Additions : 3
Updates : 11
More Details At: www.roadmapwatch.com
Regards
The Author – Blogabout.Cloud
Additions : 3
Updates : 11
More Details At: www.roadmapwatch.com
Regards
The Author – Blogabout.Cloud
Additions : 3
Updates : 14
More Details At: www.roadmapwatch.com
Regards
The Author – Blogabout.Cloud
Additions : 5 Updates : 8 More Details At: www.roadmapwatch.com
New Features | Current Status | |||
---|---|---|---|---|
Excel: Office Scripts for task and workflow automation in Excel | Rolling Out | |||
Microsoft Information Protection: Teams DLP for Adaptive Cards | In Development | |||
Microsoft Information Protection: Data loss prevention for Microsoft Teams in GCC-High and DoD | In Development | |||
Forms: Print a blank Form | In Development | |||
Microsoft Information Protection: UI for configuring Exact Data Match | In Development | |||
Updated Features | Current Status | Update Type | ||
Microsoft Teams: New file sharing experience | Rolling Out | Status | ||
Automated Incident Response for compromised user accounts | Launched | Description | ||
Advanced eDiscovery Graph APIs | In Development | Description | ||
Microsoft Graph: [TO DO TASKS] Tasks API (Preview) | In Development | Description | ||
Microsoft Teams – raise hands in Teams meetings for GCC | Launched | Status | ||
Communication Compliance: Detect adult content | Launched | Status | ||
Microsoft Information Protection: Double Key Encryption | Launched | Status | ||
Exchange online: Client Access rules support for OAuth POP and IMAP | Rolling Out | Status |
Regards
The Author – Blogabout.Cloud
Additions : 0 Updates : 3 More Details At: www.roadmapwatch.com
Updated Features | Current Status | Update Type | ||
---|---|---|---|---|
Improved user experience for the Admin Center Message Center | Launched | Status | ||
Microsoft Lists and SharePoint document libraries – Gallery view | In Development | Title, Description | ||
Outlook on the web – New tasks experience for GCC | In Development | Title |
Regards
The Author – Blogabout.Cloud
Have you ever wondered how compliant your Microsoft 365 environment is? Well with Microsoft Compliance Score you can now check your environment just like Microsoft Secure Score. This a standalone feature with a simpler, more user-friendly design to help organizations more easily manage compliance.
The following screenshots show the experience you will receive when you launch https://compliance.microsoft.com/compliancescore?viewid=overview. The first time setup can take anything between 5-10 minutes to complete depending on your environment.
Once the first time setup has been completed you will welcomed with the following 4 windows.
As you can see from the image below it shows your current score, helps you see what needs attention, and guides you to actions to improve your score. Your Compliance Score dashboard will look like this:
Improvement actions centralize your compliance activities. Each improvement action gives detailed implementation guidance to help you align with data protection regulations and standards. Actions can be assigned to users in your organization to perform implementation and testing work. You can also store documentation, notes, and record status updates within the improvement action.
Solutions list all the Microsoft products which are scored using the Compliance Score dashboard. You are able drill into each solution to understand if any additional configuration is required, as shown beleow.
An assessment is grouping of controls from a specific regulation, standard, or policy. Completing the actions within an assessment help you meet the requirements of a standard, regulation, or law. For example, you may have an assessment that, when you complete all actions within it, brings your Microsoft 365 settings in line with ISO 27001 requirements.
Assessments have several components:
When creating assessments, you’ll assign them to a group. You can configure groups in whatever way is most logical for your organization. For example, you may group assessments by year, compliance standard, service, teams within your organization, or some other way. Once you create groups, you can filter you Compliance Score dashboard to view your score by one or more groups.
As you can see from the screenshot below during the initial first launch, the default Data Protection Baseline assessment will be ran.
This will give you a base understanding of their compliance footprint once it has completed.
Regards
The Author – Blogabout.Cloud
As of 13th July Microsoft have introduced Service Release 2007 here whats available now
End users can now decide whether the applications shown in the Microsoft Intune Web Company Portal should be opened by the Company Portal app or the Company Portal website. This option is only available if the end user has the Company Portal app installed and launches a Web Company Portal application outside of a browser.
