通过使用本网站, 您同意 隐私政策.
接受
进入IT进入IT进入IT
  • 家
  • 信息技术专家
  • 技术
  • 微软
    • 天蓝色
    • 配置管理器/SCCM
    • 数字PM
    • 协调者
    • Hyper-V
    • 微软 Edge 预览体验
    • 微星指数
    • 办公室 365
    • 办公室内幕
    • 电力商业智能
    • Skype
    • SQL服务器
    • 团队
  • 视窗
    • Windows 管理中心
    • Windows客户端
    • Windows服务器
  • SCCM查询集合列表
阅读: SCCM 技术预览分支更新 1710
字体调整器氨基酸
进入IT进入IT
字体调整器氨基酸
  • 家
  • 信息技术专家
  • 技术
  • 微软
  • 视窗
  • SCCM查询集合列表
搜索
  • 家
  • 信息技术专家
  • 技术
  • 微软
    • 天蓝色
    • 配置管理器/SCCM
    • 数字PM
    • 协调者
    • Hyper-V
    • 微软 Edge 预览体验
    • 微星指数
    • 办公室 365
    • 办公室内幕
    • 电力商业智能
    • Skype
    • SQL服务器
    • 团队
  • 视窗
    • Windows 管理中心
    • Windows客户端
    • Windows服务器
  • SCCM查询集合列表
配置管理器查询集合列表
configmgr

SCCM 技术预览分支更新 1710

出版: 二月 11, 2024
6 最小阅读量
分享

SCCM 技术预览分支更新 1710.

内容
Supported in 1710 技术预览Not supported for 1710 技术预览Creating CNG certificate templatesRequired certificate template properties (Windows CA):

This month’s new preview features include:

  • Check compliance for co-managed devices from Software Center when conditional access is managed by Intune – Users can now use Software Center to check the compliance of their co-managed Windows 10 devices when conditional access is managed by Intune.
  • Limit Windows 10 enhanced telemetry to only send data relevant to Windows Analytics Device Health – You can now set the Windows 10 telemetry data collection level to Enhanced (Limited). This setting enables you to gain actionable insight about devices in your environment without devices reporting all of the data in the Enhanced telemetry level with Windows 10 version 1709 or later.
  • Configure and deploy Windows Defender Application Guard policies – You can now create and deploy Windows Defender Application Guard policies to Windows 10 clients that help protect your users by opening untrusted websites in a virtualized browser (Edge and Internet Explorer).
  • Authorize software that is trusted by the Intelligent Security Graph as part of Windows Defender Application Control – Device Guard policies in Configuration manager are now renamed to Windows Defender Application Control policies. This better reflects the scope of their functionality. On devices that run Windows 10 version 1709, software that is trusted by the Microsoft Intelligent Security Graph (ISG) can now be automatically authorized. The trustworthiness of the software is defined by reputation data from Windows Defender SmartScreen, Windows Defender Antivirus, 还有更多.
  • Configure Windows Defender Exploit Guard – Windows Defender Exploit Guard provides intrusion prevention rules and policies that make vulnerabilities more difficult to exploit in Windows 10. All Exploit Guard components are now configurable with Configuration Manager.
  • Improved descriptions for pending computer restarts – The reason for a pending computer restart is posted.
  • Run Scripts – We’ve added the ability to configure security scopes for the Run Scripts feature. We’ve also integrated an additional improved monitoring experience as part of the Run Scripts wizard.

This release also includes the following improvements based on your feedback from UserVoice:

  • Allow up to 512×512 pixel icons for application in Software Center – You can now deploy apps with up to 512×512 pixels icons to display in Software Center. This was earlier capped at 250×250 pixels and anything larger showed up blurry on Software Center. We have now changed this after receiving feedback from our customers.
  • Support for Cryptography: Next Generation certificates – We’ve added limited support for Cryptography: Next Generation (CNG) certificates.

Supported in 1710 技术预览

Beginning with the 1710 Technical Preview you can use certificates created using CNG certificate templates for client-specific scenarios. The following scenarios are supported:

  • Client registration and communication with an HTTPS management point
  • Software distribution and application deployment with an HTTPS distribution point
  • Operating system deployment
  • Cloud Management Gateway Configuration
  • Client messaging SDK (with a soon-to-be-released update) and ISV Proxy

Note: CNG is backward compatible with Crypto API (CAPI). CAPI certificates will continue to be supported even when CNG support is enabled on the client

Not supported for 1710 技术预览

  • Application Catalog Web service, Application Catalog website, Enrollment point, and Enrollment proxy point roles will not be operational when installed in HTTPS mode with a CNG certificate bound to the website in Internet Information Services (信息系统). Software Center will not display applications and packages deployed to user or user group collection as available.
  • State Migration Point will not be operational when installed in HTTPS mode with a CNG certificate bound to the website in IIS.
  • Using CNG certificates to create a Cloud Distribution Point is not supported.
  • NDES Policy Module to Certificate Registration Point (CRP) communication will fail if the NDES Policy Module is using a CNG certificate for a client authentication certificate.

Creating CNG certificate templates

You will need to create CNG certificate templates from the Certificate Authority (CA) and the enrolling certificate on the target machines (clients or servers) depending on the purpose and scenario you are testing e.g. client authentication, server authentication, etc.

Required certificate template properties (Windows CA):

  • Under the Compatibility tab, “Certification Authority” must be at least “Windows Server 2008” (recommended “Windows Server 2012”)
  • Under the Compatibility tab, “Certificate recipient” must be at least “Windows Vista/Server 2008” (recommended “Windows 8/Windows Server 2012”)
  • Under the Cryptography tab, make sure the “Provider Category” is “Key Storage Provider”

Note: The requirements for your environment or organization may be different. Please consult with your PKI expert. The important points to consider are a certificate template must use a Key Storage Provider to be able to take advantage of CNG.

标记:intune系统中心系统中心配置管理器技术预览视窗视窗 10
上一篇 配置管理器查询集合列表 SCCM 技术预览分支更新 1712
下一篇 下载VLC媒体播放器 3.0.0 x64 微星
发表评论 发表评论

发表回复 取消回复

您的电子邮件地址不会被公开. 必填字段已标记 *

该网站使用 Akismet 来减少垃圾邮件. 了解您的评论数据的处理方式.

翻译

English中文(简体)DanskNederlandsFrançaisDeutschItaliano한국어PolskiPortuguêsRomânăEspañolУкраїнська
经过 Transposh - translation plugin for wordpress

热门帖子

Windows Server 的系统要求 2016
Windows服务器
配置管理器查询集合列表
配置管理器查询集合列表
configmgr
在经典团队网站的新式页面上启用结构化/托管导航
技术
SCCM 无法从 MP 获取预期版本的 DP 位置
configmgr

最近的帖子

在 Ubuntu 上安装和配置 Fail2ban 以实现 SSH 保护 24.04
Linux
在AlmaLinux上启用和配置FirewallD
Linux
AlmaLinux中的用户创建和SSH密钥设置
Linux
如何在AlmaLinux上重置密码
Linux

© 2023 进入IT

转到移动版本
欢迎回来!

登录您的帐户

用户名或电子邮件地址
密码

丢失密码?