Sign in

ConfigMgrDogs

@configmgrdogs.bsky.social
845 followers 206 following 205 posts

linktr.ee/ConfigMgrDogs

PostsRepliesMedia
ConfigMgrDogs @configmgrdogs.bsky.social · 11/02/2026
Windows 365 now supported in New Zealand North: Today I’m pleased to announce that Windows 365 is now available in the New Zealand North region, bringing Cloud PCs even closer to our customers around the world. With this expansion, organizations in and around New Zealand can benefit… #WindowsITPro
bit.ly
Windows 365 now supported in New Zealand North
Today I’m pleased to announce that Windows 365 is now available in the New Zealand North region, bringing Cloud PCs even closer to our customers around the world. With this expansion, organizations in and around New Zealand can benefit from lower latency, improved performance, and local data residency, all delivered through our trusted Microsoft Cloud. This new region strengthens our global coverage and supports customers who need to keep data within national borders, meet industry or government compliance expectations, or simply provide their workforce with a faster, more consistent Cloud PC experience. Enabling Windows 365 in New Zealand North reinforces our commitment to supporting local digital transformation and helping organizations of all sizes deliver secure, flexible, cloud‑powered computing, without the constraints of physical hardware. As more customers adopt Windows 365 to modernize their workforce, this new region ensures they can do so with the performance, reliability, and sovereignty that’s expected from Microsoft.   Recommended next steps Below are a few actions to help you take advantage of Windows 365 availability in New Zealand North, depending on how your provisioning policies are configured. Microsoft Hosted Network (MHN) customers MHN customers can start benefiting from the New Zealand North region right away. Because Microsoft manages the networking for you, choosing the Australasia geography where New Zealand North has been added to lets the service optimize Cloud PC placement automatically for performance and resilience. To enable the New Zealand North region: * Learn more about how Microsoft Hosted Network improves resiliency and regional coverage. * Configure provisioning policy to use the Australasia geography > New Zealand region group > New Zealand North region. * Ensure you select “Auto select new region groups” and “Auto select new regions” so Windows 365 can dynamically choose the best region available. Azure Network Connection (ANC) customers If you're using ANC, you remain in control of your network topology. To use the New Zealand North region, your environment will need a quick validation or update. To enable the New Zealand North region: * Review the Azure Network Connection documentation. * Confirm your ANC setup supports New Zealand North, including virtual networks and necessary service endpoints. * Once ready, adjust your provisioning policies to target New Zealand North. Explore more about Windows 365 With New Zealand North now available, this is the perfect time to bring Cloud PCs closer to your users. Start provisioning in the new region and give your organization the performance and resiliency benefits immediately.  To explore configuration options and learn more about what’s possible next, head over to the Windows 365 documentation.    --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A. 
010
ConfigMgrDogs @configmgrdogs.bsky.social · 10/02/2026
What to know about Windows 11, version 26H1: Windows continually works in partnership with our OEMs and IHVs to support new device innovations. Windows 11, version 26H1 is a targeted release that supports some of the new device innovations coming in 2026. That means that this release… #WindowsITPro
bit.ly
What to know about Windows 11, version 26H1
Windows continually works in partnership with our OEMs and IHVs to support new device innovations. Windows 11, version 26H1 is a targeted release that supports some of the new device innovations coming in 2026. That means that this release is not being made available through broad channels but is only intended for those who purchase these new devices. At this time, devices with Qualcomm Snapdragon® X2 Series processors will come with Windows 11, version 26H1. Organizations should continue to purchase, deploy, and manage devices running broadly released versions of Windows 11 (e.g. versions 24H2 and 25H2) with confidence. Windows 11, version 26H1 is not a feature update for version 25H2. There is no need to pause device purchases or OS deployments, and no changes required to existing enterprise rollout plans. Windows will continue to have annual feature updates in the second half of the calendar year. Windows 11, version 26H1 is a scoped release * Windows 11, version 26H1 will only be available on new devices with select new silicon as they come to market in early 2026. * Windows 11, version 26H1 is not offered as an in-place update from Windows 11, version 24H2 or 25H2 on existing devices. * There is no impact to devices already in market today. * Devices running Windows 11, version 26H1 will continue receiving monthly updates for security, quality, and new features, the same as devices running Windows 11, versions 24H2 and 25H2. * Devices running Windows 11, version 26H1 will not be able to update to the next annual feature update in the second half of 2026. This is because Windows 11, version 26H1 is based on a different Windows core than Windows 11, versions 24H2 and 25H2, and the upcoming feature update. These devices will have a path to update in a future Windows release. * Windows 11, version 26H1 does not support hotpatch updates. * Windows 11, version 26H1 security updates will be manageable through typical tooling – Windows Autopatch, Microsoft Intune, Microsoft Configuration Manager, etc. This approach allows Windows to support the development of new hardware capabilities while protecting the stability and predictability that commercial customers rely on in production environments. What this means for IT planning For IT admins planning refreshes, rollouts, or purchases, Windows 11, versions 24H2 and 25H2 remain the recommended releases for enterprise deployment at this time. * New PCs being released with Windows 11, versions 24H2 and 25H2 are fully supported and continue to receive monthly security and quality updates following the official support lifecycle policy. * For organizations with homogenous environments, those who prioritize standardization, long deployment windows, and large volume management, Windows 11, versions 24H2 and 25H2 remain the right choices. You'll always have a path to the next annual release when you follow the predictable H2 update cadence. * Early adopters who wish to take advantage of the full benefits of new hardware platforms may evaluate Windows 11, version 26H1 selectively — without disruption to the rest of their estate. For instructions on how to check, see Windows 11, version 26H1 update history. In short: Windows 11, version 26H1 should not impact your current Windows deployment and purchasing strategy. There is no benefit to waiting or deferring plans based on version 26H1, unless you are specifically targeting adoption of devices with silicon that requires such. Our ongoing commitment We remain committed to: * Predictable servicing and lifecycle policies * Clear communication when action is required * Strong backward compatibility * Minimal disruption to enterprise operations If and when a Windows release requires changes to deployment planning or management practices, we will communicate that clearly, directly, and with sufficient runway. We'll continue to deliver updates through the same servicing model you rely on today. We'll keep you informed as Windows evolves and continues to improve performance and battery life for both existing and new devices.   --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
030
ConfigMgrDogs @configmgrdogs.bsky.social · 02/02/2026
Windows news you can use: January 2026: Welcome to the January 2026 Windows news you can use, including new capabilities in Windows Backup for Organizations and Windows 365. Coming up on February 5, there will be another Secure Boot AMA, so please tune in to get answers to your… #WindowsITPro
bit.ly
Windows news you can use: January 2026
Welcome to the January 2026 Windows news you can use, including new capabilities in Windows Backup for Organizations and Windows 365. Coming up on February 5, there will be another Secure Boot AMA, so please tune in to get answers to your questions. Then, on Mondays in March, join us for deep dives, AMAs, and more at Microsoft Technical Takeoff for Windows and Microsoft Intune. Check out the full schedule and start adding sessions to your calendar. Now, let's get started with the latest news you can use. New in Windows update and device management * [BACKUP] [RESTORE] – Windows Backup for Organizations is expanding to include a new restore experience at first sign-in. In early 2026, Windows 11 users will be able to restore their Windows settings and Microsoft Store app list at the very first sign-in. Even on Microsoft Entra hybrid join devices and multi-user setups. * [UPDATES] [OOBE] – Starting with the January 2026 security update, the ability to install Windows quality updates during the out-of-box experience (OOBE) will no longer be enabled by default in Microsoft Intune. * [WINDOWS 365] – Windows 365 is now available in the Brazil South region. Your organization can now provision Cloud PCs closer to your users in Brazil and across South America, helping reduce latency and support regional data residency requirements. * [INTUNE] – Get insights from the experts by watching last week's Intune edition of Tech Community Live, now available on demand. Learn how to secure endpoints with policy and Microsoft Defender, manage apps, and apply Zero Trust best practices when managing devices in Intune. New in Windows security * [NETWORK] [ACCESS] – Windows is moving toward a more secure authentication model by phasing out New Technology LAN Manager (NTLM) in favor of stronger, Kerberos‑based alternatives. Get familiar with the phased roadmap for NTLM disablement and tools that will help prepare your organization for this change. * [WINDOWS HELLO] – The January 2026 optional non-security update starts the gradual rollout of support for peripheral fingerprint sensors with Windows Hello Enhanced Sign-in Security (ESS). * [SECURE BOOT] – The Secure Boot playbook has been updated to make it easier to identify the steps and tools to help you proactively update Secure Boot certificates across your estate before they start expiring in June of 2026. Have questions? Post them now then tune in for the Secure Boot AMA on February 5, 2026 at 8:00 AM PT. * [SECURE BOOT] [INTUNE] – You can now deploy, manage, and monitor Secure Boot certificate updates using Microsoft Intune. Step-by-step guidance is now available and has been added to the Secure Boot playbook for easy reference. Additionally, a new Secure Boot status report is now available in Windows Autopatch. * [SECURE BOOT] [WINDOWS UPDATE] – Starting with the January 2026 security update, Windows quality updates include a subset of high confidence device targeting data that identifies devices eligible to automatically receive new Secure Boot certificates. Devices will receive the new certificates only after demonstrating sufficient successful update signals, ensuring a safe and phased deployment. * [DATA PROTECTION] – With the January 2026 optional non-security update, IT admins can now set how often Data Protection Application Programming Interface (DPAPI) domain backup keys rotate automatically. This strengthens cryptographic security and reduces reliance on older encryption algorithms. * [VIRTUALIZATION] [CLOUD PC] – A unified, policy-driven way to control which RDP Shortpath modes (Managed, Public/STUN, Public/TURN) are enabled across Azure Virtual Desktop session hosts and Windows 365 Cloud PCs is now available. Explore RDP Shortpath configuration via Group Policy or Microsoft Intune. * [M365] – Starting February 9, 2026, Microsoft will continue to ramp up enforcement, and users will be unable to sign in to the Microsoft 365 admin center without successfully completing multifactor authentication. * [WDS] – Starting with the January 2026 security update, you can explicitly disable WDS hands-free deployment with the help of new Event Log alerts and registry key options. In April 2026, hands-free deployment will be disabled by default. After that date, it will no longer work unless explicitly overridden with registry settings. New in AI * [WINDOWS 365] – Windows 365 for Agents introduces a set of capabilities that make it possible to run autonomous AI agents securely on Cloud PCs. Enhancements will help you automate complex tasks, reduce idle costs, and ensure trust in autonomous operations. To learn about latest capabilities for Copilot+ PCs, visit the Windows Roadmap and filter Platform by "Copilot+ PC Exclusives." New in productivity and collaboration Install the January 2026 security update for Windows 11, versions 25H2 and 24H2 to get these and other capabilities. * [START MENU] – The redesigned Start menu continues its gradual rollout to Windows devices. As the rollout progresses, more Windows devices will receive the redesigned Start menu experience. New features and improvements are coming in the February 2026 security update. You can preview them by installing the January 2026 optional non-security update for Windows 11, version 25H2 and version 24H2. This update includes the gradual rollout of: * [MOBILE] – Cross‑Device Resume is expanding to include the ability to continue activities from your Android phone on your PC based on the apps and services you use, including resuming Spotify playback, working in Word, Excel, or PowerPoint, or continuing a browsing session. * [NARRATOR] – Narrator now gives you more control over how it announces on‑screen controls. You can choose which details are spoken and adjust their order to match how you navigate apps. * [VOICE ACCESS] – Voice Access setup has been streamlined to make it easier to get started. The redesigned experience helps you download a speech model for your chosen language, select your preferred input microphone, and learn what Voice Access can help you do on your Windows PC. You can also now adjust the amount of delay before a voice command runs. * [AUDIO] – Windows now offers enhanced support for MIDI 1.0 and MIDI 2.0, including full WinMM and WinRT MIDI 1.0 support with built-in translation, shared MIDI ports across apps, custom port names, loopback, and app-to-app MIDI. * [SETTINGS] – The Device card on the Settings home page appears when you sign in with your Microsoft account. It now shows key specifications and usage details for your PC. * [COPILOT+ PC] – The Settings Agent now supports more languages, with expanded support for German, Portuguese, Spanish, Korean, Japanese, Hindi, Italian, and Chinese (Simplified). New for developers * [APPS] [TOOLS] – The Windows App Development CLI (winapp) is now available in public preview. It's a new open-source command-line tool designed to simplify the development lifecycle for Windows applications across a wide range of frameworks and toolchains. New in Windows Server For the latest features and improvements for Windows Server, see the Windows Server 2025 release notes and Windows Server, version 23H2 release notes. * [ACTIVE DIRECTORY] – Guidance is now available to help mitigate potential threats to Active Directory Domain Services, including authentication relay attacks, Kerberoasting, and unconstrained delegation. * [KERBEROS] – The first phase of protections designed to address a Kerberos information disclosure vulnerability are now available. They include new auditing and optional configuration controls that help reduce reliance on legacy encryption types such as RC4 and prepare domain controllers. * [REMINDER] – Starting with the January 2026 security update, Windows Server 2025 updates and release notes have their own KB identifiers and build numbers. These identifiers are separate from those for Windows 11, versions 24H2 and 25H2. This change improves clarity for administrators. Installation and management processes remain the same. Out-of-band updates Two out-of-band updates were released in January: * January 17, 2026 – Out-of-band update to address sign-in failures during Remote Desktop connections * January 24, 2026 – Out-of-band update to address cloud‑backed storage application issues Lifecycle milestones Check out our lifecycle documentation for the latest updates on Deprecated features in the Windows client and Features removed or no longer developed starting with Windows Server 2025. Additional resources Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources: * Windows Roadmapfor new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name * Microsoft 365 Copilot release notesfor latest features and improvements * Windows Insider Blogfor what's available in the Canary, Dev, Beta, or Release Preview Channels * Windows Server Insiderfor feature preview opportunities * Understanding update history for Windows Insider preview features, fixes, and changesto learn about the types of updates for Windows Insiders Join the conversation If you are an IT admin with questions about managing and updating Windows, add our monthly Windows Office Hours to your calendar. We assemble a crew of Windows, Windows 365, security, and Intune experts to help answer your questions and provide tips on tools, best practices, and troubleshooting. Finally, we are always looking to improve this monthly summary. Drop us a note in the Comments and let us know what we can do to make this more useful for you! --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 02/02/2026
Tune in, skill up: Windows at Tech Takeoff 2026: Four Mondays. Dozens of Windows and Windows‑in‑the‑cloud deep dives. One perfect chance to skill up. Microsoft Technical Takeoff is back for 2026—and if you're focused on Windows, Windows 365, or Azure Virtual Desktop, this year's… #WindowsITPro
bit.ly
Tune in, skill up: Windows at Tech Takeoff 2026
Four Mondays. Dozens of Windows and Windows‑in‑the‑cloud deep dives. One perfect chance to skill up. Microsoft Technical Takeoff is back for 2026—and if you're focused on Windows, Windows 365, or Azure Virtual Desktop, this year's lineup is packed with practical demos, real‑world insights, and direct access to engineering teams to help you deploy faster, recover smarter, protect better, and optimize with confidence. What is Tech Takeoff? Microsoft Technical Takeoff is a free, technical skilling event that takes place on the Microsoft Tech Community. Our engineering PMs across Windows and our Windows‑in‑the‑cloud experiences have once again been hard at work—building deep dives, crafting demos, and shaping guidance designed to help you confidently configure, roll out, manage, and support the features your organization relies on to stay secure, productive, and resilient. This year's lineup reflects months of collaboration across engineering teams, all with one goal in mind: giving you clear, actionable insights you can put to work right away. But as always, Technical Takeoff isn't just about what we've built—it's about you. Throughout every session, our engineering and product teams will be live in the chat, answering questions as they come in—and continuing to monitor discussions throughout the week. So post early, post often. Whether you're looking for troubleshooting help, implementation advice, or clarity on what's coming next, we're here and ready to dive in with you. That's the heart of Technical Takeoff: learning together, solving real problems, and helping you deliver great Windows experiences at scale. Windows sessions at Tech Takeoff 2026 Below is an easy guide to all Windows‑focused sessions, organized by date. Click into any session page to Add to Calendar, save your spot (click Attend), and post your questions in the Comments. Engineering teams will be answering live during the session and then monitoring for additional questions throughout each week. Monday, March 2 * 7:00 AM PT – Let's talk Windows and Intune: 2026 edition * 7:30 AM PT – The latest in Windows 11 security * 8:00 AM PT – Uplevel business continuity with Windows 365 Reserve * 8:30 AM PT – Hotpatch updates demystified: answers to real-world questions * 10:30 AM PT – Eliminating NTLM in Windows * 11:30 AM PT – Resiliency with Windows 365 and Azure Virtual Desktop Monday, March 9 * 7:00 AM PT – The latest in security for Windows 365 and Azure Virtual Desktop * 7:30 AM PT – Secure Boot certificate updates explained * 8:30 AM PT – Ready day one: how to get Windows users up and running fast * 9:30 AM PT – Windows 365 reporting and monitoring updates * 10:00 AM PT – Least privilege on Windows with Endpoint Privilege Management * 10:30 AM PT – Windows 365 Frontline expands with Cloud Apps and more * 11:00 AM PT – From panic to productive: point-in-time restore in Windows Monday, March 16 * 7:00 AM PT – Why smarter Windows management starts with Intune * 7:30 AM PT – Real-time reporting with Windows Autopatch update readiness * 8:00 AM PT – User experience updates: Windows 365 Boot and more * 10:30 AM PT – App Control for Business: same roots, new playbook * 11:30 AM PT – Migrating from VDI to Windows 365 Monday, March 23 * 7:00 AM PT – Powering protection: what's new in Windows hardware security * 7:30 AM PT – Zero Trust DNS: Securing Windows one connection at a time * 8:00 AM PT – Secure and manage AI and agentic capabilities in Windows * 8:30 AM PT – Deploy and manage Windows 365 with Microsoft Intune * 9:30 AM PT – Azure Virtual Desktop for hybrid environments * 10:00 AM PT – Protect users, stop attacks: Passkeys on Windows * 10:30 AM PT – AMA: AI and agentic features for Windows 365 * 11:00 AM PT – Transitioning to post-quantum cryptography * 11:30 AM PT – Resilience for the modern era: Windows quick machine recovery We want to hear from you The IT community shapes this event as much as the speakers do. What's top of mind for you today? What challenges are slowing you down, and where can we offer clarity, shortcuts, or direction? Which enhancements, policy improvements, or optimizations would make your day‑to‑day Windows management easier? Your questions and feedback help guide our product roadmaps and help us identify topics for future tech skilling videos and community events. Technical Takeoff is one of our favorite opportunities to hear from you directly—so don't be shy. Tune in live and talk with us! Bookmark https://aka.ms/TechnicalTakeoff to see the full agenda and check out What's in store for Intune at Microsoft Technical Takeoff 2026. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
010
ConfigMgrDogs @configmgrdogs.bsky.social · 29/01/2026
Advancing Windows security: Disabling NTLM by default: Windows is moving toward a more secure authentication model by phasing out New Technology LAN Manager (NTLM) in favor of stronger, Kerberos‑based alternatives. Let’s look at enhanced auditing and upcoming tools to help prepare… #WindowsITPro
bit.ly
Advancing Windows security: Disabling NTLM by default
Windows is moving toward a more secure authentication model by phasing out New Technology LAN Manager (NTLM) in favor of stronger, Kerberos‑based alternatives. Let’s look at enhanced auditing and upcoming tools to help prepare your organization for disabling NTLM by default. The evolution of Windows authentication For more than three decades, NTLM has been part of Windows authentication. It is a legacy authentication protocol that uses challenge-response verification for access to network resources, most often as a fallback when Kerberos is unavailable. NTLM consists of security protocols originally designed to provide authentication, integrity, and confidentiality to users. However, as security threats have evolved, so have our standards to meet modern security expectations. Today, NTLM is susceptible to various attacks, including replay and man-in-the-middle attacks, due to its use of weak cryptography. Microsoft is committed to helping your organization transition to stronger authentication mechanisms. In this post you’ll find a long-term roadmap to reduce, restrict, and ultimately remove NTLM from Windows. The importance of moving from deprecation to disabling NTLM Today, NTLM is classified as deprecated. Deprecated features remain available, but no longer receive updates or enhancements and may be removed in a future release. Despite its deprecated status, NTLM continues to be prevalent in environments where modern protocols, such as Kerberos, are not feasible due to legacy dependencies, network limitations, or ingrained application logic. The ongoing use of NTLM exposes organizations to the following risks: * No server authentication * Vulnerability to replay, relay, and pass-the-hash attacks * Weak cryptography * Limited diagnostic data and auditing visibility (until recently) It is now time to transition from deprecation to disabling NTLM by default in upcoming Windows releases. While the overarching objective is to eventually remove NTLM entirely, a phased strategy enables you to mitigate NTLM-related risks in a secure and predictable manner, without disrupting your organization. A phased approach that meets you where you are The roadmap below presents a three-phased approach toward this goal. Important: Timelines and feature availability outlined in this post are subject to change as engineering schedules evolve. With each phase come new capabilities so that your organization has the tools, visibility, and compatibility support needed before NTLM becomes disabled by default. Let’s take a closer look at each phase. Phase 1: Building visibility and control Available now, enhanced NTLM auditing helps your organization understand exactly where and why NTLM is still being used in your environment. This is the foundation of any NTLM migration effort. You can use it today with Windows Server 2025 and Windows 11, versions 24H2 and later. For additional guidance, see Disabling NTLM. Phase 2: Addressing the top NTLM pain points Here is how we can address some of the biggest blockers you may face when trying to eliminate NTLM: * No line of sight to the domain controller: Features such as IAKerb and local Key Distribution Center (KDC) (pre-release) allow Kerberos authentication to succeed in scenarios where domain controller (DC) connectivity previously forced NTLM fallback. * Local accounts authentication: Local KDC (pre-release) helps ensure that local account authentication no longer forces NTLM fallback on modern systems. * Hardcoded NTLM usage: Core Windows components will be upgraded to negotiate Kerberos first, reducing instances on NTLM usage. The solutions to these pain points will be available in the second half of 2026 for devices running Windows Server 2025 or Windows 11, version 24H2 and later. Phase 3: NTLM disabled by default In the next major Windows Server release and associated Windows client releases: * Network NTLM will be disabled by default. * NTLM usage will require explicit re-enablement through new policy controls. * Support for handling NTLM only cases will be built-in, reducing application breakage. Examples include accessing targets with unknown SPNs, authentication requests made using IP addresses, local accounts on domain joined machines, and new NTLM blocking policies. But what does ‘NTLM disabled by default’ really mean? Disabling NTLM by default does not mean completely removing NTLM from Windows yet. Instead, it means that Windows will be delivered in a secure-by-default state where network NTLM authentication is blocked and no longer used automatically. The OS will prefer modern, more secure Kerberos-based alternatives. At the same time, common legacy scenarios will be addressed through new upcoming capabilities such as Local KDC and IAKerb (pre-release). Note: While Microsoft continues to work toward NTLM-independent Windows, during phase 3, NTLM will remain present in the OS and can be explicitly re-enabled via policy if you still need it. This approach balances meaningful security improvements while maintaining a supported and phased transition as you move away from NTLM. Our commitment to a secure, compatible transition Disabling NTLM represents a major evolution in Windows authentication, and a critical step toward a passwordless, phishing resistant future. That is why we are committed to providing clear communication of timelines and expectations, and a phased transition with opt-in/opt-out controls. Our phased roadmap is designed to give every organization clear, predictable steps to prepare for default NTLM disablement in Windows. If your organization is beginning or accelerating its NTLM reduction efforts, now is the right time to engage your identity, security, and application owners to take concrete steps: * Deploy enhanced NTLM auditing to identify where NTLM is still used. * Map dependencies across applications and services, and prioritize remediation. This may include reaching out to application developers to update critical applications. * Migrate and validate that critical workloads succeed with Kerberos. The capabilities that will be released in the second half of 2026 will significantly expand the scenarios where you can use Kerberos successfully. * Begin testing NTLM-off configurations in non-production environments. * Enable Kerberos upgrades as they become available through the Windows Insider Program, and then more broadly later this calendar year. These actions will help you surface gaps early and prepare for NTLM being disabled by default and ultimately removed in future Windows releases. We will continue to publish updated documentation, migration guides, and scenario specific instructions as new capabilities enter flighting or reach general availability later this calendar year. If you discover unique or hard-to-mitigate scenarios where NTLM is still being used, please reach out to ntlm@microsoft.com. These insights help us validate edge cases and ensure our features fully support real-world environments. --- Securing the present, innovating for the future Security is a shared responsibility. Through collaboration across hardware and software ecosystems, we can build more resilient systems secure by design, by default and during runtime, from Windows to the cloud, enabling trust at every layer of the digital experience. Learn how to stay secure with Windows. Check out the updated Windows 11 Security Book and Windows Server Security Book, more about Windows 11, Windows Server, Windows hotpatch updates and Copilot+ PCs. To learn more about Microsoft Security Solutions, visit our website. Bookmark the Microsoft Security Blog to keep up with our expert coverage on security matters. You can also follow Microsoft Security on LinkedIn and @MSFTSecurity on X for the latest news and updates on cybersecurity.
010
ConfigMgrDogs @configmgrdogs.bsky.social · 28/01/2026
Announcing General Availability of RDP Shortpath Configuration via GPO and Microsoft Intune: We are pleased to announce the general availability (GA) of centralized RDP Shortpath configuration using Microsoft Intune and Group Policy (GPO). This update gives IT administrators a… #WindowsITPro
bit.ly
Announcing General Availability of RDP Shortpath Configuration via GPO and Microsoft Intune
We are pleased to announce the general availability (GA) of centralized RDP Shortpath configuration using Microsoft Intune and Group Policy (GPO). This update gives IT administrators a unified, policy-driven way to control which RDP Shortpath modes (Managed, Public/STUN, Public/TURN) are enabled across Azure Virtual Desktop (AVD) session hosts and Windows 365 Cloud PCs. These Shortpath controls now map directly to registry-backed policies, so IT admins can easily maintain consistent behavior across large or distributed environments. RDP Shortpath provides multiple optimized UDP-based transport paths—Managed, Public/STUN, and Public/TURN—that improve connection performance and reliability across diverse network environments. These options collectively form the RDP Shortpath feature set, and we recommend keeping them all enabled so the best path can be selected automatically. However, if your organization requires stricter control—for example, disabling STUN based traversal to ensure traffic flows only through TURN’s dedicated port and subnet—admins now have the policy-driven flexibility to do so through centralized configuration. Organizations using Windows 365 and AVD have asked for stronger policy-governed control over Shortpath behavior—especially as network environments grow more complex. With this release, admins: * No longer need per-host manual configuration. * Gain predictable, enforced behavior across managed devices. * Can centrally govern Shortpath modes based on security, NAT topology, or network readiness. This release brings Shortpath into the same modern management motion that customers already use for Windows configuration, compliance, and security. Benefits of centralized Shortpath configuration Unified policy management across AVD and Windows 365 Admins can centrally control all three Shortpath modes through GPO or Intune, which directly writes the relevant registry-backed configuration on each session host. This ensures consistent and governed behavior across all devices. Operates in addition to AVD host pool configuration For Azure Virtual Desktop, these GPO and Intune configurations act in addition to host pool network settings. This gives admins an extra layer of control at the session host level. When both host pool settings and policies are configured, the session-host policy takes precedence, ensuring deterministic behavior. This layering model is reinforced in internal discussions where session host configuration remained necessary in cases such as enabling UDP listener paths.   Important! The settings described in this article update registry-backed policies that enable or disable RDP Shortpath modes. Network prerequisites must still be in place (UDP allowed; STUN/TURN endpoints reachable) for connections to succeed. After policies apply, restart the session hosts or Cloud PCs for changes to take effect. See Optimization of RDP documentation for more detail.   Configuring RDP Shortpath using Intune To enable the RDP Shortpath listener on your session hosts using Microsoft Intune:   * Sign in to the Microsoft Intune admin center. * Create or edit a configuration profile  for Windows 10 and later devices, with the Settings catalog profile type. * In the settings picker, browse to Administrative templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Azure Virtual Desktop > RDP Shortpath. * Expand the Administrative Templates category. * For each RDP Shortpath type, toggle the setting to Enabled or Disabled. * Enabled or Not Configured: The connection will attempt to use the specified network path. * Disabled: The connection will not use this network path. * Available RDP Shortpath types: * RDP Shortpath for managed networks using NAT traversal * RDP Shortpath for public networks using NAT traversal * RDP Shortpath for public networks using Relay (TURN) * Select Next. * Optional: On the Scope tags tab, select a scope tag to filter the profile. For more information about scope tags, see Use role-based access control (RBAC) and scope tags for distributed IT.  * On the Assignments tab, select the group containing the computers providing a remote session you want to configure, then select Next.  * On the Review + create tab, review the settings, then select Create. * Once the policy applies to the computers providing a remote session, restart them for the settings to take effect.  Configuring RDP Shortpath using Group Policy (GPO) in an Active Directory domain To configure the RDP Shortpath using Group Policy in an Active Directory domain:  * Make the administrative template for Azure Virtual Desktop available in your domain by following the steps in Use the administrative template for Azure Virtual Desktop.  * Open the Group Policy Management console on a device you use to manage the Active Directory domain.  * Create or edit a policy that targets the computers providing a remote session you want to configure.  * Navigate to Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Azure Virtual Desktop > RDP Shortpath.   * Review the available RDP Shortpath types:  * RDP Shortpath for managed networks using NAT traversal   * RDP Shortpath for public networks using NAT traversal   * RDP Shortpath for public networks using Relay(TURN)   * Double-click the policy setting Enable RDP Shortpath for managed networks to open it.  * Set the policy to Enabled or Disabled:   * Enabled or Not Configured: The connection will attempt to use the specified network path.  * Disabled: The connection will not use this network path.  * Ensure the policy is applied to the session hosts, then restart them for the settings to take effect.  Note After you configure the GPO policy, restart the session to ensure the changes take effect. Summary The GA of RDP Shortpath configuration via GPO and Microsoft Intune gives administrators:  * Stronger policy-governed control  * Deterministic Shortpath behavior  * A layered model that works with AVD host pool configuration  * A consistent management experience across Windows 365 and AVD  While these policy settings simplify administration, network prerequisites still determine whether Shortpath will successfully establish.  We welcome your feedback and hope these enhancements help streamline your connectivity strategy across Windows 365 and Azure Virtual Desktop environments.    Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A .
