<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Configuration Manager Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/bg-p/ConfigurationManagerBlog</link>
    <description>Configuration Manager Blog articles</description>
    <pubDate>Fri, 17 Apr 2026 17:57:51 GMT</pubDate>
    <dc:creator>ConfigurationManagerBlog</dc:creator>
    <dc:date>2026-04-17T17:57:51Z</dc:date>
    <item>
      <title>Announcing the Annual Release Cadence for Microsoft Configuration Manager</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/announcing-the-annual-release-cadence-for-microsoft/ba-p/4464794</link>
      <description>&lt;P&gt;Starting with version 2609, Microsoft Configuration Manager will transition to an annual release cadence. This change is a formalization of the direction we’ve communicated at events and in customer conversations. Microsoft Intune is the future of device management, and all new innovations will occur there. Configuration Manager will continue to serve your on-premises devices, with a renewed focus on security, stability, and long-term support.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Why Move to an Annual Release Cadence?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Historically, Configuration Manager followed a semi-annual release schedule. As the industry shifts toward cloud-native management, we’re aligning our release cycle to better support your long-term planning and operational stability. This annual cadence allows IT teams to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Plan upgrades with confidence - knowing when to expect new releases.&lt;/LI&gt;
&lt;LI&gt;Focus on stability and security - with each release prioritizing reliability over new features.&lt;/LI&gt;
&lt;LI&gt;Transition at your own pace - while Microsoft Intune receives all future investments and innovations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;What Does This Mean for You?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Here’s what you can expect from upcoming releases:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;2509 (December 2025): Stability and quality updates, including ARM64 support.&lt;/LI&gt;
&lt;LI&gt;2603 (March 2026): Enhanced security aligned with the &lt;A class="lia-external-url" href="https://www.microsoft.com/trust-center/security/secure-future-initiative" target="_blank" rel="noopener"&gt;Microsoft Secure Future Initiative&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;2609 (September 2026): The first annual release under the new cadence.&lt;/LI&gt;
&lt;LI&gt;2709 (September 2027): Future-focused release (details to be determined).&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;Focus on Security and Stability&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Annual releases will align with the Windows client security and stability cadence (H2). Our top priority is to maintain a secure, reliable Configuration Manager experience. This means:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Applying critical updates and patches as needed.&lt;/LI&gt;
&lt;LI&gt;Providing hotfix rollups only when absolutely necessary (e.g., for critical security or functionality issues).&lt;/LI&gt;
&lt;LI&gt;Continuing to support existing environments, with advance notice for any feature deprecations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;Support Lifecycle&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;The support lifecycle remains unchanged; each version receives 18 months of support from its release date. Here’s a quick reference, but you should always refer to the lifecycle management chart here: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/lifecycle/products/microsoft-configuration-manager" target="_blank"&gt;https://learn.microsoft.com/en-us/lifecycle/products/microsoft-configuration-manager&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 46.3889%; height: 262px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr style="height: 39px;"&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Support Start&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Support End&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 39px;"&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;2403&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;April 22, 2024&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;October 22, 2025&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 39px;"&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;2409&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;December 4, 2024&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;June 6, 2026&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 39px;"&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;2503&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;March 31, 2025&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;September 30, 2026&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 39px;"&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;2509&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;December 2025&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P&gt;June 2027&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;&lt;STRONG&gt;Frequently Asked Questions&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Q: Is this a new direction for Configuration Manager?&lt;/P&gt;
&lt;P&gt;A: No. While we’ve discussed this shift publicly for some time, this is the first time we’re formally documenting it. The only “new” aspect is the official annual cadence and the clarity it brings to your planning.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Q: Will there be hotfixes or out-of-band updates?&lt;/P&gt;
&lt;P&gt;A: Only if absolutely necessary - such as for critical security or functionality issues. Otherwise, updates will be bundled into the annual release.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Q: What about support for existing environments?&lt;/P&gt;
&lt;P&gt;A: We remain committed to supporting your Configuration Manager environments. Any changes or deprecations will be communicated well in advance.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Looking Ahead&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;This annual release cadence is designed to give you predictability, stability, and the confidence to plan for the future. As you consider your long-term device management strategy, remember that Microsoft Intune is where all new innovation happens.&lt;/P&gt;
&lt;P&gt;Whether you’re getting started with Intune or currently using Configuration Manager, Microsoft provides clear guidance to help you modernize at your own pace. Explore the&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/intune-service/fundamentals/deployment-guide-intune-setup" target="_blank" rel="noopener"&gt;Intune deployment guide&lt;/A&gt; to set up or move to Intune, and see the section on &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/intune-service/fundamentals/deployment-guide-intune-setup#currently-use-configuration-manager" target="_blank" rel="noopener"&gt;using Configuration Manager&lt;/A&gt; for co-management or a phased transition.&lt;/P&gt;
