Policy CSP . Microsoft makes no warranties, express or implied, with respect to the information provided here. The Policy configuration service provider enables the enterprise to configure policies on Windows 1. Use this configuration service provider to configure any company policies. The Policy configuration service provider has the following sub- categories: Policy/Config/Area. Name – Handles the policy configuration request from the server. Policy/Result/Area. Name – Provides a read- only path to policies enforced on the device. The following diagram shows the Policy configuration service provider in tree format as used by both Open Mobile Alliance Device Management (OMA DM) and OMA Client Provisioning./Vendor/MSFT/Policy. The root node for the Policy configuration service provider. A WMI Primer. If the SQL Server database is the heart of ConfigMgr, consider WMI its lifeblood. WMI has been the core management infrastructure for all Windows. ![]() Supported operation is Get. Policy/Config. Node for grouping all policies configured by one source. The configuration source can use this path to set policy values and later query any policy value that it previously set. One policy can be configured by multiple configuration sources. If a configuration source wants to query the result of conflict resolution (for example, if Exchange and MDM both attempt to set a value,) the configuration source can use the Policy/Result path to retrieve the resulting value. Supported operation is Get. Policy/Config/Area. Name. The area group that can be configured by a single technology for a single provider. Once added, you cannot change the value. Supported operations are Add, Get, and Delete. Policy/Config/Area. Name/Policy. Name. Specifies the name/value pair used in the policy. The following list shows some tips to help you when configuring policies: Separate substring values by the Unicode & #x. F0. 00; in the XML file. Note. A query from a different caller could provide a different value as each caller could have different values for a named policy. In Sync. ML, wrap this policy with the Atomic command so that the policy settings are treated as a single transaction. Supported operations are Add, Get, Delete, and Replace. Value type is string. ![]() Policy/Result. Groups the evaluated policies from all providers that can be configured. Supported operation is Get. Policy/Result/Area. Name. The area group that can be configured by a single technology independent of the providers. Supported operation is Get. Policy/Result/Area. Name/Policy. Name. Specifies the name/value pair used in the policy. Supported operation is Get. Policy/Config. Operations. Added in Windows 1. The root node for grouping different configuration operations. Supported operations are Add, Get, and Delete. Policy/Config. Operations/ADMXInstall. Added in Windows 1. Allows settings for ADMX files for Win. Centennial apps to be imported (ingested) by your device and processed into new ADMX- backed policies or preferences. By using ADMXInstall, you can add ADMX- backed polices for those Win. Centennial apps that have been added between OS releases.
A utility to help system administrators diagnose and repair problems with the WMI service. ![]() ADMX- backed policies are ingested to your device by using the Policy CSP URI: ./Vendor/MSFT/Policy/Config. Operations/ADMXInstall. Each ADMX- backed policy or preference that is added is assigned a unique ID. For more information about using Policy CSP to configure Win. Centennial app policies, see Win. Centennial app policy configuration. Note. The OPAX settings that are managed by the Microsoft Office Customization Tool are not supported by MDM. For more information about this tool, see Office Customization Tool. ADMX files that have been installed by using Config. Operations/ADMXInstall can later be deleted by using the URI delete operation. Deleting an ADMX file will delete the ADMX file from disk, remove the metadata from the ADMXdefault registry hive, and delete all the policies that were set from the file. The MDM server can also delete all ADMX policies that are tied to a particular app by calling delete on the URI, ./Vendor/MSFT/Policy/Config. Operations/ADMXInstall/. Specifies the name of the Win. Centennial app associated with the ADMX file. Supported operations are Add, Get, and Delete. Policy/Config. Operations/ADMXInstall/App. Name/Policy. Added in Windows 1. Specifies that a Win. Centennial app policy is to be imported. Supported operations are Add, Get, and Delete. Policy/Config. Operations/ADMXInstall/App. Name/Policy/Unique. IDAdded in Windows 1. Specifies the unique ID of the app ADMX file that contains the policy to import. Supported operations are Add and Get. Does not support Delete. Policy/Config. Operations/ADMXInstall/App. Name/Preference. Added in Windows 1. Specifies that a Win. Centennial app preference is to be imported. Supported operations are Add, Get, and Delete. Policy/Config. Operations/ADMXInstall/App. Name/Preference/Unique. IDAdded in Windows 1. Specifies the unique ID of the app ADMX file that contains the preference to import. Supported operations are Add and Get. Does not support Delete. Note. The policies supported in Windows 1. S is the same as in Windows 1. Pro, except that policies under Appliations. Defaults are not suppported in Windows 