011
ConfigMgrDogs @configmgrdogs.bsky.social · 26/01/2026
Windows 365 now supported in Brazil South: Today, we’re pleased to announce that Windows 365 is now available in the  Brazil South region. Organizations can now provision Cloud PCs closer to their users in Brazil and across South America, helping reduce latency and support regional… #WindowsITPro
bit.ly
Windows 365 now supported in Brazil South
Today, we’re pleased to announce that Windows 365 is now available in the  Brazil South region. Organizations can now provision Cloud PCs closer to their users in Brazil and across South America, helping reduce latency and support regional data residency requirements. With this update, Brazil South joins the list of supported Azure regions for Windows 365, giving IT teams greater flexibility in how they deploy and scale Cloud PCs. Note: Brazil South was previously available only through an exception process. With capacity now in place to support all customers, the region is now fully open for general availability. To take advantage of Brazil South and future regional expansions, we recommend configuring your provisioning policies at the geography level using  Multi‑Region Selection. This automatically places Cloud PCs in the best available region within the selected geography, improving resiliency and ensuring users always land on the optimal regional capacity. Recommended next steps Below are the tailored steps depending on the networking model your organization uses. If you use Microsoft Hosted Network (MHN) Microsoft Hosted Network is the simplest way to gain immediate benefits from new regions such as Brazil South. Microsoft manages all network placement decisions, so selecting a geography ensures your Cloud PCs are kept within the best available region automatically. Steps: * Review the documentation on enhanced resiliency with Microsoft Hosted Network. * Configure provisioning policies to use Geography (for example, “South America”). * Use automatic region selection for the most flexibility and scalability. If you use Azure Network Connection (ANC) Azure Network Connection customers continue to maintain control over networking and may need to update configurations to use Brazil South. Steps: * Review the documentation on Azure Network Connection. * Ensure your ANC supports the Brazil South region, including virtual network availability and required endpoints. * Update provisioning policies to select Brazil South or a broader region group once your network configuration is validated. Get started You can now provision Cloud PCs in Brazil South using your existing provisioning workflows. To learn more about configuration options, resiliency, and future regional expansion, visit the Windows 365 documentation. Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 14/01/2026
Windows Backup for Organizations expands to first sign-in restore: Exciting news! Windows Backup for Organizations is expanding to include a new restore experience at first sign-in. In early 2026, Windows 11 users will be able to restore their Windows settings and Microsoft Store apps… #WindowsITPro
bit.ly
Windows Backup for Organizations expands to first sign-in restore
Exciting news! Windows Backup for Organizations is expanding to include a new restore experience at first sign-in. In early 2026, Windows 11 users will be able to restore their Windows settings and Microsoft Store apps at the very first sign-in. Even on Microsoft Entra hybrid joined, multi-user setups, and Windows 365 Cloud PCs. Learn more and sign up to preview it today. What's new in Windows Backup for Organizations? Windows Backup for Organizations enables you to streamline your transition to the latest version of Windows by securely preserving Windows settings, the list of installed Microsoft Store apps, and Start menu pins. Whether part of a device refresh strategy or migration away from Windows 10 (now out of support), Windows Backup for Organizations is all about helping get users productive faster after a reset or reimage. A new first sign-in restore experience (currently in private preview) is part of our ongoing commitment to resilience and productivity. Users signed in with a Microsoft Entra ID on eligible devices get a “second chance” to restore their environment if they missed the option during the out-of-box experience (OOBE). Note: If users deliberately choose to skip the restore opportunity during OOBE, their preference will be respected. With first sign-in restore, your users get back to work faster, with their preferred settings and Microsoft Store app list ready to go. Key benefits of offering restore at first sign-in You've already been able to help keep users productive when moving to a new PC or restoring after an incident—at scale. With a first sign-in restore experience, you benefit from: * Broader coverage: Safely restore more devices, including Microsoft Entra hybrid joined devices, multi-user setups, and Windows 365 Cloud PCs. * Same seamless experience: Restore Windows settings and the Microsoft Store app list at first sign-in, as you would during OOBE, minimizing downtime and accelerating productivity. * Continued focus on user-centric recovery: Even if users miss the opportunity to restore during OOBE by accident or due to a technical issue, they can still get their personalized environment at first sign-in. No more starting from scratch. Learn more and help shape what's next If you're new to Windows Backup for Organizations, you can familiarize yourself with this feature by reading the following articles” * Windows Backup for Organizations is now available * Windows Backup for Organizations overview Look out for this new capability in early 2026. In the meantime, if you're interested in testing it early, consider joining the private preview! Complete an interest form, which can also be accessed by scanning the QR code below. The form and the opportunity to sign up will remain open through Friday, February 13, 2026. To be eligible for the preview you need to be part of the Microsoft Management Customer Connection Program and have a signed non-disclosure agreement (NDA). If you're not a current member of the program, sign up today. We're excited to bring you this expansion. Your feedback continues to be invaluable as we shape the future of Windows Backup for Organizations and roll out exciting new features. Thank you for partnering with us to make Windows even better! --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 06/01/2026
Windows news you can use: December 2025: Last month, Windows security experts hosted an Ask Me Anything about updating Secure Boot certificates on Windows devices before the certificates expire in June 2026. Be sure to watch the video and read the questions and answers posted in the… #WindowsITPro
bit.ly
Windows news you can use: December 2025
Last month, Windows security experts hosted an Ask Me Anything about updating Secure Boot certificates on Windows devices before the certificates expire in June 2026. Be sure to watch the video and read the questions and answers posted in the discussion section. Also, please bookmark the Secure Boot Playbook page to stay up to date on the latest details and guidance on this topic. While December is usually a “quiet” month, there was still Windows news to be shared. Here's a quick recap: New in Windows update and device management * [AUTOPATCH] – Try the new Common Vulnerabilities and Exposures (CVEs) report in Windows Autopatch. It provides a comprehensive view of Windows CVEs addressed by recent quality updates, along with direct links to remediation documentation and device-level vulnerability status. * [INTUNE] – Microsoft is bringing Microsoft Intune Suite capabilities to Microsoft 365 E3 and Microsoft 365 E5. No action is necessary. Find out which capabilities will be included in Microsoft 365 plans. Then keep an eye on Microsoft 365 admin center notifications for release dates. * [CLOUD] [RESILIENCY] – Multi-region selection is now available and rolling out to all organizations utilizing Windows 365. We are also reducing the number of geographies and increasing the number of regions within each geography. Ready for more flexibility, regional resiliency, and latency optimization? New in Windows security * [BITLOCKER] – BitLocker now takes advantage of system on chip (SoC) and central processing unit (CPU) capabilities. You can now achieve better performance and security for current and future NVMe drives. Learn how hardware-accelerated BitLocker works and find out how to check if your devices are using this latest improvement. * [ENTRA] – Starting with the December 2025 security update, you can now authenticate Microsoft Entra ID app sign-ins through Web Account Manager (WAM) with WebView2, the Chromium-based web control. This improvement supports modern web standards, advanced security, and future-ready scenarios. * [SECURE BOOT] – Preparing to update Secure Boot certificates on Windows devices? The certificates expire in June 2026. Check out the recording of our December Ask Me Anything. New in AI * [COPILOT+ PC] – The latest Windows skilling snack packages up a robust set of resources. Get up to speed on using and managing AI-powered features and experiences unique to Copilot+ PCs. Access all of our bite-sized technical learning journeys, each designed to be consumed in two hours or less, via the refreshed Windows skilling snack library! New in productivity and collaboration * [CLOUD] [VIRTUALIZATION] – Multimedia call redirection on Azure Virtual Desktop and Windows 365 now supports Genesys Cloud and Five9 Contact-Center-as-a-Service (CCaaS) platforms. Get a more optimized calling experience for contact center agents using Genesys Cloud or Five9 in virtual environments. New in Windows Server For the latest features and improvements for Windows Server, see the Windows Server 2025 release notes and Windows Server, version 23H2 release notes. * [WS2025] – Starting with the January 2026 security update, Windows Server 2025 will have its own KBIDs, separate from Windows 11, versions 24H2 and 25H2. This change improves clarity for administrators. Installation and management processes remain the same. * [NVMe] [WS2025] – You can now opt in to native NVMe support in Windows Server 2025. With native NVMe, Windows Server can communicate directly with NVMe devices. This removes reliance on SCSI commands and significantly enhances storage performance and efficiency. Lifecycle milestones Check out our lifecycle documentation for the latest updates on Deprecated features in the Windows client and Features removed or no longer developed starting with Windows Server 2025. Additional resources Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources: * Windows Roadmap for new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name * Microsoft 365 Copilot release notes for latest features and improvements * Windows Insider Blog for what's available in the Canary, Dev, Beta, or Release Preview Channels * Windows Server Insider for feature preview opportunities * Understanding update history for Windows Insider preview features, fixes, and changes to learn about the types of updates for Windows Insiders As we enter 2026, we're looking to make this monthly summary more helpful to you! Please drop us a note below and let us know what information you most want to hear about. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
210
ConfigMgrDogs @configmgrdogs.bsky.social · 19/12/2025
Announcing hardware-accelerated BitLocker: We know that users desire both security and great performance. Historically, we have strived to keep BitLocker performance overhead within single digit percentage points. However, with the rapid rise in popularity and advancement of… #WindowsITPro
bit.ly
Announcing hardware-accelerated BitLocker
We know that users desire both security and great performance. Historically, we have strived to keep BitLocker performance overhead within single digit percentage points. However, with the rapid rise in popularity and advancement of Non-Volatile Memory Express (NVMe) drive technology, these drives now achieve much higher Input/Output (I/O) operation speeds. As a result, corresponding BitLocker cryptographic operations can require a higher proportion of CPU (Central Processing Unit) cycles. This makes the performance impact of BitLocker more pronounced, especially on high-throughput and I/O intensive workloads like gaming or video editing. As NVMe drives continue to evolve, their ability to deliver extremely fast data transfer rates has set new expectations for system responsiveness and application performance. While this is a major benefit for users, it also means that any additional processing — such as real-time encryption and decryption by BitLocker — can become a bottleneck if not properly optimized. For example, professionals working with large video files, developers compiling massive codebases, or gamers demanding the lowest possible latency may notice delays or increased CPU usage when BitLocker is enabled on these high-speed drives. Balancing robust security with minimal performance impact is more challenging than ever. The need to protect sensitive data remains critical, but users also expect their devices to operate at peak efficiency. As a result, the industry has needed to innovate new solutions that ensure both security and speed are maintained even as hardware capabilities advance. To achieve this, we announced hardware-accelerated BitLocker at Microsoft Ignite last month.  Hardware-accelerated BitLocker is designed to provide the best combination of performance and security. Starting with the September 2025 Windows update for Windows 11 24H2 and the release of Windows 11 25H2, in addition to existing support for UFS (Universal Flash Storage) Inline Crypto Engine technology, BitLocker will take advantage of upcoming system on chip (SoC) and central processing unit (CPU) capabilities to achieve better performance and security for current and future NVMe drives. These capabilities are: * Crypto offloading – BitLocker shifts bulk cryptographic operations from the main CPU to a dedicated crypto engine. This capability frees up CPU resources for other tasks and helps improve both performance and battery life. * Hardware protected keys – BitLocker bulk encryption keys, when necessary SoC support is present, are hardware wrapped, which helps increase security by reducing their exposure to CPU and memory vulnerabilities. This is an addition to the already supported Trusted Platform Module (TPM), which protects intermediate BitLocker keys, putting us on a path to completely eliminate BitLocker keys from the CPU and memory.   When enabling BitLocker, supported devices with NVMe drives along with one of the new crypto offload capable SoCs will use hardware-accelerated BitLocker with the XTS-AES-256 algorithm by default. This includes automatic device encryption, manual BitLocker enablement, policy driven enablement, or script-based enablement with some exceptions. (Please see the Enablement and management experiences section below for more details.) We have enhanced the architecture and implementation of the Windows storage and security stacks to support these new capabilities as an operating system enhancement that will bring value to all capable PCs over time. Upcoming Intel vPro® devices featuring Intel® Core™ Ultra Series 3 (formally codenamed Panther Lake) processors will provide initial support for these capabilities with support for other vendors and platforms planned. Coordinate with your suppliers and keep an eye on listings from us and other vendors as PCs become available on the market. How Hardware-accelerated BitLocker works – diagram A diagram comparing a software BitLocker to hardware accelerated BitLocker. These diagrams show data flow for both software BitLocker and hardware-accelerated BitLocker. The type of the arrows indicate if we are dealing with unencrypted data (dotted arrow), encrypted data (solid arrow) or key management operations (dashed arrow).  1. In software BitLocker all the cryptographic operations for I/O (reads and writes) are executed on the main CPU before the I/O reaches the drive. 2. In hardware-accelerated BitLocker all the cryptographic operations for I/O (reads and writes) are executed on the dedicated part of the SoC before the I/O reaches the NVMe drive. Additionally, the BitLocker bulk encryption key is hardware protected by the SoC (if SoC supports it). Performance improvement over software BitLocker According to our tests, storage performance with hardware-accelerated BitLocker can approach NVMe performance without BitLocker encryption across common workloads.​ We see performance improvements in storage and I/O metrics like sequential and random writes and reads when comparing hardware-accelerated BitLocker to software BitLocker. In addition to the better storage performance, hardware-accelerated BitLocker provides on average a 70% savings in CPU cycles compared with software BitLocker. The CPU cycle savings can result in longer battery life.​ A bar chart comparing an average number of cycles per IO between hardware-accelerated BitLocker and software BitLocker as opposed to without BitLocker encryption Note: Test outcomes may differ and are influenced by the platform’s H/W configuration. Validation To check if your device is using hardware-accelerated BitLocker, open a command prompt as an administrator and run manage-bde -status. Look at the Encryption Method section — if you see Hardware accelerated shown, it indicates that BitLocker is utilizing the SoC’s crypto acceleration capabilities. A command-prompt interface shows hardware-accelerated BitLocker as the encryption method We are working on improving our tools’ status readout to clearly show which capabilities are used. Product demo: comparing Software BitLocker and Hardware-accelerated BitLocker performance This video compares software BitLocker and hardware-accelerated BitLocker by enabling both via command line, verifying encryption methods, and running benchmarks to assess performance differences. It concludes by demonstrating hardware-protected keys. Video from the Microsoft Ignite 2025 conference comparing software BitLocker to hardware-accelerated BitLocker. Note: (0:28 - 0:41) Accelerated for demo purposes, actual times may vary. Enablement and management experiences For BitLocker provisioning during the WinPE (Windows Preinstallation Environment) flow and other offline provisioning scenarios, cryptographic offloading will function as intended provided that the disk is used on compatible hardware with appropriate drivers, and the chosen algorithm and encryption method align with those supported by the SoC. Hardware-accelerated BitLocker will not be used in Windows if: * A user enables BitLocker manually through the command line or PowerShell and specifies an algorithm or key size that is not supported by the SoC vendor. This also applies to any automation tools or scripts.​ * An administrator applies an enterprise policy (through MDM or GPO) with a key size or algorithm that the SoC vendor does not support (such as AES-CBC-128 bit or AES-CBC-256 bit). We plan to modify this behavior in an early spring update by automatically increasing the key size for new BitLocker enablements, but not changing the algorithm itself. For instance, if the policy specifies AES-XTS-128 bit, it will be upgraded to AES-XTS-256 to enable hardware-accelerated BitLocker on supported platforms. However, if the policy specifies AES-CBC-128 or AES-CBC-256, the algorithm will not be changed to AES-XTS, and hardware-accelerated BitLocker will not be utilized.   * An IT Administrator enables the “System cryptography: Use FIPS 140 compliant cryptographic algorithms, including encryption, hashing, and signing algorithms” policy (link). The use of hardware-accelerated BitLocker relies on whether the SoC reports FIPS certification of its hardware key wrapping and crypto offloading capabilities to Windows. We encourage you to leverage these advancements to help maximize both security and performance on your devices. Thank you for taking the time to stay informed and proactive about device protection. Securing the present, Innovating for the future Security is a shared responsibility. Through collaboration across hardware and software ecosystems, we can build more resilient systems secure by design and by default, from Windows to the cloud, enabling trust at every layer of the digital experience. The updated Windows Security book and Windows Server Security book  are available to help you understand how to stay secure with Windows. Learn more about Windows 11, Windows Server and Copilot+ PCs.. To learn more about Microsoft Security Solutions, visit our website.  Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.  Windows 11 security book - Windows security book introduction | Microsoft Learn --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/12/2025
Windows skilling snacks: bite-sized technical learning: If you are looking for a quick way to get up to speed on features, tools, and recommended approaches for deploying and managing Windows, skilling snacks are here to help. With the wealth of Microsoft articles, demos, tools, and… #WindowsITPro
bit.ly
Windows skilling snacks: bite-sized technical learning
If you are looking for a quick way to get up to speed on features, tools, and recommended approaches for deploying and managing Windows, skilling snacks are here to help. With the wealth of Microsoft articles, demos, tools, and resources available, it can be difficult to know where to start or what to prioritize. With Windows skilling snacks, we've curated a library of technical learning journeys, each of which can be consumed in less than two hours. That means you can skill up during a slow morning, over a long lunch break, or whenever it best suits your schedule. Follow and bookmark this page for new installments—and comment below if there is there is a topic you'd like us to cover. Navigate to: New on the menu | Device and update management | Security | Accessibility and productivity | Extra bites New on the menu * Get started with AI in Windows * AI and Windows admin management * AI on Windows Copilot+ PCs * AI for Windows developers * Get started with Microsoft 365 Copilot Chat   Device and update management * Windows Autopilot 101 * Configure devices with Windows Autopilot * Windows Autopilot device preparation * Windows monthly updates * Managing Windows 11 updates * Windows Autopatch * Hotpatch on Windows client and server * Windows driver update management * Mobile device management in Microsoft Intune * Windows device management in the public sector * Best practices for shared and frontline Windows devices * Reduce bandwidth for Microsoft content delivery * Microsoft Store apps and app migration * Do more with Microsoft Graph * Windows lifecycle   Security * Security fundamentals * Windows hardware security * Windows application security * Data security basics for IT pros * Windows passwordless options * BitLocker management for enterprises * Network security basics for endpoints * Advanced network security * Windows Server security * Windows security for developers   Accessibility and productivity * Accessibility in Windows 11 * Voice access in Windows * Tools for creating accessible content * Cloud-based printing with Universal Print   Extra bites * Your Windows release information toolbox * Windows events and communities * Windows app compatibility * Windows 11 end-user readiness * Windows 365 or Azure Virtual Desktop   Archive These resources contain information that may be dated, but still offer valuable historical context, foundational guidance, or reference material. While not fully current, they can help you understand earlier approaches or provide background knowledge. * Plan, prepare, and deploy Windows 11 * From on premises to the cloud * Feature update management * Using Windows Update for Business * Application control for Windows * Windows LAPS --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 11/12/2025
Skilling snack: AI on Windows Copilot+ PCs: You can be a lot more productive with AI on Copilot+ PCs, the newest type of Windows PCs. In the past year, we’ve added several new features and capabilities designed to boost productivity and inclusivity. See how Copilot+ PCs evolved with… #WindowsITPro
bit.ly
Skilling snack: AI on Windows Copilot+ PCs
You can be a lot more productive with AI on Copilot+ PCs, the newest type of Windows PCs. In the past year, we’ve added several new features and capabilities designed to boost productivity and inclusivity. See how Copilot+ PCs evolved with AI powered features like Click to Do, Recall, improved Windows search, and Fluid dictation (in preview). Windows accessibility features are designed for everyone, empowering people of all abilities to work, create, and connect seamlessly including AI-driven tools and functionality. Learn more and start managing Copilot+ PCs with their exclusive features with this collection of resources.   Time to learn: 128 mins Introduction to Copilot+ PCs * Copilot+ PCs and features for business (1 min): Watch this short video at the top of the page to get introduced to Copilot+ PCs. They’re the fastest, most intelligent, and most secure Windows devices, with the best battery life and performance on the market. * Get started with Copilot+ PC features (6 mins): Access your Copilot+ PC features in several ways. Get tips on creating, enhancing your calls, and personalizing your productivity. The evolution of Copilot+ PCs * Evolving Windows: new Copilot and AI experiences at Ignite 2025 (11 mins): Check out the latest productivity and accessibility features offered by M365 Copilot. On Windows 11, interact with Copilot with voice, check on the agents on the taskbar, use search and Ask Microsoft 365 Copilot directly in the taskbar, get file assistance from File Explorer Home, and prepare for meetings in the agenda view in the Notification Center. This and more can be done on Copilot+ PCs! There’s more on accessibility features, agent support, and security enhancements. * Empowering the future: The expanding Arm app ecosystem for Copilot+ PCs (6 mins): If you’re a developer, find out about what’s now available on Arm for Copilot+ PCs. Learn about endpoint protection apps, VPN and Zero Trust Network Access (ZTNA) apps, endpoint management tools, productivity apps, and more. Measuring Copilot+ PC impact for your organization * New technology: The projected Total Economic Impact™ of Microsoft Copilot+ PCs (27 mins): Building a business case for Copilot+ PCs for your organization? This Microsoft commissioned Forrester study calculates the 3-year projected return on investment to be 137%-367%, depending on a variety of factors. Compare your context with the composite organization to visualize what your quantified and unquantified benefits might be. * Copilot+ PCs: The fastest, most intelligent Windows PCs ever! (31 mins): For resources to share with the technical decision makers at your organization, get this on-demand video. Managing Copilot+ PCs and AI * AMA: Manage AI and intelligent agents in Windows (30 mins): Learn how to enable AI experiences for your organization with security and control. Get tips on using Microsoft Intune or Group Policy to fine-tune popular features like Recall, Copilot, Click to Do, and Image Creator. * Configure the agent in Windows Settings (3 mins): This unique Copilot+ PC feature uses on-device AI to help users at your organization find and change settings on their device. * Updated Windows and Microsoft 365 Copilot Chat experience (10 mins): Short press the Copilot key (or Windows key+C shortcut) to invoke the Microsoft 365 Copilot Chat prompt box. Long press the Copilot key (or Win+C shortcut) or say “Hey Copilot” (available in Frontier in the coming weeks) to directly activate voice in Microsoft 365 Copilot and start a back-and-forth conversation. Not ready to use Copilot yet? Remap the Copilot key on Copilot+ PCs! Read about managing the Copilot key. AI for accessibility on Copilot+ PCs * Fluid dictation (in preview) (3 mins): Preview how to manage a unique Copilot+ PC feature for voice access, available in all English locales and enabled by default. Fluid dictation automatically corrects grammar, punctuation, and filler words as you speak. Most Windows 11 accessibility features are not exclusive to Copilot+ PCs. The following AI resources are also available to meet accessibility needs of people at your organization: * Accessibility tools for Microsoft Copilot (time varies): Find a list of screen reader capabilities across Microsoft 365 apps available to users at your organization. Follow the corresponding links to learn more. * Using Copilot in accessibility (time varies): Browse accessibility scenarios that Microsoft Copilot can help with. See how you can simplify your workflows by functional area or industry, key performance indicators (KPIs), or accessibility roles. Download and share these tools with your organization. This wraps up our series of skilling snacks on Windows and AI! Did you miss any? * Skilling snack: Get started with AI in Windows * Skilling snack: AI and Windows admin management * Skilling snack: Get started with Microsoft 365 Copilot Chat * Skilling snack: AI for Windows developers For more resources on a variety of topics, check out our growing Windows skilling snacks library. Let us know what other topics you’re hungry for! ___________________________________________________________________________________________________________________________________________________ --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 10/12/2025
Introducing resiliency improvements with Microsoft Hosted Network: Resilience improvements with Microsoft Hosted Network At Microsoft, we understand that customers need a desktop service that is reliable and resilient — in other words, a service that simply works. Continuing our… #WindowsITPro
bit.ly
Introducing resiliency improvements with Microsoft Hosted Network
Resilience improvements with Microsoft Hosted Network At Microsoft, we understand that customers need a desktop service that is reliable and resilient — in other words, a service that simply works. Continuing our efforts to deliver customers a robust and productive Cloud PC experience, today we are announcing several new features that enhance reliability and resiliency even further. Introducing Microsoft Hosted Network (MHN) enhancements As the number of Azure regions and the number of regions that Windows 365 supports has continued to grow, we saw an opportunity to re-organize region grouping in a way that simplifies region selection and maximizes platform availability when issues occur. Additionally, customers have requested a streamlined way to achieve their data sovereignty requirements when deploying Cloud PCs. To meet this requirement, we are introducing a new region group location tier that will sit between the current geography and region locations. We are also re-organizing region grouping to provide better availability of the underlying Azure capacity that your Cloud PCs require. Introducing the new Region Group location tier We are now introducing a new Region Group tier that provides improved data sovereignty along with improved resiliency. You now have three options for locations that can be selected within a provisioning policy:   The Geography tier remains unchanged, except for the number and region membership of each which is discussed later. It now contains the new region group tiers, which will include multiple regions. When creating a new provisioning policy all region groups within that geography will be selected by default, as well as all regions within the region groups. Our recommendation is to keep all region groups selected as it maximizes regions available and increases overall workload resiliency. The Region Group tier is new. This tier will group Azure regions into groupings for data sovereignty requirements, while also providing multiple regions for resiliency, across which the resulting Cloud PCs are distributed. A region group typically maps to a single country or a specific geographical boundary (E.g. US East, US West etc.) Choosing this tier establishes the data sovereignty for all Cloud PCs deployed via a MHN provisioning policy where a region grouping has been selected. As new regions are enabled for Windows 365, these will be added into the appropriate region group, providing future resiliency improvements. The Region tier remains unchanged and still allows you to select a specific region if that is your requirement. However, selecting a specific region limits your benefits of the grouping of regions, i.e. the automatic distribution of your Cloud PC estate across multiple Azure regions, which may increase the impact of an Azure region outage. We are removing the MHN-Automatic option from the region selection part of the provisioning policy user interface and making this same behavior an automatic and intrinsic part of the service when selecting a geography or region group. We recommend using the Geography tier whenever possible for maximum resiliency and flexibility. If you have country-specific data sovereignty requirements, choose a region group instead. Region groups still support cross-region deployments, though with fewer regions than a geography. Even if a group currently has only one region, please select it as future additions will automatically provide multi-region benefits. New location selection for Microsoft-hosted network and network type within a provisioning policy, with an example showing three-tier provisioning selections. Re-organizing the region grouping to provide better availability of underlying Azure capacity In addition to the new three-tiered location selection, and to maximize the effectiveness of these improvements, we are reducing the number of geographies and increasing the number of regions within each of these geographies, which in turn provides more selection flexibility, reginal resiliency, and latency optimization. The new location selection matrix is listed below: Geography Region Group Region Asia Singapore Southeast Asia Hong Kong East Asia Japan Japan East Japan West South Korea Korea Central Australasia Australia Australia East Canada Canada Canada Central Europe France (EU) France Central Germany (EU) Germany West Central Ireland (EU) North Europe Italy (EU) Italy North Netherlands (EU) West Europe Poland (EU) Poland Central Spain (EU) Spain Central Sweden (EU) Sweden Central Norway Norway East United Kingdom UK South Switzerland Switzerland North India India India Central Africa South Africa South Africa North US Central US Central Central US South Central US US East US East East US East US 2 US West US West West US 2 West US 3 South America Brazil Brazil South Middle East Israel Israel Central UAE UAE North Qatar Qatar Central Mexico Mexico Mexico Central New Azure region organization available within a provisioning policy, showing the reduced number of geographies, the new “region group” mid-tier, and more regions available within the geographies. Grouping an increased number of regions into a smaller number of geographies and introducing the new middle region group tier provides more flexibility for the Windows 365 service. As new regions come online, they will be added into the relevant region group and geography where appropriate. New service capabilities to enhance resilience and flexibility Besides Microsoft Hosted Network (MHN) enhancements, we are introducing two new service capabilities for newly created provisioning policies that will apply to Cloud PCs deployed to either the geography or region group tiers without requiring manual intervention. * Intelligent Cross region distribution To maximize Cloud PC resiliency, Windows 365 now distributes deployments across all healthy regions within a geography or region group when selected. This is applied to all new Cloud PCs within a provisioning policy, minimizing the impact of any single region issue. If your estate of 100 Cloud PCs has been distributed across ten regions and a single region has an outage, then only ten percent of your estate will be affected, as opposed to 100%, which could happen if they were all deployed to the region experiencing the outage. All regions within a geography or region group will be within a similar latency boundary. You can check regional location in two easy ways: 1. Within the All Cloud PCs blade: there will be a new Cloud PC Region column (hidden by default) in the All Cloud PCs view. This displays the current deployment region of each Cloud PC. You can enable this column to surface the region information in the Intune portal. 2. Via the Microsoft Graph API: The ListCloudPCs API includes a deviceRegionName property in its response, which indicates the provisioning region for each Cloud PC. * Snapshot distribution When using cross region disaster recovery with MHN and multi-region selection, recovery snapshots are distributed across multiple regions instead of being stored in one region. So, if the disaster recovery region faces issues during recovery, only Cloud PCs with snapshots in that region are affected. Remaining Cloud PCs can still recover from their respective regions. These new features are only available via the MHN network type when selecting either a geography, a region group, or a group of individual regions. They will not be made available in the Azure Network Connection (ANC) network type. Likewise, region grouping improvements are only applicable when using MHN, so we encourage customers to use the MHN network type as much as possible. Click here for further detailed instructions: Enhance Microsoft Hosted Network (MHN) Cloud PC Resiliency with Multi-Region Selection A layered approach to business continuity With today’s announcement, Windows 365 now offers a more complete and flexible resiliency strategy, one that meets customers where they are and scales with their needs. Whether you're looking for built-in protection from localized disruptions or enterprise-grade continuity across regions, Windows 365 provides a completely customizable layered approach to workload resiliency that adapts to your business.  Level 1: Point-in-time restore, included within the service. Level 2: Enhanced MHN functionality, new and included within the MHN service. Level 3: Premium disaster recovery: cross region disaster recovery and disaster recovery plus, which are both paid add-ons. Level 4: Windows 365 Reserve, a new separate licensed offering for Windows 365 that can enhance physical device resiliency. The enhancements we are announcing today will provide important improvements for the on-going management of your total physical and Cloud PC estate, all taken care of by Microsoft so that you don’t have to. By selecting the geography or region group options, Windows 365 will balance your Cloud PC estate across multiple regions within a geography, reducing the impact that a regional issue may have. The additional resiliency enhancements enabled within the platform demonstrate our commitment to providing more reliable service for our customers. We encourage you to take full advantage of these features in Windows 365 — just tell Microsoft which geography you want your Cloud PCs in and we will manage the rest for you. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 09/12/2025
Now generally available: Modernizing Microsoft Entra ID auth flows with WebView2 in Windows 11: We’re thrilled to share an important update: Entra ID app sign-in through Web Account Manager (WAM) now has the option to be powered by WebView2, the Chromium-based web control, starting… #WindowsITPro
bit.ly
Now generally available: Modernizing Microsoft Entra ID auth flows with WebView2 in Windows 11
We’re thrilled to share an important update: Entra ID app sign-in through Web Account Manager (WAM) now has the option to be powered by WebView2, the Chromium-based web control, starting with KB5072033 (OS Builds 26200.7462 and 26100.7462) or later. This release marks a significant step forward in delivering a secure, modern, and consistent sign-in experience across apps and services. What is a WebView? A WebView is a UI component that allows you to display web content (HTML, CSS, JavaScript) inside a native application. Instead of opening a full browser, a WebView embeds a browser engine within your app so you can render web pages or web-based UI directly in your application window. Windows has many user experiences that use WebViews to gather web information and present it to users that look like native content. One common scenario for this is authentication flows, where a user is prompted for their username and provides credentials. Why we made this change Authentication is the front door to your digital world. As identity experiences evolve, we need a foundation that supports modern web standards, advanced security, and future-ready scenarios. WebView2 provides exactly that. Key benefits This update includes several benefits, including: * Modern Standards: Built on Chromium, WebView2 supports the latest web technologies, enabling richer, more responsive sign-in interfaces and compatibility with modern frameworks like React and Fluent UI. * Future-Ready Experiences: Unlocks advanced scenarios such as Passwordless sign-in, passkeys, and seamless integration with Conditional Access policies — all with fewer redirects and friction. * Better Compatibility: Improves support for third-party identity providers and enterprise apps that rely on modern web frameworks, ensuring consistent experience across diverse environments. Getting started This transition is seamless for most users and apps. If you manage enterprise deployments: * Ensure your environment meets WebView2 runtime requirements (including in recent Windows builds or available via evergreen installer). * Customers that have already seen their auth flows work in Microsoft Edge-based browsers should work without any configuration change. If any issues are observed, please see: o   Microsoft Edge identity support and configuration | Microsoft Learn o   Configure browsers to use Windows Integrated Authentication (WIA) with AD FS | Microsoft Learn * Visit https://learn.microsoft.com/ for detailed guidance on WebView2 integration and troubleshooting. Enabling WebView2 in the Entra ID plugin After installing KB5072033 (OS Builds 26200.7462 and 26100.7462) or later, enable the WebView2Integration registry key by using regedit, command line, or policy to configure a registry entry by updating the registry with: Reg key location: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AAD Reg key value: WebView2Integration as a DWORD and assign it to “1” for WebView2 integration to be ON. Note: If the AAD key does not exist, create it by right-clicking on Windows, selecting New > Key, and naming it AAD. Figure 1 - Screenshot of the registry value to add After applying the registry key, the device should be ready to use. Try authenticating or adding a work account in apps such as Teams, Feedback Hub, Office, or Edge.  Disabling WebView2 in the Entra ID plugin Disable the WebView2Integration registry key by using the registry, command line, or policy to configure a registry entry by updating the registry with: Reg key location: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AAD Reg key value: WebView2Integration as a DWORD and assign it to “0” for WebView2 integration to be OFF. After applying the registry key, the device should be ready to use. Try authenticating or adding a work account in apps such as Teams, Feedback Hub, Office, or Edge.  Looking ahead WebView2 will become the default framework for WAM authentication in an expected future Windows release, with the EdgeHTML WebView being deprecated. Therefore, we encourage users to deploy now and participate in the opt-in process, enable this experience in their environments, and make any necessary adjustments — such as updating proxy rules or modifying code in services involved in the logon process. Contact Customer Support Services if you'd like to provide feedback. Moving to WebView2 is more than a technical upgrade — it’s a strategic investment in secure, user-friendly identity experiences. We’re committed to evolving Entra ID to meet the needs of modern organizations and developers. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 04/12/2025
Genesys Cloud and Five9 now supported on Azure Virtual Desktop and Windows 365: We’re excited to announce that multimedia call redirection on Azure Virtual Desktop and Windows 365 now supports Genesys Cloud and Five9, both Contact-Center-as-a-Service (CCaaS) platforms. This… #WindowsITPro
bit.ly
Genesys Cloud and Five9 now supported on Azure Virtual Desktop and Windows 365