&lt;P&gt;We’re here to support your journey - wherever you are on the path to cloud-native Windows.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have any questions, leave a comment on this post or reach out on X&amp;nbsp;@&lt;A class="lia-external-url" href="https://aka.ms/MSConfigMgrTeam" target="_blank" rel="noopener"&gt;MSConfigMgrTeam&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 19:02:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/announcing-the-annual-release-cadence-for-microsoft/ba-p/4464794</guid>
      <dc:creator>Danny_Guillory</dc:creator>
      <dc:date>2025-11-07T19:02:56Z</dc:date>
    </item>
    <item>
      <title>Update 2409 for Microsoft Configuration Manager current branch is now available.</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2409-for-microsoft-configuration-manager-current-branch/ba-p/4351640</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Update 2409 for Configuration Manager current branch is available as an in-console update. Apply this update on sites that run version 2303 or later. This article summarizes the changes and new features in Configuration Manager, version 2409.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Configuration Manager now supports SQL Extended Protection for Authentication&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configuration Manager now supports SQL extended protection for authentication. It's a security feature that enhances protection against MITM attacks, making SQL server more secure when connections are made using extended protection. These enhancements collectively reduce the risk of unauthorized access and protect sensitive data managed by the SQL Server database engine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/sql/database-engine/configure-windows/connect-to-the-database-engine-using-extended-protection" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;Connect to the Database Engine Using Extended Protection&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Introducing Centralized Search - Desired Workspace Selection&lt;/H3&gt;
&lt;P&gt;The centralized search box now enables the option to select the desired workspace for searching. Users can easily refine their search results by selecting the desired workspace from the dropdown menu.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Configuration Manager does not support SQL Server 2012 and 2014&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting with version 2409, Configuration Manager no longer supports SQL Server 2012 and 2014. Upgrade to the latest SQL Server version or at least SQL Server 2016. If you don’t upgrade, CM upgrades are blocked, and you see an error during the pre-req check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/configmgr/core/plan-design/configs/support-for-sql-server-versions" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Supported SQL Server versions for Configuration Manager&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Operating System support added for Windows 11 24H2 and Windows Server 2025&lt;/H3&gt;
&lt;P&gt;With this version of Configuration Manager, support is added for Windows 11 24H2 and Windows Server 2025.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows 11 24H2 &amp;amp; Windows Server 2025 are added to the Product lifecycle dashboard and supported platform.&lt;/LI&gt;
&lt;LI&gt;Windows 11 24H2 &amp;amp; Windows Server 2025 client support is added.&lt;/LI&gt;
&lt;LI&gt;Boot image creation in CM on Windows Server 2025 now supports latest Windows ADK.&lt;/LI&gt;
&lt;LI&gt;Windows upgrade readiness dashboard now supports Windows 11 24H2 for upgrading clients.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;Note: Windows Server and Windows 11 24H2 do not support Firewall Rules. This will result in a non-compliant status in the Configuration Manager applet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Software metering support in Arm64 devices&lt;/H3&gt;
&lt;P&gt;The Configuration Manager now supports Software metering for Arm64 devices. Software metering is used to monitor Windows PC desktop apps with a filename ending in .exe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/configmgr/apps/deploy-use/monitor-app-usage-with-software-metering" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Software metering in Configuration Manager&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;BitLocker support in Arm64 devices&lt;/H3&gt;
&lt;P&gt;Configuration Manager now supports BitLocker task sequence steps for Arm64 devices. In BitLocker Management, policies that include OS drive encryption with a TPM protector and fixed drive encryption with the Auto-Unlock option are supported on Arm64 devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/configmgr/protect/plan-design/bitlocker-management#supported-configurations" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Bitlocker Supported configurations&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;CMG Entra Application secret key renewal &lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The 'Renew Secret Key' feature now opens a dialog with four options for the validity period. This update also prevents applications older than 800 days (approximately two years) from renewing their secret keys. The same options are available when creating a new app.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Note: The admin must sign in using tenant global administrator credentials and then click on the Renew button.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;CMG Enhanced security option&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CMG Setup now uses managed Identities and third-party&amp;nbsp;&lt;STRONG&gt;Server App&lt;/STRONG&gt;&amp;nbsp;to interact with CMG's Azure Storage account, instead of storage account keys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Hence storage account key access is disabled for new CMG setup.&lt;/LI&gt;
&lt;LI&gt;For sessions upgrading from earlier versions to 2409, the 'CMG enhanced security' button is shown as enabled.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Known Issues&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Upgrade SQL 2012 or 2014 Express, Standard, Enterprise edition to SQl 2016 or latest version.&amp;nbsp;&lt;STRONG&gt;VC++ Redistributable Version&lt;/STRONG&gt;&amp;nbsp;need to be upgraded to latest version on&amp;nbsp;&lt;STRONG&gt;Secondary sites&lt;/STRONG&gt;.&amp;nbsp;&lt;A href="https://aka.ms/vs/17/release/vc_redist.x64.exe" target="_blank" rel="noopener" data-linktype="external"&gt;Download Latest Microsoft Visual C++ Redistributable Version&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Other Updates&lt;/H2&gt;