1. S. Policies. Above. Lock/Allow. Action. Center. Notifications. Note. This policy is only enforced in Windows 1. Mobile and not supported in Windows 1. Specifies whether to allow Action Center notifications above the device lock screen. The following list shows the supported values: 0 – Not allowed. Allowed. Most restricted value is 0. Above. Lock/Allow. Cortana. Above. Lock. Added in Windows 1. Specifies whether or not the user can interact with Cortana using speech while the system is locked. If you enable or don’t configure this setting, the user can interact with Cortana using speech while the system is locked. If you disable this setting, the system will need to be unlocked for the user to interact with Cortana using speech. The following list shows the supported values: 0 – Not allowed. Allowed. Above. Lock/Allow. Toasts. Specifies whether to allow toast notifications above the device lock screen. The following list shows the supported values: 0 – Not allowed. Allowed. Most restricted value is 0. Accounts/Allow. Adding. Non. Microsoft. Accounts. Manually. Specifies whether user is allowed to add non- MSA email accounts. The following list shows the supported values: 0 – Not allowed. Allowed. Most restricted value is 0. Note. This policy will only block UI/UX- based methods for adding non- Microsoft accounts. Even if this policy is enforced, you can still provision non- MSA accounts using the EMAIL2 CSP. Accounts/Allow. Microsoft. Account. Connection. Specifies whether the user is allowed to use an MSA account for non- email related connection authentication and services. The following list shows the supported values: 0 – Not allowed. Allowed. Most restricted value is 0. Accounts/Allow. Microsoft. Account. Sign. In. Assistant. Added in Windows 1. Allows IT Admins the ability to disable the . Otherwise, the string should contain a pipe- separated list of domains that are allowed to sync email on the device. For example, . When this setting is enabled, the administrator can create a list of approved Activex Install sites specified by host URL. If you enable this setting, the administrator can create a list of approved Active. X Install sites specified by host URL. If you disable or do not configure this policy setting, Active. X controls prompt the user for administrative credentials before installation. Note: Wild card characters cannot be used when specifying the host URLs. ADMX Info: GP english name: Approved Installation Sites for Active. X Controls. GP name: Approved. Active. XInstall. Sites. GP path: Windows Components/Active. X Installer Service. GP ADMX file name: Active. XInstall. Service. App. Virtualization/Allow. App. VClient. This policy setting allows you to enable or disable Microsoft Application Virtualization (App- V) feature. Reboot is needed for disable to take effect. ADMX Info: GP english name: Enable App- V Client. GP name: Enable. App. VGP path: System/App- VGP ADMX file name: appv. App. Virtualization/Allow. Dynamic. Virtualization. Enables Dynamic Virtualization of supported shell extensions, browser helper objects, and Active. X controls. ADMX Info: GP english name: Enable Dynamic Virtualization. GP name: Virtualization. Acceptable range is 0~2. A good practice is, don't set this time to a busy hour, e. AM. Delay reporting for the random minutes: The maximum minutes of random delay on top of the reporting time. For a busy system, the random delay will help reduce the server load. Repeat reporting for every (days): The periodical interval in days for sending the reporting data. Data Cache Limit: This value specifies the maximum size in megabytes (MB) of the XML cache for storing reporting information. The default value is 2. MB. The size applies to the cache in memory. When the limit is reached, the log file will roll over. When a new record is to be added (bottom of the list), one or more of the oldest records (top of the list) will be deleted to make room. A warning will be logged to the Client log and the event log the first time this occurs, and will not be logged again until after the cache has been successfully cleared on transmission and the log has filled up again. Data Block Size: This value specifies the maximum size in bytes to transmit to the server at once on a reporting upload, to avoid permanent transmission failures when the log has reached a significant size. The default value is 6. When transmitting report data to the server, one block at a time of application records that is less than or equal to the block size in bytes of XML data will be removed from the cache and sent to the server. Each block will have the general Client data and global package list data prepended, and these will not factor into the block size calculations; the potential exists for an extremely large package list to result in transmission failures over low bandwidth or unreliable connections. ADMX Info: GP english name: Reporting Server. GP name: Reporting. Example usage: /FILEEXCLUSIONLIST='desktop; my pictures'. Download The WMI Diagnosis Utility - - Version 2. Official Microsoft Download Center. Supported Operating System. Windows 7, Windows 8, Windows 8. Windows Server 2. Windows Server 2. Windows Server 2. R2, Windows Server 2. Windows Server 2. R2, Windows Vista.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. Archives
August 2017
Categories |