Intune is removing support for the Exchange On-Premises Connector feature from the Intune service beginning in the 2007 (July) release. Existing customers with an active connector will be able to continue with the current functionality at this time. New customers and existing customers that do not have an active connector will no longer be able to create new connectors or manage Exchange ActiveSync (EAS) devices from Intune. For those customers, Microsoft recommends the use of Exchange hybrid modern authentication (HMA) to protect access to Exchange on-premises. HMA enables both Intune App Protection Policies (also known as MAM) and Conditional Access through Outlook Mobile for Exchange on-premises.
You can now enable S/MIME for Outlook on iOS and Android Enterprise devices using app configuration polices for devices managed without enrollment. In Microsoft Endpoint Manager admin center, select Apps > App configuration policies > Add > Managed apps. Additionally, you can choose whether or not to allow users to change this setting in Outlook. For general information about S/MIME, see S/MIME overview to sign and encrypt email in Intune. For more information about Outlook configuration settings, see Microsoft Outlook configuration settings and Add app configuration policies for managed apps without device enrollment. For Microsoft Exchange specific S/MIME information, see S/MIME scenarios and Configuration keys – S/MIME settings.
When you create a VPN profile using the IKEv2 connection type, there are new settings you can configure (Devices > Configuration profiles > Create profile > Windows 10 and later for platform > VPN for profile > Base VPN):
To see the settings you can configure, go to Windows device settings to add VPN connections using Intune.
Applies to:
On Android Enterprise Fully Managed devices, you can configure more Microsoft Launcher settings using a device restrictions profile (Devices > Configuration profiles > Create profile > Android Enterprise for platform > Device Owner only > Device restrictions > Device experience > Fully managed).
To see these settings, go to Android Enterprise device settings to allow or restrict features.
You can also configure the Microsoft Launcher settings using an app configuration profile.
Applies to:
On Android Enterprise devices, administrators can use device configuration profiles to customize the Managed Home Screen on dedicated devices using multi-app kiosk mode (Devices > Configuration profiles > Create profile > Android Enterprise for platform > Device Owner Only > Device Restrictions for profile > Device experience > Dedicated device > Multi-app).
Specifically, you can:
For more information, see Android Enterprise device settings to allow or restrict features and this blog.
Applies to:
The ADMX settings available for Microsoft Edge have been updated. End users can now configure and deploy new ADMX settings added in Edge 84. For more information, see the Edge 84 release notes.
Intune now supports Android Enterprise corporate-owned devices with a work profile for OS versions Android 8 and above. Corporate-owned devices with a work profile is one of the corporate management scenarios in the Android Enterprise solution set. This scenario is for single user devices intended for corporate and personal use. This corporate-owned, personally-enabled (COPE) scenario offers:
The first public preview release will include a subset of the features that will be included in the generally available release. Additional features will be added on a rolling basis. The features that will be available in the first preview include:
For more information about corporate-owned with work profile preview, see the support blog.
Changes to the remote lock action for macOS devices include:
The Device actions report now differentiates between the wipe and protected wipe actions. To see the report, go to Microsoft Endpoint Manager admin center > Devices > Monitor > Device Actions (under Other).
As a public preview, we’re working on a PowerShell based tool that will migrate Microsoft Defender Firewall rules. When you install and run the tool, it automatically creates endpoint security firewall rule policies for Intune that are based on the current configuration of a Windows 10 client. For more information, see Endpoint security firewall rule migration tool overview.
As part of endpoint security in Intune, the Endpoint detection and response (EDR) policies for use with devices managed by Configuration Manager are no longer in preview and are now Generally Available.
To use EDR policy with devices from a supported version of Configuration Manager, configure Tenant attach for Configuration Manager. After you complete the tenant attach configuration, you can deploy EDR policies to onboard devices managed by Configuration Manager to Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP).
We’ve added settings to manage Bluetooth on Windows 10 devices to the Device control profile for Endpoint security Attack surface Reduction policy. These are the same settings as those that have been available in Device restriction profiles for Device configuration.
We’ve added two new settings to the Updates category of endpoint security antivirus policy for Windows 10 devices that can help you manage how devices get update definitions:
With the new settings you can add UNC file shares as download source locations for definition updates, and define the order in which different source locations are contacted.
