";"><span style="font-family: "verdana" , sans-serif;">My personal experience on: </span><a href="http://henkhoogendoorn.blogspot.nl/2016/09/microsoft-lumia-950-experience-after-9.html" target="_blank"><span style="color: purple; font-family: "verdana" , sans-serif;">Microsoft Lumia 950 experience after 9 months (pro's and cons)</span></a><span style="font-family: "verdana" , sans-serif;"> </span></span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;"><u>Other news on Lumia smartphones:</u></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="http://www.valuewalk.com/2016/09/goodbye-microsoft-lumia-hello-new-surface-phone/" target="_blank">Goodbye, Microsoft Lumia. Hello New Surface Phone</a></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="http://www.windowscentral.com/should-you-wait-surface-phone-or-buy-lumia-950-now" target="_blank">Should you wait for the Surface Phone or buy a Lumia 950 now?</a></span><br />
-<a href="http://www.itechpost.com/articles/27978/20160907/top-4-reasons-microsoft-surface-phone-will-best-enter-market.htm" target="_blank"><span style="font-family: "verdana";">Top 4 Reasons The Microsoft Surface Phone Will Be The Best Phone To Enter The Market</span></a><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="https://mspoweruser.com/microsofts-rumoured-surface-phone-may-not-arrive-next-fall/" target="_blank">Microsoft’s rumoured ‘Surface Phone’ may not arrive until next Fall</a></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="http://www.itechpost.com/articles/27692/20160906/microsoft-surface-phone-replace-lumia-950-line-release-date-moved.htm" target="_blank">Microsoft Surface Phone To Replace Lumia 950 Line; Release Date Moved To 2017?</a></span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-253453370486182372016-09-14T19:29:00.001+02:002016-09-20T13:53:25.115+02:00Microsoft Lumia 950 experience after 9 months (pro's and cons)<span style="font-family: "verdana" , sans-serif;">Since December last year I'm using a Microsoft Lumia 950 as my primary phone. Since start I experienced many bugs, with lot's of unexpected reboots, overheating and all kind of nasty issues. With later builds this was getting better, but still I experience lot's of bugs. Where Windows Phone 8.1 (Samsung Ativ S) did perform excellent for many years, Windows 10 Mobile still isn't at some points. Let's have a look at my experiences so far.</span><br />
<span style="font-family: "verdana" , sans-serif;">
</span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-DGfnteTJRR8/V8BC03sMnQI/AAAAAAAAE7U/L5s8UlKTsyMcIF5hcKEQDT0BtVbsB8ubgCLcB/s1600/lumia_950_continuum.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="179" src="https://1.bp.blogspot.com/-DGfnteTJRR8/V8BC03sMnQI/AAAAAAAAE7U/L5s8UlKTsyMcIF5hcKEQDT0BtVbsB8ubgCLcB/s320/lumia_950_continuum.jpg" width="320" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;"><br /></span><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">
<b><span style="font-family: "verdana" , sans-serif;">Pro's</span></b></span></span><br />
<span style="font-family: "verdana" , sans-serif;">-Real Microsoft phone :-)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Windows 10 Operating System</span><br />
<span style="font-family: "verdana" , sans-serif;">-Resolution (2560x1440, 564 ppi)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Lot's of updates (with Insider builds)</span><br />
<span style="font-family: "verdana" , sans-serif;">-20 MP Camera (good quality)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Windows Hello (when working)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Gorilla Glass (no scratches)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Battery (enough for one day)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Fast charging (Superb!)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Glance screen (very useful)</span><br />
<span style="font-family: "verdana" , sans-serif;"><br /></span><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">
<span style="font-family: "verdana" , sans-serif;"><b>Cons</b></span></span></span><br />