We’re excited to announce that multimedia call redirection on Azure Virtual Desktop and Windows 365 now supports Genesys Cloud and Five9, both Contact-Center-as-a-Service (CCaaS) platforms. This enhancement enables a more optimized calling experience for contact center agents using Genesys Cloud or Five9 in virtual environments. To see a full list of supported CCaaS solutions, refer to our documentation. What is multimedia call redirection? Multimedia call redirection optimizes WebRTC-based calls by redirecting audio data from Azure Virtual Desktop session hosts or Windows 365 Cloud PCs to the user’s local device. This offloading helps reduce latency, improve call quality, and deliver a “like-local” communication experience, as if the call was happening directly on the user’s physical device rather than through a remote cloud connection. Benefits of using multimedia call redirection Integrating multimedia call redirection with CCaaS solutions on Azure Virtual Desktop and Windows 365 offers direct benefits for customers, particularly those in contact centers or hybrid work environments: * Enhanced call quality: By redirecting WebRTC calls to the local device, multimedia call redirection is designed to minimize latency and packet loss, helping ensure clearer audio. This can be especially important for contact center agents where clear communication directly impacts customer satisfaction and support case completion rates. * Improved productivity: With multimedia call redirection, agents experience an enhanced, like-local call experience, helping reduce interruptions and allowing them to better focus on delivering quality customer service. * Resource optimization: Multimedia call redirection offloads multimedia processing from the Azure Virtual Desktop session host or Windows 365 Cloud PC to the physical endpoint, helping to reduce the computational load on the underlying virtual machine by bypassing the remote session and helping improve audio quality and reduce latency. This can also help optimize resource usage in the cloud, especially for organizations that are scaling their virtual desktop environments. * Seamless integration with Windows App: Multimedia call redirection works effortlessly with Windows App, a unified platform that connects users to Windows desktops and apps from Azure Virtual Desktop, Windows 365, and other Microsoft services. * Enhanced flexibility for remote and hybrid workforces: Multimedia call redirection can help support remote and hybrid teams with reliable, high-quality communication tools. Agents can use Genesys Cloud or Five9 on Azure Virtual Desktop or Windows 365 from any supported device, helping promote consistent performance regardless of location. Getting started To take advantage of multimedia call redirection, ensure your environment meets the following requirements: * Multimedia call redirection host version: Use version 1.0.2507.21006 or higher (download the MSI installer ). This is already included in the Windows gallery image for Windows 365. * Browser support: Install the latest version of Microsoft Edge or Google Chrome on your session hosts. * Setup guide: Follow the detailed instructions in the Microsoft documentation to configure multimedia call redirection for Azure Virtual Desktop or Windows 365. * Refer to the following links for all necessary configuration details: o   Genesys Cloud documentation and blog o   Five9 documentation and blog Certify your CCaaS solution for multimedia call redirection Are you a CCaaS provider or developer looking to certify your WebRTC-based calling app for multimedia call redirection? Multimedia call redirection provides a versatile solution compatible with most calling apps. You can start testing your app’s compatibility by following these validation steps. Contact us to officially list your app as supported or reach out to Microsoft Support for any compatibility issues. _______________________________________________________________________________________________________________________________________________________________ --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 04/12/2025
New Windows Autopatch report on CVEs: Your security team needs clear, actionable insights to protect your organization from emerging threats. The new Common Vulnerabilities and Exposures (CVEs) report in Windows Autopatch delivers just that. Get a comprehensive view of Windows CVEs… #WindowsITPro
bit.ly
New Windows Autopatch report on CVEs
Your security team needs clear, actionable insights to protect your organization from emerging threats. The new Common Vulnerabilities and Exposures (CVEs) report in Windows Autopatch delivers just that. Get a comprehensive view of Windows CVEs addressed by recent quality updates, along with direct links to remediation documentation and device-level vulnerability status. Why CVE reporting matters With the increasing pace of security updates and the complexity of enterprise environments, it can be a struggle to track which vulnerabilities have been remediated and which devices remain at risk. The CVE report bridges this gap and joins your other Windows quality update reports right in the Microsoft Intune admin center. This empowers your organization to prioritize update deployment, demonstrate compliance, and maintain a robust security posture. Key features of the new Windows Autopatch report * Comprehensive CVE list: View all Windows CVEs addressed in the past 90 days, including severity ratings and exploitation status. * Device vulnerability tracking: Identify which managed devices are missing updates for specific CVEs. * Access to technical details and remediation guidance: Each CVE entry links to the Windows update KB article (also known as a release note) that describes the fix. * Search and filter: Easily locate CVEs by ID, severity, or update release * Export: Share and use this report offline as you implement your response strategy. * Timely insights: The report latency is two hours, reflecting the latest changes for the most actionable insights. How to access the report * Navigate to the Microsoft Intune admin center. * Go to Reports > Windows Autopatch > Windows quality updates. * Select the Reports tab. * Select the Common Vulnerabilities and Exposures (CVEs) report Screenshot of the Common Vulnerabilities and Exposures (CVEs) report in Microsoft Intune admin center Inside the report The report contains details and links relevant to the CVE, to the update that addresses it, and to your environment. CVEs are unique identifiers assigned to publicly disclosed security vulnerabilities that Microsoft has investigated, confirmed, and published. For each CVE, see related columns of CVE Name, CVE Base Score, and Exploited to learn about its status. The columns Release, KB Article, and Published relate to the Windows update that contains the fix for this CVE. Review the number of devices in the column Devices Missing Update. Select a cell to invoke a flyout with the complete list of device names and their OS versions to inform your next steps. Screenshot of the flyout of Devices missing a selected CVE, including device names and OS versions Improve your vulnerability response strategy today The new CVE report in Windows Autopatch can help strengthen your vulnerability response strategy. Once you identify devices exposed to a high severity CVE, depending on the scenario, you can: * Use Windows Autopatch update readiness (currently in preview) to proactively monitor, troubleshoot, and repair devices to help ensure they receive quality updates smoothly. * Expedite corresponding updates using Microsoft Intune or Microsoft Graph. To learn more, see Get the most out of expedited Windows quality updates. * Use the Security Copilot Vulnerability Remediation Agent in Intune (currently in limited public preview). Try the new report today and let us know what you think! Here’s what else can get you started: * Common Vulnerabilities and Exposures (CVEs) report * MSRC Security Update Guide: Vulnerabilities * Windows Autopatch documentation * Security Copilot Vulnerability Remediation Agent in Microsoft Intune --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 02/12/2025
Windows news you can use: November 2025: In case you haven’t yet had time to catch up on all the announcements from Microsoft Ignite, I’m happy to offer a recap of what was revealed in the world of Windows and Windows 365 plus a few security and Microsoft Intune highlights. Have… #WindowsITPro
bit.ly
Windows news you can use: November 2025
In case you haven’t yet had time to catch up on all the announcements from Microsoft Ignite, I’m happy to offer a recap of what was revealed in the world of Windows and Windows 365 plus a few security and Microsoft Intune highlights. Have questions on any of what you read below? Join us this week for Windows Tech Community Live. We’ll be live streaming panel-based discussions today—then answering your questions on the session pages through Friday. That means there is plenty of time to get the answers you need to keep your deployment and device management projects moving. Let’s jump in! New in Windows update and device management * [AUTOPATCH] [TOOLS] – Announced at Microsoft Ignite, Windows Autopatch update readiness brings improved clarity, reporting, automation, and control to Windows update management. Capabilities include automated checks, device update journey maps, actionable alerts, guided remediation, advanced cloud-based policies for managing monthly updates with control, and reporting. * [RECOVERY] [AUTOPATCH] – With quick machine recovery, you can automatically detect, diagnose, and remediate boot critical issues from WinRE. No need for hands-on, in-person intervention. This capability can be enabled by IT policy for devices running Windows 11, version 24H2 or 25H2. A preview of quick machine recovery management in Windows Autopatch is also available. Start controlling the deployment of quick machine recovery updates, including approvals, schedules, alerts, and reporting.  * [RESTORE] – A preview of point-in-time restore is being rolled out to Windows Insiders in the Beta and Dev Channels. With this feature, you can remotely restore a PC to a previous state from restore points stored on the device. When a device or group of devices has been suddenly impacted, point-in-time restore provides a fast way to return to productivity without waiting for a targeted fix. * [AUTOPATCH] [GCC] – Windows Autopatch is available to US government organizations as part of Microsoft 365 Government. It has been added to the Azure FedRAMP High Provisional Authorization to Operate (P-ATO). Work is underway to expand the service to also meet the requirements of US Government Community Cloud High (GCC High) and Department of Defense (DoD) environments. * [WINDOWS 365] [LINK] – Key updates for Windows 365 Link are coming in the first quarter of 2026. You’ll get support for pairing Bluetooth® devices during the out-of-box experience, support for tenant branding, and the ability to restore a device to its factory default state using a bare metal recovery image. * [ROLLBACK] – Known Issue Rollback is a robust mitigation technology that can quickly return an impacted device back to productive use if an issue arises during a Windows update. A new article provides insight into how Known Issue Rollback works, scenarios it supports, and answers to frequently asked questions. New in Windows security * [SECURE BOOT] – Tools and prescriptive guidance are now available to help you proactively update your Secure Boot certificates before they expire in June of 2026. Have questions about this Secure Boot milestone? Save the date and join our Secure Boot Ask Microsoft Anything (AMA) event on December 10. * [FOUNDATIONS] – Read the November 2025 Secure Future Initiative Progress Report to explore recent advancements in Windows security and resilience. You’ll also learn how Surface leads the Windows ecosystem by enabling all recommended Windows security features by default. * [PASSWORDLESS] – With the November 2025 security update, Windows 11 includes native support for passkey managers. This means you can choose your favorite passkey manager — whether it’s Microsoft Password Manager or trusted third-party providers. * [SYSMON] – Native Sysmon functionality is coming to Windows 11 and Windows Server 2025 next year. With this change, you’ll be able to capture granular diagnostic data without having to deploy and maintain Sysmon manually across your digital estate. * [WINDOWS 365] [DATA PROTECTION] – Windows Cloud Keyboard Input Protection is now in public preview. This capability ensures the confidentiality and integrity of sensitive input data. How? By encrypting user keystrokes at the kernel level and decrypting them exclusively within the remote virtual environment. The public preview is available for both Windows 365 Cloud PCs and for Azure Virtual Desktop session hosts and virtual machines (VMs). * [WINDOWS 365] [IDENTITY] – With the latest updates to Windows 365 and Azure Virtual Desktop, you now can provide access to users outside your organization. Simply invite them into your organization. No need to create and assign brand new, temporary accounts. * [INTUNE] [ZERO TRUST] – Aligning network policies with Zero Trust and cloud-native architecture can require trade-offs. Explore common models, benefits, and implementation guidance. New in AI * [COPILOT] – Windows is evolving to include agent-like functions built into the operating system, new tools offered by Microsoft 365 Copilot on Windows, and capabilities powered by Copilot+ PC hardware. Explore the announcements from Microsoft Ignite. Get early access to new features through the Windows Insider Program and by setting your tenant (or selected users) up for Targeted Release in the Microsoft 365 admin center. * [WINDOWS 365] [AI] – Windows 365 AI-enabled Cloud PCs combine Windows 365 with AI acceleration to help users boost productivity and discover information faster. All that while maintaining enterprise-level security and compliance. For early access, explore Frontier. * [WINDOWS 365] [AI] – Are you an agent maker? Now in public preview, Windows 365 for Agents provides a comprehensive set of APIs that you can use to manage and utilize compute resources. * [INTUNE] [AI] – Microsoft Intune is evolving to include assistive chat-based and agentic experiences. They will help you make smarter decisions, achieve better compliance, and reduce risk through intelligence and automation. Intune is also introducing admin tasks, a centralized view for high-priority items, so you can act quickly on what matters most.  New in productivity and collaboration Install the November 2025 security update for Windows 11, versions 25H2 and 24H2 to get these and other capabilities. * [START MENU] – When you launch the Start menu, you can switch and choose between two new views. Category view groups apps by type and highlights frequently used ones. Grid view lists apps alphabetically with more horizontal space for easier scanning. Select Show all for a scrollable list of all your apps. The Start menu is also more responsive, enabling larger displays to show more pinned apps, recommendations, and categories by default. * [BATTERY] – New battery icons in the system tray utilize color indicators to show charging status and batter levels. These icons also now appear in the lower-right corner of the lock screen to make it easier to check your device’s charging status and battery level at a glance. New in Windows Server For the latest features and improvements for Windows Server, see the Windows Server 2025 release notes and Windows Server, version 23H2 release notes. * [START MENU] [WS2025] – A Boolean option has been added to the Configure Start Pins policy to allow admins to apply Start menu pins that appear on first use. Users can then make any changes to their Start pinned layout and have those changes preserved.  * [SECURITY] [WS2025] – Explore API support for NIST post-quantum cryptography algorithms ML-KEM and ML-DSA in accordance with FIPS 203 and FIPS 204 standards. * [MANAGEMENT] – Windows Admin Center Virtualization Mode (vMode) has been released in Public Preview. Windows Admin Center vMode helps you easily manage on-premises Windows Server Hyper-V virtualization at scale – across multiple hosts and clusters – while bridging your environment with Azure Arc. Lifecycle milestones Check out our lifecycle documentation for the latest updates on Deprecated features in the Windows client and Features removed or no longer developed starting with Windows Server 2025. * [WINDOWS 10] – Have you taken steps to ensure that the Windows 10 devices in your organization are activated with an ESU license? If not yet, check out our step-by-step guide. Additional steps are needed to enable ESUs for local devices accessing Windows 365. * [WINDOWS 11 23H2] – Windows 11, version 23H2 (Home and Pro editions) reached end of servicing on November 11, 2025. Enterprise and Education editions will continue to receive updates through November 10, 2026 per the Modern Lifecycle Policy. * [SERVER] – Officially deprecated in Windows Server 2022, the Windows Internet Name Service (WINS) will be removed from all Windows Server releases after Windows Server 2025. Standard support will continue through the lifecycle of Windows Server 2025, which is supported until November of 2034. * [CONFIGMGR] – Starting with version 2609, Microsoft Configuration Manager will transition to an annual release cadence.  Additional resources Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources: * Windows Roadmap for new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name * Microsoft 365 Copilot release notes for latest features and improvements * Windows Insider Blog for what’s available in the Canary, Dev, Beta, or Release Preview Channels * Windows Server Insider for feature preview opportunities * Understanding update history for Windows Insider preview features, fixes, and changes to learn about the types of updates for Windows Insiders What else can we include in this monthly summary to make it more useful? Drop us a note below with your feedback. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 26/11/2025
Ask the Windows experts at Tech Community Live: Join us December 2 for a Windows edition of Tech Community Live. Together, my colleagues across Windows will be answering your questions on the new features and capabilities announced at Microsoft Ignite and in recent months. This event… #WindowsITPro
bit.ly
Ask the Windows experts at Tech Community Live
Join us December 2 for a Windows edition of Tech Community Live. Together, my colleagues across Windows will be answering your questions on the new features and capabilities announced at Microsoft Ignite and in recent months. This event is your opportunity to engage directly with the engineering teams behind the features and get the information you need to keep your updates flowing and your deployments progressing. Tech Community Live: Windows edition – May 31, 2023 This edition of Tech Community Live features four back-to-back Ask Microsoft Anything (AMA) sessions. Click the title(s) below to access the session pages, where you can add them to your calendar. While you’re there, sign in to—or sign up for—the Tech Community and post your questions now while they are top of mind. Once signed in, click the Attend button to let us know you’re coming and receive reminders. Time Ask Microsoft Anything about... 8:00 AM PST (4:00 PM UTC) Managing Windows updates  9:00 AM PST (5:00 PM UTC) Managing AI and agents in Windows 9:30 AM PST (5:30 PM UTC) Windows backup and restore options 10:00 AM PST (6:00 PM UTC) Windows accessibility in the enterprise How do I participate? Anyone can watch the event. To actively participate and post a question, you need to be signed in to the Tech Community. If you haven’t already signed up, select Sign in in the top right corner of this site and join the Windows community today! Once you’re signed in, scroll to the bottom of the session page and select Comment. A text box will appear. To make sure we see and can respond to each of your questions, it helps if you post each one individually as a separate comment vs. all in one bulleted or numbered list. If you find that your company’s policies prevent you from watching the live stream, you can tune in from a personal device—or join us on LinkedIn. Need captions? The live broadcast will feature live, AI-generated captions captioning. We'll then produce and post real, human-generated captions by the end of the week, including text-based transcripts, so you have an accurate recap of the questions and answers presented. What if I can't attend the live event? Not a problem. You can post your questions now—in the Comments section of the session pages—then check back at a convenient time for you. We’ll leave the Q&A open in the chat through Friday and publish a Q&A summary after the event for easy reference. Hope to see you there! Tech Community Live events are a great way to get in touch with our engineers beyond large events like Microsoft Ignite. Like our monthly Windows Office Hours, we’ll have friends from the Microsoft Intune and security teams also pitching in to help your answer questions. If there’s a specific topic you’d like us to cover in the next Windows edition of Tech Community Live, drop me your ideas in the comments. ______________________________________________________________________________________________________________________________________________________________ --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Windows 365 Frontline updates and Cloud Apps general availability: Since launching in 2021, Windows 365 has simplified secured, remote access to desktops by introducing the Cloud PC, a persistent Windows experience streamed from the Microsoft Cloud to any device anywhere. Today, we’re… #WindowsITPro
bit.ly
Windows 365 Frontline updates and Cloud Apps general availability
Since launching in 2021, Windows 365 has simplified secured, remote access to desktops by introducing the Cloud PC, a persistent Windows experience streamed from the Microsoft Cloud to any device anywhere. Today, we’re taking the next step to modernize shared devices and task-based workflows, making it easier for IT teams to support diverse environments while improving end-user productivity. The introduction of Windows 365 Frontline brought Cloud PCs to employees who only needed part-time or occasional access to Windows desktops, offering cost-effective and scalable cloud computing to new types of users without adding complexity. Now, we’re excited to announce powerful functionality that extends the reach of Windows 365 Frontline even further - with options to scale the service to an entire workforce. Windows 365 Cloud Apps, now generally available, uses Windows 365 Frontline in shared mode to provide users with access to individual applications, without requiring each user to have their own dedicated Cloud PC. Alongside Cloud Apps, we are launching key technical enhancements to simplify rollout and adoption, including User Experience Sync, which is now generally available, and Windows Autopilot Device Preparation profile, in public preview. User Experience Sync enables app settings and accessibility preferences to persist across sessions, delivering a personalized experience for users even in shared environments. For IT admins, Windows Autopilot Device Preparation profile simplifies provisioning by pre-installing critical apps as needed, without maintaining complex images.   Together, these capabilities in Windows 365 make it easy for IT to deploy both apps and desktops, giving users the productivity they expect from first launch — whether they need a 24/7 desktop, part-time desktop access, or even occasional access to an individual application.  Let’s take a deeper look at these capabilities and how they transform the Windows 365 experience: Just the essentials — Windows 365 Cloud Apps for task-based workflows Windows App launching Windows 365 Cloud Apps Now your workforce can quickly perform tasks by accessing the business applications they need right from the Windows App. This also delivers simplified management through Microsoft Intune, reduced infrastructure complexity, and faster deployment — all while maintaining enterprise-grade security and compliance. Windows 365 Cloud Apps are especially useful for organizations wanting to modernize legacy virtual desktop infrastructure (VDI) environments, where existing solutions can be challenging to scale and complex to manage, leading to outages, misconfigurations, or security gaps. Migrating published VDI apps to the Windows 365 service offers the advantages of Cloud PC manageability and experience, with cost-effective pricing. To learn more about Windows 365 Cloud Apps, visit Windows 365 Cloud Apps Apply a consistent experience to shared Cloud PC scenarios Shared workstations often sacrifice personalization for cost savings. With User Experience Sync, Windows 365 Frontline in shared mode delivers a consistent experience every time, reducing frustration and improving productivity for users in shared environments. It ensures that applications which save user settings or application data persist that info across sessions, and maintains other aspects of the Windows experience, such as accessibility options. We’re also investing in faster sign-in experiences across Windows 365 Frontline modes (dedicated and shared) to help users get productive from the first click, so workflows start seamlessly without delays. Screenshot of User Experience Sync admin configuration Managing cloud storage with User Experience Sync As a key component of our service offering, User Experience Sync is included at no additional cost in Windows 365 Frontline. Storage for user settings data is built in and determined by the size of the OS disk in the Cloud PC configuration. For example, Cloud PCs with a 128GB OS disk will have an additional 128GB of storage available, dedicated to User Experience Sync. This space is pooled across users, with larger disks providing greater storage capacity. IT admins can set user storage limits to match differing scenarios, monitor usage through Intune, and configure alerts when storage runs low. This storage is created during a user’s Cloud PC or app first-run experience, offering flexibility without limiting the number of assigned users. To learn more about User Experience Sync, visit User Experience Sync configuration. Screenshot of a provisioning policy, with a graph showing available and used user storage Autopilot app installs bring productivity from first use Time-to-productivity is critical for organizations of all types and sizes. Ensuring that workers have access to the applications that they need right away leads to improved employee satisfaction, enhanced security, and increased productivity. With Autopilot Device Preparation profile capabilities, IT admins can use Microsoft-provided images for Windows 365, then target an app or set of apps for automatic deployment, ensuring they are pre-installed before a user ever signs in. This reduces IT overhead and complexity, while delivering a meaningful first run experience. This is a notable improvement compared to traditional VDI, where admins often spend considerable effort maintaining sets of custom or “golden” images — and represents significant time savings for IT admins managing Windows 365. This public preview feature has now been expanded to include support for Windows 365 Enterprise and all Windows 365 Frontline Cloud PC configurations, including Windows 365 Cloud Apps. This means that IT admins can also easily deploy applications through Intune as Windows 365 Cloud Apps without taking on the complexities associated with custom image management. Get started with Windows 365 Frontline and Windows 365 Cloud Apps today With powerful new features such as Windows 365 Cloud Apps, User Experience Sync, and Autopilot Device Preparation profiles at your fingertips, there’s never been a better time to move to Windows 365. These innovations simplify deployment, reduce IT overhead, and empower your workforce with secure, flexible access to the apps and desktops it needs. To get started: * Deploy Windows 365 Cloud Apps in a Windows 365 Frontline environment to deliver task-based access to applications without dedicated Cloud PCs. * Enable User Experience Sync with Windows 365 Frontline in shared mode to give users a consistent experience across sessions. * Use Autopilot device preparation profiles to pre-install critical apps and accelerate first-use productivity for users. Start implementing these capabilities today to deliver a modern and scalable desktop or app virtualization environment. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Scalable Windows Resiliency with new recovery tools: Today at Ignite, we’re announcing new Windows recovery capabilities designed to help IT admins respond quickly — whether it’s restoring a single PC that’s misbehaving or recovering large sets of devices during a widespread outage.… #WindowsITPro
bit.ly
Scalable Windows Resiliency with new recovery tools
Today at Ignite, we’re announcing new Windows recovery capabilities designed to help IT admins respond quickly — whether it’s restoring a single PC that’s misbehaving or recovering large sets of devices during a widespread outage. Device recovery scenarios vary, and customers need different tools for different situations. That’s why we’re providing a range of solutions, all managed through a familiar, centralized platform. Microsoft Intune brings these capabilities together, and other modern device management vendors can integrate similar functionality if they choose. In this blog post, we are covering the tools that are available to you this week. Stay tuned for future blog posts that will deep dive into other capabilities. Quickly recover Windows devices during a widespread outage Large outages affecting millions of devices are rare but frustrating when they can only be remediated by an in-person action. These devices are usually stuck on WinRE. That is when quick machine recovery (QMR) comes into play. QMR is a Windows capability that automatically detects, diagnoses, and remediates boot critical issues from WinRE, helping restore productivity without requiring hands on, in-person intervention. QMR is generally available and enabled by default on Windows Home and will be soon enabled on Pro devices that are not managed by IT. It requires Windows 11 24H2 or 25H2. On managed Windows Pro and Enterprise devices, QMR needs to be enabled by IT policy, and soon can be enabled just-in-time by Autopatch management. We are introducing the preview of QMR management in Windows Autopatch. Autopatch empowers IT administrators with comprehensive control over the deployment of QMR updates, including approvals, scheduling, alerting, and reporting. To discover more details, visit the Ignite Autopatch blog post and attend the Ignite breakout session BRK345: Resilient by design: How Windows has evolved with new recovery tools for a demo. Restore Windows devices to a previous state in minutes A device disruption doesn’t have to be widespread — it can strike any device at any time and cost organizations valuable time and productivity. That’s why we’re excited to introduce point-in-time restore for Windows, a new recovery capability that enables devices to be rolled back to a previous state within minutes. This feature is designed to help minimize downtime and simplify remediation, without the need for technical expertise or lengthy troubleshooting. A public preview of this feature will be available this week for Windows Insiders. Point-in-time restore will help IT admins (remotely) or end users (locally) restore a PC to a previous state from restore points stored on the device. This feature can be used to help customers recover from both widespread and one-off issues. When a device or group of devices has been suddenly impacted, point-in-time restore provides a fast way to return to productivity without waiting for a targeted fix. Point-in-time restore aims to address the need for: * Flexibility, as a restore can help resolve both isolated and widespread incidents * Fast and simple recovery in minutes without advanced troubleshooting needed. * Built‑in reliability and predictability, including recurring capture of restore points, a short restore point retention period, and disk space limits * Comprehensive rollback of the entire system to a previous state, including OS, apps, settings, configurations, and local files How is this different from System Restore? Organizations may be wondering how this capability differs from System Restore. While both point-in-time restore and system restore use Volume Shadow Copy Service and are designed to restore the system to a previous state, there are important differences: Point-in-time restore System Restore Restore points Automatic, configurable cadence. User files are included in restore point. Event-triggered or manual only. User files are excluded from restore point. Reliability Strict retention and cleanup policies No retention limits User experience Integrated in system settings Limited to control panel Fundamental impact Designed to minimize storage impact Higher impact to storage space Management Will support robust remote management capabilities Limited remote management capabilities How does this feature in Windows 11 compare to point-in-time restore for Windows 365? Both point-in-time restore for Windows and point-in-time restore for Windows 365 are designed to help organizations recover quickly from system failures, flawed updates, or user errors. While these features share the same core goal of minimizing downtime and restoring productivity during disruptions, their implementations differ due to architectural differences and design choices unique to each environment. Below are the key differences that IT administrators should be aware of when evaluating or deploying point-in-time restore across environments:   Windows client Windows 365 Feature enablement Can be enabled or disabled Always on Restore point retention Up to 72 hours Up to 1 month Restore point types Short-term only Short-term, long term, and manual Restore point sharing No sharing, restore points remain local Support sharing across Windows 365 and Azure Cloud Restore speed Likely faster due to local storage of restore point Speed is affected by network latency and bulk vs. single restores Storage constraints Bound by physical disk limits Scalable, cloud storage Limitations and risks for Windows client As with any recovery solution, it is important to be aware of some limitations and risks. * Data loss: point-in-time restore is a comprehensive recovery solution that reverts the entire system — including user files, applications, settings, passwords, secrets, certificates, and keys — to the selected restore point. Any changes made after the restore point will be lost. Data stored in cloud services such as OneDrive is not affected. * Storage constraints: restore points are stored locally and require sufficient disk space to be maintained. If available disk space becomes limited, the oldest restore points will be deleted automatically to free up space. To complete a restore, the device must have at least as much free space as the total size of all restore points on the system. * Restore points are retained for a maximum of 72 hours and are deleted after this period. * There is no guarantee that a rollback will always result in a bootable or fully functional system, as certain system states or updates may impact reliability. What will be available in the preview this week? Starting this week Windows Insiders in the Beta and Dev Channels can test point-in-time restore by installing the latest Insider Preview build for Windows 11.  Point-in-time restore settings page in System > Recovery Devices running Home, Pro or Enterprise editions of Windows will have access to view all configurations, however, only administrators will have the ability to configure the feature.  Configurations are available in Windows 11 System Settings and are outlined below: Configuration Default (preview) Options Feature On/Off On* On, Off Restore point frequency Every 24 hours 4, 6, 12, 16, 24 hours Restore point retention 72 hours 6, 12, 16, 24, 72 hours Maximum usage limit 2% of disk Percent of disk (min 2GB, max 50GB equivalent) *Only devices with a total disk size of 200GB or greater will have the feature on by default. Devices with disk sizes below 200GB can still configure the feature to be on if desired. For preview, a restore can only be triggered locally by the end user when the device is in WinRE only (remote management of this feature and triggering a restore from full Windows is not included in the preview). Point-in-time restore shown in the Troubleshoot menu for WinRE The steps to perform a point-in-time restore are below: * In WinRE select Troubleshoot > Point-in-time restore * Enter BitLocker recovery key . * Select a restore point to restore PC to the exact state it was at the time of the restore point. * Review and acknowledge the risks and limitations associated with this feature by selecting Continue. * Review the restore point selection, OS version, and warning of data loss, and select Restore to start the restore process. File your feedback via the Feedback Hub (under Recovery and Uninstall > Point-in-time restore) to help us refine and optimize this feature. Next steps Stay tuned for future enhancements as we continue to strengthen Windows resilience and support IT admins in maintaining seamless business operations. Point-in-time restore and quick machine recovery (QMR) with Autopatch are available this week — start testing both to help build your own recovery framework. Additional tools will become available in the first half of 2026. Attend the Ignite breakout session Resilient by design: How Windows has evolved with new recovery tools (BRK345) for more details and demos. The session will be recorded, so you can stream it on demand. To learn more about the Windows Resiliency Initiative, see the Windows Resiliency e-book . Disclaimer: This blog post is for informational purposes only and outlines Microsoft’s current product direction and plans. Product availability, licensing terms and capabilities may vary by region and are subject to change. All third-party trademarks are the property of their respective owners. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Keyboard Input Protection for Windows 365 and Azure Virtual Desktop now in preview: The evolving threat landscape for virtualization The rapid adoption of cloud-based virtualization has transformed how organizations deliver secure, scalable workspaces. This shift has also expanded… #WindowsITPro
bit.ly
Keyboard Input Protection for Windows 365 and Azure Virtual Desktop now in preview
The evolving threat landscape for virtualization The rapid adoption of cloud-based virtualization has transformed how organizations deliver secure, scalable workspaces. This shift has also expanded the attack surface for cybercriminals. Recent market intelligence highlights that endpoint malware like infostealers, keyloggers, screen scrapers, and ransomware continue to target user devices. This includes personal devices like those used for Bring Your Own Device (BYOD) strategies, as those unmanaged devices may be less secure and thus an easier target. Harvesting sensitive data at the endpoint device has become a top method for attackers using tools like Infostealer malware, which has become a leading threat that is used to steal sensitive data from both managed and unmanaged devices. [1] Attackers are increasingly targeting personal devices that access corporate resources, exploiting gaps in endpoint security. Shifting the trust boundary to the endpoint For organizations embracing a remote workforce, endpoint protection is no longer optional — it’s essential. While virtualization solutions secure the cloud and network layers, they cannot fully shield against threats originating on user devices.  * Malware risk: Keyloggers and screen scrapers on unmanaged endpoints can capture sensitive data before it reaches the cloud. * BYOD exposure: Personal devices often lack enterprise-grade security, creating compliance and data loss risks. * Detection delays: Endpoint breaches can go unnoticed for months, giving attackers time to harvest credentials and compromise sessions. Customers need assurance that every device connected to a cloud service meets security posture requirements. Enforcing keyboard input protection on the endpoint and verification checks from the cloud side — within the virtualized environment — offers end to end protection and closes these gaps and ensures safety guardrails are always applied, regardless of device type. This is critical for safeguarding sensitive data and maintaining compliance in a distributed workforce.  Introducing Windows Cloud Keyboard Input Protection We are excited to announce Windows Cloud I/O Protection capabilities, to help protect Windows 365 Cloud PC and Azure Virtual Desktop VM endpoints from malware and other risks stemming from inputs or displays. The first of these new capabilities is Windows Cloud Keyboard Input Protection, now in public preview, purpose-built to address endpoint security concerns for Windows 365 and Azure Virtual Desktop. It establishes a secure communication channel that begins at the endpoint device’s kernel and extends to Windows 365 Cloud PCs or Azure Virtual Desktop session host or virtual machines (VMs). Windows Cloud Keyboard Input Protection solution ensures the confidentiality and integrity of sensitive input data by encrypting user keystrokes at the kernel level and decrypting them exclusively within the remote virtual environment. As a result, unauthorized interception or manipulation of input is effectively prevented throughout the entire path—from the moment the user types until the data reaches the Cloud PC.  Solution components include: * Kernel-level encryption: A software kernel driver and system-level encryption service work together to route all keyboard inputs directly from the physical device to the Cloud PC or Azure Virtual Desktop VM’s in encrypted format. This prevents interception by OS-level malware, including keyloggers and screen scrapers. * VM-side decryption: Only the remote Cloud PC or VM can decrypt the keystrokes, ensuring that sensitive data never appears in clear text on the endpoint device. * Seamless user experience: The protection is transparent to users and IT admins, maintaining productivity while enforcing robust security without performance impact. Activating Windows Cloud Keyboard Input Protection Security IT admins can enable Windows Cloud Keyboard Input Protection using Group Policy in an Active Directory domain by opening the Group Policy Management console, navigating to Windows Components > Remote Desktop Services > Remote Desktop Session Host > Azure Virtual Desktop > Enable Keyboard Input Protection, and enabling it as shown below. IT admins can easily enable keyboard input protection for Windows 365 or Azure Virtual Desktop. After the feature is enabled, the end user with admin privileges will need to install Windows Cloud IO Protect endpoint enablement package (WCIO Protect.msi) on their physical device. This feature is supported in: * Windows Azure Virtual Desktop VMs with the latest Microsoft supported Windows Client OS versions. * Supported endpoint device OS: * Supported: Windows 11 physical devices running supported Windows App (Version should be 2.0.704.0 or newer) with Windows Cloud IO Protect msi installed on them To learn more about setting up Windows Cloud Keyboard Input Protection, visit our Learn page. How Windows Cloud Keyboard Input Protection helps With the proliferation of endpoint threats and the rise of remote work, organizations need more than just cloud security — they need endpoint-to-cloud protection. Windows Cloud IO Keyboard Input Protection delivers: * Compliance assurance: By preventing unauthorized data capture at the endpoint, organizations can better meet regulatory requirements for data protection and privacy. * Reduced breach risk: Utilizing secure communication channels from the end point kernel to the remote VM dramatically lowers the risk of credential theft and data exfiltration from resident threats. * Future-ready security: As attackers evolve, Microsoft’s approach — combining kernel-level protection, device compliance, and cloud integration — sets a new standard for secure desktop delivery. Next steps Windows Cloud Keyboard Input Protection will be rolling out to organizations using Windows 365 and Azure Virtual Desktop in the coming weeks. To learn more about this feature, and other security capabilities within Windows Cloud, please visit our resources: * Windows 365 Learn doc on Win Cloud IO Protection * For an overview of Windows 365 Security concepts, visit https://aka.ms/w365security * To see more about our Ignite announcements around Windows 365 and Azure Virtual Desktop, see our Windows blog * To see our security announcements bringing B2B and external identity support for Windows 365 and Azure Virtual Desktop, visit this blog * To learn more about the security risks and mitigations for BYOD, and how Windows 365 can help, visit https://aka.ms/w365byodebook * The 2025 Verizon Data Breach Investigations Report found that 30% of compromised systems were enterprise-licensed, while 46% were non-managed endpoints, often due to BYOD policies. ↑ --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community , then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A .
