Since December 8, 2015 ConfigMgr Current Branch is Generally Available. This based on version 1511, which stands for November 2015 (MMYY). Since this release (and even before that too), there are monthly features added in Technical Preview, which are merged in public release (1602, 1606). Let's have a look at new features so far. When available this blogpost will be updated with new releases.
Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Really love the speed on new builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)
New features in production so far:
[1610]
Deny previously approved application requests:
As an administrator you can deny a previously approved application request. To install this application later, users must resubmit a request. This does not uninstall the application.
Exclude clients from automatic upgrade:
When you configure settings to control how clients automatically upgrade you can now specify a collection to exclude specific clients from the upgrade. This applies to automatic upgrade as well as other methods such as software update-based upgrade. This can be used for a collection of computers that need greater care when upgrading the client.
Filter by content size in automatic deployment rules:
Use the content size filter in automatic deployment rules to prevent large software updates from automatically downloading to better support simplified Windows down-level servicing when network bandwidth is limited.
Improvements to the notification experience for high-impact task sequence and required application deployments:
Task sequence deployments that have a high-impact to the end user, for example operating system deployments, now display more intrusive notifications. However, end users can dismiss (snooze) these notifications, and control when they reappear. Any relevant client settings for notification frequency are still honored.
[1609]
Android, iOS, and Windows Additional Settings:
New settings have been added for Android, iOS, and Windows.
Boundary Group Improvements:
Improvements have been made to boundary groups to allow more granular control of fallback behavior, and greater clarity of what distribution points are used.
Deploy Office 365 apps to clients:
We have added a new Office 365 Servicing node in the Software Library where you can deploy Office 365 apps to clients.
Improvements for BIOS to UEFI conversion:
An OS deployment task sequence can now be customized with a new variable, TSUEFIDrive, so that the Restart Computer step will prepare the drive for transition to UEFI. See the documentation for additional details on the necessary customizations.
Intune Compliance Charts:
Administrators can get a quick view of overall compliance, and top reasons for non-compliance using new charts under Monitoring.
Native Connection Types for Windows 10 VPN Profiles:
You can now create Windows 10 VPN profiles with Microsoft Automatic, IKEv2, and PPTP connection types in the Configuration Manager console without using OMA-URI.
Office 365 Servicing Dashboard:
Use the Office 365 servicing dashboard to track Office 365 updates and deployments.
TouchID, ApplePay and Zoom DEP Settings:
DEP provides the ability for admins to create enrollment profiles to skip initial setup screens for new iOS devices. TouchID, ApplePay and Zoom have now been added as options to configure in the iOS enrollment profiles.
Windows 10 Upgrade Analytics:
Assess and analyze device readiness and compatibility with Windows 10 to allow smoother upgrades. This is done through integration with Windows Upgrade Analytics.
Windows Store for Business:
Windows Store for Business allows administrators to obtain applications (purchased or free) and deploy them to users in their organization.
[1608]
Application Requests from Software Center:
Users are now able to request approval for applications and view the request history for applications in the Application Details view in Software Center. The Request button in Application Details no longer redirects to the web-based Application Catalog.
Improvements to Asset Intelligence:
In the Configuration Manager 1608 Technical Preview, we have added a field to the properties for inventoried software that lets you set a parent and child relationship with other software. In the Inventoried Software list, you can view the parent of any software and also hide all child software.
New Software Indicators in Software Center:
The Software Center Applications, Updates, and Operating Systems tabs now show what software was recently added. Numbers in the navigation pane show how many new pieces of software are in each tab.
Remote Control Keyboard Translation:
In a remote control session, keys typed are now mapped by default to the sharer's keyboard when the keyboard languages do not match, so that the viewer is able to type normally. This behavior may be turned off in the Remote Control viewer Action menu.
[1607]
Customizable Branding for End-User Dialogs:
End-user dialogs that are opened from Software Center or taskbar notifications now show the same organization name, color and icon branding as Software Center. The administrator workflow for specifying branding settings remains unchanged.
Manage duplicate hardware identifiers:
Add known duplicate MAC addresses or SMBIOS IDs to be ignored hierarchy-wide for PXE boot and client registration.
Microsoft Operations Management Suite (OMS) Connector:
Sync data such as collections from ConfigMgr to OMS.
Windows 10 Edition Upgrade:
Upgrade Configuration Manager clients running Windows 10 Professional edition to Windows 10 Enterprise edition with just a product key; no reimaging required.
Part 1 of this series can be found HERE.
Will be updated with further 2016 updates!
Showing posts with label Technical Preview. Show all posts
Showing posts with label Technical Preview. Show all posts
Wednesday, October 19, 2016
New ConfigMgr Current Branch features from 1511 till now! (part 2)
Labels:
1511,
1607,
1608,
1609,
1610,
1611,
1612,
ConfigMgr as a service,
ConfigMgr Current Branch,
Technical Preview
Wednesday, October 12, 2016
New ConfigMgr Current Branch features from 1511 till now! (part 1)
Since December 8, 2015 ConfigMgr Current Branch is Generally Available. This based on version 1511, which stands for November 2015 (MMYY). Since this release (and even before that too), there are monthly features added in Technical Preview, which are merged in public release (1602, 1606). Let's have a look at new features so far. When available this blogpost will be updated with new releases.
Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Really love the speed on new builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)
New features in production so far:
[1606]
Cloud Proxy Service:
The Cloud Proxy Service provides a simple way to manage ConfigMgr clients on the Internet. The service, which is deployed to Microsoft Azure and requires an Azure subscription, connects to your on-premises ConfigMgr infrastructure using a new role called the cloud proxy connector point. You use the ConfigMgr console to deploy the service and configure the supported roles to allow cloud proxy traffic. Cloud Proxy Service currently only supports the management point, distribution point, and software update point roles.
Device Categories:
You can create device categories, which can be used to automatically place devices in device collections when used in hybrid environments. Users are then required to choose a device category when they enroll a device in Intune.
Device Guard: ConfigMgr as a managed installer with manual client configuration:
Administrators can use the new Managed Installer AppLocker rules to configure clients so that ConfigMgr-deployed software is automatically trusted, but software from other sources is not. You cannot currently configure this functionality from the ConfigMgr console. Use the instructions at this blog post to manually configure client computers to use this functionality.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Enforcement grace period for application and software update deployments:
Give users a grace period to install required application or software updates beyond any deadlines you configured after their computers are offline for an extended period of time.
Multiple device management points available for enrolled Windows 10 Anniversary Edition devices:
On-premises Mobile Device Management (MDM) supports a new capability in Windows 10 Anniversary Edition (Redstone 1) that automatically configures an enrolled device to have more than one device management point available for use. This capability allows the device to fallback to another device management point when the one it was using is not available.
You can deploy offline-licensed applications to a Windows 10 desktop PC managed by on-premises MDM:
You can deploy an app with an offline license from the Windows Store for Business to a Windows 10 PC managed by on-premises MDM.
[1605]
Auto-Connect App List in Windows 10 VPN Profiles:
Admins can specify desktop and universal applications in Windows 10 VPN profiles that automatically establish a connection with the VPN when launched on the client. Admins can decide whether or not to limit VPN traffic to the apps in the list.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Improvements to the Install Software Updates task sequence step:
This release includes improvements to smsts.log to help you troubleshoot, and a new task sequence variable, SMSTSSoftwareUpdateScanTimeout, to control the timeout on the software updates scan during the Install Software Updates task sequence step.
New tabs for Updates and Operating Systems in Software Center:
Software Updates and Operating Systems now have their own respective tabs in Software Center, rather than being accessible via the categories dropdown in the Applications tab.
On-premises Health Attestation Service integration:
Collect Health Attestation information via on-premises Health Attestation Service with a few critical bug fixes from 1604 Technical Preview.
Pre-Declare Corporate Owned Devices:
You can now identify corporate-owned devices by importing their international station mobile equipment identity (IMEI) numbers. You can upload a comma-separated values (.csv) file containing device IMEI numbers or you can manually enter device information. You can also import serial numbers for iOS devices. Imported information will set ownership of the devices that enroll as “Corporate”. An Intune license is still required for each user that accesses the service. View a video walkthrough of the Pre-declare Corporate Owned Devices feature.
Remote Device Actions Experience Update:
The admin experience for wiping, resetting the passcode, remote locking, and bypassing iOS Activation Lock on mobile devices has been adjusted. The states of these actions are now part of the devices' details and properties.
Remote Full Wipe for Windows 10 desktop devices:
Support for remotely wiping and resetting Windows 10 desktop devices to factory settings.