<span style="font-family: "verdana" , sans-serif;">-Continuum (less features then expected)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Unexpected reboots (cannot count them anymore)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Camera button not working (very annoying, reboot needed)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Camera reacts very slow sometimes (reboot needed)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Camera app not working (error message, reboot needed)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Lock screen black with red light only (happens sometimes)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Incoming call cannot answer (very annoying, reboot needed)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Store or other apps not working (error message, reboot needed)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Windows Hello active during the night (very annoying, happens rarely)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Photo saved as white image (guess this is a Micro SD problem?)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Photo (un)zoom crash (happens almost all the time, no fix found)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Bad photos in dark environments (guess because of camera)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Less apps available then expected (very bad and not as promised)</span><br />
<span style="font-family: "verdana" , sans-serif;">-Pointer on screen not accurate (during games, happens a lot)</span><br />
<span style="font-family: "verdana" , sans-serif;"><br /></span><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">
<span style="font-family: "verdana" , sans-serif;"><strong>Note:</strong> On every location which says [reboot needed], the issue is (temporarily) solved, but not gone completely.</span></span></span><br />
<span style="font-family: "verdana" , sans-serif;"><br /></span><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">
<span style="font-family: "verdana" , sans-serif;">As you can see I experience more cons then pro's after heavy usage and many updates. This because I'm using camera and photo app a lot, and both are (still) not stable. Besides of that I ordered the Lumia 950 for Windows Hello and Continuum, where both I'm not using. Windows Hello is to slow for me, and doesn't recognize me sometimes. Continuum is not as expected, with less supported apps available, and not a full PC environment as promised on start. No possibility to open apps twice either.</span></span></span><br />
<span style="font-family: "verdana" , sans-serif;"><br /></span><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">
<span style="font-family: "verdana" , sans-serif;">Windows 10 Mobile (even on 1607) is not stable all the time, where apps (even Camera and Store) can crash, the lock screen can crash, and incoming calls can crash too. The Windows store isn't updated with iOS and/or Android apps as promised earlier. Therefore I thinking about switching my device to another platform now. Guess the Lumia 950 will be my secondary phone from now on, which is pity because Microsoft could have a winner here!</span></span></span><br />
<span style="font-family: "verdana" , sans-serif;"><br /></span><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">
<u><span style="font-family: "verdana" , sans-serif;">Other news on Windows 10 Mobile:</span></u></span></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="http://betanews.com/2016/04/21/microsofts-biggest-fan-doesnt-want-windows-10-mobile/" target="_blank">Even Microsoft's biggest fan doesn't want Windows 10 Mobile</a></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="http://www.winbeta.org/news/mary-jo-foley-becomes-latest-dump-windows-phone-android" target="_blank">Mary Jo Foley becomes the latest to dump Windows Phone for Android</a></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="http://www.zdnet.com/article/why-i-broke-up-withwindows-phone-its-not-me-its-you/" target="_blank">Why I broke up with Windows Phone: It's not me, it's you</a></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="https://redmondmag.com/articles/2016/03/01/last-call-for-windows-mobile.aspx" target="_blank">Is It Last Call for Windows Mobile?</a></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="https://www.thurrott.com/mobile/windows-phone/76028/great-windows-phone-app-exodus-2016" target="_blank">The Great Windows Phone App Exodus of 2016 (Premium)</a></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="https://www.thurrott.com/mobile/windows-phone/74196/rethinking-windows-phone" target="_blank">Rethinking Windows Phone (Premium)</a></span><br />