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Windows 365 and Azure Virtual Desktop support external identities, now generally available: With Windows 365 and Azure Virtual Desktop, organizations have been able to offer Windows delivered from the cloud to users to be productive, connect to IT resources, and to securely sign in… #WindowsITPro
bit.ly
Windows 365 and Azure Virtual Desktop support external identities, now generally available
With Windows 365 and Azure Virtual Desktop, organizations have been able to offer Windows delivered from the cloud to users to be productive, connect to IT resources, and to securely sign in across devices. Previously, you could only do so for member users, with accounts and credentials that are fully managed in your organization. With our latest updates, you can provide access to users who are outside your organization by simply inviting them into your organization, without having to create and assign brand new, temporary accounts. We’re excited to announce: * Connecting to Windows 365 and Azure Virtual Desktop with an external identity is now generally available * Using FSLogix as a user profile management solution for external identities with Azure Virtual Desktop is now in public preview What external identity support means With support for external identities in Windows 365 and Azure Virtual Desktop, you can standardize your approach to virtualization for users that are either internal or external to your organization. External identities may include roles like contractors or third-party vendors. You can also leverage other Microsoft Entra investments for external identities: * Enforce conditional access (CA) controls specific to external identities * Enforce multi-factor authentication (MFA) registration for the external identity in your tenant * Enforce Global Secure Access (GSA) configuration on the Windows machine the external identity will be using to access your resources. Note: Because external identities are cloud-only users and do not have a representation in Windows Server Active Directory, Kerberos authentication can’t be used. In the screenshot above, you can see that Cameron Baker is originally from the Fabrikam (fabrikam.com) organization, but is seeing resources that the Contoso (windows365-demo.microsoft.com) organization has assigned to them as an external identity. Assign a resource to external identities (generally available) The admin flow for provisioning a Windows 365 Cloud PC or assigning Azure Virtual Desktop resources to an external identity is nearly identical to doing so for a member user in your tenant. The steps for assigning an external identity include: * Assigning the user the appropriate licenses. * Assigning the user to an Entra user group. * Assign the Entra user group to the Cloud PC provisioning policy or Azure Virtual Desktop application group. a.   Note: For Azure Virtual Desktop, make sure you also assign the Virtual Machine User Login Azure role-based access control (RBAC) role to the external identity on any Azure Virtual Machine (VM) they may sign in to. After completing these steps, the user can access their assigned resources, just like other assigned users in your organization. For your Windows 365 or Azure Virtual Desktop environment, make sure to consider the following: * You must configure Microsoft Entra single sign-on for the user’s connection. * The Cloud PC or Azure Virtual Desktop session host must be Entra joined. * The Cloud PC or Azure Virtual Desktop session host must be running Windows 11, version 24H2 or later with the 2025-09 Cumulative Updates for Windows 11 (KB5065789) or later installed. Configure FSLogix on Azure Files for external identities (public preview) To provide a streamlined experience in an Azure Virtual Desktop pooled environment for external identities, you can create a file share in Azure Files to store the FSLogix profiles for these identities. This capability is now in public preview. To create an SMB file share for FSLogix profiles for external identities: * Create a new storage account and file share configured to use Microsoft Entra Kerberos authentication. * (New) When assigning permissions for the file share, use the new Manage access page to assign ACLs to the Entra ID group containing your external identities. In the screenshot above, you can see the Manage access page, where each row is an individual permission added to the SMB file share. In this example, WCX-External-Identities is the Entra group containing the external identities, and they have been assigned permissions in the file share which will be used to create and access each external identity user’s FSLogix profile container. * Configure FSLogix in your session hosts to use this Azure File share. Once configured, the external identities can sign in to the Azure Virtual Desktop environment and have an FSLogix user profile just like other users in your organization. This provides a seamless experience when landing across different session hosts in the same host pool. For full step-by-step instructions, see how to Store FSLogix profile containers on Azure Files using Microsoft Entra ID. A more secure Bring Your Own Device (BYOD) strategy These capabilities can help organizations looking for a more secure BYOD experience, or when provisioning identities to a contractor, external partner, and more. To see the latest guidance from Microsoft on how to use Windows 365 to secure your BYOD strategy, visit the https://aka.ms/W365BYODeBook. Additional resources We continue to roll out more features to help organizations secure their Cloud PCs and VMs. See our other latest security announcements, here: * To see our Ignite announcements for Windows 365 and Azure Virtual Desktop, visit the Windows Experience blog here. * To learn more about new Windows Cloud input protection capabilities for Windows 365 and Azure Virtual Desktop, visit here.   --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Windows 365 Link - What's new for the first Cloud PC device: Since we first announced Windows 365 Link — the simple, secure, purpose-built device for Windows 365 — at Microsoft Ignite last year, we have been energized to see organizations deploying it in shared spaces ranging from… #WindowsITPro
bit.ly
Windows 365 Link - What's new for the first Cloud PC device
Since we first announced Windows 365 Link — the simple, secure, purpose-built device for Windows 365 — at Microsoft Ignite last year, we have been energized to see organizations deploying it in shared spaces ranging from retail stores to factory floors and even clean rooms. We have highlighted how, according to a Microsoft commissioned Forrester TEI study, it is projected to deliver a substantial return on investment up to 195% over six years for a composite organization replacing desktops for frontline and knowledge workers.* This year at Microsoft Ignite, we’re highlighting what’s new for Windows 365 Link and diving deeper into how it can boost productivity and strengthen security while helping you optimize IT investments — particularly for your frontline. Tune into our upcoming Microsoft Ignite 2025 breakout session and read on to learn more.  “Windows 365 Link provides secure access to cloud desktops, transforming hardware-dependent services into agile, cloud-based solutions. In shared environments, it offers a low-cost alternative without sacrificing user experience. In Retail, it will boost security, supporting a zero-trust model that safeguards critical customer systems while removing friction.” - Matt Harkness, Product Manager Modern Workplace, One NZ “Regeneron uses the power of science to bring new medicines to patients in need. By standardizing on Windows 365 Link devices across our clean room environments, we’ve minimized endpoint maintenance and enabled seamless hotdesking. This shift not only lowers operational costs but also enhances compliance and manufacturing agility as we can implement data integrity controls centrally and immediately.” - Matt Humphreys, Senior Director of Global Enterprise Operations IT, Regeneron Pharmaceuticals Inc. Windows 365 Link devices are configured out of the box to receive regular updates to enhance the end-user experience and streamline IT management. Recent updates include: * Support for use with Windows 365 Reserve Cloud PCs, making Windows 365 Link a great backup option when someone’s primary desktop is unavailable due to hardware failure. * Support for voice access to enhance accessibility, enabling users to control their PC and insert text using voice commands, without needing a keyboard or mouse. * Support for smart card redirection, enabling authentication to apps and websites in a Cloud PC through a smart card reader. * Support for users with multiple Cloud PCs to choose which Cloud PC to connect to after initial sign-in. Connection Center showing multiple Cloud PCs after sign-in Looking ahead, here are some key updates targeted for release in the first quarter of 2026: * Support for pairing Bluetooth® devices during the out-of-box experience, so you can use a wireless keyboard and mouse to set up the device. * Support for tenant branding including setting a custom wallpaper, logo, and name on the sign-in screen, so you can provide a tailored experience for your employees. * The ability for IT to restore a device to its original factory default state using a bare metal recovery image, providing one more way to recover the device in case you need to join it to another tenant. * Improvements to the sign-in experience to support a broader set of interactive authentication experiences when connecting to Cloud PCs. We have heard that organizations appreciate how Windows 365 Link devices support high-fidelity Microsoft Teams meetings, and they also want support for media redirection with partner solutions. We are happy to share that Webex by Cisco and Zoom are actively working to enable high-fidelity meetings on Cloud PC devices. The Webex VDI Plugin for optimizing meeting experiences on Cloud PC devices is targeted for preview release in the first half of 2026. Additional third-party communication app providers who are interested in enabling a plugin for Windows 365 Link can reach out via this form. Windows 365 Link is now available in 13 countries and will expand early next year to seven more. If you want to purchase Windows 365 Link for desk-based and frontline users in your organization, contact your Microsoft account team or authorized resellers in Australia, Canada, Denmark, France, Germany, India, Japan, the Netherlands, New Zealand, Sweden, Switzerland, the United Kingdom, and the United States. Availability will further expand to Belgium, Finland, Ireland, Italy, Poland, Singapore, and Spain starting in February 2026. *ROI estimate is based on a commissioned study conducted by Forrester Consulting on behalf of Microsoft, New Technology: The Projected Total Economic Impact™ of Windows 365 Link, July 2025. The Forrester study findings are for a composite organization with 2,000 employees, 500 contractors and $4 billion in annual revenue informed by interviews with six IT decision-makers who had experience using Windows 365 Link and survey responses from 212 IT decision-makers and end-user managers who had experience with or interest in using Windows 365 Link. ROI projections reflect perceived benefits reported by participants and are not guaranteed. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community , then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A .
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Windows Autopatch — Elevate Your Update Experience for Modern Work: As AI adoption continues to accelerate across organizations of all sizes, it is critical for IT leaders to secure their devices estate to keep their organizations protected, productive, and ahead of the curve.… #WindowsITPro
bit.ly
Windows Autopatch — Elevate Your Update Experience for Modern Work
As AI adoption continues to accelerate across organizations of all sizes, it is critical for IT leaders to secure their devices estate to keep their organizations protected, productive, and ahead of the curve. Managing Windows updates should be a seamless, intelligent process that empowers teams to focus on strategic priorities. That’s why Microsoft is continuing to build the future of Windows update management with Windows Autopatch, bringing improved clarity, reporting, automation, and control to update readiness. By combining real-time visibility, proactive remediation, streamlined scheduling, and resilient recovery solutions, Autopatch helps to keep your devices protected and businesses stay agile. In this post, we’ll share how these innovations are transforming IT operations, delivering peace of mind, and setting a new standard for secure, automatic Windows update management. Windows Autopatch is available for customers with Windows Enterprise, Frontline, US Government, Education and Business Premium SKUs. Learn more here. Elevate your IT experience: Autopatch brings update readiness to the forefront Every month it feels like IT environments become more complex and dynamic, creating challenging, time-consuming workloads for system administrators. Deploying at scale means IT leaders need technology that adjusts to meet fast evolving work demands. In the latest enhancements to Autopatch, update readiness is ready to give IT teams just that — the tools they need to anticipate issues, streamline deployments, and maintain organizational resilience, including reporting enhancements IT administrators have long asked for. Proactive peace of mind: Automated checks and early remediation Readiness means more than just numbers on a dashboard. Proactive checks help catch hidden prerequisites and safeguards before deployment, reducing manual troubleshooting and minimizing user disruption. Rather than fixing issues after they happen, administrators can review lists of devices that need remediation (for example, a list of devices not ready for quality updates due to prerequisites) and address issues up front, saving time and avoiding unnecessary rework. Fewer disruptions, happier users — it's a win-win. Follow every device’s journey: Streamlined troubleshooting made simple We know the complexity of your diverse environments sometimes require more than an “in progress” update status, which is why Autopatch’s new device update journey maps out every device’s progress in clear, actionable steps. Granular timelines and audit trails make it simple to spot where an update might stall, including reasons why a hotpatch couldn’t take place, so problems can be resolved quickly and confidently.  Repair with confidence IT teams can spot devices that need repair, identify any that might face update blockers, and use targeted remediations to stay secure, all through Autopatch. Actionable alerts guide administrators through each step, while integrated audit logs ensure nothing gets missed and progress is always transparent. Actionable alerts, transparent progress When something needs your attention, Autopatch makes sure you’re in the loop with actionable alerts and guided remediation. Each step is tracked, leading to a clearer IT backlog and measurable gains in compliance. Best of all? These features work with your current deployment process — no need to change how you roll out updates. Streamlined quality update scheduling and approvals Autopatch now delivers advanced, cloud-based policies for managing monthly Windows updates, empowering IT teams with precise controls and transparent reporting.  Choose between automatic or manual approvals for security, non-security, and out-of-band updates. This flexibility ensures your update workflow aligns with organizational requirements. Configure deferral settings to implement gradual rollouts, enabling prompt validation with reduced risk and minimal disruption. Autopatch enables you to pause or resume releases as needed, ensuring update deployment remains responsive to business priorities. Enhanced quality update reports offer clear visibility into deployment health, device compliance, approved updates, and actionable alerts — helping IT teams stay proactive and confident throughout the update process.  Extended security updates As Windows 10 has reached end of support, organizations need a dependable way to maintain protection while planning their upgrade path. Extended Security Updates (ESU) deliver critical fixes for devices that have not yet transitioned to Windows 11, supporting business continuity without compromise. With Autopatch, you can still stay protected— ESU integrates smoothly to provide full visibility into coverage and compliance. IT teams can monitor enrollment status through quality update reports, which clearly show devices enrolled in ESU, and receive alerts for those behind on security updates or missing ESU coverage. This proactive approach helps administrators act quickly, maintain compliance, and keep systems protected while preparing for Windows 11. Read more on upgrading to Windows 11 using Autopatch here.   Hotpatch and maintenance windows keep your business secure with minimal disruption Last year, we introduced hotpatch updates, which deliver instant security fixes without requiring device restart and reduce exposure to vulnerabilities. Since then, we have launched hotpatch updates on 64-bit ARM devices, enabling this technology on millions of devices. From your feedback we’ve heard one thing loud and clear: more disruption-free updates. Starting Q1 calendar year 2026, you will have the power to create that experience yourself with maintenance windows. It allows you to streamline all your updates from drivers, .NET, and applications to fit your business needs. You decide, down to the hour, when to restart your machines. Quick machine recovery (QMR) management in Windows Autopatch We live in a world where every minute of downtime can put business at risk, which means uninterrupted device access is crucial to maintaining productivity and organizational continuity. When critical issues in your environments lead to boot failures or outages, small or big, immediate and reliable remediation becomes imperative. Autopatch addresses this challenge with Quick Machine Recovery (QMR) management, a solution that helps recover Windows devices from boot failures (caused by us or 3rd party kernel mode drivers) during large-scale incidents through the Windows Recovery Environment, as part of our Windows Resiliency Initiative. When a large-scale outage occurs, impacted Autopatch-managed devices initiate a QMR scan to check for a Microsoft-published target fix. Based on applicability and approval settings, these fixes are deployed promptly, restoring device functionality and reducing the risk of prolonged outages. Advanced QMR deployment controls Autopatch empowers IT administrators with comprehensive control over the deployment of QMR updates. By default, all Autopatch-managed devices are QMR scan-ready, ensuring that recovery options are available whenever needed. Administrators may opt out of default scans or fine-tune approval settings within quality update policies, choosing between automatic approvals — with customizable deferral windows — or manual reviews for enhanced oversight. This flexibility allows organizations to tailor their response, balancing swift action with governance, especially during critical events. Integrated alerts and remediation reporting Beyond the boundaries of policy management, Autopatch integrates QMR with robust alerting and reporting capabilities. Administrators receive timely notifications when QMR updates become available or when prerequisites are not met, facilitating rapid intervention. The Autopatch portal provides a comprehensive view of all impacted devices, while detailed remediation reports track recovery status. These reports deliver actionable insights, highlighting successful restorations and identifying devices where further attention is required. By supporting fast, secure device recovery that aligns with organizational policies — even during large-scale boot failures — Autopatch enables IT teams to maintain a resilient Windows environment, meeting your priorities: fewer disruptions, improved business continuity, and greater confidence in your organization’s Windows update strategy. Start benefiting today — no disruption required All these capabilities significantly enhance the impact Autopatch has on your organization, so you can enjoy better visibility, proactive checks, and targeted fixes without overhauling your workflows. Designed to deliver immediate value, Autopatch helps IT teams boost confidence and minimize toil, making Windows update management simpler, more secure, and more insightful than ever. * Start using Autopatch now: Discover how here. * Get early access to Autopatch update readiness and Quality Update scheduling and approvals: Sign up now. * Join the Microsoft Customer Connection Program for exclusive opportunities to help shape our product, get early access to the roadmap, and connect with a community of IT professionals. Disclaimer: This blog post is for informational purposes only and outlines Microsoft’s current product direction and plans. Product availability, licensing terms, and capabilities may vary by region and are subject to change. All third-party trademarks are the property of their respective --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community , then follow us @MSWindowsITPro on X and on LinkedIn . Looking for support? Visit Windows on Microsoft Q&A .
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Windows 365 for Agents unlocks secured, scalable AI automation: Windows 365 has established itself as a market leader in virtualization, empowering human users with secure, scalable Cloud PCs for productivity from any location on any device. Now, as AI evolves, a new class of computer… #WindowsITPro
bit.ly
Windows 365 for Agents unlocks secured, scalable AI automation
Windows 365 has established itself as a market leader in virtualization, empowering human users with secure, scalable Cloud PCs for productivity from any location on any device. Now, as AI evolves, a new class of computer use is emerging: AI agents that interact with computers much like people do. Agent makers — developers and organizations building these agents — are driving innovation in automation and productivity. Windows 365 for Agents extends the platform to support these new workloads, while continuing to serve human users. This opens the door to enable AI-powered systems, such as Copilots, agents, and autonomous workflows, to access a full Cloud PC.   As agent makers push the boundaries of intelligent AI systems, Windows 365 for Agents empowers them to focus on innovation — not infrastructure. Our platform reduces the complexity of compute management, delivering built-in security, scalability, and observability. These agents can browse websites, process data, and automate tasks, all within a secured, policy-controlled Cloud PC streamed from the Microsoft Cloud. Now in public preview, Windows 365 for Agents is the cloud platform designed to power computer use and help agent makers deliver the best agentic experience to organizations and end users.  Empowering agent makers Windows 365 for Agents provides a comprehensive set of APIs for agent makers to manage and utilize compute resources. Windows 365 is designed to support a broad spectrum of agent solutions, operating systems, and data access controls, empowering agent makers to innovate freely. This future-ready approach ensures that as agentic computer use needs evolve, Windows 365 will be ready to support them.  * Advanced lifecycle management Windows 365 for Agents offers end-to-end Cloud PC lifecycle management from session management and networking to capacity and regional data residency. * End-user visualization and observability The service provides agent makers the functionalities of real-time visualization with take-control experience, or audit screenshots with time stamps on demand. * Cost efficiency with pay-as-you-go pricing   Agent makers only pay for what they use, providing an affordable choice for dynamic workloads and budget-conscious teams.  * Broad OS support The Cloud PCs can operate Windows, Linux, and browser-based environments, enabling a broad range of agentic workloads including open-source and cross-platform scenarios. * Flexible data control options From enterprise-grade access control for commercial scenarios to quick start experiences for consumer offerings, Windows 365 for Agents meets agent solutions where they are. Windows 365 for Agents is the backbone of some of the most advanced Microsoft AI initiatives and partner solutions. * It serves as the execution platform for agents built into Microsoft Copilot Studio computer use — the Microsoft toolkit for building custom Copilot AI agents to automate web tasks right from a prompt. Here, Windows 365 unlocks a seamless, secure automation experience with no machine setup required. * It’s also embedded within Project Opal, a new capability in Microsoft 365 Copilot. Opal uses Windows 365 for Agents for work task completion securely and intelligently on users’ behalf, so teams can focus on what matters most. * Researcher with Computer Use in Microsoft 365 Copilot  allows users to automate website navigation and actions with real-time visualization. It is the first supported Microsoft solution that leverages Cloud PCs running a Linux environment. Copilot Studio custom agent automating tasks on managed Cloud PCs  Opal operating on a Windows 365 for Agents Cloud PC Researcher with Computer Use running Windows 365 for Agents We are excited to share that leading agent makers — Manus AI, Fellou, Genspark, Simular, and TinyFish — are already looking forward to leveraging Windows 365 for Agents to deliver next-generation AI solutions. Manus AI, for example, is using Windows 365 for non-domain-joined Cloud PCs, empowering everyday consumers to access intelligent PowerPoint creation and editing.    “Windows 365 for Agents provides the secured, scalable, and always-available compute foundation that Manus AI needs to thrive. By harnessing the power of the Cloud PC, our general AI agent can operate with greater agility, responsiveness, and reach — empowering users to access intelligent assistance wherever they work.” – Xiao Hong, CEO of Manus AI.  Manus AI integration with Windows 365 for Agents Trusted infrastructure for organizations In addition to agent makers, we developed Windows 365 for Agents to meet the complex requirements of enterprise organizations. As professional industries adopt cutting-edge AI systems for productivity, agents are held accountable to even a higher bar in security and compliance. Organizations looking to scale AI responsibly can rely on Windows 365 for:  * Enterprise-grade security & compliance   Agent sessions can be configured for enterprise-grade security and compliance, including Microsoft Entra join, Microsoft Intune management, and network configurations. * On-demand scalability   Agents can launch as many Cloud PCs as needed, supporting a wide range of workloads and parallel processes. The infrastructure is designed to scale flexibly with organizations’ needs, ensuring reliable performance for dynamic scenarios. * Seamless IT management   No new tools. No new training. IT admins can manage agent Cloud PCs just like user Cloud PCs on Intune, Microsoft 365 Admin Center, and Power Platform Admin Center — streamlined, familiar, and integrated into existing processes. We invite you to explore how Windows 365 can transform your approach to automation and AI. Get started with Copilot Studio powered by Windows 365 with 50 free hours of Cloud PC pool usage — no additional sign-up or IT setup required. Visit here to get started. If you’re an agent maker, IT leader, or developer interested in being among the first to try Windows 365 for Agents , sign up here to express your interest in our preview. Don’t miss your opportunity to shape the future of autonomous work and experience the platform that’s setting the standard for AI-powered productivity.   --- Continue the conversation, find best practices. Bookmark the Windows Tech Community , then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A .  