&lt;H3&gt;Performance Enhancement of policy processing and collection evaluation&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The performance of policy processing and collection evaluation has been enhanced. Previously, blocking chains from sp_ProcessPolicyChanges, called by PolicyPv, would run for hours, disrupting multiple workloads including collection management and policy processing.&lt;/P&gt;
&lt;H2&gt;Deprecated features&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Learn about support changes before they're implemented in&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/deprecated/removed-and-deprecated" target="_blank" rel="noopener" data-linktype="relative-path"&gt;removed and deprecated items&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The&amp;nbsp;&lt;STRONG&gt;MDT Integration with CM and Standalone&lt;/STRONG&gt; is no longer supported with Configuration Manager. Customers should remove MDT TS steps, followed by removing MDT integration, to avoid TS corruption and modification failures&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/deprecated/removed-and-deprecated-cmfeatures" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Removed and deprecated features for Configuration Manager.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Next steps&lt;/H2&gt;
&lt;P&gt;As of December 16, 2024, version 2409 is globally available for all customers to install.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: For existing Fast ring current branch 2409 customers, you will see Slow ring upgrade package in console. Install 2409 Slow ring package to be in production current branch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you're ready to install this version, see&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/configmgr/core/servers/manage/updates" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Installing updates for Configuration Manager&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/configmgr/core/servers/manage/checklist-for-installing-update-2409" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Checklist for installing update 2409&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Tip : To install a new site, use a baseline version of Configuration Manager.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For known significant issues, see the &lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/release-notes" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Release notes&lt;/A&gt;. After you update a site, also review the&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/configmgr/core/servers/manage/checklist-for-installing-update-2409#post-update-checklist" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Post-update checklist&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Configuration Manager team&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources:&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/whats-new-incremental-versions" target="_blank" rel="noopener"&gt;What’s New in Configuration Manager&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbdocs" target="_blank" rel="noopener"&gt;Documentation for Configuration Manager&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/CMAnnounce" target="_blank" rel="noopener"&gt;Microsoft Configuration Manager announcement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/MEMVisionPaper" target="_blank" rel="noopener"&gt;Microsoft Configuration Manager vision statement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/get-started/evaluate-with-lab-environment" target="_blank" rel="noopener"&gt;Evaluate Configuration Manager in a lab&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/upgrade-to-configuration-manager" target="_blank" rel="noopener"&gt;Upgrade to Configuration Manager&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener"&gt;Configuration Manager Forums&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener"&gt;Configuration Manager Support&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener"&gt;Report an issue&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/configmgrsuggestions" target="_blank" rel="noopener"&gt;Provide suggestions&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 16 Dec 2024 18:44:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2409-for-microsoft-configuration-manager-current-branch/ba-p/4351640</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2024-12-16T18:44:36Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager technical preview version 2411</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2411/ba-p/4349866</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Operating System support added for Windows 11 24H2 and Windows Server 2025&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With this version of Configuration Manager, support is added for Windows 11 24H2 and Windows Server 2025.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows 11 24H2 &amp;amp; Windows Server 2025 are added to Product lifecycle dashboard and supported platform.&lt;/LI&gt;
&lt;LI&gt;Windows 11 24H2 &amp;amp; Windows Server 2025 Client support is added.&lt;/LI&gt;
&lt;LI&gt;Boot image creation in SCCM on Windows Server 2025 now supports latest Windows ADK&lt;/LI&gt;
&lt;LI&gt;Windows upgrade readiness dashboard now supports Windows 11 24H2 for upgrading clients.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Note: Windows Server and Windows 11 24H2 do not support Firewall Rules. This will result in a non-compliant status in the Configuration Manager applet.&lt;/P&gt;
&lt;H2&gt;Enhanced Security for CMG&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CMG Setup now uses Managed Identities and third-party &lt;STRONG&gt;Server App&lt;/STRONG&gt;&amp;nbsp;to interact with CMG's Azure Storage Account, instead of storage account keys.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Hence storage account key access is disabled for new CMG setup.&lt;/LI&gt;
&lt;LI&gt;For sessions upgrading from earlier versions to 2405 TP, the 'CMG enhanced security' button is shown as enabled.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;When the enhanced security option is selected, the VMSS OS Auto Upgrade feature is also activated. An extra panel appears, prompting the admin to provide maintenance window details. Azure uses this information to schedule upgrades whenever new OS images become available.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H3&gt;CMG Entra Application secret renewal&lt;/H3&gt;