<span style="font-family: "verdana" , sans-serif;">-<a href="http://www.theverge.com/2016/5/23/11743594/microsoft-windows-phone-market-share-below-1-percent" target="_blank">Windows Phone market share sinks below 1 percent</a></span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com1tag:blogger.com,1999:blog-7396481053359703519.post-6012478923392876902016-09-12T20:47:00.001+02:002016-09-12T20:47:44.210+02:00Unable to promote pre-production client in ConfigMgr Current Branch<span style="font-family: "verdana" , sans-serif;">Today I did an upgrade on ConfigMgr Current Branch from version 1602 to 1606. During the upgrade I choose to validate the client package in pre-production first. After the upgrade however, there was no possiblity to promote the ConfigMgr client to the latest version. I restarted the ConfigMgr server and console, but without any luck. After that I decided to install Update Rollup 1, which was successful again, but still the same behaviour. No possibility to promote the ConfigMgr client to the latest version again.</span><br />
<span style="font-family: "verdana";"></span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-0Oi80yNuDpQ/V9aTel3ApqI/AAAAAAAAE9c/DVeCWcDsAE0VQr8GdWMzciX7a0syQ1WSgCLcB/s1600/2016-09-12_11-12-39.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="59" src="https://1.bp.blogspot.com/-0Oi80yNuDpQ/V9aTel3ApqI/AAAAAAAAE9c/DVeCWcDsAE0VQr8GdWMzciX7a0syQ1WSgCLcB/s320/2016-09-12_11-12-39.png" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">Lucky me I found the following thread: <a href="https://social.technet.microsoft.com/Forums/en-US/b45510a5-eed8-488e-b027-34def3cb81fd/unable-to-promote-preproduction-client" target="_blank"><strong>Microsoft TechNet</strong></a></span><span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">It mentioned: I solved my problem. It seems to be a RBAC problem. The user I used in ConfigMgr was "Full Administrator" but assigned though an AD group and not directly assigned. When I added my user directly as a user account in the ConfigMgr console and gave him "Full Administrator" rights then I could promote the client to production.</span><br />
<br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-0Mxs9Y75NHc/V9aTmNrjXdI/AAAAAAAAE9g/Th61H6JCLWQ4-JrSetJfvYJ3SK4HT_ikwCLcB/s1600/2016-09-12_13-08-51.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="59" src="https://4.bp.blogspot.com/-0Mxs9Y75NHc/V9aTmNrjXdI/AAAAAAAAE9g/Th61H6JCLWQ4-JrSetJfvYJ3SK4HT_ikwCLcB/s320/2016-09-12_13-08-51.png" width="320" /></a></div>
<span style="font-family: "verdana" , sans-serif;">In my case (customer location) this was the same situation. The user which did the upgrade and was logged on is part of an security group. That's a nasty situation for sure! </span><span style="font-family: "verdana" , sans-serif;">Long story short: I added the user directly as Full Administrator in the console, and the "Promote Pre-production Client" button became available again. Hope that Microsoft will fix this for future builds, because adding users instead of groups is not the way to go. Hope it helps!</span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-56788366119116936432016-09-08T16:20:00.001+02:002016-09-08T16:20:23.550+02:00Software Center not showing applications in ConfigMgr Current Branch <span style="font-family: "verdana" , sans-serif;">Recently I had an issue at customer location where applications were not showing in ConfigMgr Current Branch. When opening Application Catalog instead all applications showing up without any problem. In the old days only software packages were displayed in Software Center, leaving the Application Catalog for applications. Apparently I was closer to the solution then expected, because I was still looking at the older Software Center, where using the new one was enabled in Client settings. Let's have a closer look.</span><br />
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">At this location the shortcut was offered by Group Policy Preferences instead of ConfigMgr default. Microsoft did update the Software Center in ConfigMgr Current Branch, but did not replace the executable which is used. Therefore the link which is used for the old and new Software Center differs form each other:</span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-Zax9qipDNW0/V9FzSGAKu_I/AAAAAAAAE88/jKMFgiGUhVMvs5RGQiVIh3jj_Ij-8g2wQCLcB/s1600/Old.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="112" src="https://4.bp.blogspot.com/-Zax9qipDNW0/V9FzSGAKu_I/AAAAAAAAE88/jKMFgiGUhVMvs5RGQiVIh3jj_Ij-8g2wQCLcB/s320/Old.JPG" width="320" /></a></div>
<div style="text-align: center;">