Server groups:
Control settings for software updates in server groups, including the order and percentage of devices that can be updated at any one time. These capabilities introduce some enhancements over our pre-release "Servicing a cluster aware collection" feature, including the ability to control the order and better monitoring.
Windows 10 Enterprise Data Protection policies:
Enterprise data protection (EDP) policy settings - with this technical preview, you can create and deploy EDP policies for Windows devices running Windows 10 Insider Preview and Windows 10 Mobile Preview builds, including specifying apps, defining network boundaries, choosing the restriction modes and other EDP settings.
Windows Defender Advanced Threat Protection:
Manage Windows Defender Advanced Threat Protection policies for onboarding and offboarding Windows 10 clients to the cloud service, and view agent health in the monitoring dashboard. (Requires a Windows Defender ATP tenant in Azure.)
Windows Store for Business Integration:
ConfigMgr can manage and deploy applications purchased through the Windows Store for Business portal for both online and offline licensed apps. The 1605 Technical Preview adds the ability to create both online and offline apps with the ability to deploy offline apps to Intune and ConfigrMgr managed devices. View video walkthroughs of how to set up and deploy Windows Store for Business apps.
[1604]
Client cache size:
We added a new item to Client Settings called "Client Cache Settings". Use this to configure the client cache size as a percentage of overall disk space and megabytes.
Client Peer Cache:
A built-in ConfigMgr solution for clients to share content with other clients, directly from their local Cache with monitoring and troubleshooting capabilities.
Passport for Work:
Administrators can now deploy Passport for Work policies to domain-joined Windows 10 devices managed by the ConfigMgr client.
Policy Setting to Disable Smart Lock and other Trust Agents:
Hybrid administrators can now deploy a policy in the ConfigMgr console that disables Smart Lock and other trust agents from being used to circumvent passcode policy on devices running Android 5.0 or higher.
Software Updates Compliance Dashboard:
The Software Updates Dashboard continues our commitment to helping you keep your devices up to date with the latest security updates and Windows features. The dashboard allows you to view the current compliance status of devices in your organization and quickly analyze the data to see which devices are at risk.
Switch Software Update Point:
Administrators will be able to switch Software Update Points for clients when there are multiple SUPs available on a primary site. Administrators should use this option when clients are failing SUM scenarios due to SUP/WSUS issues on their assigned SUP. When administrators switch SUPs for a collection of clients, the selected clients will look for another SUP at the next scan interval. To try out this change go to the Asset and Compliance tab -> Device Collections -> and in the context menu of a device collection click on "Switch to Next Software Update Point".
VPN for Windows 10:
You can use 3rd party VPN providers for computers with the ConfigMgr client. These include Pulse Secure, F5 Edge, Dell SonicWall and Checkpoint.
[1603]
List View for Applications in Software Center:
In the Software Center Applications tab, users now have the option to switch between the default tile view and a new list view by clicking on the view selection icons underneath the search bar.
Install Selected Updates in Software Center:
In the new Updates tab in Software Center, click on the select mode button at the top left of the list of updates. In select mode, multiple updates may be selected and then simultaneously installed using the Install Selected button.
Content Status links in the Admin Console:
The Content Status links for objects like applications, packages, task sequences or software updates, now go directly to the related Content Status object node.
PXE Provider TFTP Window Size:
The administrator can now configure the TFTP window size (RamDiskTFTPWindowSize) via a registry setting on the PXE-enabled distribution point.
Limit access to the Clipboard in Remote Control Sessions:
You can now enable the remote tools client setting "Prompt user for shared clipboard file transfer permission" to limit access to the shared clipboard in a remote control session. When enabled, the end-user who is sharing a remote session must grant permissions to the viewer of that session before they can transfer files from the shared clipboard.
[1602]
Support for in-place upgrade of ConfigMgr Site Server's operating system:
In-place upgrade of the ConfigMgr's Site Server's operating system from Windows Server 2008 R2 to Windows Server 2012 R2 is now supported.
Sync Policy button in Software Center:
The new Sync Policy button helps you keep machine and user policies in sync. The button is available through the Software Center options tab, under Computer Maintenance.
Automatic creation of Microsoft Office mobile apps for iOS and Android:
Microsoft Office mobile apps for iOS and Android are pre-created for users using ConfigMgr integrated with Microsoft Intune.
iOS Activation Lock management:
iOS Activation Lock management capabilities include: enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices.
[1601]
Windows 10 Team configuration settings:
New configuration settings added and supported for Windows 10 Team when using either Intune managed (hybrid) devices, or ConfigMgr full client devices.
Windows 10 Microsoft Edge configuration settings:
Specify Windows 10 Edge settings and assign them to users or devices in their organization.
Windows 10 Conditional Access new compliance checks:
Set 3 new compliance checks: require a password to unlock an idle device, time until the device is locked, and require automatic updates with minimum classification. These policy rules are evaluated as part of overall device compliance.
Windows 10 Conditional Access with Health Attestation service:
For Intune managed devices, Windows 10 Health Attestation data can be used as part of device compliance when used with Conditional Access.
Device Compliance report:
Device Compliance report provides you the number and percentage of devices and their compliance state for each compliance policy.
Windows 10 Health Attestation service reports:
Users can view reports on Windows 10 Health Attestation data collected by Intune. Windows 10 device Health Attestation helps evaluate the vulnerability of Windows 10 desktop and mobile devices.
Kiosk mode for Samsung KNOX devices:
ConfigMgr kiosk mode allows you to lock a managed mobile device only to allow certain features. For example, you can allow a device only to run a specific managed app, or you can disable the device's volume buttons.
Client Online Status:
View the online status of devices in Assets and Compliance. New icons indicate the status of a device as online or offline.
Conditional Access for ConfigMgr Managed PCs:
To help secure Office 365 access and other services on PCs enrolled with ConfigMgr, use Conditional Access. Conditions that can be used to control access include: Workplace Join, BitLocker, Antimalware, and Software Updates.
On-Premises Exchange Default Rule Override:
Set a default on-premises Exchange rule to block mobile devices from accessing email. You can allow Intune-enrolled and compliant mobile devices to access mail. You can also choose to override the default Exchange rule to allow Intune-enrolled and compliant devices to access email, even when the default rule is set to Block or Quarantine.
iOS App Configuration:
Create and deploy iOS app configuration policies to dynamically change settings such as server name or port for iOS applications that support configuration.
Apple Volume Purchase Program:
ConfigMgr can manage and deploy applications purchased through the Apple Volume Purchase Program for Business portal.
[1512]
New antimalware policy settings:
Added settings for protection against Potentially Unwanted Applications, user control of automatic sample submission, and scanning of network drives during a full scan.
Device Health Attestation:
Users are able to view the status of Windows 10 Device Health Attestation in the ConfigMgr console, to ensure that client computers have trustworthy BIOS, TPM, and boot software.
User acceptance of Terms and Conditions:
Users who use ConfigMgr integrated with Intune (hybrid) can view which users have accepted the Terms and Conditions configured by IT and which users have not, right from the ConfigMgr console.
Will be continued in a next blogpost!
Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Really love the speed on new builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)
New features in production so far:
[1606]
Cloud Proxy Service:
The Cloud Proxy Service provides a simple way to manage ConfigMgr clients on the Internet. The service, which is deployed to Microsoft Azure and requires an Azure subscription, connects to your on-premises ConfigMgr infrastructure using a new role called the cloud proxy connector point. You use the ConfigMgr console to deploy the service and configure the supported roles to allow cloud proxy traffic. Cloud Proxy Service currently only supports the management point, distribution point, and software update point roles.
Device Categories:
You can create device categories, which can be used to automatically place devices in device collections when used in hybrid environments. Users are then required to choose a device category when they enroll a device in Intune.
Device Guard: ConfigMgr as a managed installer with manual client configuration:
Administrators can use the new Managed Installer AppLocker rules to configure clients so that ConfigMgr-deployed software is automatically trusted, but software from other sources is not. You cannot currently configure this functionality from the ConfigMgr console. Use the instructions at this blog post to manually configure client computers to use this functionality.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Enforcement grace period for application and software update deployments:
Give users a grace period to install required application or software updates beyond any deadlines you configured after their computers are offline for an extended period of time.
Multiple device management points available for enrolled Windows 10 Anniversary Edition devices:
On-premises Mobile Device Management (MDM) supports a new capability in Windows 10 Anniversary Edition (Redstone 1) that automatically configures an enrolled device to have more than one device management point available for use. This capability allows the device to fallback to another device management point when the one it was using is not available.