&lt;P&gt;The 'Renew Secret Key' feature now opens a dialog with four options for the validity period. This update also prevents applications older than 800 days (approximately two years) from renewing their secret keys. The same options are available when creating a new app.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Note: The admin must sign in using tenant global administrator credentials and then click on the renew button.&lt;/P&gt;
&lt;H2&gt;SQL 2012 and 2014 support are deprecated&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting with this version, Configuration Manager no longer supports SQL Server 2012 and 2014. Upgrade to the latest SQL Server version or at least SQL Server 2016. If you don’t upgrade, CM upgrades are blocked, and you see an error during the pre-req check.&lt;/P&gt;
&lt;H2&gt;Software metering support in Arm64 devices&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Configuration Manager now supports Software metering for Arm64 devices. Software metering is used to monitor Windows PC desktop apps with a filename ending in .exe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, &lt;A href="https://learn.microsoft.com/en-us/mem/configmgr/apps/deploy-use/monitor-app-usage-with-software-metering" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Software metering in Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Update 2411 for Technical Preview Branch is available in the Microsoft Configuration Manager Technical Preview console. For new installations, the 2411 baseline version of Microsoft Configuration Manager Technical Preview Branch is available on the link:&amp;nbsp; &lt;A class="lia-external-url" href="https://aka.ms/MECM2206TP-Baseline" target="_blank" rel="noopener"&gt;CM2411TP-Baseline&lt;/A&gt;&amp;nbsp;or from&amp;nbsp;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager-technical-preview" target="_blank" rel="noopener"&gt;Eval center&lt;/A&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Technical Preview Branch releases give you an opportunity to try out new Configuration Manager features in a test environment before they are made generally available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would love to hear your thoughts about the latest Technical Preview! Send us&amp;nbsp;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener"&gt;feedback&lt;/A&gt;&amp;nbsp;directly from the console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;The Configuration Manager team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Configuration Manager Resources:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/core/get-started/technical-preview" target="_blank" rel="noopener"&gt;Documentation for Configuration Manager Technical Previews&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-system-center-configuration-manager-and-endpoint-protection-technical-preview" target="_blank" rel="noopener"&gt;Try the Configuration Manager Technical Preview Branch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/" target="_blank" rel="noopener"&gt;Documentation for Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener"&gt;Configuration Manager Forums&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener"&gt;Configuration Manager Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 17:23:25 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2411/ba-p/4349866</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2024-12-16T17:23:25Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager technical preview version 2405</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2405/ba-p/4162763</link>
      <description>&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 id="bkmk_Sqlepa" class="heading-anchor"&gt;Configuration Manager now supports SQL Extended Protection for Authentication&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Configuration Manager now supports SQL Extended Protection for Authentication. It's a security feature that enhances protection against MITM attacks, making SQL Server more secure when connections are made using Extended Protection. These enhancements collectively reduce the risk of unauthorized access and protect sensitive data managed by the SQL Server Database Engine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/sql/database-engine/configure-windows/connect-to-the-database-engine-using-extended-protection" target="_self" data-linktype="absolute-path"&gt;Connect to the Database Engine Using Extended Protection&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_Armbit" class="heading-anchor"&gt;BitLocker support in Arm devices&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Configuration Manager now supports BitLocker Task Sequence steps for Arm devices. In BitLocker Management, policies that include OS Drive encryption with a TPM protector and Fixed Drive encryption with the Auto-Unlock option are supported on Arm devices.&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_GSearchbox" class="heading-anchor"&gt;Introducing Centralized Search - Desired Workspace Selection&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;The centralized search box now enables the option to select the desired workspace for searching. Users can easily refine their search results by selecting the desired workspace from the dropdown menu.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 class="heading-anchor"&gt;Fixes&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_perform" class="heading-anchor"&gt;Performance Enhancement of policy processing and collection evaluation&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;The performance of policy processing and collection evaluation has been enhanced. Previously, blocking chains from sp_ProcessPolicyChanges, called by PolicyPv, would run for hours, disrupting multiple workloads including collection management and policy processing.&lt;/P&gt;
&lt;H2 id="known-issues" class="heading-anchor"&gt;Known issues&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="unable-to-import-or-connect-to-powershell-configuration-manager-module-via-console" class="heading-anchor"&gt;Unable to import or connect to Powershell Configuration Manager module via console&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;While importing or connecting to Configuration manager Powershell module via CM console users get the following error message :&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;PS C:\Build\AdminConsole\bin&amp;gt; Import-Module .