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Smarter IT, lower emissions: Sustainability with Windows, Microsoft Intune, and modern endpoints: From forward-looking frontier firms to businesses just getting off the ground, every Microsoft customer is seeking ways to improve performance and sustainability efforts. For commercial… #WindowsITPro
bit.ly
Smarter IT, lower emissions: Sustainability with Windows, Microsoft Intune, and modern endpoints
From forward-looking frontier firms to businesses just getting off the ground, every Microsoft customer is seeking ways to improve performance and sustainability efforts. For commercial organizations, Windows meets this need with a chip-to-cloud computing foundation that helps conserve energy, reduce waste, and efficiently manage resources.    Built-in energy efficiency settings in Windows 11 First, Windows 11 is a carbon-aware operating system When devices are plugged in, turned on, connected to the internet and regional carbon intensity data is available, Windows Update will schedule installations at specific times of the day. Installing updates at these specific times might result in lower-carbon emissions because a higher proportion of electricity is coming from lower-carbon sources on the electric gridi. Figure 1: Windows Update is carbon-aware Windows provides energy recommendations with options like shorter screen-off times and disabling unused devices, to further boost efficiency. These come together in Energy Saver mode, now available in Microsoft Intune.   These tools and features can help support your sustainability efforts while maintaining a smooth and productive Windows experience.  Smarter printing, less waste We are proud to announce that cloud-based Universal Print now includes an IT badge secure release feature.   To get their document(s), the person must be present at the printer and authenticate with a QR scan or physical badge. This feature can help support efforts to reduce unnecessary paper and toner use associated with unclaimed printouts.   Figure 2: Universal Print Anywhere with badge release Windows in the cloud: A lower-carbon option In new research by WSP USA, analysts compared the carbon emissions associated with provisioning physical PCs and cloud-based virtualization using Windows 365 and Azure Virtual Desktop (Windows in the Cloud Sustainability Report: Estimating the Carbon Emissions Impact of Transitioning to Windows 365 and Azure Virtual Desktop. Microsoft-commissioned study, September 2025).   Figure 3: WSP USA Windows in the Cloud Sustainability Report The findings were compelling. For users with low-to-medium intensity workloads, using a Windows 365 Cloud PC instead of a new laptop resulted in annual carbon reductions of approximately 70–90 kilograms of CO₂ equivalent per user in the United States and 60–80 kilograms in Europe.ii ,iii These savings stem from avoiding the manufacturing and transportation emissions associated with new devices. This can help you minimize e-waste and lower Scope 3 emissions.                 At scale, the impact is substantial. A group of 1,000 of these Cloud PC users could avoid the same emissions as those produced by burning 30 metric tons of coal in a year.iv For high-intensity users, such as engineers and designers, moving workloads from high-powered physical machines to Azure Virtual Desktop or Windows 365 is estimated to yield annual emissions reductions of about 70 kilograms of CO₂ per user in the U.S. and 55 kilograms in Europe, due to avoiding the manufacturing and transportation emissions associated with new devices.iii; iv A group of 1,000 high-intensity Cloud PC users could avoid the same emissions as not burning approximately 27 metric tons of coal in a year.v NOTE: These models may not reflect the specific circumstances or operational realities of any individual company. As such, the results should not be used for regulatory reporting, greenhouse gas (GHG) inventories, or other formal disclosures. Companies are encouraged to conduct their own analysis to determine emissions impacts relevant to their unique business structure and activities.  Data-driven insights and automation with Microsoft Intune Sustainability requires ongoing monitoring and optimization. Microsoft Intune and the Intune Suite comprise a cloud-based unified endpoint management solution that offers deep visibility into consumption patterns.   Now you can enforce power-efficient configurations at scale to reduce environmental impact and improve device longevity and efficiency.  * Manage Energy Saver settings centrally via Microsoft Intune and Group Policy. Configure policies for screen timeout, sleep settings, and Energy Saver activation thresholds across all managed PCs.   * The Intune Advanced Analytics Battery Health report offers a fleet-wide view of battery performance and usage patterns. Get a Battery Health Score for each device to help identify aging or failing batteries that may increase energy consumption or device issues.   * The Resource Performance report in Intune Advanced Analytics extends sustainability benefits beyond battery management, with CPU and RAM Spike Analysis. This identifies devices that consume excessive power due to hardware stress.   * Intune anomaly detection identifies devices with inefficient resource utilization. IT teams can easily investigate and remediate issues, so devices run more efficiently and consume less power.   *  Remote Help, another Intune feature, reduces the need for on-site visits and associated transportation emissions. * Finally, with the recent Windows 365 integration with Copilot in Intune, IT admins gain insights into Cloud PC connectivity trends, performance issues, and deployment gaps.   Figure 4: Copilot for Intune now manages Windows 365 Cloud PCs ENERGY STAR® - certified devices Microsoft and its Original Equipment Manufacturer (OEM) partners offer energy-efficient devices that incorporate recycled materials to help reduce environmental impact. Many laptops and tablets meet rigorous ENERGY STAR and EPEAT Gold standards — recognized benchmarks for energy use and environmental performance.   Surface embeds circular design in every device to help reduce carbon and minimize waste. Packaging is paper based, designed to use less material and minimize plastic content. Devices are engineered to deliver high performance while meeting energy efficiency standards. Pro, 12-inch performs 48% better than the ENERGY STAR baseline, while Laptop, 13-inch outperforms it by 68%.vi Additionally, the availability of spare parts and accessible repair guides has ensured easy serviceability to extend device use.vii The Microsoft Surface Emissions Estimator, now available on the web, and the Surface Management Portal in Intune offer more insights on Surface device fleets, including estimated carbon emissions resulting from manufacturing and usage.viii This model-level transparency allows procurement and sustainability teams to make informed decisions, track progress toward emissions goals, and align IT investments with corporate ESG commitments.  Figure 5: Microsoft Surface Emissions EstimatorFigure 6: Windows 365 Link Windows 365 Link is a compact, purpose-built Cloud PC device by Microsoft to connect users directly to Windows 365. It contains a minimum of 63% recycled content and has 100% paper-based packaging. It is estimated to use 50% less energy than the current ENERGY STAR© computer specification requirement and is designed to be long-lasting and repairable,.ix         And Windows 365 Boot allows organizations to extend the use of older PCs by enabling them to boot directly into a Cloud PC experience running Windows 11. This approach can allow you to make the most of your existing hardware while supporting your sustainability efforts and user needs.  Reduce, reuse, and recycle local machines Many Microsoft partners offer IT Asset Disposal (ITAD) or trade-in services to enterprises, government, small and medium businesses, schools, and consumers.   Microsoft also offers voluntary mail-back recycling programs for Microsoft-branded consumer products, batteries and/or packaging. There are also often recycling services in your community as well. Look online or ask Microsoft Copilot for guidance.   Real-world results and customer perspectives ENGIE, a global energy company, adopted both Windows 11 and Intune to support productivity and sustainability objectives. With cloud management and efficient features, ENGIE reduced its carbon footprint while enhancing employee experiences.  “Reducing waste, generating clean energy, and lowering emissions are part of our mission. And having a modern, secure, and scalable IT foundation supports all of that.” — Torsten Lesniak, Head of IT, Energy company EEW  Conclusion: Accelerating your sustainability journey Windows 11, Intune, and Universal Print are catalysts for more sustainable IT. From dynamic energy-saving features and cloud-based management to advanced analytics, implementing these products and services can help you take measurable steps toward sustainability.   Use Windows chip-to-cloud solutions and Microsoft Intune to make your computing endpoints more sustainable, efficient, and cost-effective.  ###   Resources * Read and share the Windows in the Cloud Sustainability Report   * Balance PC performance and energy efficiency with Energy Saver in Microsoft Intune  * Universal Print learn.microsoft.com/universal-print/  ____________________________ i Where available, Windows can schedule updates when greater amounts of low carbon energy sources (like wind, solar and hydro) are available on the local electrical grid. ii Based on comparison of virtual machines selected using the Microsoft Azure Virtual Machine Selector and a sample of in-market laptops with CPU count, RAM, and SSD storage in line with popular devices running low-to-medium-intensity workstreams, such as email, productivity apps, and streaming content. Emissions associated with manufacturing and transportation of new laptops (i.e., embodied carbon) are spread out over an expected use timeframe of three years to appropriately allocate emissions on an annual basis. iii Estimates are from the Azure Data Explorer platform using Azure Emissions Impact Dashboard data in October 2024 with an emissions data range of October 2023 – September 2024. The emissions calculation methodology aligns with the GHG Protocol Corporate Value Chain Scope 3 Standard and provides estimates for one year within the U.S. and Europe. Regional difference due to variations in location-specific grid emissions intensity. iv Based on Greenhouse Gas Equivalencies Calculator | US EPA. v Based on comparison of virtual machines selected using the Microsoft Azure Virtual Machine Selector with robust system specifications, such as geographic info systems-based analysis and computer-aided drafting and design. Emissions associated with manufacturing and transportation of new laptops (i.e., embodied carbon) are spread out over expected use timeframe of three years to appropriately allocate emissions on an annual basis. vi Computers that have earned the ENERGY STAR label are third-party certified to be energy efficient and use 25% - 40% less than conventional models by using the most efficient components and better managing energy use when idle. vii Replacement components available through online Microsoft Store and iFixIt for out-of-warranty repair. Components can be replaced by individuals with the knowledge and experience to repair electronic devices following Microsoft’s Service Guide. Microsoft tools (sold separately) may also be required. Availability of replacement components and service options may vary by product, market and over time. See [Self-repair information for your Surface device - Microsoft Support]. Opening and/or repairing a device can present electric shock, device damage, fire and personal injury risk, and other hazards. Use caution if undertaking self-service repairs. Unless required by law, damage caused during repair is not covered under Microsoft’s Limited Hardware Warranty or protection plans. viii The Microsoft Surface Emissions Estimator is only available in certain markets and only applies to Surface devices currently for sale. Contact your Surface seller for more details. ix Based on validation performed by Underwriter Laboratories, Inc. using Environmental Claim Validation Procedure, UL 2809-2, Second Edition, June 20, 2024. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Experience next-gen productivity with Windows 365 AI-enabled Cloud PCs: In our first 4 years in market, we focused on optimizing the Cloud PC experience for our customers and end users. Now, we have exciting news to share at the intersection of cloud and AI — Windows 365 AI-enabled… #WindowsITPro
bit.ly
Experience next-gen productivity with Windows 365 AI-enabled Cloud PCs
In our first 4 years in market, we focused on optimizing the Cloud PC experience for our customers and end users. Now, we have exciting news to share at the intersection of cloud and AI — Windows 365 AI-enabled Cloud PCs are combining the power of Windows 365 with AI acceleration to help users boost productivity, discover information faster, and streamline workflows, all while maintaining enterprise-level security and compliance. AI-enabled Cloud PCs deliver integrated Windows AI experiences to any device in any location, and are now available through the Microsoft Frontier Program. Frontier is an early-access initiative designed to accelerate AI innovation by giving select customers, partners, and influencers hands-on access to experimental features before they reach general availability. It is not just a beta program — it’s also about co-creation. Participants explore cutting-edge AI capabilities, provide feedback, and influence Microsoft’s roadmap . Availability and specifications are subject to change without notice. Learn more about Frontier . Disclaimer: Productivity improvements may vary based on configuration and usage. How are Windows 365 AI-enabled Cloud PCs different from Copilot+ PCs? Copilot+ PCs are physical devices with local 40+ TOPS NPUs that deliver AI features directly on the device. Windows 365 AI-enabled Cloud PCs, by contrast, run in the Microsoft Cloud and stream AI-powered Windows to any device and platform. With AI-enabled Cloud PCs, customers can count on: * Windows AI access anywhere: o   Experience high-performance Windows AI on any device with Cloud PCs that dynamically adapt compute power for more on-demand performance, streamed securely from the Microsoft Cloud. * Effortless productivity o   With improved Windows search and Click to Do, quickly find and act on files, images, and data with AI-powered search and context-aware answers — no app switching, just streamlined workflows. * Enterprise-grade security o   All data remains within your trusted Cloud PC environment, honoring regional compliance boundaries (European Database - EUDB). IT admins retain full control over enabling AI features for specific users.   Note: AI-enabled Cloud PCs are available on all 8 vCPU Cloud PCs in the following Azure datacenter regions: West US 2, West US 3, East US, East US 2, Central India, Central US, South East Asia, Australia East, UK South, North Europe, and West Europe. They will be coming to Japan East soon. Regional availability subject to change; check documentation for the latest updates. A new AI-enabled end-user experience AI-enabled Cloud PCs are identified by an “AI-enabled” label displayed on the device card within the Windows App. Windows App — logon experience for Windows The AI-enabled end-user experience also works on other platforms such as Apple iOS Mac devices. Windows App — logon experience for Apple Clients To use the new AI capabilities, improved Windows search and Click to Do, follow the instructions below. Cloud PC — desktop experience Supported Windows AI features in Windows 365 AI-enabled Cloud PCs offer the following features: * Improved Windows search (including OneDrive federated files support) * Click to Do AI-enabled Cloud PCs are marked by a magnifying glass with a sparkle icon within the search box on the taskbar. Improved Windows search With improved Windows search, users can locate files using descriptive queries, leveraging AI to interpret intent and deliver relevant results within the Windows search box in the taskbar and in File Explorer. For example, if you have a picture of a rugby game titled “Picture3.jpg”, and you search “rugby”, the correct file should appear. Accuracy of results may vary based on file content and indexing. Improved search experience in File Explorer Users can also search across multiple sources (local files and cloud storage through OneDrive) in a unified experience based on the content of the files rather than just metadata such as the title. This experience works within the Windows search box in the taskbar and in File Explorer. Improved search Start menu experience Note: Users can search for OneDrive files that haven’t been downloaded yet by entering keywords found inside the file’s text. To learn more about improved Windows search, see Find files fast with improved Windows search . Click to Do and Microsoft 365 Copilot & AI actions Click to Do simplifies the steps necessary to perform common actions on highlighted text or images on the screen. To activate this feature, press Windows key + Q or hold down the Windows key while clicking left on an element on your screen to export directly into Microsoft 365 Copilot for deeper integration, summarization, and other actions. Disclaimer: Feature requires Windows Insider Beta enrollment; functionality may change before general availability. Click to Do experience Microsoft 365 Copilot shows the prompt in a simple view to adjust the action, add your own AI agents to it, or simply click on the blue arrow button to push the prompt forward. Microsoft 365 Copilot — message box Ask Microsoft 365 Copilot — Summarizing and taking action. Microsoft 365 Copilot — app experience for summarizing data via Click to Do New AI actions are ready at your fingertips as new File Explorer context menu options. To learn more about Click to Do, see Click to Do: Do more with what's on your screen How to enable access to AI-enabled Cloud PCs IT admin controls By default, AI features are disabled on Cloud PCs, putting IT admins fully in control of when and for whom these capabilities are enabled — a key benefit for enterprise security and compliance. IT admins can enable AI-enabled Cloud PCs via a newly introduced policy setting within the Devices – Onboarding: Windows 365 > User Settings blade, and further filter access based on Microsoft Entra ID group access. How to join Frontier and access Windows 365 AI-enabled PCs To participate in our Frontier public release, you must meet the user and Cloud PC specifications, assign AI-enablement to Cloud PCs in Microsoft Intune, and enroll in the Windows Insider Program’s Beta channel. To enroll your Cloud PC in the Windows Insider Program, you must go to Windows Settings , followed by Windows Insider Program . Once ready, be sure to enroll in the Windows Insider Program with your Microsoft account or Microsoft Entra ID account and opt into the Beta Channel (Recommended) option. Note: We’re working on getting these features available outside of the Windows Insider Program. We will update this blog once it is ready. Windows Insider Preview Setup instructions for bulk Cloud PCs enrollment with Intune Here are step-by-step setup instructions for enrolling endpoints in the Windows Insider Program at scale using Intune, with pre-release builds enabled and the Beta Channel selected: * Sign into the Microsoft Intune admin center . * Navigate to: Devices > Windows > Update rings for Windows 10 and later * Create or edit an update ring policy : * Click + Create profile or select an existing policy to edit. * Configure Insider Builds : * Under Settings , find the section for Windows Insider build . * Set Enable pre-release builds to Yes . * In the same policy, locate the Pre-release channel setting. * Select Beta Channel from the dropdown menu. * Under Assignments , choose the groups containing the devices you want to enroll. Microsoft Intune — Windows Insider Program preview enrollment For more details, see Managing preview builds across your organization - Windows Insider Program . Health monitoring and analytics IT admins can also check whether a Cloud PC is AI-enabled or not via the Cloud PC overview Reports dashboard. Review information about AI-enabled features for Cloud PCs, including status and date created. Microsoft Intune — AI-enabled Cloud PC monitoring Or from the Essentials tab of the Intune Devices page. Microsoft Intune — AI-enabled Cloud PC monitoring Cloud PC licenses and regional support specifications To use AI-enabled features, your Cloud PC must meet the following requirements: * Have a Windows 365 Enterprise SKU that has at least 8vCPU, 32GB of RAM and 256GB of total disk storage. o   Note: final licensing with minimum requirements and other license options are subject to change. * Be deployed in one of the following supported regions: o   West US 2 o   West US 3 o   East US o   East US 2 o   Central India o   Central US o   South East Asia o   Australia East o   UK South o   West Europe o   North Europe, * Coming soon (not yet supported): o   Japan East * Where to find the AI-enabled Cloud PC Windows Cloud AI wallpaper o   Go to C:\Windows\Web\Wallpaper\Windows\ as part of 24H2 and 25H2 Windows 11 images in your Cloud PCs provisioned in November ’25 or later. Regional availability subject to change; check documentation for latest updates. For more detailed documentation and requirements, please go to our documentation at aka.ms/AICloudPCsLearn Reporting feedback on this Frontier release We’d love to hear from you — please use the following channels to provide feedback on our Frontier preview: * Feedback Hub (please report that you are using an AI-enabled Cloud PC.) * Windows 365 Tech Community Important note: Feedback may inform future development but does not guarantee implementation. Windows — Feedback Hub Watch our Windows in the Cloud podcast Watch the podcast below to learn more about the announcements today, the people who build the features, more real demos, and other behind the scenes information. aka.ms/AICloudPCsvideo Continue the conversation. Find best practices. Bookmark the Windows Tech Community , then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A .
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/11/2025
Evolving Windows: new Copilot and AI experiences at Ignite 2025: At Ignite this year, we’re unveiling how Windows is evolving from an operating system into the canvas for AI, embedding intelligence across system, silicon, and hardware. This transformation helps organizations to move… #WindowsITPro
bit.ly
Evolving Windows: new Copilot and AI experiences at Ignite 2025
At Ignite this year, we’re unveiling how Windows is evolving from an operating system into the canvas for AI, embedding intelligence across system, silicon, and hardware. This transformation helps organizations to move beyond experimentation and deliver AI-driven outcomes. For those aiming to become Frontier Firms — the world’s most ambitious organizations blending human ingenuity with intelligent systems — Windows is the foundation that makes it possible.   Windows is evolving to include agent-like functions built into the operating system, new tools offered by Microsoft 365 Copilot on Windows, and capabilities powered by Copilot+ PC hardware. As organizations seek to leverage AI, we’re envisioning Windows as an OS that aims to make interactions more natural, increase productivity, and offer a strong platform and ecosystem for AI innovation.  In this blog, we’ll provide a deeper dive into the Windows AI innovations we’re sharing at Ignite and what this means for your organization. We’re committed to ensuring Windows is the secure, manageable, and future-ready platform that prepares your organization to adopt AI and agentic innovations.   Join early access and learn more. Simple, personalized AI experiences on Windows 11 Windows empowers organizations to deliver flexible user experiences that feel truly personal — where employees can work how they want, without friction or compromise. With support for multi-modal interaction and deeper integration of Microsoft 365 Copilot capabilities in Windows 11, AI becomes more than just a natural part of everyday workflows; it makes every interaction intuitive and intelligent.   * A key example of new interaction models in Windows is voice in Microsoft 365 Copilot, which helps users quickly capture ideas for brainstorming, drafting responses, or preparing meetings. Simply say “Hey Copilot” (available in Frontier in the coming weeks) or press the Copilot key (Win+C shortcut for devices without a Copilot key) to open the quick view input box to activate voice. This allows you to stay focused or multitask, tapping into Copilot without any interruption of switching apps and windows. Start a back-and-forth conversation with Copilot, receiving real-time spoken responses based on both web and work data. Voice in Microsoft 365 Copilot is available now.   Voice in Microsoft 365 Copilot enables back-and-forth conversation and real-time spoken responses.   * When using AI agents that need a longer time to complete their tasks, like Researcher, Agents on the taskbar will show at-a-glance status and chain-of-thought logic, making it easy to check in on the agent’s progress and see its completion status. Coming soon in preview, this unifies how users invoke and manage AI agents across the OS and makes agents seamlessly accessible and interactive.   Monitor long-running agents directly on the Windows taskbar.   * Also coming soon in preview, users can conveniently use search and Ask Copilot on the taskbar in the new composer experience. Additionally, AI agents can be started directly from Ask Copilot on the taskbar by using the “tools” menu or typing ‘@’.   Use search and Ask Microsoft 365 Copilot directly in the taskbar with the new composer experience.   Tag an AI agent directly in Ask Copilot on the taskbar by typing “@”.   * In File Explorer Home, users will be able to hover over files in File Explorer and Ask M365 Copilot for on-demand assistance or insights. Users can enjoy streamlined file productivity without leaving their current context. This is rolling out before the end of 2025.   Hover over files in File Explorer Home and Ask M365 Copilot for on-demand assistance or insights.   * Need assistance with organizing your day? Coming soon to preview in December 2025, the new Agenda view appears right in Notification Center—offering a quick-glance, chronological list of your upcoming events, seamlessly integrated with Calendar in one unified interface. Users will also be able to interact directly with the events shown in their Agenda view, such as joining a scheduled meeting or engaging with Microsoft 365 Copilot. This makes it easier to prepare for upcoming meetings and streamline your day.   Agenda view provides a chronological list of upcoming events in one unified interface.   AI is also accelerating how organizations can support people across a diverse spectrum of accessibility needs to make the most out of their Windows 11 experience.   * Now in preview for Copilot+ PC users, AI-powered fluid dictation makes voice typing fast, accurate, and natural — enabling people to turn speech into text with minimal effort and need for manual corrections. Fluid dictation is available via the Win+H shortcut and dictation tools like voice typing and voice access, leveraging local, on-device models.   Fluid dictation for Copilot+ PCs leverages on-device AI models to make voice typing fast, accurate, and natural.   * Windows is also offering users a natural and life-like reading experience powered by Azure’s latest on-device text-to-speech models for English (US). These high-definition voices — now available in Windows Narrator and Magnifier voices — are built on advanced generative AI and adapt tone and pace contextually to make interactions feel intuitive and engaging. The cloud version of HD models is generally available in Azure Speech services. Find out about the latest updates to Azure Speech.   * Narrator announcements today are verbose and generic, offering little flexibility. In preview soon, AI-powered Narrator personalization addresses this by giving users precise control over what is announced and how. Users can now customize verbosity for control types and reorder their properties and create app-based profiles, so Narrator behaves differently in Word, Excel, or Outlook. They can make these adjustments using natural language and preview changes instantly before saving. This brings flexibility, speed, and focus to Narrator — allowing users to shape their experience to their work, not the other way around. "Having Microsoft 365 Copilot directly in Windows 11 and my everyday tools makes it feel like part of my workflow, not another app to learn." - Ryan Katreeb, Finance Manager, Levi's Expanded productivity capabilities on Copilot+ PCs In today’s fast-paced work environment, efficiency isn’t optional — it’s essential. Copilot+ PCs redefine what productivity looks like by bringing AI directly into Windows. Instead of navigating endless menus or switching between apps, employees gain an intuitive experience where AI anticipates intent and delivers context-aware guidance. Copilot+ PCs transform routine tasks into seamless actions, enabling teams to focus on creativity and problem-solving rather than process. The following features are exclusive to Copilot+ PCs:  * Find what you need, simply by describing it with improved Windows search. This semantic search capability enables you to find the right file without needing to remember exact file names or words in file content. Improved Windows search spans both local files and now cloud-based Microsoft 365 files, improving discoverability. This is gradually rolling out to commercial Microsoft 365 Copilot customers on Copilot+ PCs.  Improved Windows search on Copilot+ PCs now spans both local files and cloud-based Microsoft 365 files, improving discoverability.   * Act on what’s on your screen with Click to Do. You can send content to and Ask Microsoft 365 Copilot a question about what is on your screen without needing to switch context. Or, a table you see on your screen can instantly become a usable Excel table. Whether it’s an image from the web or something that’s being shown in a Teams meeting, Click to Do makes it easy to convert a table to Excel.   * Write with efficiency, confidence, and clarity. In preview soon, Writing Assistance with Microsoft 365 Copilot helps employees craft compelling content with AI-powered rewrite and proofreading. This is also available offline to Copilot+ PC users, as Writing Assistance leverages the on-device NPU on Copilot+ PCs to run AI models locally, reducing dependency on connectivity.   Writing Assistance with Microsoft 365 Copilot provides AI-powered rewrite and proofreading capabilities.   * Users can also summarize lengthy emails directly in Outlook, even when offline for Copilot+ PC users. This is rolling out to Copilot+ PC users at the end of the month. Windows for the agentic ecosystem It’s not just Windows 11 and Copilot+ PCs that demonstrate what’s possible when Windows and AI work together. * Windows also provides platform primitives for enterprises and developers to build and enable agentic workflows. Today, we’re introducing native support for the Model Context Protocol (MCP) in public preview, giving AI agents a standardized way to connect with apps and tools to automate routine scenarios and perform tasks on behalf of users. Built-in agent connectors for File Explorer and Windows Settings make it easy for agents to manage local files and modify device configurations seamlessly. In private preview, the new Agent workspace provides a contained, policy-controlled, and auditable environment where agents can operate like people — performing tasks in parallel without disrupting the user’s primary session. Finally, we’re expanding on-device AI capabilities with Microsoft Foundry on Windows, introducing new Windows AI APIs like Video Super Resolution (VSR) and Stable Diffusion XL (SDXL) to power next-generation AI experiences. Learn more about these new platform capabilities.   * Windows 365 for Agents enables AI-powered systems — such as Copilots, agents, and autonomous workflows — to access a full Cloud PC. These agents can browse websites, process data, and automate tasks, all within a secured, policy-controlled Cloud PC streamed from the Microsoft Cloud. Windows 365 is the backbone of some of the most advanced Microsoft AI initiatives and partner solutions. It serves as the execution platform for computer-using agents built into Microsoft Copilot Studio computer use — Microsoft’s toolkit for building custom Copilot AI agents to automate web tasks right from a prompt. Leading agent makers — Manus AI, Fellou, Genspark, Simular, and TinyFish — are already looking forward to leveraging Windows 365 to deliver next-generation AI solutions. Learn more about Windows 365 for Agents, now in preview.  A secure and manageable foundation Windows continues to deliver innovation without compromising on security or manageability, to meet the needs of your organization, wherever you may be on your AI journey. With Windows Autopatch, update readiness, hotpatch, and the Windows Resiliency Initiative, we continue to provide organizations with the tools needed to maintain a secure, resilient foundation.  * Available soon in public preview, IT admins will be able to manage agentic capabilities in Windows using familiar enterprise tools like Intune, Entra, and Group Policy. This includes enabling or disabling agent connectors and workspaces, setting minimum security policies for agent connectors, and deploying agent connectors with MSIX. Event logs provide visibility into agent activity, and advanced controls are planned for 2026, ensuring organizations can adopt AI on their terms. Learn more about enterprise management policies and capabilities.   * Recall with Microsoft Purview integration enables organizations to take advantage of Recall’s productivity features on Copilot+ PCs, while still maintaining robust data loss prevention controls. Recall is enterprise-ready, respecting organizational policies and Purview safeguards to help secure sensitive data across Office, Outlook, and Teams. This is now in preview for organizations with Copilot+ PCs. Read the blog, case study, and learn how to manage Recall in your organization.   Recall and Purview integration on Copilot+ PCs is now in preview.   Windows gives IT and organizations choice and control. By adopting Windows as your OS with security, compliance, and manageability at the core, your organization can adopt AI innovations at your own pace and build a future-ready foundation. Join early access to get the latest features To get early access to these features, join the relevant Windows and Microsoft 365 pre-release programs: * Join the Windows Insider Program Enroll devices in the Windows Insider Program (Dev or Beta Channel) to get pre-release builds of Windows. * Enable Targeted Release for Microsoft 365 In the Microsoft 365 admin center, set your tenant or selected users to Targeted Release to receive early updates to Microsoft 365 and Copilot. * Join the Office Insider Program (optional but recommended for local app previews) Get early access to new features in Word, Excel, PowerPoint, and other desktop apps. Learn more Read more about the Windows and AI at Microsoft Ignite 2025: Windows at the Frontier of Work. We look forward to seeing you in person and online at Microsoft Ignite: * Tuesday, November 18th, 2:30PM PST: BRK344 Agents at Work: Windows Powers the Era of Intelligent Productivity * Tuesday, November 18th, 5PM PST: BRK346 Secure & Manage the Most Productive, Intelligent OS: Windows 11 * Thursday, November 20th, 9AM PST: THR786 Copilot+ PCs & Microsoft 365: Secure, Smart, Efficient Windows For more information, please visit Windows 11 on Microsoft Learn and Microsoft Adoption Center. You can also join us here on December 2nd, 2025, for a Windows Tech Community Live AMA. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 13/11/2025
Secure Boot playbook for certificates expiring in 2026: The first set of tools and steps are now available to help you proactively update your Secure Boot certificates before they expire in June of 2026. Secure Boot is more mature and robust today than it was some years ago. Coupled… #WindowsITPro
bit.ly
Secure Boot playbook for certificates expiring in 2026
The first set of tools and steps are now available to help you proactively update your Secure Boot certificates before they expire in June of 2026. Secure Boot is more mature and robust today than it was some years ago. Coupled with the Unified Extensible Firmware Interface (UEFI) firmware signing process, Secure Boot uses cryptographic keys, known as certificate authorities (CAs), to validate that firmware modules come from a trusted source. This helps prevent malware from running early in the startup sequence of a Windows device. Secure Boot certificates have always had expiration dates. New certificates help ensure that your devices stay up to date with the latest security protections.i That is why your organization will need to install the 2023 CAs before the 2011 CAs start expiring in June of 2026. Note: Need a refresher on why updating Secure Boot certificates is so important? * Read Act now: Secure Boot certificates expire in June 2026. * Bookmark Windows Secure Boot certificate expiration and CA updates. * Learn more about Secure Boot, signature databases and keys, and boot sequence. Many Windows PCs manufactured since 2024 already have the updated 2023 certificates. For the remaining devices, Microsoft is delivering new Secure Boot certificates through Windows monthly updates, with partner original equipment manufacturers (OEMs) making firmware updates available to help ensure compatibility. If you wish to proactively update your Secure Boot certificates, this post contains initial steps you can take and tools you can use, with more scalable approaches coming soon. At a minimum, we encourage you to monitor the progress of your device fleet from the start. Let’s get started. Here’s a summary of what you can do today to prepare: * Step 1: Inventory and prepare your environment * Step 2: Monitor and check your devices for Secure Boot status * Step 3: Apply OEM firmware updates before Microsoft updates * Step 4: Plan and pilot Secure Boot certificate deployments * Step 5: Troubleshoot and remediate common issues Step 1: Inventory and prepare your environment For most devices in your organization, Microsoft will automatically update high-confidence devices via Windows Update. However, you can validate and actively roll out these updates, in which case, you would start by conducting an inventory. Inventory Most devices manufactured since 2012 have Secure Boot enabled, but you should always verify that. You should also check the status of the Secure Boot certificates with sample inventory PowerShell commands or by checking the value of the UEFICA2023Status registry key (it should ultimately be “updated”). Out of the devices that show up as not updated, build a small, representative sample. We recommend that you focus on the less common devices, for which high confidence determination isn’t automatic. Then follow the rest of the steps outlined in this post to pilot the certificate updates and help ensure that deployment is successful Prepare select devices To prepare devices for Secure Boot certificate deployment, consider how you’ll manage it. There are several approaches to managing Secure Boot certificate updates. Today, you can use registry keysii or Group Policy. A Configuration Service Provider (CSP) for mobile device management (MDM), such as Microsoft Intune, is coming soon. Bookmark https://aka.ms/GetSecureBoot for the latest updates. * The primary method is to deploy the certificates to devices that have been validated as ready for the update. See Step 4 when you’re ready to deploy these updates! * For the more common device configurations in your environment, you can utilize two “assists” to manage your deployment: * * Get new certificates through monthly Windows updates for high-confidence devices. This option is enabled by default for devices that are ready for new certificates. Microsoft will update these devices for you unless you opt out. To opt out, set the HighConfidenceOptOut registry keyii value to 1 or set the Automatic Certificate Deployment via Updates Group Policy to Disabled. * Opt devices in to Microsoft-managed controlled feature rollout. With registry keys, set the value of MicrosoftUpdateManagedOptIn to 1 to opt in to Microsoft-managed controlled feature rollout. The value of 0 or non-existent key means that you’re opted out. With Group Policy, configure the Certificate Deployment via Controlled Feature Rollout policy to Enabled. Note: To opt in, please configure devices to share required diagnostic data with Microsoft. Important: All Secure Boot registry keys are under these two paths: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot and HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing. See Registry key updates for Secure Boot: Windows devices with IT-managed updates for more details. Group Policy settings are available to you under the following path: Computer Configuration > Administrative Templates > Windows Components > Secure Boot. To get the updates that include the Group Policy for deploying Secure Boot certificate updates, download the latest Administrative Templates (.admx) for Windows 11 and Windows Server. Step 2: Monitor and check your devices for Secure Boot status Check the Secure Boot status of your devices before and after deployment. Soon, you will be able to use your preferred management and reporting tools. For now, you can use registry keysii or Windows Event Log events to identify which devices already have new certificates and which ones need attention. Deployment progress The text value of the UEFICA2023Status registry key will indicate if your certificate deployment status is not started, in progress, or updated. The value will change progressively until all new certificates and the new boot manager have been deployed successfully. Successful deployment * Audit the Windows System Event Log events for Event ID 1808.iii This informational event indicates that the device has the required new Secure Boot certificates applied to the device’s firmware. * Audit the UEFICA2023Error registry key for issues. This key should not exist unless an error is pending. * Check that the text value of the UEFICA2023Status registry key reads as “Updated.” Errors during deployment * Audit the Windows System Event Log for Event ID 1801.iiiThis error event indicates that the updated certificates have not been applied to the device. Analyze details specific to the device, including device attributes, that will help you in correlating which devices still need updating. * Check if the UEFICA2023Error registry key exists. If so, it indicates an error in certificate deployment. The error itself won’t appear in the Event Log. Trace related issues through Secure Boot DB and DBX variable update events. Step 3: Apply OEM firmware updates before Microsoft updates Updated firmware can help prevent compatibility problems and ensure new Secure Boot certificates are accepted. If your organization has identified Secure Boot update issues or your OEM recommends a firmware update, apply the latest BIOS/UEFI update before installing Secure Boot–related Windows updates. Some OEMs provide firmware updates that include important fixes and updated certificate stores. These updates help Secure Boot function correctly with new Windows certificates. Microsoft works closely with OEM partners to ensure these updates integrate smoothly with Windows. Step 4: Plan and pilot Secure Boot certificate deployments As you’ve seen in Step 1, Microsoft can assist with your Secure Boot updates if you enable diagnostic data. You can also deploy new Secure Boot certificates yourself for devices that don’t already have them. Choose a way to do this with registry keys,ii via Windows Configuration System (WinCS) command-line interface (CLI), or using Group Policy today. Pilot your desired method first on a representative set of devices to gain confidence. In a typical enterprise deployment, whatever option you choose, allow approximately 48 hours and one or more restarts after changing configuration for updates to fully apply. See How updates are deployed for more details. For testing scenarios, you can accelerate the experience by following the steps outlined in Device Testing Using Registry Keys. Important: Avoid mixing deployment methods on the same device. For additional technical recommendations to help you plan and deploy your Secure Boot updates, see Deployment strategies. Option 1: Deploy certificates with registry keys Find the AvailableUpdates registry key located under this registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot Set its value to 0x5944 to deploy all needed certificates and update to the Windows UEFI CA 2023 signed boot manager. This key corresponds to the Group Policy setting Enable Secure Boot certificate deployment. For details, see Registry key updates for Secure Boot: Windows devices with IT-managed updates. Option 2: Deploy certificates via Windows Configuration System (WinCS) New command-line tools are now available for domain-joined clients on Windows 11, versions 25H2, 24H2, and 23H2. These include both a traditional executable and a PowerShell module to query and apply Secure Boot configurations locally to a device. For step-by-step guidance, see Windows Configuration System (WinCS) APIs for Secure Boot. Deploy the Secure Boot updates via WinCS: * Feature name: Feature_AllKeysAndBootMgrByWinCS * WinCS key value: F33E0C8E002 * Secure Boot configuration state: Enabled Option 3: Deploy certificates using Group Policy Group Policy settings are available by navigating to Computer Configuration > Administrative Templates > Windows Components > Secure Boot. To apply Secure Boot updates to devices using Group Policy, set the Enable Secure Boot certificate deployment policy to Enabled. This lets Windows automatically begin the certificate deployment process. This setting corresponds to the registry key AvailableUpdates. Be sure to get the latest version of the .admx for Windows 11 and Windows Server. For more details, see Group Policy Objects (GPO) method of Secure Boot for Windows devices with IT-managed updates. Option 4: Deploy certificates using mobile device management (coming soon) Soon, you’ll be able to manage Secure Boot updates using MDM solutions, such as Microsoft Intune. When this method is available, we will post updated guidance at https://aka.ms/GetSecureBoot. Step 5. Troubleshoot and remediate common issues You can also use registry keys and Windows Event Log events to identify and resolve common issues: * The UEFICA2023Error registry key doesn’t exist if there are no errors. If it exists with a value other than 0, check your remediation recommendations in Secure Boot DB and DBX variable update events. * The AvailableUpdates registry key on a device is set to 0x4104. If it doesn’t clear the 0x0004 bit even after multiple restarts, the device doesn’t progress past deploying the new Key Exchange Key (KEK) certificate. If you encounter this error, check with your OEM to confirm they have followed the steps outlined in Windows Secure Boot Key Creation and Management Guidance. * If Event Viewer Windows Logs for System registers an Event ID 1795,ii it means that there was an error when Windows attempted to hand off the certificates to firmware. Check with the OEM to see if there is a firmware update available for the device to resolve this issue. Your update strategy begins today Today, you can start preparing, monitoring, deploying, and troubleshooting Secure Boot certificates in advance of the June 2026 expiration date. The new registry keys, WinCS, Group Policy, and Windows Log tools are here to support you and are just the beginning. More tools for additional scenarios are in development. For the latest information, bookmark Windows Secure Boot certificate expiration and CA updates. Looking for a specific topic? * Find the deployment playbook and troubleshooting guidance in the updated Secure Boot Certificate Updates: Guidance for IT Professionals and Organizations. * New! Registry key updates for Secure Boot: Windows devices with IT-managed updates. * New! Group Policy Objects (GPO) method of Secure Boot for Windows devices with IT-managed updates. * New! Windows Configuration System (WinCS) APIs for Secure Boot. * Have a question? Browse answers to Frequently asked questions about the Secure Boot update process. * If you’re an OEM, find helpful resources at Windows Secure Boot Key Creation and Management Guidance. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A. iUpdated certificates are the latest security measure to address the BlackLotus UEFI bootkit vulnerability tracked by CVE-2023-24932. iiRegistry key support is available to Windows 10, version 22H2 and newer versions (including 21H2 LTSC), all supported versions of Windows 11, as well as Windows Server 2022 and later. Any other versions of Windows still in support will get these registry keys soon. iiiFor all events, go to Event Viewer > Windows Logs > System. Please see complete details under Secure Boot DB and DBX variable update events.