You can deploy offline-licensed applications to a Windows 10 desktop PC managed by on-premises MDM:
You can deploy an app with an offline license from the Windows Store for Business to a Windows 10 PC managed by on-premises MDM.
[1605]
Auto-Connect App List in Windows 10 VPN Profiles:
Admins can specify desktop and universal applications in Windows 10 VPN profiles that automatically establish a connection with the VPN when launched on the client. Admins can decide whether or not to limit VPN traffic to the apps in the list.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Improvements to the Install Software Updates task sequence step:
This release includes improvements to smsts.log to help you troubleshoot, and a new task sequence variable, SMSTSSoftwareUpdateScanTimeout, to control the timeout on the software updates scan during the Install Software Updates task sequence step.
New tabs for Updates and Operating Systems in Software Center:
Software Updates and Operating Systems now have their own respective tabs in Software Center, rather than being accessible via the categories dropdown in the Applications tab.
On-premises Health Attestation Service integration:
Collect Health Attestation information via on-premises Health Attestation Service with a few critical bug fixes from 1604 Technical Preview.
Pre-Declare Corporate Owned Devices:
You can now identify corporate-owned devices by importing their international station mobile equipment identity (IMEI) numbers. You can upload a comma-separated values (.csv) file containing device IMEI numbers or you can manually enter device information. You can also import serial numbers for iOS devices. Imported information will set ownership of the devices that enroll as “Corporate”. An Intune license is still required for each user that accesses the service. View a video walkthrough of the Pre-declare Corporate Owned Devices feature.
Remote Device Actions Experience Update:
The admin experience for wiping, resetting the passcode, remote locking, and bypassing iOS Activation Lock on mobile devices has been adjusted. The states of these actions are now part of the devices' details and properties.
Remote Full Wipe for Windows 10 desktop devices:
Support for remotely wiping and resetting Windows 10 desktop devices to factory settings.
Server groups:
Control settings for software updates in server groups, including the order and percentage of devices that can be updated at any one time. These capabilities introduce some enhancements over our pre-release "Servicing a cluster aware collection" feature, including the ability to control the order and better monitoring.
Windows 10 Enterprise Data Protection policies:
Enterprise data protection (EDP) policy settings - with this technical preview, you can create and deploy EDP policies for Windows devices running Windows 10 Insider Preview and Windows 10 Mobile Preview builds, including specifying apps, defining network boundaries, choosing the restriction modes and other EDP settings.
Windows Defender Advanced Threat Protection:
Manage Windows Defender Advanced Threat Protection policies for onboarding and offboarding Windows 10 clients to the cloud service, and view agent health in the monitoring dashboard. (Requires a Windows Defender ATP tenant in Azure.)
Windows Store for Business Integration:
ConfigMgr can manage and deploy applications purchased through the Windows Store for Business portal for both online and offline licensed apps. The 1605 Technical Preview adds the ability to create both online and offline apps with the ability to deploy offline apps to Intune and ConfigrMgr managed devices. View video walkthroughs of how to set up and deploy Windows Store for Business apps.
[1604]
Client cache size:
We added a new item to Client Settings called "Client Cache Settings". Use this to configure the client cache size as a percentage of overall disk space and megabytes.
Client Peer Cache:
A built-in ConfigMgr solution for clients to share content with other clients, directly from their local Cache with monitoring and troubleshooting capabilities.
Passport for Work:
Administrators can now deploy Passport for Work policies to domain-joined Windows 10 devices managed by the ConfigMgr client.
Policy Setting to Disable Smart Lock and other Trust Agents:
Hybrid administrators can now deploy a policy in the ConfigMgr console that disables Smart Lock and other trust agents from being used to circumvent passcode policy on devices running Android 5.0 or higher.
Software Updates Compliance Dashboard:
The Software Updates Dashboard continues our commitment to helping you keep your devices up to date with the latest security updates and Windows features. The dashboard allows you to view the current compliance status of devices in your organization and quickly analyze the data to see which devices are at risk.
Switch Software Update Point:
Administrators will be able to switch Software Update Points for clients when there are multiple SUPs available on a primary site. Administrators should use this option when clients are failing SUM scenarios due to SUP/WSUS issues on their assigned SUP. When administrators switch SUPs for a collection of clients, the selected clients will look for another SUP at the next scan interval. To try out this change go to the Asset and Compliance tab -> Device Collections -> and in the context menu of a device collection click on "Switch to Next Software Update Point".
VPN for Windows 10:
You can use 3rd party VPN providers for computers with the ConfigMgr client. These include Pulse Secure, F5 Edge, Dell SonicWall and Checkpoint.
[1603]
List View for Applications in Software Center:
In the Software Center Applications tab, users now have the option to switch between the default tile view and a new list view by clicking on the view selection icons underneath the search bar.
Install Selected Updates in Software Center:
In the new Updates tab in Software Center, click on the select mode button at the top left of the list of updates. In select mode, multiple updates may be selected and then simultaneously installed using the Install Selected button.
Content Status links in the Admin Console:
The Content Status links for objects like applications, packages, task sequences or software updates, now go directly to the related Content Status object node.
PXE Provider TFTP Window Size:
The administrator can now configure the TFTP window size (RamDiskTFTPWindowSize) via a registry setting on the PXE-enabled distribution point.
Limit access to the Clipboard in Remote Control Sessions:
You can now enable the remote tools client setting "Prompt user for shared clipboard file transfer permission" to limit access to the shared clipboard in a remote control session. When enabled, the end-user who is sharing a remote session must grant permissions to the viewer of that session before they can transfer files from the shared clipboard.
[1602]
Support for in-place upgrade of ConfigMgr Site Server's operating system:
In-place upgrade of the ConfigMgr's Site Server's operating system from Windows Server 2008 R2 to Windows Server 2012 R2 is now supported.
Sync Policy button in Software Center:
The new Sync Policy button helps you keep machine and user policies in sync. The button is available through the Software Center options tab, under Computer Maintenance.
Automatic creation of Microsoft Office mobile apps for iOS and Android:
Microsoft Office mobile apps for iOS and Android are pre-created for users using ConfigMgr integrated with Microsoft Intune.
iOS Activation Lock management:
iOS Activation Lock management capabilities include: enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices.
[1601]
Windows 10 Team configuration settings:
New configuration settings added and supported for Windows 10 Team when using either Intune managed (hybrid) devices, or ConfigMgr full client devices.
Windows 10 Microsoft Edge configuration settings:
Specify Windows 10 Edge settings and assign them to users or devices in their organization.
Windows 10 Conditional Access new compliance checks:
Set 3 new compliance checks: require a password to unlock an idle device, time until the device is locked, and require automatic updates with minimum classification. These policy rules are evaluated as part of overall device compliance.
Windows 10 Conditional Access with Health Attestation service:
For Intune managed devices, Windows 10 Health Attestation data can be used as part of device compliance when used with Conditional Access.
Device Compliance report:
Device Compliance report provides you the number and percentage of devices and their compliance state for each compliance policy.
Windows 10 Health Attestation service reports:
Users can view reports on Windows 10 Health Attestation data collected by Intune. Windows 10 device Health Attestation helps evaluate the vulnerability of Windows 10 desktop and mobile devices.
Kiosk mode for Samsung KNOX devices:
ConfigMgr kiosk mode allows you to lock a managed mobile device only to allow certain features. For example, you can allow a device only to run a specific managed app, or you can disable the device's volume buttons.
Client Online Status:
View the online status of devices in Assets and Compliance. New icons indicate the status of a device as online or offline.
Conditional Access for ConfigMgr Managed PCs:
To help secure Office 365 access and other services on PCs enrolled with ConfigMgr, use Conditional Access. Conditions that can be used to control access include: Workplace Join, BitLocker, Antimalware, and Software Updates.
On-Premises Exchange Default Rule Override:
Set a default on-premises Exchange rule to block mobile devices from accessing email. You can allow Intune-enrolled and compliant mobile devices to access mail. You can also choose to override the default Exchange rule to allow Intune-enrolled and compliant devices to access email, even when the default rule is set to Block or Quarantine.
iOS App Configuration:
Create and deploy iOS app configuration policies to dynamically change settings such as server name or port for iOS applications that support configuration.
Apple Volume Purchase Program:
ConfigMgr can manage and deploy applications purchased through the Apple Volume Purchase Program for Business portal.
[1512]
New antimalware policy settings:
Added settings for protection against Potentially Unwanted Applications, user control of automatic sample submission, and scanning of network drives during a full scan.