\ConfigurationManager.psd1 Import-Module : The module manifest 'C:\Build\AdminConsole\bin\ConfigurationManager.psd1' could not be processed because it is not a valid Windows PowerShell restricted language file. Remove the elements that are not permitted by the restricted language&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="configuration-manager-console-wont-automatically-update" class="heading-anchor"&gt;Configuration Manager console won't automatically update&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;If you update a technical preview site from version 2401 to a later version, the Configuration Manager console fails to update. This problem is because of a known issue in the extension installer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Mitigation:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;To work around this issue, after you update the site from version 2401 to a later version, manually uninstall the previous console and run&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;ConsoleSetup.exe&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/install-consoles" target="_self" data-linktype="relative-path"&gt;Install the Configuration Manager console&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;Update 2405 for Technical Preview Branch is available in the Microsoft Configuration Manager Technical Preview console. For new installations, the 2405 baseline version of Microsoft Configuration Manager Technical Preview Branch is&amp;nbsp;available on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/MECM2206TP-Baseline" target="_self" rel="noreferrer"&gt;CM2405TP-Baseline&lt;/A&gt;&amp;nbsp;or from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager-technical-preview" target="_self" rel="noreferrer"&gt;Eval center&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Technical Preview Branch releases give you an opportunity to try out new Configuration Manager features in a test environment before they are made generally available.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;We would love to hear your thoughts about the latest Technical Preview! Send us&amp;nbsp;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;feedback&lt;/A&gt;&amp;nbsp;directly from the console.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Thanks,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;The Configuration Manager team&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Configuration Manager Resources:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/core/get-started/technical-preview" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager Technical Previews&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-system-center-configuration-manager-and-endpoint-protection-technical-preview" target="_blank" rel="noopener noreferrer"&gt;Try the Configuration Manager Technical Preview Branch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Forums&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 15:07:23 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2405/ba-p/4162763</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2024-06-26T15:07:23Z</dc:date>
    </item>
    <item>
      <title>Update 2403 for Microsoft Configuration Manager current branch is now available.</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2403-for-microsoft-configuration-manager-current-branch/ba-p/4119853</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;Update 2403 for Configuration Manager current branch is available as an in-console update. Apply this update on sites that run version 2211 or later. When installing a new site, it will also be available as a&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/manage/updates#bkmk_note1" target="_blank" rel="noopener"&gt;baseline version&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;soon after general availability. This article summarizes the changes and new features in Configuration Manager, version 2403.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Site infrastructure&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="logged-in env-production page-responsive" data-turbo-body=""&gt;
&lt;DIV class="application-main " data-commit-hovercards-enabled="" data-discussion-hovercards-enabled="" data-issue-and-pr-hovercards-enabled=""&gt;
&lt;DIV class=""&gt;
&lt;DIV id="repo-content-pjax-container" class="repository-content "&gt;
&lt;DIV data-target="react-app.reactRoot"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 fSWWem"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 kPPmzM"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 cIAPDV"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 emFMJu"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 hlUAHL"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 iStsmI" tabindex="0" data-selector="repos-split-pane-content"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 hVZtwF"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 iJmJly"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 jACbi container"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 ytOJl"&gt;
&lt;SECTION class="Box-sc-g0xbh4-0 eRvpKx" aria-labelledby="file-name-id-wide file-name-id-mobile"&gt;
&lt;DIV class="Box-sc-g0xbh4-0 cTsUqU js-snippet-clipboard-copy-unpositioned" data-hpc="true"&gt;
&lt;ARTICLE class="markdown-body entry-content container-lg"&gt;
&lt;DIV class="markdown-heading lia-align-left" dir="auto"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="markdown-heading lia-align-left" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;&lt;STRONG&gt;Microsoft Azure Active Directory rebranded to Microsoft Entra ID&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-microsoft-azure-active-directory-rebranded-to-microsoft-entra-id" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#microsoft-azure-active-directory-rebranded-to-microsoft-entra-id" target="_blank" rel="noopener" aria-label="Permalink: Microsoft Azure Active Directory rebranded to Microsoft Entra ID"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;Starting Configuration Manager version 2403, Microsoft Azure Active Directory is renamed to Microsoft Entra ID within Configuration Manager.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Automated diagnostic Dashboard for Software Update Issues&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-automated-diagnostic-dashboard-for-software-update-issues" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#automated-diagnostic-dashboard-for-software-update-issues" target="_blank" rel="noopener" aria-label="Permalink: Automated diagnostic Dashboard for Software Update Issues"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;A new dashboard is added to the console under monitoring workspace, which shows the diagnosis of the software update issues in your environment this feature can easily identify any issues related to software updates. You can fix software update issues based on troubleshooting documentations.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;Special credit to Shankar Subramanian and Smita Jadhav for their details and troubleshooting notes.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/manage/software-update-health-dashboard" target="_blank" rel="noopener"&gt;Software update health dashboard.