020
ConfigMgrDogs @configmgrdogs.bsky.social · 11/11/2025
Windows 11 expands passkey manager support: Windows is committed to making sign-in simpler, quicker, and more secure for every user. Today, we’re excited to announce a major step forward in passwordless authentication: native support for passkey managers in Windows 11. This new… #WindowsITPro
bit.ly
Windows 11 expands passkey manager support
Windows is committed to making sign-in simpler, quicker, and more secure for every user. Today, we’re excited to announce a major step forward in passwordless authentication: native support for passkey managers in Windows 11. This new capability empowers users to choose their favorite passkey manager — whether it’s Microsoft Password Manager or trusted third-party providers. It’s generally available with the Windows November 2025 security update. By partnering closely with third-party managers, we’re delivering a more flexible, secure, and intuitive experience for Windows users everywhere, starting with 1Password today and other passkey managers coming soon.  “Working alongside the Windows Security team on the development of the passkey plugin API for Windows 11 has been a rewarding partnership. As the first password manager to offer native passkey support in Windows 11, we’re proud to give customers a seamless passwordless experience inside and outside the browser. Together, we’ve ensured that 1Password and other third-party passkey providers can deliver a secure, standards-based experience natively on Windows, marking another major step towards a passwordless future.” - Travis Hogan, End User Group Product Manager, 1Password Why plugin passkey managers? Passkeys are phish-resistant, less vulnerable to data breaches, and easier and faster to use than passwords. With plugin passkey manager support, you get: * Choice and flexibility: Use your preferred passkey manager natively on Windows. * Easy authentication: Create and sign in with passkeys using Windows Hello. * Passkeys everywhere: Your passkeys are synced between your Windows PCs and mobile devices. They go where you go. Saving a passkey to 1Password Easier authentication, with Windows Hello With plugin passkey manager support, packaged credential managers can integrate directly into Windows. Users can save, manage, and use passkeys across browsers and native apps — thanks to the new plugin provider capability. Setting up your credential manager is part of the passkey creation flow. Authentication uses Windows Hello — whether that is PIN, face, or fingerprint — so only you can access your credentials. Microsoft Password Manager We’ve integrated Microsoft Password Manager from Microsoft Edge natively into Windows as a plugin. That means you can use it in Microsoft Edge, other browsers, or any app that supports passkeys. Saving a passkey to the Microsoft Password Manager plugin on Windows This integration of Microsoft Password Manager from Microsoft Edge comes with added security benefits: * Passkey operations (creation, authentication, and management) are protected by Windows Hello. * Passkeys stored in Microsoft Password Manager will be synced and available on other Windows devices where the user is logged into Microsoft Edge with the same Microsoft account. * Syncing is protected by your Microsoft Password Manager PIN and a cloud enclave solution. * Azure Managed Hardware Security Modules (HSMs) help protect encryption keys. * Sensitive operations are performed inside a hardware-isolated environment in Azure Confidential Compute.  * There is tamper-proof recovery with Azure Confidential Ledger. In other words, your passkeys are securely stored and easy to use. Securing the present, innovating for the future Join us as we build a passwordless future - one passkey at a time. Security is a shared responsibility. Through collaboration across hardware and software ecosystems, we can build more resilient systems that are secured by design and by default, from Windows to the cloud, enabling trust at every layer of the digital experience. The updated Windows 11 Security Book and Windows Server 2025 Security Book are great tools to help you understand how to stay more secure with Windows. Learn more about Windows 11, Windows Server, and Copilot+ PCs. To learn more about Microsoft Security Solutions, visit our website.  Bookmark the Microsoft Security Blog to keep up with our expert coverage on security matters. Also, follow Microsoft Security on LinkedIn and @MSFTSecurity on X for the latest news and updates on cybersecurity.  --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
010
ConfigMgrDogs @configmgrdogs.bsky.social · 07/11/2025
Windows Autopatch for the US government: How to get started: The power of automated Windows update management is coming to government SKUs! Starting this month, you can use Windows Autopatch to help keep devices at your organization secure and productive with minimal disruption to… #WindowsITPro
bit.ly
Windows Autopatch for the US government: How to get started
The power of automated Windows update management is coming to government SKUs! Starting this month, you can use Windows Autopatch to help keep devices at your organization secure and productive with minimal disruption to users. This cloud-based service that has a proven record with enterprises has now been approved to be added to the Azure FedRAMP High Provisional Authorization to Operate (P-ATO). Learn what this means for your environment and how to get started! New Windows Autopatch service for GCC subscriptions Windows Autopatch is now available to US government organizations as part of Microsoft 365 Government. This is what Windows Autopatch allows you to accomplish for your Government Community Cloud (GCC) devices: * Windows Autopatch provides control over which content is approved for deployment to which devices through Windows Update. * Windows Autopatch groups help you automate a safe rollout process. You can distribute devices into rings and recommend release schedules, leaving you with the final say. * Get secure faster with hotpatching: apply security patches without waiting for a restart. * Pause or expedite monthly quality updates or drivers for groups of devices in your environment. * Simplify update compliance reporting. Windows Autopatch reporting tracks which devices have the latest updates installed with less than 4-hour latency. * Manage policy and see reporting through the Microsoft Intune admin center. Get started with Windows Autopatch To begin, double-check that your devices meet the prerequisites for Windows Autopatch. Configure role-based access control to manage access to your organization’s resources and network. If you’re using Microsoft Intune, the easiest way to automate your update process is to create one or more Windows Autopatch groups: * Go to the Microsoft Intune admin center. * In the left pane, select Tenant administration and then navigate to Windows Autopatch > Autopatch groups. * Create a Windows Autopatch group and assign devices, automating a few things: * Distribute devices for gradual rollout into a set of Microsoft Entra groups. * Configure a safe rollout schedule using update rings. * (Optional) Configure content approval using feature and driver update policies. * (Optional) Configure update settings for Microsoft 365 Apps and Microsoft Edge. * Enroll devices to receive hotpatch updates, getting them secure faster. * That’s it! Just monitor the reports to ensure that you’re hitting your update compliance targets. Instead of Windows Autopatch groups, you can also create individual policies: * Update rings: Control update settings on targeted endpoints. * Windows quality updates: Configure your device to receive hotpatch updates. * Expedited quality updates: Deploy a specific quality update more quickly. * Windows feature updates: Choose the version of Windows approved for deployment for a group of devices. * Driver and firmware updates: Control which drivers are approved for deployment for a group of devices. Regardless of which setup option you choose, if your device is included in a policy, it will show up in the reports for that content type. What about other Azure Government Cloud offerings? Windows Autopatch is not currently supported in US Government Community Cloud High (GCC High) or Department of Defense (DoD) environments. We are working on expanding our service to meet those requirements. Welcome to automated update management! Come be part of the Windows Autopatch community! Here are the resources you’ll need to get started and get support: * Windows Autopatch documentation * Windows Autopatch on the Windows IT Pro Blog * Windows Autopatch: Your playbook for advanced update management * Inside hotpatch updates for Windows * Hotpatch for client: Frequently asked questions --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
001
ConfigMgrDogs @configmgrdogs.bsky.social · 03/11/2025
Windows news you can use: October 2025: Microsoft Ignite 2025 is coming soon: November 18 – 21. Read up on the range of sessions including breakouts (in person and online), hands-on labs, community roundtables, and much more. You can register for digital Microsoft Ignite and plan your… #WindowsITPro
bit.ly
Windows news you can use: October 2025
Microsoft Ignite 2025 is coming soon: November 18 – 21. Read up on the range of sessions including breakouts (in person and online), hands-on labs, community roundtables, and much more. You can register for digital Microsoft Ignite and plan your event schedule now. Have questions about what you learned at Microsoft Ignite? Save the date for Tech Community Live: Windows edition on December 2. Ask Microsoft Anything sessions start at 8 AM PT and are a great way to get answers to your questions from our engineering teams. Keep reading to catch up on other important articles and announcements from October 2025. New in Windows update and device management [HOTPATCH] Curious why hotpatch updates are smaller in size than standard Windows updates? Find a quick explanation and learn why smaller updates help you achieve security and compliance more quickly. Learn how Microsoft implemented hotpatch updates internally. [INTUNE SETTINGS CATALOG] New settings for Windows 11, version 25H2 are now available in the Microsoft Intune Settings Catalog and are ready for you to use in your device configuration profiles. [INTUNE ADVANCED ANALYTICS] Get to know Microsoft Intune Advanced Analytics and the real-world scenarios that benefit from deeper insights into device health, the user experience, and organizational trends. [INTUNE] Discover the 10 key Microsoft Intune capabilities that will simplify the upgrade to Windows 11. These include readiness insights, policy controls, and app compatibility tools. [FRONTLINE] Emergency services increasingly use mobile devices to empower early responders and teams in the field. Get tips on how to manage devices for early responders so they have real-time access to the information they need on the frontlines. [EPHEMERAL OS DISK SUPPORT] Ephemeral OS disk support on Azure Virtual Desktop is now in public preview. Designed for stateless workloads, this capability stores the OS on the virtual machine’s local storage instead of remote storage, enabling faster session host creation and improved performance. [PREINSTALLED APP MANAGEMENT] You can now remove select provisioned in-box apps using a straightforward policy rather than custom imaging and complex scripts. This policy is available for devices running Windows 11 Enterprise, version 25H2 and Windows 11 Education, version 25H2. [WINDOWS 365] Get guidance on identifying the ideal connection option for Windows 365 Cloud PCs for your users. Explore use cases for Windows 365 Link, Windows 365 Boot, Windows 365 Switch, and the Windows App. [WINDOWS UPDATE] We are simplifying Windows Update titles for clarity and consistency across Windows, .NET framework, drivers, AI components, and Visual Studio updates. Explore the latest changes and stay tuned for future improvements. New in Windows security [SFI] Check out the latest Microsoft Secure Future Initiative (SFI) patterns and practices for actionable, relevant guidance in the areas of network, engineering systems, and security response. New in AI [AI FOR WINDOWS DEVELOPERS] Now that Windows Machine Learning (ML) is generally available, check out our guide of helpful resources for AI development in Windows. [UPDATES] The October 2025 non-security update for Windows 11, version 25H2 and version 24H2 includes the following feature, which will be rolled out gradually. * [MICROSOFT 365 COPILOT] A new Microsoft 365 Copilot page has been added to the Get Started experience for commercial devices with an active Microsoft 365 subscription. Learn more about Microsoft 365 Copilot features and how to get started using them. New in productivity and collaboration New features and improvements are coming in the November 2025 security update. You can preview them by installing the October 2025 optional non-security preview update for Windows 11, version 25H2 and version 24H2. This update includes the gradual rollout of: * [START] The Start menu layout has been redesigned to help you access your apps more quickly and smoothly, making it easier than ever to find what you need. * [BATTERY] The battery icons now display colored icons to indicate charging states and feature simplified overlays that don’t block the percentage bars, plus there’s an option to display battery percentage. * [ACCOUNTS] The “Email & accounts” section is now called "Your accounts." You can manage all your accounts under Settings > Accounts. Lifecycle milestones Check out our lifecycle documentation for the latest updates on Deprecated features in the Windows client and Features removed or no longer developed starting with Windows Server 2025. * [WINDOWS 11 23H2] Windows 11, version 23H2 (Home and Pro editions) will reach end of servicing on November 11, 2025. Enterprise and Education editions will continue to be serviced through November 10, 2026 per the Modern Lifecycle Policy. * [WINDOWS 10 ESU FOR WINDOWS 365] Windows 10 reached end of support on October 14, 2025. Learn how to extend your Windows 10 devices with Windows 365, including creating Windows 10 custom images with Extended Security Updates (ESUs), using ESUs for physical PCs connecting to Windows 365, and more. * [WINDOWS 10 ESU FOR AZURE VIRTUAL DESKTOP] Windows 10 reached end of support on October 14, 2025. Learn about the Windows 10 Extended Security Updates (ESUs) for Azure Virtual Desktop across these scenarios: Existing session hosts, creating new session hosts, Microsoft 365 Apps support for Windows 10, and Windows 10 ESU support. Additional resources Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, Windows Server, the Windows and Windows Server Insider Programs, and more? Check out these resources: * Windows Roadmap for new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name * Microsoft 365 Copilot release notes for latest features and improvements * Windows Server 2025 release notes and Windows Server, version 23H2 release notes for the latest features and improvements for Windows Server * Windows Insider Blog * Windows Server Insider for feature preview opportunities * Understanding update history for Windows Insider preview features, fixes, and changes to learn about the types of updates for Windows Insiders. If you’re planning to be in San Francisco for Microsoft Ignite 2025, please stop by the Windows booth and say hi—I’ll even pose for selfies! In our November edition, we’ll provide a wrap-up of Microsoft Ignite 2025—and much more Windows news you can use. We’re looking to make this monthly summary more helpful to you! Please drop us a note below and let us know what information you most want to hear about. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
010
ConfigMgrDogs @configmgrdogs.bsky.social · 03/11/2025
Preparing commercial Windows 10 devices for ESUs: As support for Windows 10 officially ended on October 14, 2025, it is important that organizations with devices remaining on Windows 10 stay as protected as possible through the Windows 10 Extended Security Updates (ESU) program. To… #WindowsITPro
bit.ly
Preparing commercial Windows 10 devices for ESUs
As support for Windows 10 officially ended on October 14, 2025, it is important that organizations with devices remaining on Windows 10 stay as protected as possible through the Windows 10 Extended Security Updates (ESU) program. To help ensure your Windows 10 devices are activated with an ESU license, here is a quick guide on: * Where to find the Multiple Activation Key (MAK) included with your Windows 10 ESU purchase. * How to activate those licenses on your devices. * How to prepare Windows 10 physical endpoints utilized by users with an active Windows 365 subscription. For complete details on how to prepare your Windows 10 devices, see Enable Extended Security Updates. Activating a Windows 10 ESU license on a physical device Prerequisites for ESU activation To activate the Windows 10 ESU MAK on a device, ensure the following requirements are met: * Windows 10, version 22H2 with KB5066791, or a later update installed * Local administrative privileges required * Devices must be able to reach Microsoft activation endpoints: * https://go.microsoft.com * https://login.live.com * https://activation.sls.microsoft.com * http://crl.microsoft.com * https://validation.sls.microsoft.com * https://activation-v2.sls.microsoft.com * https://validation-v2.sls.microsoft.com * https://displaycatalog.mp.microsoft.com * https://licensing.mp.microsoft.com * https://purchase.mp.microsoft.com * https://displaycatalog.md.mp.microsoft.com * https://licensing.md.mp.microsoft.com * https://purchase.md.mp.microsoft.com Additional endpoints needed for Windows 10 devices accessing Windows 365 Cloud PCs: * https://dls.microsoft.com * https://login.windows.net Locating your Windows 10 ESU Multiple Activation Key Note: You must be assigned either the Product Key Reader or VL Administrator role in the Microsoft 365 Admin Center to view MAK keys.  More information can be found at Manage volume licensing user roles | Microsoft Learn. After ensuring that your account has the necessary admin role: * Sign in to the Microsoft 365 admin center at https://admin.microsoft.com. * Navigate to Billing > Your Products > Volume licensing. * Select View contracts and locate your ESU purchase. * Click View product keys to display all available MAK keys. If you cannot find your organization’s Windows 10 ESU MAK key, contact Microsoft volume licensing support. Activating the ESU license on each device You manage licensing and activation on devices using slmgr.vbs. To activate the ESU key on the client device, you have the following options: * Use a management tool such as Microsoft Intune or Microsoft Configuration Manager to run the script. * Use the Volume Activation Management Tool (VAMT) as a proxy activationserver. * Manually run a command line script on the device. * Activate ESU keys via telephone. For complete details on how to activate an ESU license your Windows 10 devices, see Enable Extended Security Updates. Verifying device licensing and ESU enrollment via MAK To verify that the ESU key is installed and activated, run the following command from an elevated Command Prompt: slmgr.vbs /dlv The output should show the Name of the corresponding ESU program and the License Status as “Licensed” for that program. Windows 365 and Windows 10 ESUs Cloud PCs running Windows 10, version 22H2 in Azure are automatically entitled to Windows 10 ESUs at no additional cost and do not require license activation. If your users connect to a Windows 365 Cloud PC from a physical Windows 10 endpoint, that endpoint may be entitled to ESUs at no additional cost. However, there are some requirements to enable the physical endpoint to receive ESUs: * Devices must be Microsoft Entra joined or Microsoft Entra hybrid joined. * Users with a Windows 365 subscription associated with their Microsoft Entra ID must sign in to the Windows 10 endpoint with their Microsoft Entra ID at least once every 22 days. * A policy or registry key must be enabled on each physical device to enable the verification of the Windows 365 subscription. Extended Security Updates for local devices accessing Windows 365 Windows 10 devices accessing Windows 365 Enterprise Cloud PCs and Windows 365 Frontline Cloud PCs in dedicated mode are automatically entitled to ESU for the duration of the ESU offer if the user has an active Windows 365 Enterprise license assigned or Windows 365 Frontline Cloud PC in dedicated mode provisioned, provided the following conditions are met: * The local Windows 10 device is either Microsoft Entra joined or Microsoft Entra hybrid joined. * Devices that are only Microsoft Entra registered or on-premises Active Directory joined aren't eligible for commercial ESU access with Windows 365. Windows Autopatch enrollment is not a requirement. * Personal or BYOD devices that are not managed by the organization and are only Microsoft Entra registered will not qualify for this entitlement. These devices should be enrolled via the Consumer ESU program. An eligible user can activate up to 10 devices. * Users must sign in to their physical Windows 10 device using the same Microsoft Entra ID account they use for Windows 365 Cloud PCs at least once every 22 days to maintain eligibility for ESU updates on that device. Note: IT administrators must use Microsoft Intune or another MDM provider to deploy a custom policy that enables the EnableESUSubscriptionCheck flag. This policy helps verify whether a device is enrolled in the Windows 10 ESU subscription program. For complete details on how to prepare your Windows 10 devices, see Enable Extended Security Updates. Verifying device licensing and ESU enrollment You can verify that Windows 10 ESU entitlements are assigned to your users’ Windows 10 Cloud PCs and their physical Windows 10 endpoints in these locations: * Windows 365 Enterprise - In the Microsoft 365 admin center, navigate to Billing > Licenses > Windows 365 Enterprise > Assign licenses. The box for "Windows 10 ESU Commercial" should be checked. * Physical Windows 10 endpoints - In the Registry Editor, navigate to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\ESU. There should be a DWORD value for EnableESUSubscriptionCheck. The data should be 1. Or, in the Event Viewer, look for Event ID 113 under Applications and Services Logs > Microsoft > Windows > ClipESU. Note: This event log is specific to the Windows 10 Cloud PC scenario and not MAK key scenarios in general. Azure Virtual Desktop and Windows 10 ESUs Windows 10 ESUs are available at no additional cost for Windows 10 virtual machines in the following Microsoft-hosted or Azure-integrated environments: * Azure Virtual Desktop * Azure virtual machines * Azure Dedicated Host * Azure Local (formerly Azure Stack HCI) * Azure Stack Hub * Azure Stack Edge No additional configuration or keys are needed for these environments. Other virtualization platforms that run on Microsoft Azure, (such as Nutanix, Citrix, or Omnissa Horizon on Azure VMware Solution) may require manual ESU key activation. Contact your Microsoft account team to obtain a 5x5 key. Activation can be managed with the VAMT or with a script. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 30/10/2025
Your guide to Windows at Microsoft Ignite 2025:   The Windows Platform is evolving—learn the latest Microsoft Ignite 2025 is coming to San Francisco, November 18-21, and we’re excited to share the latest details on everything new in Windows! Whether you’re attending in-person or… #WindowsITPro
bit.ly
Your guide to Windows at Microsoft Ignite 2025
  The Windows Platform is evolving—learn the latest Microsoft Ignite 2025 is coming to San Francisco, November 18-21, and we’re excited to share the latest details on everything new in Windows! Whether you’re attending in-person or digitally, we’ve got you covered.   We’ve talked about how we’re helping customers to build AI-enabled, cloud-powered IT platforms that are flexible, secure, and resilient, and this year we’re furthering that vision. At Ignite 2025, you’ll have the opportunity to dig deep into how Windows is becoming the platform for AI experiences that empower you to unlock new levels of productivity and innovation:  * Up your knowledge and skillsets in our in-depth technical breakouts * Gain practical takeaways from theater sessions and demos * Get immersive, hands-on experience in the labs * Swing by the EMU/HUB for live demos, games, and prizes as we celebrate 40 years of Windows — honoring the past and shaping the future!  If you’re joining us in person, Ignite is always a great moment to connect with your professional network of peers, partners and customers as well, so do not miss out—hope to see you there! Featured breakout session Agents at Work: Windows Powers the Era of Intelligent Productivity Tuesday November 18th, 2:30pm-3:15pm PST The future of work is here. See how Windows combines security, adaptability, cloud, and AI to empower organizations and people to create, decide, and grow. Breakout sessions (in person and online) Last year, thousands came together to learn, connect, and discover solutions—showcasing the future of Windows innovation and customer-driven breakthroughs. Don’t miss what’s next! Join these powerful breakout sessions to learn the latest about Windows AI innovation, cloud-powered productivity, enhanced security, seamless device recovery, and groundbreaking Windows 365 features. Agents at Work: Windows Powers the Era of Intelligent Productivity Tuesday November 18th, 2:30pm-3:15pm PST The future of work is here. See how Windows combines security, adaptability, cloud, and AI to empower organizations and people to create, decide, and grow. Unlock the full power of Windows 365 Tuesday November 18th, 1:00pm-1:45pm PST Join us to discover the power of the cloud with Windows 365. Learn how the latest platform improvements and core features deliver strong resiliency and seamless integration with new AI capabilities, exciting feature updates, and the rest of Microsoft ecosystem. Experience user-friendly enhancements designed to boost your productivity and satisfaction. Get practical insights and actionable strategies to help you unlock the full potential of Windows 365.  Unlock efficiencies with Windows 365 Frontline & Cloud PC devices Wednesday November 19th, 1:30pm-2:15pm PST Learn how the latest innovations in Windows 365 Frontline and Cloud PC devices such as Windows 365 Link can boost productivity, strengthen security, and improve end-user experience while helping you optimize IT investments. From manufacturing, to retail, to call centers, discover how new capabilities and offerings for Windows in the cloud including purpose-built devices can unlock efficiencies in shared spaces.  Resilient by design: How Windows has evolved with new recovery tools Thursday November20th, 1:00pm-1:45pm PST Explore advancements in Windows resiliency. Learn about joint efforts with security partners to develop security tools that operate outside the Windows kernel. Get to know new Windows recovery tools and features designed to restore devices efficiently after unforeseen PC incidents. Secure & Manage the Most Productive, Intelligent OS: Windows 11 Tuesday November18th, 5:00pm-5:45pm PST For 40 years, Windows has powered work. Now, Windows 11 redefines productivity and manageability - combining secure-by-design architecture, energy-efficient silicon, and seamless M365 and Copilot integration. As Windows evolves into an agentic OS, it enables smarter workflows with local AI, NPU-accelerated experiences, and new LOB app potential. Join us to explore the future of secure, AI-powered work. What’s new & what’s next in Azure Virtual Desktop Thursday November 20th, 9:45am-10:30am PST Azure Virtual Desktop continues to evolve, helping you enhance management efficiency, scalability, and connectivity for your workloads. Learn about the latest innovations in Azure Virtual Desktop, understand why it is especially attractive to industries like healthcare, and discover how to accelerate your cloud migration with Azure Virtual Desktop. The future of managing updates on Windows Wednesday November 19th, 4:00pm-4:45pm PST Discover best practices for managing updates on Windows. Learn how to enable hotpatch updates, the recommended way to keep devices secure with the latest updates. See how easy it is to use Windows Autopatch for update deployment, management, and (now) update readiness and reporting! We also cover what it means for Windows to be an agentic OS and how you can manage AI capabilities for Windows in your environment today. Theater sessions Check out the theater sessions taking place in the expo hall to quickly grasp complex technical concepts and see product functionalities in action.   Cloud PC devices: Get started with Windows 365 Link and see what's new Wednesday November19th, 4:00pm-4:30pm PST Cloud PC devices such as Windows 365 Link are simple, secure, purpose-built devices for Windows 365 that can help you improve end-user and IT efficiency in shared spaces. Join us to get an overview of the benefits of this solution, discover how to efficiently deploy and manage it using Microsoft Intune, and learn what’s new across end-user and IT experiences.  Get started with Windows 365 Frontline and Cloud Apps Tuesday November 18th, 5:15pm-5:45pm PST Discover how Windows 365, enhanced with Frontline in shared mode and Cloud Apps capability, delivers flexible, secure, and cost-effective solutions tailored for today’s dynamic workforce. Join us to see why Windows 365 is the smart choice to empower your organization’s evolving needs and streamline IT management. Hybrid AI: Unlocking Latency, Privacy & Cost Benefits with Copilot+ PC Tuesday November 18th 3:45pm-4:15pm PST The future of AI is hybrid - running inference on a PC and in the cloud. Discover applications and vertical use cases that leverage local AI through Windows AI Foundry while running on Copilot+ PC, for improved latency, data privacy, and cost. Copilot+ PCs & Microsoft 365: Secure, Smart, Efficient Windows Thursday November 20th, 9:00am-9:30am PST Discover how Copilot+ PCs and Microsoft 365 combine to deliver the most intelligent, secure, performant, and efficient Windows experience. Featuring AI-powered productivity, enhanced security with Microsoft Pluton, up to 22 hours of video playbook, 30% faster device management proactive diagnostics, and data protection in the AI era, ideal for IT leaders optimizing ROI. Future of managing Windows Thursday November 20th, 11:00am-11:30am PST We release new Windows features and enhancements year-round. Learn how to stay up-to-date on what’s coming next in security, productivity, and AI. Learn how to preview features on individual devices, virtual machines, or across your organization so you can deploy the latest features and updates faster and with confidence. We'll also explore how you can engage directly with the product teams with related programs like the Customer Connection Program. Windows in the Cloud: Resilience Meets Productivity Thursday November 20th, 4:00pm-4:30pm PST Disruptions happen—whether from device failures, cyberattacks, or unexpected outages—but downtime doesn’t have to. Join us to learn how Windows in the cloud delivers end-to-end resiliency, and discover how Windows 365 Reserve helps organizations rapidly recover, keep employees productive, and maintain business continuity—even in the face of disruptions. Labs Ignite labs are in high-demand, so please RSVP and arrive 5 minutes before the start time, at which point remaining spaces are open to those on standby.  Manage AI capabilities for Copilot+ PCs and Windows 11 Thursday November 18th, 4:30pm-5:45pm PST Get hands-on experience with enabling and managing AI experiences for Windows. Explore the customizations available to users and the controls available to IT admins. Learn how to use Microsoft Intune or Group Policy to fine-tune popular features like Recall, Copilot, Click to Do, and Image Creator. We’ll also walk through managing privacy and compliance, and end user readiness.  Windows 365 Reserve: Fast, Flexible, and Ready for Anything Tuesday November 18th, 1:00pm-2:15pm PST In this hands-on lab, learn how to deploy secure, on-demand Cloud PCs using Windows 365 Reserve—ideal for travel, recovery, and temporary access. You'll create provisioning profiles, assign Cloud PCs, and configure Conditional Access, Entra ID, and networking. Experience the full user journey from sign-in to productivity. Leave equipped to streamline endpoint readiness with minimal overhead and respond to unexpected needs. Windows 365 Frontline: Explore Dedicated, Shared, Cloud Apps Tuesday November 18th, 2:45pm-4:00pm PST Go from zero to hero in this hands-on lab exploring Windows 365 Frontline. Learn to create and configure Dedicated, Shared, and Cloud Apps environments. Understand when to use each model for shift workers, task-based roles, or app-only access. Walk through provisioning, Entra ID, Intune, and Conditional Access. Experience the user journey and leave ready to optimize for performance, cost, and compliance. Windows 365 AI Lab: Improved Windows Search & Click to Do in action Tuesday November 18th, 4:30pm-5:45pm PST Explore Windows 365 AI in this hands-on lab! Configure and experience features like Advanced Search and Click to Do on Cloud PCs. Learn prerequisites, enable AI-driven workflows, and boost productivity for IT admins and end users. Automate tasks with natural language and take smart, context-aware actions directly from your screen. Windows 365 Deployment Lab: Cloud Native, Zero Trust, Fully Ready Wednesday November 19th, 10:00am-11:15am PST Learn to deploy Windows 365 Cloud PCs using a secure, scalable model. In this hands-on lab, set up provisioning policies, integrate with Microsoft Entra, apply Zero Trust networking, and configure Conditional Access. Experience the full user journey and admin setup. Monitor and manage with ease. Leave with a blueprint to deploy, secure, and scale Cloud PCs efficiently. Online sessions On-demand sessions are 15-45 minutes in length prerecorded sessions that can be watched on demand. Recordings will be available beginning Tues Nov 18th starting at 10am.   Lighting up continuous innovation in Windows 11 On demand Continuous innovation means that we release new features and enhancements for Windows 11 year-round, when they are ready based on quality and reliability. Learn how to stay up-to-date on what’s coming next and set up deployments rings so that you can empower your users with the best experiences, sooner. Windows & Intune: Enabling the Sustainable Enterprise of the Future On demand Discover how Windows and Intune are enabling sustainable IT transformation. Learn how cloud-powered devices, intelligent management, and carbon-aware features help reduce emissions and improve efficiency. Backed by a recent WSP USA analyst report, this session offers data-driven insights and strategies to build a greener, smarter enterprise. In person, in San Francisco If you’re joining us in person at Microsoft Ignite 2025, make the most of your experience by planning ahead and engaging directly with the Windows team!   Don’t miss the chance to stop by our booth in the EMU/HUB, where you can celebrate 40 years of Windows with live demos, games, and exclusive anniversary swag. Take advantage of 1:1 consultations with Windows experts, connect with peers during networking events, and immerse yourself in the latest innovations designed to inspire and empower you throughout Ignite. See the below day by day schedule of all the Windows happenings.  Connect with peers and experts Connect directly with the people building the Windows platform in The Hub at the Expert Meetup area in the main exhibit hall. 1:1 consultations with engineering SMEs are also available. Log in to the Microsoft Ignite site to sign up! After Microsoft Ignite Tech Community Live: Windows edition After catching up on latest Windows platform capabilities, join us for four hours of Ask Microsoft Anything sessions December 2 at Tech Community Live! Save the date and get more details.   --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
031
ConfigMgrDogs @configmgrdogs.bsky.social · 30/10/2025
Windows App to replace Remote Desktop app for Windows: Editor's note 9.26.2025 – The date for blocking connections has moved. Now connections to Windows 365, Azure Virtual Desktop, and Microsoft Dev Box will be blocked when using the Remote Desktop app starting September 30, 2025.… #WindowsITPro
bit.ly
Windows App to replace Remote Desktop app for Windows
Editor's note 9.26.2025 – The date for blocking connections has moved. Now connections to Windows 365, Azure Virtual Desktop, and Microsoft Dev Box will be blocked when using the Remote Desktop app starting September 30, 2025. Connections to Remote Desktop Services and remote PC connections will remain unaffected. Editor's note 3.11.2025 – This blog applies only to the Windows App replacement of the Remote Desktop app downloaded from the Microsoft Store. It does not apply to the Remote Desktop client standalone installer (MSI), which can be downloaded from Download and install the Remote Desktop client for Windows (MSI). --- Starting May 27, 2025, the Remote Desktop app for Windows from the Microsoft Store will no longer be supported or available for download and installation. Users must transition to Windows App to ensure continued access to Windows 365, Azure Virtual Desktop, and Microsoft Dev Box. Windows App provides several improvements over the Remote Desktop app for Windows, including: * Unified access to multiple Windows services, including Cloud PCs and virtual desktops from a single, streamlined interface. * Customizable home screens, multimonitor support, and dynamic display resolutions. Enhanced remote work experiences with features such as device redirection, Microsoft Teams optimizations, and easy account switching. Connections to Windows 365, Azure Virtual Desktop, and Microsoft Dev Box via the Remote Desktop app from the Microsoft Store will be blocked after May 27, 2025. For all other users, the Remote Desktop app will no longer be supported. Prepare for the transition Windows 365, Azure Virtual Desktop, and Microsoft Dev Box users: * Get started: Review the get started guide for more information on each platform. * Download Windows App: Windows App can be downloaded from the Microsoft Store or directly from What's new in Windows App. Remote desktop users: Users connecting to remote desktops from the Remote Desktop app should use Remote Desktop Connection until support for this connection type is available in Windows App. Remote Desktop Services users: Users connecting to Remote Desktop Services from the Remote Desktop app should use RemoteApp and Desktop Connection until support for this connection type is available in Windows App. Known issues: To understand if there are current feature gaps that may create challenges for migrating to Windows App, review Known issues and limitations of Windows App. Be sure to check this list over time as the feature gaps will be resolved. Uninstall the Remote Desktop app: For uninstallation methods that align with how you manage your apps, visit our Uninstall your apps and Remove Apps documentation. IT administrators can help prepare their organizations by encouraging users of Remote Desktop app for Windows to start their transition to Windows App, and by updating internal resources such as user guidance, help desk documentation, and administrative materials, as needed. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 30/10/2025
When to use Windows 10 Extended Security Updates: 4.24.2025: Microsoft 365 Apps running on Windows 10 will continue to receive security updates for three years after Windows 10 end of support. Learn more at Windows 10 end of support and Microsoft 365 Apps. 2.14.2025: This post has… #WindowsITPro
bit.ly
When to use Windows 10 Extended Security Updates