Device Health Attestation:
Users are able to view the status of Windows 10 Device Health Attestation in the ConfigMgr console, to ensure that client computers have trustworthy BIOS, TPM, and boot software.
User acceptance of Terms and Conditions:
Users who use ConfigMgr integrated with Intune (hybrid) can view which users have accepted the Terms and Conditions configured by IT and which users have not, right from the ConfigMgr console.
Will be continued in a next blogpost!
Labels:
1511,
1512,
1601,
1602,
1603,
1604,
1605,
1606,
ConfigMgr as a service,
ConfigMgr Current Branch,
Technical Preview
New ConfigMgr Current Branch features from 1511 till now! (part 1)
Since December 8, 2015 ConfigMgr Current Branch is Generally Available. This based on version 1511, which stands for November 2015 (MMYY). Since this release (and even before that too), there are monthly features added in Technical Preview, which are merged in public release (1602, 1606). Let's have a look at new features so far. When available this blogpost will be updated with new releases.
Really love the speed on new (Windows and ConfigMgr) builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)
Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Let's have a look at new features (in production) so far:
[1606]
Cloud Proxy Service:
The Cloud Proxy Service provides a simple way to manage ConfigMgr clients on the Internet. The service, which is deployed to Microsoft Azure and requires an Azure subscription, connects to your on-premises ConfigMgr infrastructure using a new role called the cloud proxy connector point. You use the ConfigMgr console to deploy the service and configure the supported roles to allow cloud proxy traffic. Cloud Proxy Service currently only supports the management point, distribution point, and software update point roles.
Device Categories:
You can create device categories, which can be used to automatically place devices in device collections when used in hybrid environments. Users are then required to choose a device category when they enroll a device in Intune.
Device Guard: ConfigMgr as a managed installer with manual client configuration:
Administrators can use the new Managed Installer AppLocker rules to configure clients so that ConfigMgr-deployed software is automatically trusted, but software from other sources is not. You cannot currently configure this functionality from the ConfigMgr console. Use the instructions at this blog post to manually configure client computers to use this functionality.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Enforcement grace period for application and software update deployments:
Give users a grace period to install required application or software updates beyond any deadlines you configured after their computers are offline for an extended period of time.
Multiple device management points available for enrolled Windows 10 Anniversary Edition devices:
On-premises Mobile Device Management (MDM) supports a new capability in Windows 10 Anniversary Edition (Redstone 1) that automatically configures an enrolled device to have more than one device management point available for use. This capability allows the device to fallback to another device management point when the one it was using is not available.
You can deploy offline-licensed applications to a Windows 10 desktop PC managed by on-premises MDM:
You can deploy an app with an offline license from the Windows Store for Business to a Windows 10 PC managed by on-premises MDM.
[1605]
Auto-Connect App List in Windows 10 VPN Profiles:
Admins can specify desktop and universal applications in Windows 10 VPN profiles that automatically establish a connection with the VPN when launched on the client. Admins can decide whether or not to limit VPN traffic to the apps in the list.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Improvements to the Install Software Updates task sequence step:
This release includes improvements to smsts.log to help you troubleshoot, and a new task sequence variable, SMSTSSoftwareUpdateScanTimeout, to control the timeout on the software updates scan during the Install Software Updates task sequence step.
New tabs for Updates and Operating Systems in Software Center:
Software Updates and Operating Systems now have their own respective tabs in Software Center, rather than being accessible via the categories dropdown in the Applications tab.
On-premises Health Attestation Service integration:
Collect Health Attestation information via on-premises Health Attestation Service with a few critical bug fixes from 1604 Technical Preview.
Pre-Declare Corporate Owned Devices:
You can now identify corporate-owned devices by importing their international station mobile equipment identity (IMEI) numbers. You can upload a comma-separated values (.csv) file containing device IMEI numbers or you can manually enter device information. You can also import serial numbers for iOS devices. Imported information will set ownership of the devices that enroll as “Corporate”. An Intune license is still required for each user that accesses the service. View a video walkthrough of the Pre-declare Corporate Owned Devices feature.
Remote Device Actions Experience Update:
The admin experience for wiping, resetting the passcode, remote locking, and bypassing iOS Activation Lock on mobile devices has been adjusted. The states of these actions are now part of the devices' details and properties.
Remote Full Wipe for Windows 10 desktop devices:
Support for remotely wiping and resetting Windows 10 desktop devices to factory settings.
Server groups:
Control settings for software updates in server groups, including the order and percentage of devices that can be updated at any one time. These capabilities introduce some enhancements over our pre-release "Servicing a cluster aware collection" feature, including the ability to control the order and better monitoring.
Windows 10 Enterprise Data Protection policies:
Enterprise data protection (EDP) policy settings - with this technical preview, you can create and deploy EDP policies for Windows devices running Windows 10 Insider Preview and Windows 10 Mobile Preview builds, including specifying apps, defining network boundaries, choosing the restriction modes and other EDP settings.
Windows Defender Advanced Threat Protection:
Manage Windows Defender Advanced Threat Protection policies for onboarding and offboarding Windows 10 clients to the cloud service, and view agent health in the monitoring dashboard. (Requires a Windows Defender ATP tenant in Azure.)
Windows Store for Business Integration:
ConfigMgr can manage and deploy applications purchased through the Windows Store for Business portal for both online and offline licensed apps. The 1605 Technical Preview adds the ability to create both online and offline apps with the ability to deploy offline apps to Intune and ConfigrMgr managed devices. View video walkthroughs of how to set up and deploy Windows Store for Business apps.
[1604]
Client cache size:
We added a new item to Client Settings called "Client Cache Settings". Use this to configure the client cache size as a percentage of overall disk space and megabytes.
Client Peer Cache:
A built-in ConfigMgr solution for clients to share content with other clients, directly from their local Cache with monitoring and troubleshooting capabilities.
Passport for Work:
Administrators can now deploy Passport for Work policies to domain-joined Windows 10 devices managed by the ConfigMgr client.
Policy Setting to Disable Smart Lock and other Trust Agents:
Hybrid administrators can now deploy a policy in the ConfigMgr console that disables Smart Lock and other trust agents from being used to circumvent passcode policy on devices running Android 5.0 or higher.
Software Updates Compliance Dashboard:
The Software Updates Dashboard continues our commitment to helping you keep your devices up to date with the latest security updates and Windows features. The dashboard allows you to view the current compliance status of devices in your organization and quickly analyze the data to see which devices are at risk.
Switch Software Update Point:
Administrators will be able to switch Software Update Points for clients when there are multiple SUPs available on a primary site. Administrators should use this option when clients are failing SUM scenarios due to SUP/WSUS issues on their assigned SUP. When administrators switch SUPs for a collection of clients, the selected clients will look for another SUP at the next scan interval. To try out this change go to the Asset and Compliance tab -> Device Collections -> and in the context menu of a device collection click on "Switch to Next Software Update Point".
VPN for Windows 10:
You can use 3rd party VPN providers for computers with the ConfigMgr client. These include Pulse Secure, F5 Edge, Dell SonicWall and Checkpoint.
[1603]
List View for Applications in Software Center:
In the Software Center Applications tab, users now have the option to switch between the default tile view and a new list view by clicking on the view selection icons underneath the search bar.
Install Selected Updates in Software Center:
In the new Updates tab in Software Center, click on the select mode button at the top left of the list of updates. In select mode, multiple updates may be selected and then simultaneously installed using the Install Selected button.
Content Status links in the Admin Console:
The Content Status links for objects like applications, packages, task sequences or software updates, now go directly to the related Content Status object node.
PXE Provider TFTP Window Size:
The administrator can now configure the TFTP window size (RamDiskTFTPWindowSize) via a registry setting on the PXE-enabled distribution point.
Limit access to the Clipboard in Remote Control Sessions:
You can now enable the remote tools client setting "Prompt user for shared clipboard file transfer permission" to limit access to the shared clipboard in a remote control session. When enabled, the end-user who is sharing a remote session must grant permissions to the viewer of that session before they can transfer files from the shared clipboard.
[1602]
Support for in-place upgrade of ConfigMgr Site Server's operating system:
In-place upgrade of the ConfigMgr's Site Server's operating system from Windows Server 2008 R2 to Windows Server 2012 R2 is now supported.
Sync Policy button in Software Center:
The new Sync Policy button helps you keep machine and user policies in sync. The button is available through the Software Center options tab, under Computer Maintenance.