&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;&lt;STRONG&gt;Introducing centralized search box: Effortlessly find what you need in the console!&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-introducing-centralized-search-box-effortlessly-find-what-you-need-in-the-console" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#introducing-centralized-search-box-effortlessly-find-what-you-need-in-the-console" target="_blank" rel="noopener" aria-label="Permalink: Introducing centralized search box: Effortlessly find what you need in the console!"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;Users can now use the global search box in CM console, which streamlines the search experience and centralizes access to information. This feature enhances the overall usability, productivity and effectiveness of CM. Users no longer need to navigate through multiple nodes or sections/ folders to find information they require, saving valuable time and effort.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/manage/admin-console-tips#improvements-to-console-search" target="_blank" rel="noopener"&gt;Improvements to console search.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;&lt;STRONG&gt;Added Folder support for Scripts node in Software Library&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-added-folder-support-for-scripts-node-in-software-library" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#added-folder-support-for-scripts-node-in-software-library" target="_blank" rel="noopener" aria-label="Permalink: Added Folder support for Scripts node in Software Library"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;You can now organize scripts by using folders. This change allows for better categorization and management of scripts. Full Administrator and Operations Administrator roles can manage the folders.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/apps/deploy-use/create-deploy-scripts#folder-support-for-scripts" target="_blank" rel="noopener"&gt;Folder support for scripts.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;HTTPS or Enhanced HTTP should be enabled for client communication from this version of Configuration Manager&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-https-or-enhanced-http-should-be-enabled-for-client-communication-from-this-version-of-configuration-manager" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#https-or-enhanced-http-should-be-enabled-for-client-communication-from-this-version-of-configuration-manager" target="_blank" rel="noopener" aria-label="Permalink: HTTPS or Enhanced HTTP should be enabled for client communication from this version of Configuration Manager"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;HTTP-only communication is deprecated, and support is removed from this version of Configuration Manager. Enable HTTPS or Enhanced HTTP for client communication.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/list-of-prerequisite-checks#enable-site-system-roles-for-https-or-enhanced-http" target="_blank" rel="noopener"&gt;Enable site system roles for HTTPS or Enhanced HTTP.&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/deprecated/removed-and-deprecated-cmfeatures" target="_blank" rel="noopener"&gt;Deprecated features&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;&lt;STRONG&gt;Windows Server 2012/2012 R2 operating system site system roles are not supported from this version of Configuration Manager&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-windows-server-20122012-r2-operating-system-site-system-roles-are-not-supported-from-this-version-of-configuration-manager" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#windows-server-20122012-r2-operating-system-site-system-roles-are-not-supported-from-this-version-of-configuration-manager" target="_blank" rel="noopener" aria-label="Permalink: Windows Server 2012/2012 R2 operating system site system roles are not supported from this version of Configuration Manager"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;Starting 2403, Windows Server 2012/2012 R2 operating system site system roles aren't supported in any CB releases. Clients with extended support (ESU) will continue to support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/configs/supported-operating-systems-for-site-system-servers" target="_blank" rel="noopener"&gt;Supported-operating-systems-for-site-system-servers.&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;&lt;STRONG&gt;Resource access profiles and deployments will block Configuration manager upgrade&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-resource-access-profiles-and-deployments-will-block-configuration-manager-upgrade" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#resource-access-profiles-and-deployments-will-block-configuration-manager-upgrade" target="_blank" rel="noopener" aria-label="Permalink: Resource access profiles and deployments will block Configuration manager upgrade"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;Any configured Resource access profiles and deployments block Configuration manager upgrade. Consider deleting them and moving the co-management workload for Resource Access (if co-managed) to Intune.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/protect/plan-design/resource-access-deprecation-faq.yml" target="_blank" rel="noopener"&gt;FAQ&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/list-of-prerequisite-checks" target="_blank" rel="noopener"&gt;Resource access policies are no longer supported.&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H2 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;Software updates&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-software-updates" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#software-updates" target="_blank" rel="noopener" aria-label="Permalink: Software updates"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;New parameter SoftwareUpdateO365Language is added to Save-CMSoftwareUpdate cmdlet&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-new-parameter-softwareupdateo365language-is-added-to-save-cmsoftwareupdate-cmdlet" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#new-parameter-softwareupdateo365language-is-added-to-save-cmsoftwareupdate-cmdlet" target="_blank" rel="noopener" aria-label="Permalink: New parameter SoftwareUpdateO365Language is added to Save-CMSoftwareUpdate cmdlet"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;A new parameter&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SoftwareUpdateO365Language&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is now added to PowerShell Save-CMSoftwareUpdate cmdlet. Customers now don't have to check a specific language in the SUP Properties (causing a metadata download for that language for all updates).&lt;/P&gt;