<span style="font-family: "verdana";">Old location > C:\Windows\CCM\SCClient.exe</span></div>
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-H_ve-BvduOg/V9FzWBT-D-I/AAAAAAAAE9A/e20lMHco6HEa8twZVQZBm4F5ft0BiyiggCLcB/s1600/New.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" height="176" src="https://2.bp.blogspot.com/-H_ve-BvduOg/V9FzWBT-D-I/AAAAAAAAE9A/e20lMHco6HEa8twZVQZBm4F5ft0BiyiggCLcB/s320/New.JPG" width="320" /></a></div>
<div style="text-align: center;">
<span style="font-family: "verdana";">New location > C:\Windows\CCM\ClientUX\SCClient.exe</span></div>
<span style="font-family: "verdana";"></span><br />
<span style="font-family: "verdana";">So yes, you can offer both old and new Software Center, where the old one only showing software packages, and the new one offers both software packages and applications. Long story short: after changing the shortcut in Group Policy Preferences, the issue was gone. Happy with this easy solution ;-)</span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com3tag:blogger.com,1999:blog-7396481053359703519.post-35795658016770578822016-09-07T16:26:00.000+02:002016-09-07T16:26:09.798+02:00Update Rollup 1 for ConfigMgr Current Branch, version 1606 available now!<span style="font-family: Verdana, sans-serif;">Today the following ConfigMgr update is released: <strong>Update Rollup 1 for ConfigMgr Current Branch, version 1606</strong>. It fixes 16 issues and 1 additional change is included. </span><span style="font-family: Verdana, sans-serif;">It sounds like a cumulative update with many improvements to me :) Let's have a look at the fixes.</span><br />
<span style="font-family: Verdana, sans-serif;"></span><br />
<span style="font-family: Verdana, sans-serif;"><u>This update includes the following improvements:</u></span><br />
<span style="font-family: Verdana;">-Administrator Console (1 fix)<br />-Updates and servicing (1 fix)<br />-Client (4 fixes)</span><br />
<span style="font-family: Verdana;">-Software Updates (2 fixes)</span><br />
<span style="font-family: Verdana;">-Site Systems (1 fix)</span><br />
<span style="font-family: Verdana;">-Operating System Deployment (1 fix)</span><br />
<span style="font-family: Verdana;">-Windows Store for Business (4 fixes)</span><br />
<span style="font-family: Verdana;">-Software distribution and content management (1 fix)</span><br />
<span style="font-family: Verdana;">-Endpoint Protection (1 fix)</span><br />
<span style="font-family: Verdana;"><br /><u>Additional changes included in this update:</u><br />-<strong>Windows Server 2016</strong> is now available in the supported platform list for Content Distribution, Software Update Management, and Settings Management.<br />
<br />
This update is available for installation in the Updates and Servicing node of the ConfigMgr console. If the service connection point is in offline mode, you have to re-import the update so that it is listed in the ConfigMgr console. Refer to Install <a href="https://technet.microsoft.com/en-US/library/mt607046.aspx" target="_blank"><span style="color: purple;">Updates for System Center Configuration Manager</span></a> for details.<br />
<br />
For more details and to view the full list of new features in this update check out our <a href="https://support.microsoft.com/en-us/kb/3186654" target="_blank"><span style="color: purple;">documentation on TechNet</span></a>.</span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0tag:blogger.com,1999:blog-7396481053359703519.post-65488742505816270012016-09-06T15:55:00.000+02:002016-09-06T16:00:08.802+02:00Create and deploy a Wi-Fi profile with pre-shared key in Microsoft Intune<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;">Recently I wanted to deploy a Wi-Fi profile with pre-shared key in Microsoft Intune. This both on Windows 10 Enterprise (Surface Pro 3) and Mobile (Lumia 950). </span><span style="font-family: "verdana" , sans-serif;">This is described on multiple blogposts and can be done in various ways. But after some hours digging it still didn't work. Finally I found a solution which did the trick. In this blogpost I share my thoughts about it.</span></span></span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">Within Intune you can choose between a Custom configuration policy or Wi-Fi import (Windows 8.1 or later). With both solutions you need an XML file with the Wi-Fi configuration. This file can be created with the command: <strong>netsh wlan export profile name="ProfileName" folder="Source"</strong>. When not sure which ProfileName to choose, use the command <strong>netsh wlan show profiles</strong> to see an overview of all Wi-Fi connections used before.</span><br />