Automatic creation of Microsoft Office mobile apps for iOS and Android:
Microsoft Office mobile apps for iOS and Android are pre-created for users using ConfigMgr integrated with Microsoft Intune.
iOS Activation Lock management:
iOS Activation Lock management capabilities include: enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices.
[1601]
Windows 10 Team configuration settings:
New configuration settings added and supported for Windows 10 Team when using either Intune managed (hybrid) devices, or ConfigMgr full client devices.
Windows 10 Microsoft Edge configuration settings:
Specify Windows 10 Edge settings and assign them to users or devices in their organization.
Windows 10 Conditional Access new compliance checks:
Set 3 new compliance checks: require a password to unlock an idle device, time until the device is locked, and require automatic updates with minimum classification. These policy rules are evaluated as part of overall device compliance.
Windows 10 Conditional Access with Health Attestation service:
For Intune managed devices, Windows 10 Health Attestation data can be used as part of device compliance when used with Conditional Access.
Device Compliance report:
Device Compliance report provides you the number and percentage of devices and their compliance state for each compliance policy.
Windows 10 Health Attestation service reports:
Users can view reports on Windows 10 Health Attestation data collected by Intune. Windows 10 device Health Attestation helps evaluate the vulnerability of Windows 10 desktop and mobile devices.
Kiosk mode for Samsung KNOX devices:
ConfigMgr kiosk mode allows you to lock a managed mobile device only to allow certain features. For example, you can allow a device only to run a specific managed app, or you can disable the device's volume buttons.
Client Online Status:
View the online status of devices in Assets and Compliance. New icons indicate the status of a device as online or offline.
Conditional Access for ConfigMgr Managed PCs:
To help secure Office 365 access and other services on PCs enrolled with ConfigMgr, use Conditional Access. Conditions that can be used to control access include: Workplace Join, BitLocker, Antimalware, and Software Updates.
On-Premises Exchange Default Rule Override:
Set a default on-premises Exchange rule to block mobile devices from accessing email. You can allow Intune-enrolled and compliant mobile devices to access mail. You can also choose to override the default Exchange rule to allow Intune-enrolled and compliant devices to access email, even when the default rule is set to Block or Quarantine.
iOS App Configuration:
Create and deploy iOS app configuration policies to dynamically change settings such as server name or port for iOS applications that support configuration.
Apple Volume Purchase Program:
ConfigMgr can manage and deploy applications purchased through the Apple Volume Purchase Program for Business portal.
[1512]
New antimalware policy settings:
Added settings for protection against Potentially Unwanted Applications, user control of automatic sample submission, and scanning of network drives during a full scan.
Device Health Attestation:
Users are able to view the status of Windows 10 Device Health Attestation in the ConfigMgr console, to ensure that client computers have trustworthy BIOS, TPM, and boot software.
User acceptance of Terms and Conditions:
Users who use ConfigMgr integrated with Intune (hybrid) can view which users have accepted the Terms and Conditions configured by IT and which users have not, right from the ConfigMgr console.
Will be continued in a next blogpost!
Really love the speed on new (Windows and ConfigMgr) builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)
Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Let's have a look at new features (in production) so far:
[1606]
Cloud Proxy Service:
The Cloud Proxy Service provides a simple way to manage ConfigMgr clients on the Internet. The service, which is deployed to Microsoft Azure and requires an Azure subscription, connects to your on-premises ConfigMgr infrastructure using a new role called the cloud proxy connector point. You use the ConfigMgr console to deploy the service and configure the supported roles to allow cloud proxy traffic. Cloud Proxy Service currently only supports the management point, distribution point, and software update point roles.
Device Categories:
You can create device categories, which can be used to automatically place devices in device collections when used in hybrid environments. Users are then required to choose a device category when they enroll a device in Intune.
Device Guard: ConfigMgr as a managed installer with manual client configuration:
Administrators can use the new Managed Installer AppLocker rules to configure clients so that ConfigMgr-deployed software is automatically trusted, but software from other sources is not. You cannot currently configure this functionality from the ConfigMgr console. Use the instructions at this blog post to manually configure client computers to use this functionality.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Enforcement grace period for application and software update deployments:
Give users a grace period to install required application or software updates beyond any deadlines you configured after their computers are offline for an extended period of time.
Multiple device management points available for enrolled Windows 10 Anniversary Edition devices:
On-premises Mobile Device Management (MDM) supports a new capability in Windows 10 Anniversary Edition (Redstone 1) that automatically configures an enrolled device to have more than one device management point available for use. This capability allows the device to fallback to another device management point when the one it was using is not available.
You can deploy offline-licensed applications to a Windows 10 desktop PC managed by on-premises MDM:
You can deploy an app with an offline license from the Windows Store for Business to a Windows 10 PC managed by on-premises MDM.
[1605]
Auto-Connect App List in Windows 10 VPN Profiles:
Admins can specify desktop and universal applications in Windows 10 VPN profiles that automatically establish a connection with the VPN when launched on the client. Admins can decide whether or not to limit VPN traffic to the apps in the list.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Improvements to the Install Software Updates task sequence step:
This release includes improvements to smsts.log to help you troubleshoot, and a new task sequence variable, SMSTSSoftwareUpdateScanTimeout, to control the timeout on the software updates scan during the Install Software Updates task sequence step.
New tabs for Updates and Operating Systems in Software Center:
Software Updates and Operating Systems now have their own respective tabs in Software Center, rather than being accessible via the categories dropdown in the Applications tab.
On-premises Health Attestation Service integration:
Collect Health Attestation information via on-premises Health Attestation Service with a few critical bug fixes from 1604 Technical Preview.
Pre-Declare Corporate Owned Devices:
You can now identify corporate-owned devices by importing their international station mobile equipment identity (IMEI) numbers. You can upload a comma-separated values (.csv) file containing device IMEI numbers or you can manually enter device information. You can also import serial numbers for iOS devices. Imported information will set ownership of the devices that enroll as “Corporate”. An Intune license is still required for each user that accesses the service. View a video walkthrough of the Pre-declare Corporate Owned Devices feature.
Remote Device Actions Experience Update:
The admin experience for wiping, resetting the passcode, remote locking, and bypassing iOS Activation Lock on mobile devices has been adjusted. The states of these actions are now part of the devices' details and properties.
Remote Full Wipe for Windows 10 desktop devices:
Support for remotely wiping and resetting Windows 10 desktop devices to factory settings.
Server groups:
Control settings for software updates in server groups, including the order and percentage of devices that can be updated at any one time. These capabilities introduce some enhancements over our pre-release "Servicing a cluster aware collection" feature, including the ability to control the order and better monitoring.
Windows 10 Enterprise Data Protection policies:
Enterprise data protection (EDP) policy settings - with this technical preview, you can create and deploy EDP policies for Windows devices running Windows 10 Insider Preview and Windows 10 Mobile Preview builds, including specifying apps, defining network boundaries, choosing the restriction modes and other EDP settings.
Windows Defender Advanced Threat Protection:
Manage Windows Defender Advanced Threat Protection policies for onboarding and offboarding Windows 10 clients to the cloud service, and view agent health in the monitoring dashboard. (Requires a Windows Defender ATP tenant in Azure.)
Windows Store for Business Integration:
ConfigMgr can manage and deploy applications purchased through the Windows Store for Business portal for both online and offline licensed apps. The 1605 Technical Preview adds the ability to create both online and offline apps with the ability to deploy offline apps to Intune and ConfigrMgr managed devices. View video walkthroughs of how to set up and deploy Windows Store for Business apps.
[1604]
Client cache size:
We added a new item to Client Settings called "Client Cache Settings". Use this to configure the client cache size as a percentage of overall disk space and megabytes.
Client Peer Cache:
A built-in ConfigMgr solution for clients to share content with other clients, directly from their local Cache with monitoring and troubleshooting capabilities.
Passport for Work:
Administrators can now deploy Passport for Work policies to domain-joined Windows 10 devices managed by the ConfigMgr client.
Policy Setting to Disable Smart Lock and other Trust Agents:
Hybrid administrators can now deploy a policy in the ConfigMgr console that disables Smart Lock and other trust agents from being used to circumvent passcode policy on devices running Android 5.0 or higher.
Software Updates Compliance Dashboard:
The Software Updates Dashboard continues our commitment to helping you keep your devices up to date with the latest security updates and Windows features. The dashboard allows you to view the current compliance status of devices in your organization and quickly analyze the data to see which devices are at risk.