&lt;P class="lia-align-left"&gt;PowerShell Commandlet:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Save-CMSoftwareUpdate – SoftwareUpdateO365Language &amp;lt;language name&amp;gt; (&amp;lt;region name&amp;gt;)"&lt;/CODE&gt;&lt;/P&gt;
&lt;DIV class="markdown-alert markdown-alert-note" dir="auto"&gt;
&lt;P class="markdown-alert-title lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="markdown-alert-title lia-align-left"&gt;Note&lt;/P&gt;
&lt;P class="lia-align-left"&gt;Languages need to be in O365 format to be consistent with Admin Console UI. E.g. "Hungarian (Hungary)".&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H2 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;OS deployment&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-os-deployment" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#os-deployment" target="_blank" rel="noopener" aria-label="Permalink: OS deployment"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;Support for ARM 64 Operating System Deployment&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-support-for-arm-64-operating-system-deployment" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#support-for-arm-64-operating-system-deployment" target="_blank" rel="noopener" aria-label="Permalink: Support for ARM 64 Operating System Deployment"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;Configuration Manager operating system deployment support is now added on Windows 11 ARM 64 devices. Currently Importing and customizing Arm 64 boot images, Wipe and load TS, Media creation TS, WDS PXE for Arm 64 and CMPivot is supported.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;Enhancement in Deploying Software Packages with Dynamic Variables&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-enhancement-in-deploying-software-packages-with-dynamic-variables" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#enhancement-in-deploying-software-packages-with-dynamic-variables" target="_blank" rel="noopener" aria-label="Permalink: Enhancement in Deploying Software Packages with Dynamic Variables"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;Administrators while deploying the "Install Software Package" via Dynamic variable with "Continue on error" unchecked to clients, will not be notified with task sequence failures even if package versions on the distribution point are updated.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/osd/understand/task-sequence-steps#retry-this-step-if-computer-unexpectedly-restarts" target="_blank" rel="noopener"&gt;Options for Install Application.&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H2 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;Cloud-attached management&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-cloud-attached-management" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#cloud-attached-management" target="_blank" rel="noopener" aria-label="Permalink: Cloud-attached management"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H3 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;Upgrade to CM 2403 is blocked if CMG V1 is running as a cloud service (classic)&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-upgrade-to-cm-2403-is-blocked-if-cmg-v1-is-running-as-a-cloud-service-classic" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#upgrade-to-cm-2403-is-blocked-if-cmg-v1-is-running-as-a-cloud-service-classic" target="_blank" rel="noopener" aria-label="Permalink: Upgrade to CM 2403 is blocked if CMG V1 is running as a cloud service (classic)"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;The option to upgrade Configuration Manager 2403 is blocked if you're running cloud management gateway V1 (CMG) as a cloud service (classic). All CMG deployments should use a virtual machine scale set.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/list-of-prerequisite-checks" target="_blank" rel="noopener"&gt;Check for a cloud management gateway (CMG) as a cloud service (classic).&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H2 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;Deprecated features&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-deprecated-features" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#deprecated-features" target="_blank" rel="noopener" aria-label="Permalink: Deprecated features"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;Learn about support changes before they're implemented in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/deprecated/removed-and-deprecated.md" target="_blank" rel="noopener"&gt;removed and deprecated items&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL dir="auto"&gt;
&lt;LI class="lia-align-left"&gt;System Center Update Publisher (SCUP) and integration with ConfigMgr planned end of support Jan 2024.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/deprecated/removed-and-deprecated-cmfeatures" target="_blank" rel="noopener"&gt;Removed and deprecated features for Configuration Manager.&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H2 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;Other updates&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-other-updates" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#other-updates" target="_blank" rel="noopener" aria-label="Permalink: Other updates"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;H4 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;Improvements to BitLocker&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-improvements-to-bitlocker" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#improvements-to-bitlocker" target="_blank" rel="noopener" aria-label="Permalink: Improvements to Bitlocker"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;This release includes the following improvements to BitLocker:&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL dir="auto"&gt;
&lt;LI class="lia-align-left"&gt;Starting in this release, this feature ensures proper verification of key escrow and prevents message drops. We now validate whether the key is successfully escrowed to the database, and only on successful escrow we add the key protector.&lt;/LI&gt;
&lt;LI class="lia-align-left"&gt;This feature now prevents a potential data loss scenario where BitLocker is protecting the volumes with keys that are never backed up to the database, in any failures to escrow happens.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-left"&gt;For more information on BitLocker management, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/protect/deploy-use/bitlocker/recovery-service" target="_blank" rel="noopener"&gt;Deploy BitLocker management.&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/protect/plan-design/bitlocker-management" target="_blank" rel="noopener"&gt;Plan for BitLocker management.&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL dir="auto"&gt;