4.24.2025: Microsoft 365 Apps running on Windows 10 will continue to receive security updates for three years after Windows 10 end of support. Learn more at Windows 10 end of support and Microsoft 365 Apps. 2.14.2025: This post has been updated to provide clarity and updated information related to the options available for activating ESUs: traditional ESU activation and ESU activation via Windows 365 and Azure Virtual Desktop. 10.31.2024: On November 1, we will begin offering the traditional 5-by-5 Extended Security Update offer through the Volume Licensing price list. The first ESU will be available in November 2025. We’ll share more details on availability of the cloud-based Extended Security Update offer on our price list in the future. 4.2.2024: The details and pricing structure outlined in this post apply to commercial organizations only. Details will be shared at a later date for consumers on our consumer end of support page. Educational organizations can find tailored information about Windows 10 end of support in the Microsoft Education Blog. --- Mark your calendars! By now, you've probably heard that Windows 10 will reach end of support on October 14, 2025 (except certain LTSC editions). If your organization must continue using Windows 10 for part of your device estate after support ends, you can enroll those PCs in the paid Extended Security Update (ESU) program. ESUs allow you to receive critical and/or important security updates for Windows 10 PCs when you need extra time to move to Windows 11. In December, we outlined a plan for Windows 10 end of support with Windows 11, Windows 365, and ESU to help you continue to move forward and keep all your devices protected. Today, let's review your options, including a special offer for those using cloud-based update management. Read on for details! Stay on a supported version of Windows Organizations that run legacy software are at a higher risk of security breaches and potential compliance violations. While Windows 10 PCs will continue to function after they reach end of support, they will no longer receive security updates, bug fixes, feature improvements, or security issue resolutions. Upgrading to Windows 11 or transitioning to a new Windows 11 PC will help you deliver the best, most secure computing experience to your employees—and help protect your organization. With Windows 10 end of support nearing, you have three options to stay on a supported version of Windows: * Upgrade existing eligible PCs that meet Windows 11 hardware requirements. Just use Windows Autopatch or Microsoft Intune! * Purchase new Windows 11 PCs. They offer powerful security features turned on by default, numerous accessibility, productivity, and AI enhancements, and are built for hybrid work. * Migrate to the cloud with Windows 365 or Azure Virtual Desktop. Make Windows 11 available to users on any device. Extended Security Updates are intended to help you make the transition Enrolling in the Windows 10 ESU program enables you to continue receiving monthly security updates for your Windows 10 devices. That way, you have more time to complete your move to Windows 11. Extended Security Updates are not intended to be a long-term solution but rather a temporary bridge. Extended Security Updates do not include new features, non-security fixes, or design change requests. The ESU program does not extend technical support for Windows 10. Technical support is limited to the activation of the ESU licenses, installation of ESU monthly updates, and addressing issues that may have been caused due to an update itself. You can purchase ESU licenses for Windows 10 devices that you don't plan to upgrade to Windows 11 starting in October 2024, one year before the end of support date. Note: The price of the ESU program will double every consecutive year, for a maximum of three years. If you decide to jump into the program in Year Two, you'll have to pay for Year One too, as ESUs are cumulative. Educational organizations can find tailored information about Windows 10 end of support in the Microsoft Education Blog. Two options for Windows 10 Extended Security Updates There are two options for ESUs for your Windows 10 estate: the traditional license using a 5-by-5 activation key or activation as part of your Windows 365 or Azure Virtual Desktop subscription. Traditional ESU activation With the 5-by-5 activation method, you'll download an activation key and apply it to individual Windows 10 devices that you've selected for your ESU program. Manage it via scripting or the Volume Activation Management Tool (VAMT), among other methods. You can use on-premises management tools such as Windows Server Update Services (WSUS) to download and apply the updates to your Windows 10 devices.  The 5-by-5 activation subscription will establish the Year One list price of ESU for Windows 10. This is the base license and will cost $61 USD per device for Year 1, similar to the Windows 7 ESU Year 1 price.[1] It is now available through Volume Licensing and will be available through Microsoft Cloud Solution Provider (CSP) partners beginning September 1. For those organizations using a Microsoft cloud-based update management solution (i.e., Microsoft Intune or Windows Autopatch), there is a special offer.[2]  You can manage and monitor the complete update process in Microsoft Intune or utilize Windows Autopatch to fully automate the update process for you. With Windows Autopatch, there is no required action on your part. Simply check the monthly update reports to understand the status of your environment. This license has a ~25% discount and will cost $45 USD per device for Year 1 and is available through Volume Licensing.[1] For information on how to activate Windows 10 ESU licenses, see Enable Extended Security Updates. ESU through Windows 365 and Azure Virtual Desktop Windows 10 Cloud PCs in Windows 365 and virtual machines in Azure Virtual Desktop are automatically entitled to ESUs at no additional charge.  Additionally, Windows 10 devices accessing Windows 11 Cloud PCs through Windows 365 will automatically be activated to receive security updates without any additional steps. Benefits of cloud-based Windows management Many organizations experience improvements for both employees and the IT organization by shifting Windows endpoint management to the cloud. For example, Westpac, Australia's first bank and oldest company, used Windows Autopatch to upgrade from Windows 10 to Windows 11 Enterprise. The industry-leading banking and financial services company supports more than 40,000 people across diverse locations. For their employees, Windows 11 Enterprise has delivered features that make it easy for them to stay organized and work securely from anywhere. "With Windows Autopatch, we cut deployment time from 90 minutes to 25. So if you apply that across our 40,000+ strong workforce, that's a lot of time saved." - Paul McKenna, Head of Workplace and Contact Centre Infrastructure, Westpac You can learn from others, such as Petrobras, and their Windows 11 migration journeys by visiting the Microsoft Customer Stories site. Simplifying the road to Windows 11 If you need support on your journey to cloud management, take advantage of Microsoft FastTrack or approved partners. FastTrack is a service that helps you move to the cloud faster and with more confidence. It offers free guidance and resources to help you identify and prioritize scenarios, as well as set business goals to measure success as you plan for rollout. It can also include guidance from Microsoft specialists, best practices, and tools. Get it all to help you migrate, deploy, and adopt Microsoft 365 solutions, including Windows 11, Windows 365 and Microsoft Intune. Questions about the solutions that can help? Tune in April 10th to a special edition of Windows in the Cloud on Windows 365, Windows Autopatch, and ESUs! --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X/Twitter. Looking for support? Visit Windows on Microsoft Q&A. --- [1] All prices are in US dollars. Regional prices will vary based on foreign exchange rates at the moment of ordering SKUs. [2] There will be special pricing for nonprofits.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 29/10/2025
Simplified Windows Update titles: Windows updates play a vital role in keeping devices secure, performant, and up to date. To further enrich the user experience, we're introducing a simplified and standardized titling system for a range of updates. This new format is designed… #WindowsITPro
bit.ly
Simplified Windows Update titles
Windows updates play a vital role in keeping devices secure, performant, and up to date. To further enrich the user experience, we're introducing a simplified and standardized titling system for a range of updates. This new format is designed primarily with the user in mind. Titles are more intuitive, consistent, and informative to help users quickly understand what updates they're receiving. Enhanced clarity and consistency across update titles The updated titles follow a clear and predictable structure across multiple update types. Each title now refers to the update by a more user-friendly name. It also includes just the most relevant identifiers, such as KB number and build or version. What we omit are the unnecessary technical details like platform architecture or date prefixes. Here are examples of what the updated titles look like: * Monthly or out-of-band security updates: Security Update (KB5034123) (26100.4747) * Monthly preview non-security updates: Preview Update (KB5062660) (26100.4770) * .NET Framework security updates: .NET Framework Security Update (KB5056579) * .NET Framework non-security updates: .NET Framework Preview Update (KB5056579) * Driver updates: Logitech Driver Update (123.331.1.0) * AI component updates: Phi Silica AI Component Update (KB5064650) (1.2507.793.0) Screenshot of the Windows Update page showing that the Preview Update has begun to download. Screenshot of the Update history page indicating the .NET Framework Preview Update has been installed. Scope and compatibility This title simplification applies to: * Windows OS quality updates (monthly security and non-security preview updates) * .NET Framework updates * Driver updates * AI component updates * Visual Studio updates New update names now appear in the following locations common to users: * Settings > Windows Update * Settings > Windows Update > Update history * Windows release health If you deploy updates through Microsoft Update Catalog or Windows Server Update Services (WSUS), most update titles remain unchanged[i] (e.g., 2025-10 Cumulative Update for Windows 11, version 25H2 for x64-based Systems (KB5066835) (26200.6899). Windows feature update titles also remain the same. Small changes that make big differences With this first large-scale improvement in update naming, we hope users at your organization can take advantage of several benefits: * Improved readability for users reviewing updates in Windows Settings or Update history. * Predictable formatting for original equipment manufacturers (OEMs) and partners integrating with servicing tools. The improved titles align with modern user interface (UI) expectations and accessibility standards, supporting security and productivity through reduced ambiguity. [i] Visual Studio update titles are now simplified across all channels as follows: Visual Studio 2022 Security Update (version). --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
022
ConfigMgrDogs @configmgrdogs.bsky.social · 27/10/2025
Windows 365: How to choose the best connection method for your team: Windows 365 delivers Cloud PCs, a complete and secure Windows experience hosted in the Microsoft Cloud that are accessible on any device. Employees, whether full-time, contractors, shift workers, or seasonal staff,… #WindowsITPro
bit.ly
Windows 365: How to choose the best connection method for your team
Windows 365 delivers Cloud PCs, a complete and secure Windows experience hosted in the Microsoft Cloud that are accessible on any device. Employees, whether full-time, contractors, shift workers, or seasonal staff, can access their personalized Windows apps, settings, desktop, and data from anywhere. This kind of flexibility is part of the beauty of Windows 365 — but with multiple connection options, you might wonder: Which one should I use? Don’t worry, we’ve got you covered. Whether you’re powering up secure shared workstations, re-purposing older devices, or working in a hybrid environment, there’s a way to access Windows 365 that fits your employees’ needs. Users don’t need any special expertise to get started; connecting to a Cloud PC is simple, secure, and delivers the same familiar, local Windows experience they already know and trust. Let’s take a closer look at each option: Windows 365 Link — Simple. Secure. Purpose-built. Ideal for: Desk-based or frontline workers in shared workspaces Experience: Purpose-built to securely connect to Windows 365 in seconds Windows 365 Link is the first Cloud PC device for Windows 365, securely connecting users to Windows in the cloud. This cloud-native solution is secure by design, simple to manage, and performant. Data, identity, and experiences are removed from the endpoint, and security features are on by default and cannot be turned off, significantly increasing its security posture. It’s managed with Microsoft Intune, and its small Windows-based OS minimizes IT admin decision points through a limited set of configuration policies, making management simple and familiar. Employees simply power it on, sign in, and are securely connected in seconds. Windows 365 Boot — Reuse hardware. Maximize flexibility. Connect seamlessly. Ideal for: Repurposed PCs of any form-factor, frontline workers, shared and dedicated devices Experience: Boot directly to your Cloud PC from any Windows 11 device With Windows 365 Boot, users can sign in and go straight to their Cloud PC with a familiar Windows 11 sign-in experience — skipping the local desktop entirely. It’s ideal for shared environments as well as dedicated workstations, where simplicity and a like-local feel are key. Windows 365 Boot is a great choice if you want to reuse existing Windows 11 hardware, deploy mobile laptops, or need maximum flexibility in how devices are configured and managed. Windows 365 Switch — Great at supporting bring-your-own-device (BYOD) programs Ideal for: BYOD, hybrid workers Experience: Seamlessly switch between your local desktop and Cloud PC Windows 365 Switch allows users to move effortlessly between their local Windows desktop and Cloud PC — just like switching apps. There’s no rebooting required, enabling a fast and fluid workflow. It is designed for hybrid users who want to keep their personal and work environment separate, while enabling quick access to both. Fast, familiar, and integrated through the Windows App, this will allow users to seamlessly move between different environments. The Windows App — Access from anywhere Ideal for: Anyone who needs cross-platform access to their Cloud PC Experience: Connect through the Windows App on Windows, macOS, web, or mobile The Windows App provides a single, consistent experience for employees to connect to their Cloud PCs from virtually any device. They can connect in windowed view or full screen mode with support for multiple monitors. Windows App also enables users to connect to other Windows virtualization services, such as Azure Virtual Desktop or Remote Desktop Services, and create PC-to-PC connections. Whether you’re using a Windows PC, Mac, tablet, or phone, you can securely access Windows remotely anytime, anywhere. Which experience is right for your users?   Your priority                                                                                                                Recommended   ___________________________________________________________________________________________________________________________ Deploy a secure and simple-to-manage Cloud PC device  Windows 365 Link  Reuse existing hardware, additional flexibility  Windows 365 Boot  Support hybrid or BYOD users  Windows 365 Switch  Access from anywhere, on any device via an app  Windows App  If you’re looking for strong security and simple, centralized management, Windows 365 Link is the recommended choice. For organizations that need more flexibility in their feature set, such as reusing existing hardware, Windows 365 Boot offers enhanced flexibility and a wider range of features. To explore these options in more detail, visit Compare Windows 365 connection methods on Windows. Windows 365 helps organizations empower every user, on any device, with a secure, high-performance Cloud PC. No matter how you connect, each option offers the same fast, reliable, and familiar Windows experience. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
010
ConfigMgrDogs @configmgrdogs.bsky.social · 24/10/2025
Policy-based removal of pre-installed Microsoft Store apps: Have you ever needed to remove pre-installed Microsoft Store apps? If so, you might have encountered scripts that break when apps change, making your job more time-consuming. Thanks to your feedback, starting this month, you… #WindowsITPro
bit.ly
Policy-based removal of pre-installed Microsoft Store apps
Have you ever needed to remove pre-installed Microsoft Store apps? If so, you might have encountered scripts that break when apps change, making your job more time-consuming. Thanks to your feedback, starting this month, you can remove select provisioned in-box apps using straightforward policy on Windows 11 Enterprise or Windows 11 Education, version 25H2. Custom imaging and complex scripts are no longer required. You’re now more in control of provisioned Microsoft Store apps than ever. Meet the new policy: Remove default Microsoft Store packages from the system. How the new app management policy works Here’s what you need to know about this new policy: * It lets you select from a defined list of preinstalled Microsoft Store apps and remove those apps from Windows 11 Enterprise and Education devices. * It works with Group Policy or your mobile device management (MDM) solution, including Microsoft Intune. * This policy is off by default, so you must explicitly enable it. * Once enabled, enforcement occurs automatically. A cleanup task deprovisions removed packages and local app data is removed from the user’s device. * The policy is applied to the user’s device during any of the following occasions: o   During the out-of-box experience (OOBE) o   When the user signs in after an operating system (OS) upgrade o   When the user signs in after an update to the policy * The policy can be used in conjunction with standard Windows provisioning methods, including Windows Autopilot. However, it’s not specific to or dependent on these methods. Why policy-based removal of apps matters By using a policy to remove preinstalled Microsoft Store apps, you can: * Reduce operational overhead. Drop fragile and manual removal scripts and automate operations. * Create a cleaner, work-ready experience. Provide a Windows experience tailored for your work environment. Policy availability and applicable apps The new policy is now available for devices running Windows 11 Enterprise, version 25H2 and Windows 11 Education, version 25H2. It currently supports removal of the following apps: * Calculator * Camera * Feedback Hub * Microsoft 365 Copilot * Microsoft Clipchamp * Microsoft Copilot (consumer version) * Microsoft News * Microsoft Photos * Microsoft Solitaire Collection * Microsoft Sticky Notes * Microsoft Teams * Microsoft To Do * MSN Weather * Notepad * Outlook for Windows * Paint * Quick Assist * Snipping Tool * Sound Recorder * Windows Media Player * Windows Terminal * Xbox Gaming App * Xbox Identity Provider * Xbox Speech to Text Overlay * Xbox TCUI The list will be updated as appropriate for future releases. Enable in-box app removal via policy This app management policy is available to you via Microsoft Intune settings catalog, configuration service provider (CSP), and Group Policy Object (GPO). To make use of it, you’ll need to enable it and tailor the list of preselected apps to your organization’s requirements. Avoid applying both an Intune and a GPO removal policy to the same device. Recommended: Configure devices with Microsoft Intune  You can use Microsoft Intune to configure devices with a settings catalog policy or a CSP policy. * In Microsoft Intune admin center, go to Devices > Manage devices > Configuration > Create > New policy to create a settings catalog policy. * Use the following settings: * Category: Administrative Templates\Windows Components\App Package Deployment * Setting name: Remove default Microsoft Store packages from the system * Value: Enabled * Set the toggle to True for each app to remove it. * Assign the policy to the desired group, or groups, of devices. Note: Intune won’t apply this policy to unsupported devices and will instead show a status of “Not applicable” for those devices. You can also configure devices with the RemoveDefaultMicrosoftStorePackages CSP policy. This ADMX-backed policy uses an XML payload to specify which apps to remove. o   Set the value of packages to be removed to True. For example, o   Set the value of packages to keep to False. For example, Use Group Policy To apply the policy to a single device, use the Local Group Policy Editor. For multiple devices joined to Active Directory, create or edit  a GPO and use the following settings: o   Group policy path: Computer Configuration\Administrative Templates\Windows Components\App Package Deployment o   Group policy setting: Remove Default Microsoft Store packages from the system o   Value: Enabled Select the apps to remove from the provided app list. One way to double-check that this policy is active is to check registry keys. The registry keys will have configured values under HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx\RemoveDefaultMicrosoftStorePackages. Customize app availability for your users today With this new app management policy, you can efficiently deploy changes to the default Microsoft Store apps available on your users’ devices. Empower your organization to be more productive by offering a more tailored user experience. Simplifying device configurations can also help strengthen your security posture and streamline daily operations. And, if you have been manually removing in-box apps because their versions are out of date, you no longer need to! We’ve solved that problem in the latest versions of Windows 11. Your built-in Microsoft Store apps now come updated out-of-the-box. Now is the perfect time to deploy Windows 11 Enterprise or Education, version 25H2, and take advantage of this new management capability.  --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
021
ConfigMgrDogs @configmgrdogs.bsky.social · 20/10/2025
How Windows 11 and AI are transforming the future of work: Imagine a workplace where technology doesn’t just support your goals—it anticipates them. AI is moving from the background to the center of the user experience in Windows, fundamentally changing how people interact with PCs.… #WindowsITPro
bit.ly
How Windows 11 and AI are transforming the future of work
Imagine a workplace where technology doesn’t just support your goals—it anticipates them. AI is moving from the background to the center of the user experience in Windows, fundamentally changing how people interact with PCs. These exciting new capabilities will also play a key role in business, specifically in how employees work, collaborate, and innovate. In a nutshell, Windows 11 is redefining the role of the PC in organizations across the world. While we don’t have new announcements today, this article builds on last week’s Windows 11 update and sets the stage for more information on how Windows is evolving to more effectively empower organizations to innovate, adapt, and thrive in a rapidly changing business landscape driven by AI. Our aim here is to guide you and get you energized for the news coming at Ignite. Windows leads the AI-native shift Windows is evolving into an AI-native platform: secure, scalable, and built for agentic work. With the latest AI features, organizations gain an enterprise-grade foundation where AI powered capabilities operate safely and effectively, unlocking new levels of productivity and business agility. Copilot+ PCs bring this foundation to life with breakthrough performance and native AI experiences, right on the device. Features like Click to Do, streamlined search, and integration of Copilot into Windows settings are designed for commercial reliability. They are either generally available or in Windows 11 Insider Preview Builds. And because these capabilities are built into Windows, you can deploy and manage them using the same trusted tools and controls you rely on today—helping to ensure security, compliance, and readiness at scale. Windows 365 extends this secure, AI-ready environment to the cloud, giving employees access to a Cloud PC – their personalized desktop, apps, settings, and configurations - on any device anywhere, while simplifying IT management for your organization. Windows 365 Cloud PCs are also 20% off for new customers, now through April 30, 2026; learn more here. New interaction models that fit the way you work A key part of last week’s announcements for Windows 11 focused on a new era of interaction for users—making technology more natural and accessible for every worker: * Copilot Voice: Just talk to your PC. Use voice commands to search, get help, and automate tasks, making daily work more intuitive and hands-free. * Copilot Vision: Your PC can see what you see. With Vision, users get real-time, contextual assistance, whether learning a new app, troubleshooting, or collaborating on creative projects. * Copilot Action: Take action - instantly. New features in Windows 11 (coming first to Windows Insiders in Copilot Labs) let Copilot agents perform tasks for users—like opening apps, changing settings, or starting workflows—based on context and intent. * Click to Do: Streamline workflows with a single click. Click to Do empowers you to act instantly, such as scheduling meetings or launching tasks, directly from their workspace. These interaction models open up exciting possibilities for consumers and businesses alike, offering seamless support for voice, touch, and traditional PC input methods to empower everyone. Look for additional details from Microsoft soon on how these innovative features will be made available to organizations around the world. The future of work is already here Windows 11 and AI are designed to make technology feel invisible, so employees can focus on what matters. From intuitive voice commands to contextual assistance, these innovations help your teams move faster, collaborate better, and unlock new levels of creativity. Furthermore, Windows sits at the center of the Microsoft ecosystem, connecting pilot and Microsoft Copilot Studio to enable intelligent workflows for users across the enterprise.1 This deep integration helps your organization reduce complexity, unlock cross-platform intelligence, and deliver seamless experiences across teams and tools. As millions upgrade to Windows 11 and CoPilot+ PCs, AI is becoming a daily reality.2 By embracing these tools now, your organization will be best positioned to amplify human potential, foster trust, and deliver experiences that delight—now and in the future. And this is just the beginning Stay tuned for Microsoft Ignite in November, where we’ll be unveiling even more commercial innovations designed to help organizations transform how they work, secure their data, and empower every employee. The next chapter of Windows and AI is on the horizon, and it’s built for business. The journey starts now, with technology that’s built for people, built for progress, and built for the future. Explore how Windows 11 and AI can transform your business today.   1Microsoft Annual Report 2025 2Business of Apps, Oct 7,2025 --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 14/10/2025
Windows 10 Extended Security Updates for Windows 365: Windows 10 reaches end of support on October 14, 2025. A great place to learn about all the Windows 10 Extended Security Updates (ESU) options is in our blog post, When to use Windows 10 Extended Security Updates. In this… #WindowsITPro
bit.ly
Windows 10 Extended Security Updates for Windows 365
Windows 10 reaches end of support on October 14, 2025. A great place to learn about all the Windows 10 Extended Security Updates (ESU) options is in our blog post, When to use Windows 10 Extended Security Updates. In this article, I will provide more detail on the Windows 10 lifecycle for Windows 365 across the following scenarios: * Existing Cloud PCs running Windows 10 * Creating new and reprovisioned Cloud PCs with Windows 10 * How to create a Windows 10 custom image with Extended Security Updates * ESUs for physical PCs that connect to Windows 365 * Microsoft 365 Apps support for Windows 10 * Windows 10 ESU support Existing Cloud PCs running Windows 10 On existing Cloud PCs running Windows 10 22H2 in Azure, ESUs are available at no additional cost—read about the Extended Security Updates (ESU) program for Windows 10 for more information. The ESU program enables PCs to continue to receive critical and important security updates. ESUs will be offered on Cloud PCs running 22H2 when Windows Update or Autopatch is run without requiring any admin action. Updates will be installed based on Windows Update configurations of each Cloud PC and are applied automatically after deployment. Creating new and reprovisioned Cloud PCs with Windows 10 Starting October 14, 2025 the Windows 10 gallery images have been removed and are no longer available to create new provisioning policies. If you still need to create Windows 10-based provisioning policies, please follow the process to create a custom image based on the Azure Marketplace Images that are available until April 14, 2026. Windows 365 provisioning policies that use Windows 10 22H2 gallery images (with or without Microsoft 365 Apps) will continue to work until April 14, 2026. After that date, these images will be retired and no longer available. For any provisioning policies that still reference these images, the image status will change to “out of support” and new provisioning attempts will fail. To learn more, please read Lifecycle policies and end of support for Cloud PC operating systems. The final monthly update to the Windows 365 Windows 10 gallery images will be the Windows 10 October 2025 update. Between October 2025 and April 2026, Cloud PCs created will need to install ESUs to be current. Microsoft recommends switching to Windows 11 for a more secure Windows experience. A Windows 10 22H2 image that contains the October 2025 update will remain published in the Azure Marketplace. This is the same version as published in Volume Licensing and Visual Studio downloads. It does not contain any Windows 365 or Microsoft 365 app customizations. How to create a Windows 10 custom image with Extended Security Updates After April 2026, customers that want to create a Windows 10 image will need to create a custom image and import it into Windows 365. Here’s how: * Create an Azure Virtual Machine using Windows 10 22H2 from Azure Marketplace. *  Note: the last Windows 10 image available is October 2025. * Perform a Windows Update to ensure the latest ESUs are installed. Multiple reboots may be required. * Review support details before installing Microsoft 365 apps. * Follow all instructions for creating and importing custom images into Windows 365. ESUs for physical PCs that connect to Windows 365 If users are connecting to Cloud PCs from Windows 10 physical PCs that are Intune-managed, each physical PC is automatically entitled to receive Windows 10 ESUs. This benefit’s purpose is to extend the life of Windows 10 PCs that do not meet Windows 11 hardware requirements. Note: Physical devices connecting to Windows 365 Frontline Shared and Windows 365 Reserve Cloud PCs are not eligible for free ESUs. Learn more about enabling Extended Security Updates (ESU). Microsoft 365 Apps support for Windows 10 Visit Windows 10 end of support and Microsoft 365 Apps to learn more. Windows 10 ESU support We will determine if the issue pertains to Windows 365 or with Windows 10. If the issue is determined to be with Windows 365, we will support as expected and work towards a resolution to your reported issue. If the issue is determined to pertain to the operating system, we will request/require an attempt to reproduce the same issue on a currently supported version of Windows 11. If that issue is able to reproduce on Windows 11, we will work that issue as it is supported. Once resolved, and if applicable, we can attempt to apply that same solution to the originally reported Windows 10 system. If the Windows 11 solution does not resolve the issue on Windows 10, we would recommend upgrading to Windows 11 as Windows 10 is no longer supported. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 13/10/2025
Hotpatch efficiency unlocked: Smaller update size: Did you know that hotpatch updates are significantly smaller than standard Windows updates? Rather than the larger cumulative packages that take more time to install on devices, hotpatch updates bring faster security and improved… #WindowsITPro
bit.ly
Hotpatch efficiency unlocked: Smaller update size
Did you know that hotpatch updates are significantly smaller than standard Windows updates? Rather than the larger cumulative packages that take more time to install on devices, hotpatch updates bring faster security and improved productivity. Their smaller size translates to optimized network performance, faster installation, and quicker compliance, among other benefits. Smaller updates, same security, smarter delivery Hotpatch enables devices to receive critical security updates without restarting. Instead of downloading the full monthly update, hotpatch delivers only the in-memory code changes needed to address security vulnerabilities. For several releases, the hotpatch package has been reported to be more than 10 times smaller than the standard cumulative update. Importantly, these significantly smaller packages still maintain the same level of security and compliance. Benefits of smaller updates for your organization Hotpatch updates don’t just save time. They drive business continuity by ensuring that users remain secure and productive, without disruption. By reducing update sizes, hotpatch unlocks new levels of efficiency: * Optimized network performance: Reduced download sizes result in lower bandwidth consumption, easing the load on corporate networks. Fewer megabytes travel across your network to allow large fleets to update smoothly without spikes in WAN usage. * Sustainability benefits: Smaller updates reduce energy consumption tied to downloading updates, reducing the carbon footprint significantly. * Faster security compliance: Smaller updates are faster to install and therefore help you achieve security compliance more quickly. These efficiency boosters add to the general benefit that hotpatching installs in the background with no interruption or restarts for increased user and IT productivity. Why is the hotpatch size smaller than standard cumulative update? Standard Windows cumulative updates are designed to be comprehensive. Each package contains not only the latest security fixes but also quality and feature updates, along with security and feature updates from previous releases. This way, any device can get fully up to date from a single package. But this also makes the update larger in size. Hotpatch takes a leaner approach: * Security-only updates: Hotpatch focuses exclusively on delivering security fixes, rather than combining them with quality and feature updates. This narrower scope significantly reduces package size. * Incremental model: Whereas standard updates carry forward all the past fixes and features, hotpatch updates build only on top of the most recent quarterly baseline update. Each hotpatch package contains only the incremental security changes for the specific months, within the current quarter. Note: If a device has been disconnected for a long time, expect its next update to be larger. First, it will receive the latest baseline, which would be the standard cumulative update, followed by the hotpatch update. What your hotpatching calendar looks like * Baseline update: Delivered on the first month of each quarter (January, April, July, and October). This is the same composition and size as the standard cumulative update. This update is released on the second Tuesday of the month. * Hotpatch updates: Delivered on the two months following the baseline update. Devices receive only incremental, security patches that are installed without a restart. These updates also get released on the second Tuesday of the month.  Find the detailed hotpatch release cycle here. Looking ahead With reduced patch sizes and fewer restarts, you can join thousands of enterprise customers in achieving your security compliance faster and focusing more on innovation. Hotpatch is part of the Microsoft commitment to simplify and modernize update management. Discover related resources to start with hotpatching today: * Check if your organization is ready for hotpatch updates. * Has your question already been asked? See Hotpatch for client: Frequently asked questions. * Learn about Windows Autopatch required to create and deploy hotpatch updates. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 08/10/2025
Skilling snack: AI for Windows developers: Are you a new Windows developer or looking to skill up on the latest in AI? This skilling snack is for you! Start at the top to learn about Windows Machine Learning (ML)—now generally available—or skip down to the resources that meet your… #WindowsITPro
bit.ly
Skilling snack: AI for Windows developers
Are you a new Windows developer or looking to skill up on the latest in AI? This skilling snack is for you! Start at the top to learn about Windows Machine Learning (ML)—now generally available—or skip down to the resources that meet your current needs. Time to learn: 73 mins Get started with Windows Machine Learning (ML) * Windows ML is generally available: Empowering developers to scale local AI across Windows devices (10 mins): Ready to scale local AI across Windows devices? Learn how to build AI experiences that are more responsive, private, and cost-effective. Watch this one-minute video teaser for a quick introduction. * Introducing Windows ML: The future of machine learning development on Windows (10 mins): Preview Windows ML to create AI-infused applications with ease. It’s a cutting-edge runtime optimized for performant on-device model inference and simplified deployment with the foundation of Windows AI Foundry. * What is Windows ML (4 mins): Visit our technical documentation to learn more about how Windows ML works and what you’ll need to start using it. Get introduced to execution providers (EPs) and learn about automatic EP management for different hardware (CPUs, GPUs, and NPUs). * Get started with Windows ML (3 mins): Review your device and language-specific prerequisites before using Windows ML. Follow steps to install or update the Windows App SDK depending on whether you use C#, C++, or Python. Then download and register EPs. The latest from Microsoft Build * An IT pro’s guide to Windows at Microsoft Build 2025 (5 mins): Get a summary and links to on-demand sessions on developing with and for Windows. * Advancing Windows for AI development: New platform capabilities and tools introduced at Build 2025 (23 mins): See how Windows is becoming a better dev box for AI development. Find out about Windows AI Foundry, Windows ML, AI APIs, Model Context Protocol (MCP), improvements to Windows Developer tools, security, and more. Watch this one-minute video teaser! Additional resources for AI development in Windows * Copilot+ PCs developer guide (11 mins): This updated guidance for developers now includes Windows ML! Find out about device prerequisites, considerations for different silicon chips, unique AI features, and other helpful tips. * Windows AI Foundry (time varies): Bookmark this gateway to all things Windows AI Foundry as a unified, reliable, and secure platform. It supports the AI developer lifecycle from model selection, fine-tuning, optimizing, and deployment across CPU, GPU, NPU, and cloud. * Securing the Model Context Protocol: Building a safer agentic future on Windows (7 mins): Learn about MCP as a foundational layer of secure, interoperable agentic computing, currently in preview. Review the requirements, possibilities, and security controls that MCP covers for hosts, clients, and servers. What are you most excited about building next? Have you tried Windows ML yet? Leave us a comment below and share these resources with your peers! The Windows skilling snacks library has more on Windows and AI, as well as other topics of interest. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