Switch Software Update Point:
Administrators will be able to switch Software Update Points for clients when there are multiple SUPs available on a primary site. Administrators should use this option when clients are failing SUM scenarios due to SUP/WSUS issues on their assigned SUP. When administrators switch SUPs for a collection of clients, the selected clients will look for another SUP at the next scan interval. To try out this change go to the Asset and Compliance tab -> Device Collections -> and in the context menu of a device collection click on "Switch to Next Software Update Point".
VPN for Windows 10:
You can use 3rd party VPN providers for computers with the ConfigMgr client. These include Pulse Secure, F5 Edge, Dell SonicWall and Checkpoint.
[1603]
List View for Applications in Software Center:
In the Software Center Applications tab, users now have the option to switch between the default tile view and a new list view by clicking on the view selection icons underneath the search bar.
Install Selected Updates in Software Center:
In the new Updates tab in Software Center, click on the select mode button at the top left of the list of updates. In select mode, multiple updates may be selected and then simultaneously installed using the Install Selected button.
Content Status links in the Admin Console:
The Content Status links for objects like applications, packages, task sequences or software updates, now go directly to the related Content Status object node.
PXE Provider TFTP Window Size:
The administrator can now configure the TFTP window size (RamDiskTFTPWindowSize) via a registry setting on the PXE-enabled distribution point.
Limit access to the Clipboard in Remote Control Sessions:
You can now enable the remote tools client setting "Prompt user for shared clipboard file transfer permission" to limit access to the shared clipboard in a remote control session. When enabled, the end-user who is sharing a remote session must grant permissions to the viewer of that session before they can transfer files from the shared clipboard.
[1602]
Support for in-place upgrade of ConfigMgr Site Server's operating system:
In-place upgrade of the ConfigMgr's Site Server's operating system from Windows Server 2008 R2 to Windows Server 2012 R2 is now supported.
Sync Policy button in Software Center:
The new Sync Policy button helps you keep machine and user policies in sync. The button is available through the Software Center options tab, under Computer Maintenance.
Automatic creation of Microsoft Office mobile apps for iOS and Android:
Microsoft Office mobile apps for iOS and Android are pre-created for users using ConfigMgr integrated with Microsoft Intune.
iOS Activation Lock management:
iOS Activation Lock management capabilities include: enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices.
[1601]
Windows 10 Team configuration settings:
New configuration settings added and supported for Windows 10 Team when using either Intune managed (hybrid) devices, or ConfigMgr full client devices.
Windows 10 Microsoft Edge configuration settings:
Specify Windows 10 Edge settings and assign them to users or devices in their organization.
Windows 10 Conditional Access new compliance checks:
Set 3 new compliance checks: require a password to unlock an idle device, time until the device is locked, and require automatic updates with minimum classification. These policy rules are evaluated as part of overall device compliance.
Windows 10 Conditional Access with Health Attestation service:
For Intune managed devices, Windows 10 Health Attestation data can be used as part of device compliance when used with Conditional Access.
Device Compliance report:
Device Compliance report provides you the number and percentage of devices and their compliance state for each compliance policy.
Windows 10 Health Attestation service reports:
Users can view reports on Windows 10 Health Attestation data collected by Intune. Windows 10 device Health Attestation helps evaluate the vulnerability of Windows 10 desktop and mobile devices.
Kiosk mode for Samsung KNOX devices:
ConfigMgr kiosk mode allows you to lock a managed mobile device only to allow certain features. For example, you can allow a device only to run a specific managed app, or you can disable the device's volume buttons.
Client Online Status:
View the online status of devices in Assets and Compliance. New icons indicate the status of a device as online or offline.
Conditional Access for ConfigMgr Managed PCs:
To help secure Office 365 access and other services on PCs enrolled with ConfigMgr, use Conditional Access. Conditions that can be used to control access include: Workplace Join, BitLocker, Antimalware, and Software Updates.
On-Premises Exchange Default Rule Override:
Set a default on-premises Exchange rule to block mobile devices from accessing email. You can allow Intune-enrolled and compliant mobile devices to access mail. You can also choose to override the default Exchange rule to allow Intune-enrolled and compliant devices to access email, even when the default rule is set to Block or Quarantine.
iOS App Configuration:
Create and deploy iOS app configuration policies to dynamically change settings such as server name or port for iOS applications that support configuration.
Apple Volume Purchase Program:
ConfigMgr can manage and deploy applications purchased through the Apple Volume Purchase Program for Business portal.
[1512]
New antimalware policy settings:
Added settings for protection against Potentially Unwanted Applications, user control of automatic sample submission, and scanning of network drives during a full scan.
Device Health Attestation:
Users are able to view the status of Windows 10 Device Health Attestation in the ConfigMgr console, to ensure that client computers have trustworthy BIOS, TPM, and boot software.
User acceptance of Terms and Conditions:
Users who use ConfigMgr integrated with Intune (hybrid) can view which users have accepted the Terms and Conditions configured by IT and which users have not, right from the ConfigMgr console.
Will be continued in a next blogpost!
Labels:
1511,
1512,
1601,
1602,
1603,
1604,
1605,
1606,
ConfigMgr as a service,
ConfigMgr Current Branch,
Technical Preview
Friday, February 19, 2016
ConfigMgr 1602 for Technical Preview is available now!
Great news! as mentioned earlier this week, ConfigMgr 1602 for Technical Preview is available now!
New features that are available in this update include:
-Windows 10 Team configuration settings
-Automatic creation of Microsoft Office mobile apps for iOS and Android - Microsoft Office mobile apps for iOS and Android are pre-created for customers using ConfigMgr integrated with Microsoft Intune
-Sync Policy button – The new Sync Policy button lets you run the Machine Policy Retrieval & Evaluation Cycle and User Policy Retrieval & Evaluation Cycle with a click of a button. Find it in the Software Center options tab under Computer Maintenance
-In-place upgrade of ConfigMgr Site Server’s operating system – Support for ConfigMgr Site Server’s in-place upgrade of operating system from Windows Server 2008 R2 to Windows Server 2012 R2
-iOS Activation Lock management – Capabilities including enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices
Just install it in your LAB environment for testing purpose!
Source: ConfigMgr Team Blog
Other blogposts about this topic:
ConfigMgr 1602 tech preview and production release coming soon!
New features that are available in this update include:
-Windows 10 Team configuration settings
-Automatic creation of Microsoft Office mobile apps for iOS and Android - Microsoft Office mobile apps for iOS and Android are pre-created for customers using ConfigMgr integrated with Microsoft Intune
-Sync Policy button – The new Sync Policy button lets you run the Machine Policy Retrieval & Evaluation Cycle and User Policy Retrieval & Evaluation Cycle with a click of a button. Find it in the Software Center options tab under Computer Maintenance
-In-place upgrade of ConfigMgr Site Server’s operating system – Support for ConfigMgr Site Server’s in-place upgrade of operating system from Windows Server 2008 R2 to Windows Server 2012 R2
-iOS Activation Lock management – Capabilities including enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices
Just install it in your LAB environment for testing purpose!
Source: ConfigMgr Team Blog
Other blogposts about this topic:
ConfigMgr 1602 tech preview and production release coming soon!
Thursday, October 15, 2015
October Update for ConfigMgr 2016 (Technical Preview 3) available
Yesterday another update on ConfigMgr 2016 TP3 (Technical Preview 3) is done. This new update brings with it an early view of the new Windows 10 Servicing node, which enables you to view the state of Windows as a service in your environment, create flexible servicing plans to form deployment rings, and view alerts when Windows 10 clients are near end of support for their build of Current Branch or Current Branch for Business.
To read more about the new Windows 10 servicing dashboard, please refer to the TechNet documentation.
The Windows 10 Servicing dashboard is the latest addition to ConfigMgr’s rich support for Windows 10, including client deployment, upgrade, and management. You can find additional guidance for Windows 10 servicing and deployment on the Windows for IT Pros blog.
This update also introduces the ability to natively manage Office 365 desktop client updates using the Configuration Manager Software Update Management (SUM) workflow. You can now manage Office 365 desktop client updates just like you manage any other Microsoft Update.
In order to enable update 1510 for TP3, have a look here: System Center Configuration Manager Team Blog
Just great to have "ConfigMgr as a service" from now on!
More blogposts on ConfigMgr 2016 TP3:
Installing ConfigMgr 2016 Technical Preview 3
My experience with ConfigMgr 2016 (Technical Preview 3) so far
To read more about the new Windows 10 servicing dashboard, please refer to the TechNet documentation.
The Windows 10 Servicing dashboard is the latest addition to ConfigMgr’s rich support for Windows 10, including client deployment, upgrade, and management. You can find additional guidance for Windows 10 servicing and deployment on the Windows for IT Pros blog.