<span style="font-family: "verdana" , sans-serif;"> </span><br />
<span style="font-family: "verdana" , sans-serif;"><u>Let's have a look at both solutions now:</u></span><br />
<span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana" , sans-serif;"><span style="font-family: "verdana";">-<strong>Wi-Fi import:</strong> </span>Use the Windows Wi-Fi Import Policy to import a set of Wi-Fi settings that you can then deploy to the required user or device groups. Didn't used this solution myself, because this one is without a pre-shared key. More information can be found </span></span><a href="https://docs.microsoft.com/en-us/intune/deploy-use/wi-fi-connections-in-microsoft-intune" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">HERE</span></strong></a><span style="font-family: "verdana" , sans-serif;">.</span><br />
<span style="font-family: "verdana" , sans-serif;">-<strong>Custom configuration policy:</strong> To create a Wi-Fi profile with a pre-shared key for Android or Windows, or an EAP-based Wi-Fi profile, when you create a policy choose Custom Configuration for that device platform, rather than a Wi-Fi profile. This is based on a OMA-URI setting instead of a profile. More information can be found </span><a href="https://docs.microsoft.com/en-us/intune/deploy-use/pre-shared-key-wi-fi-profile" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">HERE</span></strong></a><span style="font-family: "verdana" , sans-serif;">.</span><br />
<span style="font-family: "verdana" , sans-serif;"> </span><br />
<span style="font-family: "verdana" , sans-serif;">Trick is there's an typo in the solution mentioned. In the document <strong>./Vendor/MSFT/Wi-Fi/Profile/<SSID>/Settings</strong> is mentioned, where <strong>./Vendor/MSFT/WiFi/Profile/<SSID>/Settings</strong> must be used. Still deployment of Wi-Fi profiles didn't work out for me. Looking on another page a different OMA-URI setting was used, <strong>./Vendor/MSFT/WiFi/Profile/MyNetwork/WlanXml</strong>. This one was working right away! Very confusing to see different solutions mentioned on Microsoft websites if you ask me. More information about that </span><a href="https://blogs.technet.microsoft.com/intunesupport/2016/01/07/microsoft-intune-support-tip-how-to-deploy-a-wi-fi-profile-to-windows-phone-using-a-pre-shared-key-psk/" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">HERE</span></strong></a><span style="font-family: "verdana" , sans-serif;">. </span><br />
<span style="font-family: "verdana" , sans-serif;"> </span><br />
<span style="font-family: "verdana" , sans-serif;">Nice thing is you can add additional OMA-URI settings too. This to disable Wi-Fi sense (sharing Wi-Fi profiles) and some other cool things ;). This setting is called <strong>AllowInternetSharing</strong> and can be found </span><a href="https://docs.microsoft.com/en-us/intune/deploy-use/windows-10-policy-settings-in-microsoft-intune" target="_blank"><strong><span style="font-family: "verdana" , sans-serif;">HERE</span></strong></a><span style="font-family: "verdana" , sans-serif;">. </span><br />
<span style="font-family: "verdana" , sans-serif;"></span><br />
<span style="font-family: "verdana" , sans-serif;">In the end the following is seen on my mobile device:</span><br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-6Smb8JeHo14/V87J5Tdc5fI/AAAAAAAAE8o/b9I9kOtTOVgQ3Z3SLpOW3WD5K2H8u21LQCLcB/s1600/Capture.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="154" src="https://1.bp.blogspot.com/-6Smb8JeHo14/V87J5Tdc5fI/AAAAAAAAE8o/b9I9kOtTOVgQ3Z3SLpOW3WD5K2H8u21LQCLcB/s320/Capture.JPG" width="320" /></span></a></div>
<div class="separator" style="clear: both; text-align: center;">
<a href="https://1.bp.blogspot.com/-bif51MARlo4/V87KV2TrakI/AAAAAAAAE8s/PXC5JVbN1O4MI7GqQj77_mni36dFAYdQQCLcB/s1600/Capture1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><span style="font-family: "verdana" , sans-serif;"><img border="0" height="177" src="https://1.bp.blogspot.com/-bif51MARlo4/V87KV2TrakI/AAAAAAAAE8s/PXC5JVbN1O4MI7GqQj77_mni36dFAYdQQCLcB/s320/Capture1.JPG" width="320" /></span></a></div>
<span style="font-family: "verdana" , sans-serif;">Just great if you ask me! ;)</span>Henk Hoogendoornhttp://www.blogger.com/profile/01066841733613965112noreply@blogger.com0