We’ve made some changes to improve the usability of the security baseline node in the Microsoft Endpoint Manager admin center. Now when you drill in to Endpoint security > Security baselines and then select a security baseline type like the MDM Security Baseline, your presented with the Profiles pane. On the Profiles pane you view the profiles you’ve created for that Baseline type. Previously the console presented an Overview pane which included an aggregate data roll up that didn’t always match the details found in the reports for individual profiles.
Unchanged, from the Profiles pane you can select a profile to drill-in to view that profiles properties as well as various reports that are available under Monitor. Similarly, at the same level as Profiles you can still select Versions to view a the various versions of that profile type that you’ve deployed. When you drill-in to a version, you also gain access to reports, similar to the profile reports.
You can now use derived credentials with your Windows devices. This will expand on the existing support for iOS/iPadOS and Android, and will be available for the same derived credential providers:
Support for Widows includes use of a derived credential to authenticate to Wi-Fi or VPN profiles. For Windows devices, the derived credential is issued from the client app that’s provided by the derived credential provider that you use.
Intune can now assume management of FileVault disk encryption on a macOS device that was encrypted by the device user, and not by Intune policy. This scenario requires:
After the user uploads their recovery key, Intune rotates the key to confirm it is valid. Intune can now manage the key and encryption as if it used policy to encrypt the device directly. Should a user need to recover their device, they can access the recovery key using any device from the following locations:
When you use endpoint security policy to configure macOS FileVault disk encryption, use the Hide recovery key setting to prevent display of the personal recovery key to the device user, while the device is being encrypted. By hiding the key during encryption, you can help keep it secure as users won’t be able to write it down while waiting for the device to encrypt.
Later, if recovery is needed, a user can always use any device to view their personal recovery key through the Intune Company Portal website, the iOS/iPadOS Company Portal, the Android Company Portal, or the Intune app.
You can now drill-in to the details for a device to view the settings details for security baselines that apply to the device. The settings appear in a simple, flat list, which includes the setting category, setting name, and status. For more information, see View Endpoint security configurations per device.
The Intune DeviceComplianceOrg logs previously only had enumerations for ComplianceState, OwnerType, and DeviceHealthThreatLevel. Now, these logs have English information in the columns.
Role-based access control permissions has changed for Assign profile and Update profile for the Automated Device Enrollment flow:
Assign profile: Admins with this permission can also assign the profiles to tokens and assign a default profile to a token for Automated Device Enrollment.
Update profile: Admins with this permission can update existing profiles only for Automated Device Enrollment.
To see these roles, go to Microsoft Endpoint Manager admin center > Tenant administration > Roles > All roles > Create > Permissions > Roles.
Additional properties are available using the Intune Data Warehouse v1.0. The following properties are now exposed via the devices entity:
1 | ethernetMacAddress |
1 | office365Version |
The following properties are now exposed via the devicePropertyHistories entity:
1 | physicalMemoryInBytes |
1 | totalStorageSpaceInBytes |
For more information, see Microsoft Intune Data Warehouse API.
Regards
The Author – Blogabout.Cloud
Additions : 7 Updates : 4 More Details At: www.roadmapwatch.com
New Features | Current Status | |||
---|---|---|---|---|
Teams: Microsoft Teams displays | In Development | |||
Yammer: Change default community post to Question | Rolling Out | |||
Yammer: Upvote answers to Yammer questions | In Development | |||
Yammer: Adding Ability to “Mute” Communities at Admin and User levels | In Development | |||
Yammer: “Embed feed” updated with new look and functionality | In Development | |||
Yammer: Collapsed pinned posts on live event page | In Development | |||
SharePoint: Share a page to Yammer | In Development | |||
Updated Features | Current Status | Update Type | ||
Outlook for Android: Time-zone support | Cancelled | Status, Description | ||
Outlook for Android: Visual cues for work and personal accounts | Launched | Status, Description | ||
Outlook on the web: Suggested replies for German, and Spanish | In Development | Title, Description | ||
Microsoft Planner: Copy a plan within an existing Group or Teams | Launched | Status |
Regards
The Author – Blogabout.Cloud