This update also introduces the ability to natively manage Office 365 desktop client updates using the Configuration Manager Software Update Management (SUM) workflow. You can now manage Office 365 desktop client updates just like you manage any other Microsoft Update.
In order to enable update 1510 for TP3, have a look here: System Center Configuration Manager Team Blog
Just great to have "ConfigMgr as a service" from now on!
More blogposts on ConfigMgr 2016 TP3:
Installing ConfigMgr 2016 Technical Preview 3
My experience with ConfigMgr 2016 (Technical Preview 3) so far
Tuesday, October 6, 2015
My experience with ConfigMgr 2016 (Technical Preview 3) so far
Last weeks I did a lot on ConfigMgr 2016 (Technical Preview 3). When installing the product (I used SQL 2014 and ADK 10 for this) and starting the console, no changes seems to be made. Thing is, most changes are not visible right away. You must use the product to see changes between the 2012 and 2016 release. The biggest one is under the hood. Let's have a look at my experience so far.
Because ConfigMgr 2016 is another x64 release, an in-place migration is possible from 2012 (when the product is final!). Only thing is, you need to update ADK (remove ADK 8.x and install ADK 10). It's possible to update SQL as well, but that's not a required thing. ConfigMgr 2016 can be installed as a servicepack (maybe it is off the record). You feel comfortable with it right away, which is quite nice. Just great to have a new release for the next coming years :)
Most important changes are:
Service connection point (connects ConfigMgr to Microsoft cloud services, it is used for Microsoft Intune subscription, and to update and service your ConfigMgr installation). You can choose between Online (persistent connection), which is recommended, and Offline (on-demand connection). Beneath Cloud Services (Administration tab) "Updates and Servicing" is added. Beneath that Features can be added by Microsoft dynamically. I installed "(Pre-Release) Version 1509 for Technical Preview" myself that way. With that you have "ConfigMgr as a service" from now on.
New task sequence: "Upgrade an operating system from upgrade package". This task sequence is used specially for Windows 10 upgrades. It contains a few steps only, but it does what it says: upgrade to Windows 10 in-place in just a few clicks. I did a Windows 8.1 to 10 upgrade within an hour with it.
Automatic Deployment Rules (ADR) can be connected to multiple collections now, without the need to set whole configuration again. Just click on the ADR and select "Add Deployment" to connect an existing ADR to another collection. When choosing properties on an existing ADR there is more overview, because of less tabs showing. Very nice there is improvement here!
Software Center and Application Catalog are (almost) merged now. Applications are showed in Software Center by default now, but approval still needs to be done in Application Catalog. Hope it will be merged totally in future soon. Software Center has a new look and feel, and can be used for (un)installing applications, software packages, and task sequence too. I use my for showing the Windows 10 upgrade task sequences available. Pity is still no e-mail notification is there by default. Other minus is that after approval the end user doesn't get an message that the application can be installed. Still some space for improvement if you ask me!
There will be full compatibility with existing features for Windows 10 (Windows as a service) in this release. And there will be a new hybrid option to manage Windows 10 devices via MDM with on-premises infrastructure. For this no ConfigMgr client is needed on the device. A workplace join (and company portal) is enough to show the device in ConfigMgr and push applications and policies. Just great isn't it?!
Hope to have my first ConfigMgr 2016 implementation and/or migration soon. This in combination with Microsoft Intune and Windows 10 for modern management. Microsoft is (still) the way to go! :) I'm very happy with the new possibilities till now.
More posts about ConfigMgr 2016:
New Microsoft System Center and Windows versions coming!
Installing ConfigMgr 2016 Technical Preview 3
Because ConfigMgr 2016 is another x64 release, an in-place migration is possible from 2012 (when the product is final!). Only thing is, you need to update ADK (remove ADK 8.x and install ADK 10). It's possible to update SQL as well, but that's not a required thing. ConfigMgr 2016 can be installed as a servicepack (maybe it is off the record). You feel comfortable with it right away, which is quite nice. Just great to have a new release for the next coming years :)
Most important changes are:
Service connection point (connects ConfigMgr to Microsoft cloud services, it is used for Microsoft Intune subscription, and to update and service your ConfigMgr installation). You can choose between Online (persistent connection), which is recommended, and Offline (on-demand connection). Beneath Cloud Services (Administration tab) "Updates and Servicing" is added. Beneath that Features can be added by Microsoft dynamically. I installed "(Pre-Release) Version 1509 for Technical Preview" myself that way. With that you have "ConfigMgr as a service" from now on.
New task sequence: "Upgrade an operating system from upgrade package". This task sequence is used specially for Windows 10 upgrades. It contains a few steps only, but it does what it says: upgrade to Windows 10 in-place in just a few clicks. I did a Windows 8.1 to 10 upgrade within an hour with it.
Automatic Deployment Rules (ADR) can be connected to multiple collections now, without the need to set whole configuration again. Just click on the ADR and select "Add Deployment" to connect an existing ADR to another collection. When choosing properties on an existing ADR there is more overview, because of less tabs showing. Very nice there is improvement here!
Software Center and Application Catalog are (almost) merged now. Applications are showed in Software Center by default now, but approval still needs to be done in Application Catalog. Hope it will be merged totally in future soon. Software Center has a new look and feel, and can be used for (un)installing applications, software packages, and task sequence too. I use my for showing the Windows 10 upgrade task sequences available. Pity is still no e-mail notification is there by default. Other minus is that after approval the end user doesn't get an message that the application can be installed. Still some space for improvement if you ask me!
There will be full compatibility with existing features for Windows 10 (Windows as a service) in this release. And there will be a new hybrid option to manage Windows 10 devices via MDM with on-premises infrastructure. For this no ConfigMgr client is needed on the device. A workplace join (and company portal) is enough to show the device in ConfigMgr and push applications and policies. Just great isn't it?!
Hope to have my first ConfigMgr 2016 implementation and/or migration soon. This in combination with Microsoft Intune and Windows 10 for modern management. Microsoft is (still) the way to go! :) I'm very happy with the new possibilities till now.
More posts about ConfigMgr 2016:
New Microsoft System Center and Windows versions coming!
Installing ConfigMgr 2016 Technical Preview 3
Monday, February 16, 2015
Windows 10 Technical Preview for phones is available now
Microsoft has announced the first build of Windows 10 Technical Preview for Phones. I used Windows 8.1 Technical Preview several months on my device. After using my Samsung Ativ S for almost 2 years now, i'm still very happy with my choice. My next Phone will run Windows 10 for sure, no doubt about that. The reason that multiple favorite apps are missing, is no obstacle for me. Microsoft rocks!
When you want to run Windows 10 Technical Preview, just make sure to follow the next steps:
-Join the Windows Insider Program
-Register your device to receive builds as over the air updates
-Builds will come to you automatically as they are ready, after being validated by engineers at Microsoft and used on their own phones
-Use the built-in Windows Feedback app to send us problem reports and suggestions
-Updates will continue all the way up to the final build that goes out to all customers
-You can roll your phone back to the previous OS any time you’d like
If you’re a Windows Phone customer and love to try the latest stuff before anyone else, or a Developer or IT Pro who works with Windows Phones, joining the Windows Insider program and trying out this build may be right for you. You’ll be getting an insider’s view and getting builds that normally would have only been available to Microsoft engineers in the past. Same as on Windows 10 Technical Preview.
There are a lot of known issues mentioned already. Just have a look at them to see what to expect. Still great to have the opportunity to try the earliest publicly available preview for Windows 10 Technical Preview. Do you take the risk or not, that's the question.
Source: Blogging Windows
When you want to run Windows 10 Technical Preview, just make sure to follow the next steps:
-Join the Windows Insider Program
-Register your device to receive builds as over the air updates
-Builds will come to you automatically as they are ready, after being validated by engineers at Microsoft and used on their own phones
-Use the built-in Windows Feedback app to send us problem reports and suggestions
-Updates will continue all the way up to the final build that goes out to all customers
-You can roll your phone back to the previous OS any time you’d like
If you’re a Windows Phone customer and love to try the latest stuff before anyone else, or a Developer or IT Pro who works with Windows Phones, joining the Windows Insider program and trying out this build may be right for you. You’ll be getting an insider’s view and getting builds that normally would have only been available to Microsoft engineers in the past. Same as on Windows 10 Technical Preview.
There are a lot of known issues mentioned already. Just have a look at them to see what to expect. Still great to have the opportunity to try the earliest publicly available preview for Windows 10 Technical Preview. Do you take the risk or not, that's the question.
