Training
Module
Implement device compliance policies - Training
This module describes how to use compliance and conditional access policies to help protect access to organizational resources.
Deze browser wordt niet meer ondersteund.
Upgrade naar Microsoft Edge om te profiteren van de nieuwste functies, beveiligingsupdates en technische ondersteuning.
Tip
This CSP contains ADMX-backed policies which require a special SyncML format to enable or disable. You must specify the data type in the SyncML as <Format>chr</Format>
. For details, see Understanding ADMX-backed policies.
The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see CDATA Sections.
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_Sensors/DisableLocation_1
This policy setting turns off the location feature for this computer.
If you enable this policy setting, the location feature is turned off, and all programs on this computer are prevented from using location information from the location feature.
If you disable or don't configure this policy setting, all programs on this computer won't be prevented from using location information from the location feature.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | DisableLocation_1 |
Friendly Name | Turn off location |
Location | User Configuration |
Path | Windows Components > Location and Sensors |
Registry Key Name | Software\Policies\Microsoft\Windows\LocationAndSensors |
Registry Value Name | DisableLocation |
ADMX File Name | Sensors.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_Sensors/DisableLocationScripting_1
This policy setting turns off scripting for the location feature.
If you enable this policy setting, scripts for the location feature won't run.
If you disable or don't configure this policy setting, all location scripts will run.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | DisableLocationScripting_1 |
Friendly Name | Turn off location scripting |
Location | User Configuration |
Path | Windows Components > Location and Sensors |
Registry Key Name | Software\Policies\Microsoft\Windows\LocationAndSensors |
Registry Value Name | DisableLocationScripting |
ADMX File Name | Sensors.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_Sensors/DisableLocationScripting_2
This policy setting turns off scripting for the location feature.
If you enable this policy setting, scripts for the location feature won't run.
If you disable or don't configure this policy setting, all location scripts will run.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | DisableLocationScripting_2 |
Friendly Name | Turn off location scripting |
Location | Computer Configuration |
Path | Windows Components > Location and Sensors |
Registry Key Name | Software\Policies\Microsoft\Windows\LocationAndSensors |
Registry Value Name | DisableLocationScripting |
ADMX File Name | Sensors.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_Sensors/DisableSensors_1
This policy setting turns off the sensor feature for this computer.
If you enable this policy setting, the sensor feature is turned off, and all programs on this computer can't use the sensor feature.
If you disable or don't configure this policy setting, all programs on this computer can use the sensor feature.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | DisableSensors_1 |
Friendly Name | Turn off sensors |
Location | User Configuration |
Path | Windows Components > Location and Sensors |
Registry Key Name | Software\Policies\Microsoft\Windows\LocationAndSensors |
Registry Value Name | DisableSensors |
ADMX File Name | Sensors.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_Sensors/DisableSensors_2
This policy setting turns off the sensor feature for this computer.
If you enable this policy setting, the sensor feature is turned off, and all programs on this computer can't use the sensor feature.
If you disable or don't configure this policy setting, all programs on this computer can use the sensor feature.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | DisableSensors_2 |
Friendly Name | Turn off sensors |
Location | Computer Configuration |
Path | Windows Components > Location and Sensors |
Registry Key Name | Software\Policies\Microsoft\Windows\LocationAndSensors |
Registry Value Name | DisableSensors |
ADMX File Name | Sensors.admx |
Training
Module
Implement device compliance policies - Training
This module describes how to use compliance and conditional access policies to help protect access to organizational resources.
Documentatie
Apparaatbeperkingsinstellingen voor Windows 10/11 in Microsoft Intune
Bekijk een lijst met alle instellingen en de bijbehorende beschrijvingen voor het maken van apparaatbeperkingen op Windows 10/11-clientapparaten. Gebruik deze instellingen in een configuratieprofiel om schermopnamen, wachtwoordvereisten, kioskinstellingen, apps in de Store, Microsoft Edge-browser, Microsoft Defender, toegang tot de cloud, startmenu en meer te beheren in Microsoft Intune.