010
ConfigMgrDogs @configmgrdogs.bsky.social · 01/10/2025
Windows news you can use: September 2025: Building upon the big milestones in Windows we announced in August, yesterday we announced the availability of Windows 11, version 25H2! Be sure to check out our IT pro’s guide to Windows 11, version 25H2 and how Wi-Fi 7 is a game changer for… #WindowsITPro
bit.ly
Windows news you can use: September 2025
Building upon the big milestones in Windows we announced in August, yesterday we announced the availability of Windows 11, version 25H2! Be sure to check out our IT pro’s guide to Windows 11, version 25H2 and how Wi-Fi 7 is a game changer for enterprises. These blogs cover the Windows 11, version 25H2 release in depth—truly news you can use! My colleagues in Windows 365 also had a wealth of new features and capabilities announced throughout the month of September—you can read more about those below. And if you have a Copilot+ PC, be sure to check out our new AI agent in Settings—it allows you to search for settings using natural language queries. Give it a try and see for yourself! Without further ado, here’s the news for September 2025. New in Windows update and device management * [W11 25H2] Windows 11, version 25H2 reached general availability yesterday, September 30, 2025. In an IT pro’s guide to Windows 11, version 25H2, you can discover tools and resources to help you roll out version 25H2 at your organization. o   Read about how to get the newest version of Windows 11 and watch this video. o   Find release information and updates on known issues on the Windows release health hub. o   Wi-Fi 7 support for enterprise access points is now generally available in Windows 11, version 24H2 and version 25H2. Discover how your organization can benefit from better speed, high throughput, improved reliability, and enhanced security. * [INTUNE] There’s a change coming on December 2, 2025, to Microsoft Intune network service endpoints. If your organization uses outbound traffic policies based on IP addresses or service tags, be sure to review and update your firewall rules before December 2, 2025 to avoid service disruptions. Learn more about what you need to do to prepare. * [INTUNE] Have questions about simplifying endpoint management, unifying data across Microsoft solutions, and how to stay ahead of the curve in device and app security? Don’t miss this Tech Community Live—Microsoft Intune edition on October 6, 2025. Engineering and product team members will be on hand to answer your questions. Save the date and post your questions in advance. * [OFFICE HOURS] Join our continuing series of live Q&A for IT professionals. Product experts, servicing experts, and engineers will be on hand to answer your questions. RSVP for the next Windows Office Hours on October 16, 2025. New in Windows security * [PURVIEW] Discover the advantages of Microsoft Purview to help reduce data breaches across your organizations. Learn about key areas of impact and the steps you can take to modernize data security and governance strategies. Looking for ways to stay current with regulations, certifications, and reporting? Consider using Microsoft Purview Compliance Manager. For more information, dive into the insights offered in the Total Economic Impact™ (TEI) of Microsoft Purview study by Forrester Consulting. * [DEFENDER] Ready to consolidate fragmented security capabilities at your organization? Learn more about using the integrated tools and AI-powered insights in Microsoft Defender. It can help strengthen your organization’s security posture and build resiliency across hybrid and multicloud environments while benefiting from significant return on investment. * [SECURE BOOT] Take action now to prepare for the expiration of Secure Boot certificates in June 2026. Learn which new certificates will be available in the coming months to maintain UEFI Secure Boot continuity. Learn more from frequently asked questions about the Secure Boot update process. New in AI * [M365 COPILOT] Beginning in October, the Microsoft 365 Copilot app will automatically be installed on Windows client devices with Microsoft 365 desktop apps. The app simplifies access to Copilot and engagement with productivity features. Review the documentation to manage this change at your organization. * [WINDOWS ML] Big news for developers: With Windows ML, now generally available, developers can deliver real-time, secure AI workloads to Windows devices. Discover how to use Windows ML to deploy production experiences. * [AI IN WINDOWS] Catch up on using AI for Windows management and how to get started using Microsoft Copilot Chat. Parts 2 and 3 of our Skilling snack series on AI in Windows offer more resources to help you use AI for management and improved work experiences. Stay tuned for more snacks—coming soon. Install the September 2025 non-security update for Windows 11, version 24H2 to get this and other capabilities, which are rolling out gradually. * [FILE EXPLORER] Use AI actions in File Explorer to edit images or summarize documents. Right click (or press Shift+F10) on the file and select AI actions. (Note: This experience is not yet available for customers in the EEA.) * [MICROSOFT 365] AI actions in Microsoft 365 make it easier to work with your documents. Use Summarize action in Copilot to quickly generate summaries of files stored in OneDrive and SharePoint, eliminating the need to open each one. (Note: Requires an active Microsoft 365 subscription and a Copilot license. Microsoft account and Microsoft Entra ID supported.) * [COPILOT+ PC] Learn about new capabilities for Copilot+ PCs in this update. New in Windows Server For the latest features and improvements for Windows Server, see the Windows Server 2025 release notes and Windows Server, version 23H2 release notes. * [WINDOWS SERVER 2025] Learn how to prepare for and use N-4 media-based upgrades to move your organization’s physical devices and virtual machines directly to Windows Server 2025 from earlier versions of Windows Server. New in productivity and collaboration [W365] Four years after Windows 365 first came to market, it continues to transform the approach to AI-driven cloud computing. This month saw expanded availability of key features and capabilities and a host of new ones. Read about these capabilities and how they can help you address key priorities at your organization such as flexibility, security and resilience, and AI-enabled endpoint management. Here are just a few highlights: * [CLOUD APPS] Windows 365 Cloud apps are now in public preview. Learn about this new way to securely stream Windows apps to any device. * [FRONTLINE] Do you help support IT at U.S. government agencies? Windows 365 Frontline is now available for Government Community Cloud (GCC) and GCC High (GCCH). It provides frontline workers with secure, compliant access to Cloud PCs from any device. Learn more about the editions that will best meet your organization’s needs. * [HEALTH CHECK] Use the health check suite for proactive troubleshooting that helps ensure optimal performance across Windows 365 and Azure Virtual Desktop environments. [UPDATES] Review the September 2025 security update for Windows 11, version 24H2 and version 23H2. For additional details, please refer to the August 2025 non-security preview update release notes for Windows 11, version 24H2 and version 23H2. To preview what’s coming in October 2025, install the September 2025 optional non-security preview update for Windows 11, version 24H2, which includes the gradual rollout of: * [NARRATOR] Narrator now includes Braille Viewer, which shows on-screen text and its Braille equivalent on a refreshable Braille display. To open Braille viewer and start Narrator, press the Windows logo key+Ctrl+Enter, press Narrator key+Alt+B. Also new in Narrator: A smoother, more natural experience in Word, with improved voice feedback, reliable continuous reading, and better navigation for footnotes, comments, lists, and tables. * [TASKBAR] IT administrators no longer need to restart explorer.exe to apply the pinning policy. After applying the policy, pins should appear on the taskbar within approximately 8 hours. * [DESKTOP] You can now move the hardware indicators for brightness, volume, airplane mode, and virtual desktops to different positions on your screen. * [PASSKEYS] There is now seamless plugin passkey manager integration in Windows 11. To use plugin credential manager for passkeys, install a credential manager application that supports integration then go to Settings > Accounts > Passkeys > Advanced options. * [SETTINGS] More settings have moved from Control Panel to Settings. You can now add additional clocks, change your time server, and customize date and time formatting directly from Settings > Time & language > Date & time. Keyboard character repeat and cursor blink rate settings are now easier to find under Settings > Accessibility. Lifecycle milestones Check out our lifecycle documentation for the latest updates on Deprecated features in the Windows client and Features removed or no longer developed starting with Windows Server 2025. * [WMIC] The Windows Management Instrumentation Command-line (WMIC) tool is moving toward the next phase for removal from Windows. It will be removed when updating to Windows 11, version 25H2. Note: Only the WMIC tool is being removed – Windows Management Instrumentation (WMI) itself remains part of Windows. To prepare for a smooth transition, learn about using PowerShell or other tools for tasks previously completed with the WMIC tool. * [W10 EOS] Windows 10 end of support (EOS) is now less than two weeks away. The October 2025 monthly security update will be the last update available for this version. Consult helpful resources in this 60-day reminder message. * [W10 EOS] [IOT] Find out which versions of Windows 10 IoT Enterprise are impacted on October 14, 2025. * [W11 22H2] Windows 11, version 22H2 (Enterprise and Education editions) no longer receives non-security preview updates. Monthly security updates will continue through October 14, 2025, when version 22H2 officially reaches end of servicing. Consult helpful resources in this 60-day reminder message. * [W11 23H2] Windows 11, version 23H2 (Home and Pro editions) will reach end of servicing on November 11, 2025. Enterprise and Education editions will continue to be serviced through November 10, 2026 per the Modern Lifecycle Policy. Additional resources Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources: * Windows Roadmap for new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name * Microsoft 365 Copilot release notes for latest features and improvements * Windows Insider Blog for what’s available in the Canary, Dev, Beta, or Release Preview Channels * Windows Server Insider for feature preview opportunities * Understanding update history for Windows Insider preview features, fixes, and changes to learn about the types of updates for Windows Insiders September was another great month of new features and capabilities! Thank you for staying up on the latest news you can use. We’re looking to make this monthly summary more helpful to you! Please drop us a note below and let us know what information you most want to hear about. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
010
ConfigMgrDogs @configmgrdogs.bsky.social · 30/09/2025
An IT pro’s guide to Windows 11, version 25H2: Windows 11, version 25H2 is now available through Windows Autopatch and the Microsoft 365 admin center.i It is also available for download from the Microsoft Software Download Service and Visual Studio Subscriptions. Windows 11, version… #WindowsITPro
bit.ly
An IT pro’s guide to Windows 11, version 25H2
Windows 11, version 25H2 is now available through Windows Autopatch and the Microsoft 365 admin center.i It is also available for download from the Microsoft Software Download Service and Visual Studio Subscriptions. Windows 11, version 25H2 will become available via Windows Server Update Services (WSUS) on October 14, 2025, with the October security update. Here is your guide to tools and resources to support your rollout of this update, plus some additional helpful information. In this release Windows 11, version 25H2 includes the same new features and enhancements delivered through our Windows 11 continuous innovation efforts. Some features that were behind temporary commercial control in Windows 11, version 24H2 are now enabled by default in version 25H2. These include: * AI actions in File Explorer * Click to Do (Copilot+ PC feature) * Agent in Settings (Copilot+ PC feature) The latest advances in update innovation also carry over with capabilities like quick machine recovery and hotpatching for Windows client available on version 25H2. Version 25H2 includes Wi-Fi 7 for enterprise connectivity. It’s designed to address evolving security needs while helping support reliable connectivity in high-density, high-throughput scenarios. You can start deploying Wi-Fi 7 enterprise-grade access points to eligible devices to take advantage of the same benefits already available to consumer devices. You also have the ability to remove select preinstalled Microsoft Store apps using policies on Windows 11 Enterprise and Windows 11 Education, version 25H2. By avoiding custom imaging and complex scripts, you’ll reduce operational overhead and create a cleaner, work-ready experience. This new capability is available via mobile device management (MDM) tools and Group Policy today, and it lights up in the Microsoft Intune Settings Catalog tomorrow! Deploying Windows 11, version 25H2 Windows 11, versions 24H2 and 25H2 use a shared servicing branch. That means that version 25H2 will be delivered as an enablement package, offering a fast, easy installation process like monthly Windows updates. If you’re not familiar with enablement packages, the features in Windows 11, version 25H2 were included in the latest monthly update for version 24H2. However, they were in an inactive and dormant state. An enablement package works like a small switch that activates the features in version 25H2, so the update from Windows 11, version 24H2 to version 25H2 takes place in roughly the same time as typical monthly Windows updates. As with all feature updates, you can use Windows Autopatch in Intune, or your preferred endpoint management solution, to roll out the update across your organization. We recommend that commercial organizations begin targeted deployments to validate that their apps, devices, and infrastructure work as expected with this new release. Tools and resources The deployment, security, and management tools you rely on have been refreshed for this update. * Windows 11, version 25H2 Security Baseline * Administrative templates (ADMX) for Windows 11, version 25H2 * Group Policy Settings Reference spreadsheet for Windows 11, version 25H2 * Windows 11 Enterprise Evaluationii We’ve also updated the Windows release health hub with release information for Windows 11, version 25H2 as well as the pages for sharing information on known issues. The Windows 11, version 25H2 update history page—where you’ll find release notes for monthly and out-of-band updates—will be available with the first monthly update for version 25H2 on October 14, 2025. Bookmark https://aka.ms/Windows11/25H2/UpdateHistory now for easy access to release notes. Lifecycle information for Windows 11, version 25H2 Today, September 30, 2025, marks the start of 36 months of servicing support for Enterprise and Education editions of Windows 11, version 25H2. Home and Pro editions receive 24 months of support. For more information, see the Windows 11 Lifecycle FAQ. Where can I get help with deploying Windows 11 feature updates? If you want to lower the cost of managing updates for your IT team, benefit from built-in protections such as feature update safeguards, and get Windows security updates faster without a restart, get started with Windows Autopatch. Windows Autopatch is included with Windows Enterprise E3 (or higher), Windows A3 (or higher), F3, and Microsoft 365 Business Premium, and can help you easily deliver both feature and quality updates for Windows, as well as driver updates. If you need additional help, tips, or best practices, join Windows Office Hours every third Thursday on the Windows Tech Community! We assemble experts from the Windows, Microsoft Intune, and Windows 365 product teams, as well as adoption and security specialists, to answer your questions in chat. Submit questions during the live one-hour event or post them in advance if that time doesn’t work for you. Our next event is Thursday, October 16, 2025. It's also a good idea to follow the Windows IT Pro Blog—and follow us on LinkedIn or @MSWindowsITPro on X—to keep up with the latest Windows announcements and new feature releases! Finally, if you’re interested in exploring new features in Windows 11 prior to release, join the Windows Insider Program. Access preview builds of Windows 11, provide feedback directly to Microsoft, and assess how your apps, hardware, and processes perform in early environments. Want to work directly with the Windows engineering teams to develop solutions that better meet your needs? Join the Customer Connection Program. iDownloads in the Microsoft 365 admin center and similar channels may be delayed. iiThe Arm64 Enterprise Evaluation will be released at a later date. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 29/09/2025
Introducing Wi-Fi 7 for enterprise connectivity: We’re excited to announce the general availability of Wi-Fi 7 support for enterprise access points. Starting with the September 2025 Windows preview non-security update, a significant leap forward in wireless networking reaches Windows… #WindowsITPro
bit.ly
Introducing Wi-Fi 7 for enterprise connectivity
We’re excited to announce the general availability of Wi-Fi 7 support for enterprise access points. Starting with the September 2025 Windows preview non-security update, a significant leap forward in wireless networking reaches Windows 11, version 24H2 and later. Windows 11 has already supported Wi-Fi 7 for consumer access points since 2024. Now, your organization can also benefit from better speed, high throughput, improved reliability, and enhanced security for modern enterprise environments that support Wi-Fi 7 enterprise access points. Wi-Fi settings show a Windows device connected to a Wi-Fi 7 enterprise access point. What makes Wi-Fi 7 a game-changer for enterprises The performance enhancements introduced by Wi-Fi 7 in the consumer space are now being extended to enterprise environments. Wi-Fi 7 for enterprise is designed to address evolving security needs while helping support reliable connectivity in high-density, high-throughput scenarios. Here’s what helps make Wi-Fi 7 a game-changer for enterprises: * Required WPA3-Enterprise authentication * Seamless roaming and enterprise-specific enhancements * Performance benefits Required WPA3-Enterprise authentication Security is a shared responsibility. Through collaboration across hardware and software ecosystems, we can build more resilient systems secure by design and by default, from Windows to the cloud, enabling trust at every layer of the digital experience. Wi-Fi 7 for enterprise helps ensure that all devices connecting to your enterprise networks benefit from stronger encryption protocols, resistance to brute-force attacks, and enhanced protection for sensitive data in transit. By enforcing WPA3-Enterprise, Wi-Fi 7 helps eliminate legacy vulnerabilities and sets a new baseline for secure, high-performance connectivity in modern enterprise environments. Learn how to Import Wi-Fi settings for Windows devices in Microsoft Intune. You can find more details on how to stay more secure with Windows through our updated Windows Security book. Seamless roaming and enterprise-specific enhancements Enterprise Wi-Fi networks are not just about peak speed. They must also help deliver easier connectivity as users move around a campus or building. Wi-Fi 7 enterprise includes advanced roaming capabilities to help ensure that laptops, tablets, and other devices can more easily transition among access points. These enhancements include Opportunistic Key Caching (OKC) on AKM 5 and 802.11r Fast Transition (FT) on AKM 3.i Performance benefits Wi-Fi 7 enterprise supports the multiple benefits inherited from the consumer version and aligned to the Institute of Electrical and Electronics Engineers (IEEE) standards: * Multi-link operation (MLO) allows devices to use multiple bands (2.4 GHz, 5 GHz, or 6 GHz) concurrently to avoid network congestion and maintain connectivity. * 320 MHz ultra-wide bandwidth in 6 GHz doubles the speed to your devices and enables new possibilities for high bandwidth and low latency applications—and scenarios using applications such as augmented reality (AR)/virtual reality (VR). * 4096-QAM modulation helps increase the data transmission by 20% and improve the quality of video streaming, video conferencing, and more. Unlock the advantages of Wi-Fi 7 for your organization Wi-Fi 7 for enterprise connectivity on Windows is the result of deep collaboration across the ecosystem. Wi-Fi silicon vendors and Wi-Fi enterprise access point manufacturers together help ensure that Wi-Fi 7 is ready for real-world enterprise deployments. To begin taking advantage of Wi-Fi 7 in your organization, review the following prerequisites: * Wi-Fi 7-capable Windows release: Devices must be on Windows 11, version 24H2, updated with the September 2025 preview non-security update or later. * Wi-Fi 7-capable Windows enterprise laptops: Devices must be equipped with Wi-Fi 7-capable chipsets. * Certified Windows Wi-Fi 7 driver support: Update enterprise Wi-Fi drivers and validate them for Wi-Fi 7 enterprise functionality in Windows. Wi-Fi 7 drivers will be available soon through your device original equipment manufacturer (OEM) or independent hardware vendor (IHV). For specific release dates, please contact your OEM/Wi-Fi chip manufacturer directly. * Wi-Fi 7 Enterprise access points: Deploy Wi-Fi 7 enterprise grade access points in your organization. With these components in place, you’re ready to enable next-generation wireless connectivity across your enterprise environments. So, begin delivering enhanced performance, security, and connectivity for users and workloads today. Learn more: * Faster and more secure Wi-Fi in Windows * What Is Wi-Fi 7? | Microsoft Surface * Wi-Fi Alliance® introduces Wi-Fi CERTIFIED 7™ | Wi-Fi Alliance --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A. iSee the latest wireless networking standard from the Institute of Electrical and Electronics Engineers (IEEE), Current Status and Directions of IEEE 802.11be, the Future Wi-Fi 7
000
ConfigMgrDogs @configmgrdogs.bsky.social · 18/09/2025
Skilling snack: Get started with Microsoft 365 Copilot Chat: Are you up to date on Microsoft 365 Copilot Chat? Have you tried AI agents with it yet? The articles, downloads, and videos offered in this collection will help you brush up on different ways to access and manage these AI… #WindowsITPro
bit.ly
Skilling snack: Get started with Microsoft 365 Copilot Chat
Are you up to date on Microsoft 365 Copilot Chat? Have you tried AI agents with it yet? The articles, downloads, and videos offered in this collection will help you brush up on different ways to access and manage these AI innovations. Don’t miss these helpful resources to set yourself and others up for success! Time to learn: 85 mins Access Microsoft 365 Copilot Chat * Start using Microsoft 365 Copilot Chat (3 mins): Get started with Copilot Chat to improve your work experience. Get an overview of its functions, the user interface, and basic access and management tips. Choose where to start: o   Access Microsoft 365 Copilot Chat on the web. o   Download the Microsoft 365 Copilot app from the Microsoft Store. Manage Microsoft 365 Copilot Chat * Updated Windows and Microsoft 365 Copilot Chat experience (13 mins): Read about managing the Copilot experience on Windows client devices. From enhanced data protection to device identity to policies and controls, get details from our official documentation. * Pin Microsoft 365 Copilot Chat to the navigation bar (5 mins): As an admin, pin Copilot Chat to the navigation bar for users signed in with their Microsoft Entra account. * New experiences coming to the Copilot key (3 mins): Do you manage devices with the Copilot key? If so, configure the target app that will open with the WindowsAI/SetCopilotHardwareKey policy. For devices without the physical key, use Windows key+C. * Copilot Analytics improves access and reporting on Microsoft 365 Copilot Chat and agents (7 mins): Looking for the number of active Copilot users, licensing data, or AI use adoption scores? Read about the unified reporting experience combining the Copilot Dashboard and Microsoft Viva Insights. Additional reporting is available through the Microsoft 365 admin center. Use agents in Microsoft 365 Copilot Chat * Agents in Microsoft 365 Copilot Chat (3 mins): Use agents to help you automate and execute frequent tasks tailored to your sphere and focus of work. Read about how to enable, author, and manage agents. * Copilot agent management and controls | Digital deep dive: Copilot Control System (51 mins): Discover how the Copilot Control System in the Microsoft 365 admin center enables you to manage Copilot agents. You will learn how to stage rollout agents, manage the cost of agents within Copilot chat, use the "Agents and Connectors" page for lifecycle management, and more. * AI agents hub – Microsoft adoption (time varies): Help your organization get started with agents. Choose Microsoft 365 Copilot as your product to browse scenarios, templates, examples, and training resources of most interest. Check out resources by role and function whether you design, build, deploy, or manage agents. Bookmark additional resources * Copilot Chat Success Kit (time varies): Download the full set of resources to help your organization get started with Copilot Chat. It includes the IT controls guide, implementation summary guide for leaders, user onboarding materials, and more. Check out Copilot Chat scenarios for different functions from customer service to sales and choose from nine available languages. * Bookmark the Copilot learning hub (time varies): Keep learning about Copilot and agent experiences. Build your confidence with multimedia resource collections. * Microsoft Copilot Studio (time varies): Subscribe to this YouTube channel for the latest video tips on how to use Copilot Studio. Transform customer and employee experiences with AI built into Microsoft Copilot Studio. Customize Microsoft Copilot for Microsoft 365 or build your own experiences. * Microsoft 365 Copilot release notes (time varies): Check out the latest features and improvements for Microsoft 365 Copilot, released in the second and fourth week of each month. Browse what’s generally available (Current Channel for Microsoft 365 apps) and specific to each platform. * Microsoft 365 Roadmap (time varies): Get a left-to-right view of the latest innovations with this roadmap tool. Set the product filter to Microsoft Copilot (Microsoft 365) to see what’s in development, what’s in preview, what’s rolling out, and what’s broadly available today. Limit your search to your desired platforms, status, release phase, cloud instance, and timeline to help you plan. What resources did you find most useful? Do you know of additional resources that would help a peer get started with Microsoft 365 Copilot Chat? Feel free to add it to the comments section below! And if you’ve missed any AI-related topics or looking for something else, check out our growing Windows skilling snacks library. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 17/09/2025
Windows 365 Cloud Apps are now in public preview: Windows 365 Cloud Apps are now available to all customers during public preview. Thank you to the customers, partners, and MVP’s who provided invaluable feedback during the private preview. Your feedback helps guide and prioritize the… #WindowsITPro
bit.ly
Windows 365 Cloud Apps are now in public preview
Windows 365 Cloud Apps are now available to all customers during public preview. Thank you to the customers, partners, and MVP’s who provided invaluable feedback during the private preview. Your feedback helps guide and prioritize the Windows 365 Cloud Apps feature roadmap. What are Windows 365 Cloud Apps? Windows 365 Cloud Apps allow administrators to give users access to specific apps delivered from the cloud instead of a full Cloud PC. This is ideal for organizations that want to streamline app delivery, reduce overhead, and modernize their virtual desktop infrastructure (VDI) environments. Windows 365 Cloud Apps runs on Windows 365 Frontline Cloud PCs in shared mode. The Windows 365 Frontline licensing model enables shared Cloud PC access for shift-based or part-time workers, allowing unlimited users per license with one active session at a time. Since Windows 365 Cloud Apps streams only essential applications like Outlook or Word without loading a full desktop, it is ideal for task-based roles. Together, Frontline and Cloud Apps deliver a flexible, resource-optimized solution for dynamic workforces, especially in frontline environments like retail, healthcare, and government. New for public preview Cloud Apps were previously supported in the Windows App during private preview. Recent changes have improved the experience for end-users, including automatically launching OneDrive and a Windows 365 filter on the Apps page of the Windows App. Now, organizations can take advantage of a secure, scalable solution to modernize how applications are accessed and managed across their workforce. By streaming only the apps users need—without provisioning full desktop environments—Windows 365 Cloud Apps helps reduce complexity and supports flexible workstyles. Windows 365 Cloud Apps in Windows App Looking ahead As organizations embrace Windows 365 Cloud Apps, Microsoft is focused on simplifying app delivery even further—making it faster, easier, and more intuitive for IT admins to deploy custom line-of-business apps at scale. Currently, customers must create custom images to deliver custom line-of-business apps as Cloud Apps. While this works, private preview participants complained that the process is outdated. As requested by customers, we are working to make Intune the single pane of glass for app deployment, enabling them to publish Intune Apps as Cloud Apps. Customers are already using Intune Autopilot in place of custom images, so we will similarly support Intune’s approach to modern app delivery for Windows 365 Cloud Apps. Customers will be able to include custom apps in a Cloud App policy’s Autopilot device preparation to publish them as Cloud Apps. How to Get Started To use Windows 365 Cloud Apps with a Windows 365 Frontline license, check out Cloud App documentation and follow the guidelines to try out the feature and evaluate Cloud Apps as an option for migrating apps to the Windows Cloud. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
012
ConfigMgrDogs @configmgrdogs.bsky.social · 17/09/2025
Announcing Windows 365 Frontline for GCC and GCCH: Big news for U.S. government agencies and contractors: Windows 365 Frontline in dedicated mode is now generally available with support for Government Community Cloud (GCC) and GCC High (GCCH) customers. This milestone brings new… #WindowsITPro
bit.ly
Announcing Windows 365 Frontline for GCC and GCCH
Big news for U.S. government agencies and contractors: Windows 365 Frontline in dedicated mode is now generally available with support for Government Community Cloud (GCC) and GCC High (GCCH) customers. This milestone brings new deployment flexibility and cost efficiency for Windows 365 Cloud PCs to U.S. government organizations. Windows 365 Frontline for GCC/GCCH joins Windows 365 Enterprise and Windows 365 Government as options for the public sector. Whether you’re supporting shift-based, part-time, or temporary workers, this offering meets the unique needs of government teams without compromising on compliance or control. Users can access secured, compliant Cloud PCs from any device, without requiring an individual license for each user. What is Windows 365 Frontline? Windows 365 Frontline is designed for organizations to provide cost-effective, secure, and scalable Cloud PC capabilities to users who need part-time or occasional access, helping organizations modernize shared workstations and reduce IT overhead. Windows 365 Frontline in dedicated mode enables shift-based, part-time, or temporary workers to access Cloud PCs during their working hours. A single license enables up to three Cloud PCs, each assigned to a different user, but only one Cloud PC can be active at a time. This is ideal for environments where users work in rotating shifts or have non-concurrent schedules. With new support for GCC and GCCH, government agencies can now deploy Windows 365 Frontline Cloud PCs in dedicated mode, meeting standards such as CJIS, IRS 1075, and FedRAMP High. For users who only require intermittent access to a Windows 365 Cloud PC, Windows 365 Frontline in shared mode enables a single license to be shared by a group of users, one at a time. When each user logs out, the desktop session resets, and no user data is retained. Windows 365 Frontline in shared mode is available to government organizations in our Windows 365 Frontline for FedRamp offering, with additional work in development for GCC and GCCH environments. How can Windows 365 Frontline help government agencies? Government organizations often face complex challenges—budgetary constraints, strict compliance requirements, and a diverse workforce. Windows 365 Frontline for GCC and GCCH in dedicated mode helps solve these with: * Cost optimization: Instead of buying a Windows 365 license for every employee, agencies can use dedicated-mode Windows 365 Frontline licenses across shifts. Up to three employees working different shifts can share one license even as they access a personalized, persistent Cloud PC, dramatically reducing costs. * Compliance: Built to meet FedRAMP High, CJIS, and IRS 1075 standards, Windows 365 Frontline for GCC and GCCH ensures secured access to sensitive data while maintaining regulatory compliance. * Operational efficiency: Replace legacy VDI with a scalable, secured, and easy-to-manage Cloud PC experience. Provisioning is done via Microsoft Intune, and Cloud PCs are managed just like physical devices. * Flexibility for staff: Support rotating staff, shared workstations, and contingent workers with persistent Cloud PCs that are available when needed—and powered off when not. Built for government, powered by Azure Windows 365 Frontline for GCC/GCCH is provisioned in U.S. government data centers, ensuring data residency and compliance. It integrates seamlessly with Microsoft Intune and Microsoft Entra ID, offering a familiar experience for IT admins and users alike. Choose the best fit for your organization’s needs Windows 365 has multiple editions suitable for the public sector: Windows 365 Enterprise, Windows 365 Government, and Windows 365 Frontline for GCC/GCCH. Read Robert Nishi’s Windows IT Pro Blog for more information about choosing the right Windows 365 offering for your agency’s needs and contact your Microsoft account team with additional questions. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000
ConfigMgrDogs @configmgrdogs.bsky.social · 17/09/2025
Extending Copilot in Intune to manage Windows 365 Cloud PCs: Windows 365 introduced the Cloud PC four years ago, securely streaming personalized Windows desktops, apps, settings, and content from the Microsoft Cloud to any device. Windows 365 and its integration with Microsoft Intune… #WindowsITPro
bit.ly
Extending Copilot in Intune to manage Windows 365 Cloud PCs
Windows 365 introduced the Cloud PC four years ago, securely streaming personalized Windows desktops, apps, settings, and content from the Microsoft Cloud to any device. Windows 365 and its integration with Microsoft Intune sets the standard for simplicity in cloud endpoint management. At the same time, we are constantly looking for new ways to accelerate IT decision-making, enhance the quality of outcomes, and uncover cost-savings opportunities for our customers. The release of Copilot in Intune support for Windows 365 is one step of many on that journey, enabling IT administrators to leverage advanced AI-driven insights and automation to manage their Cloud PCs more effectively. In this blog, we will cover the capabilities that we have released into general availability. Learn more about Copilot in Intune with Windows 365 to get started today. Simplify Cloud PC management Copilot in Intune helps endpoint admins quickly get information about their Windows 365 Cloud PCs wherever they are in the Intune portal. Suggested prompts quickly provide data and insights that are contextualized to the Windows 365 page that the admin is viewing, providing both summarized trends and per-Cloud PC content. From anywhere within Intune, admins can use natural language to discover prompts to get the same insights—potentially combining Cloud PC information from Windows 365 and device information from Intune—for a holistic understanding of what they are investigating. IT administrators can manage costs more effectively from a single portal by using Copilot in Intune. By combining license inventory data from the Microsoft 365 Admin Center with user assignments to provisioning policies in the Windows 365 pages, Copilot helps streamline cost oversight and resource allocation. Copilot in Intune can offer guidance, like the availability of Cloud PC licenses Identify and resolve issues Discover issues and identify solutions without having to navigate across multiple interfaces. Copilot can summarize relevant connectivity metrics to identify areas of focus and provide suggested mitigations to improve performance. Prompts that can help in identifying issues could include “Summarize Cloud PCs that cannot connect” or “Show Cloud PCs that are undersized”. Copilot in Intune offers guidance on performance and usage Get in-context recommendations Windows 365 has a rich set of reports to help admins get the information they need to troubleshoot issues, plan their environments, and manage costs. By combining the data available today with the natural language capabilities of Copilot, admins can now move directly from data to insights. These insights lead to actionable recommendations supported by Windows 365 documentation, streamlining IT management processes. What’s next The AI journey for Windows 365 has only just started. Microsoft is continuing to look for new ways to simplify the IT admin experience and reduce complexity for customers. In the future, we will continue to evolve our tool and AI experiences to centralize insights and automate common workflows to help admins quickly prioritize workloads and remediate issues. We invite you to explore the robust integrations available within Intune where AI assistance helps you easily manage end user connection quality, identify provisioning issues, and optimize your licenses into streamlined process with Copilot. To get started or learn more about our enhancements visit Copilot in Intune with Windows 365. To learn more about the latest in Windows 365, join the Windows 365 Tech Community. For IT professionals looking to provide feedback and help Windows engineers improve and grow our products, consider joining the Microsoft Management Customer Connection Program at https://aka.ms/JoinCommunity. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
000