Source: Blogging Windows
Friday, October 24, 2014
Windows 10 Technical Preview updated with 7,000 changes and fixes
Yesterday I updated my Windows 10 Technical Preview installation. In the update are 7,000 changes and fixes, so quite a lot! Let's have a look. When you're already running the Windows 10 Technical Preview, Windows Update will take care of downloading and installing the update automatically, depending on your download settings. Because I didn't want to wait for that, go to the "Update and recovery" section in PC settings and select Preview builds.
In my case it took al long time downloading and installing the update! A reboot is needed after installing to finalize the update. After that Windows 10 Technical Preview is updated to the new version, which is 6.4.9860. One of the new features is the Action Center (known from Windows Phone 8.1). Other new features include the ability to move apps easily from one monitor to another, and animations for switching desktops. The advise however is still to not install Windows 10 Technical Preview on your primary machine. Just run it in a virtual machine or dual boot situation instead.
Microsoft stated: Most of the changes in this build will be invisible to you, but we’ve made nearly 7,000 improvements and fixes to the product between 9841 and 9860. Many of those fixes were based on problem reports that you submitted in the Community forum or through the Windows Feedback app. Thanks! We also have a few visible changes that you’ll notice.
Microsoft has received over 250.000 pieces of feedback so far.
Very good if you ask me! The consumer is partly involved this way.
Can't wait for the final release! Great OS :-)
In my case it took al long time downloading and installing the update! A reboot is needed after installing to finalize the update. After that Windows 10 Technical Preview is updated to the new version, which is 6.4.9860. One of the new features is the Action Center (known from Windows Phone 8.1). Other new features include the ability to move apps easily from one monitor to another, and animations for switching desktops. The advise however is still to not install Windows 10 Technical Preview on your primary machine. Just run it in a virtual machine or dual boot situation instead.
Microsoft stated: Most of the changes in this build will be invisible to you, but we’ve made nearly 7,000 improvements and fixes to the product between 9841 and 9860. Many of those fixes were based on problem reports that you submitted in the Community forum or through the Windows Feedback app. Thanks! We also have a few visible changes that you’ll notice.
Microsoft has received over 250.000 pieces of feedback so far.
Very good if you ask me! The consumer is partly involved this way.
Can't wait for the final release! Great OS :-)
Friday, October 17, 2014
System Center Technical Preview VHDs available!
Maybe old news, but still want to mention that System Center Technical Preview VHDs are available for download!
System Center Technical Preview Data Protection Manager – Evaluation (VHD) System Center Technical Preview Operations Manager – Evaluation (VHD)
System Center Technical Preview Orchestrator – Evaluation (VHD) System Center Technical Preview Service Manager – Evaluation (VHD) System Center Technical Preview Virtual Machine Manager – Evaluation (VHD)
Just use them to have a look at all the new features!
Too bad no ConfigMgr evaluation VHD is available this time.
Additional information:
Release Notes for System Center Technical Preview
Features removed in System Center Technical Preview
Next version of System Center Configuration Manager announced!
System Center Technical Preview Data Protection Manager – Evaluation (VHD) System Center Technical Preview Operations Manager – Evaluation (VHD)
System Center Technical Preview Orchestrator – Evaluation (VHD) System Center Technical Preview Service Manager – Evaluation (VHD) System Center Technical Preview Virtual Machine Manager – Evaluation (VHD)
Just use them to have a look at all the new features!
Too bad no ConfigMgr evaluation VHD is available this time.
Additional information:
Release Notes for System Center Technical Preview
Features removed in System Center Technical Preview
Next version of System Center Configuration Manager announced!
Labels:
SysCtr,
System Center,
Technical Preview,
VHD
Thursday, October 9, 2014
My personal experience with Windows 10 Technical Preview
Last week I did the upgrade from Windows 8.1 Enterprise (which is needed for Direct Access) to Windows 10 Technical Preview. When looking for a download just look here. In my case the installation was done in 15 a 20 minutes on SSD drive, not too bad! After the upgrade everything seems to work okay, applications and data were still in place, and new functionality was added. Let's have a look at a few new (and really cool) features!
First there is the new Start menu (where everyone is talking about). Personally I think it's great to have it back now. No more switching between desktop and tiles is easier then loosing focus on desktop everytime. The combination of applications and apps is a good match, and looks/feels good. > Welcome back Start menu!
When you want to change back to tiles or have a tablet device, the Start screen (known from Windows 8.x) can be displayed as well. Just use what you prefer, and fits best on the device you are using. Windows 10 is looking at the device you're using and switch on Start menu or Start screen by default. Seems okay to me!?
When looking at the task bar you will see a few new icons added. They are all handy for sure. First there is 'Search' to find data (documents for example), which is much easier then before. Second there is 'Task view', where you can quickly see which programs or folders are opened/active. Just click the window you want. Another one is 'Favorites', where you can find most used and opened files and folders (e.g. Favorites, Frequent folders and Recent files).
Another great feature is when moving a task to the left- or right side of the screen. In the other part an overview is displayed on other active tasks. Just click a task, and that one will be showed in the other part of screen. When dragging a task to a random corner, it will be placed there, without showing other active tasks. In that scenario you will see 4 opened tasks with only a few clicks. You can also generate a new desktop where (active) programs are not visible at once. Just start tasks on multiple desktops with this!
Applications and apps can run both in same screen now, instead of switching from desktop to tiles screen. Apps can run in a full windows or in a window as shown in the screenshot. Much easier that way if you ask me. No need to go left above to switch from a fullscreen app to desktop (remember?), when working on a fat client device. Things are now as they should be in the first place.
Maybe I missed some more features, but for me these are enough reason to move on to Windows 10 already! No need to worry about things like Direct Access, Office 2013 or other features. All seems to work okay! Expect a Final release in May 2015 and multiple Preview versions (Consumer Preview, Release Candidate) in between.
Windows 10 may be the best OS since Windows 7 finally! Windows 10: One product family, One platform, One store. Love it!
Update: Back to Windows 8.1 now because of Privacy Statements for Windows Technical Preview. But for the few days I used it, I personally think that the OS is great already. Just want some more features like Cortana, and it will be even greater. Thanks!
First there is the new Start menu (where everyone is talking about). Personally I think it's great to have it back now. No more switching between desktop and tiles is easier then loosing focus on desktop everytime. The combination of applications and apps is a good match, and looks/feels good. > Welcome back Start menu!
When you want to change back to tiles or have a tablet device, the Start screen (known from Windows 8.x) can be displayed as well. Just use what you prefer, and fits best on the device you are using. Windows 10 is looking at the device you're using and switch on Start menu or Start screen by default. Seems okay to me!?
When looking at the task bar you will see a few new icons added. They are all handy for sure. First there is 'Search' to find data (documents for example), which is much easier then before. Second there is 'Task view', where you can quickly see which programs or folders are opened/active. Just click the window you want. Another one is 'Favorites', where you can find most used and opened files and folders (e.g. Favorites, Frequent folders and Recent files).
Another great feature is when moving a task to the left- or right side of the screen. In the other part an overview is displayed on other active tasks. Just click a task, and that one will be showed in the other part of screen. When dragging a task to a random corner, it will be placed there, without showing other active tasks. In that scenario you will see 4 opened tasks with only a few clicks. You can also generate a new desktop where (active) programs are not visible at once. Just start tasks on multiple desktops with this!
Applications and apps can run both in same screen now, instead of switching from desktop to tiles screen. Apps can run in a full windows or in a window as shown in the screenshot. Much easier that way if you ask me. No need to go left above to switch from a fullscreen app to desktop (remember?), when working on a fat client device. Things are now as they should be in the first place.
Maybe I missed some more features, but for me these are enough reason to move on to Windows 10 already! No need to worry about things like Direct Access, Office 2013 or other features. All seems to work okay! Expect a Final release in May 2015 and multiple Preview versions (Consumer Preview, Release Candidate) in between.
Windows 10 may be the best OS since Windows 7 finally! Windows 10: One product family, One platform, One store. Love it!
Update: Back to Windows 8.1 now because of Privacy Statements for Windows Technical Preview. But for the few days I used it, I personally think that the OS is great already. Just want some more features like Cortana, and it will be even greater. Thanks!
Labels:
Direct Access,
Favorites,
Keylog,
Keylogger,
Metro,
Office 2013,
Privacy,
Privacy Statements,
Search,
Task view,
Technical Preview,
Tiles,
Windows,
Windows 10,
Windows 9
Subscribe to:
Posts (Atom)