&lt;LI class="lia-align-left"&gt;From this version of Configuration Manager, the Windows 11 readiness dashboard shows charts for Windows 23H2.&lt;/LI&gt;
&lt;LI class="lia-align-left"&gt;Defender Exploit Guards policy for controlled folder now accepts regex in the file path for apps.&amp;nbsp;For example, [C:\Folder\Subfolder\app?.exe] [C:\Folder1\Sub*Name]&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="markdown-heading" dir="auto"&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="heading-element lia-align-left" dir="auto" tabindex="-1"&gt;Next steps&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;A id="user-content-next-steps" class="anchor" href="https://github.com/BalaDelli/memdocs-pr/blob/release-cm2403-cb/memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2403.md#next-steps" target="_blank" rel="noopener" aria-label="Permalink: Next steps"&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P class="lia-align-left"&gt;At this time, version 2403 is released for slow ring (all in console update), Baseline will be updated in portal soon.&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/ARTICLE&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Configuration Manager team&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Additional resources:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/whats-new-incremental-versions" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;What’s New in Configuration Manager&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbdocs" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Documentation for Configuration Manager&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/CMAnnounce" target="_blank" rel="noopener noreferrer"&gt;Microsoft Configuration Manager announcement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/MEMVisionPaper" target="_blank" rel="noopener noreferrer"&gt;Microsoft Configuration Manager vision statement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/get-started/evaluate-with-lab-environment" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Evaluate Configuration Manager in a lab&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/upgrade-to-configuration-manager" target="_blank" rel="noopener noreferrer"&gt;Upgrade to Configuration Manager&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Configuration Manager Forums&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Configuration Manager Support&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Report an issue&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/configmgrsuggestions" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Provide suggestions&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 14 May 2024 04:45:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2403-for-microsoft-configuration-manager-current-branch/ba-p/4119853</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2024-05-14T04:45:41Z</dc:date>
    </item>
    <item>
      <title>A Deep Dive look into CMG Cloud Components (Part 2)</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/a-deep-dive-look-into-cmg-cloud-components-part-2/ba-p/4080963</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;In continuation with &lt;A href="https://techcommunity.microsoft.com/t5/configuration-manager-blog/a-deep-dive-look-into-cmg-app-registrations-part-1/ba-p/4080948" target="_self"&gt;&lt;STRONG&gt;Part 1&lt;/STRONG&gt;&lt;/A&gt; of the series, in this post, we will discuss &lt;STRONG&gt;CMG App-Registrations&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Once the Installation Wizard for the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; is complete, the Service Connection Point creates a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;t&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;hread for the Cloud Manager, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;which is&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; observable in the CloudMgr.log. Our &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;server app&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; establishes a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;onnection to Azure and applies the ARM&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Template to the Resource&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Group based on the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;w&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;izard &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;roperties provided&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; which deploys the following Azure resources:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Virtual machine scale set&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Key vault&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Load Balancer&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Network security Group&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Public IP address&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Virtual network&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Storage account&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;The &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;v&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;irtual &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;m&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;achines in the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;cale set are configured &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;using&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; PowerShell Desired State Configuration. This configuration&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; is&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; found in the Installation &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;d&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;irectory of ConfigMgr ("&amp;lt;ConfigMgr-Installalocation&amp;gt;\inboxes\cloudmgr.box\cmgdsc.zip"), is uploaded to the Storage Account and applied &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;from there&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. This configuration sets up the WebServer, installs additional WebComponents, removes legacy Crypto-Provider, disables RC4, and performs &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;leanup&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; t&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;asks for Internet Information Service.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; you&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; look at the Azure Resource Visualizer, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;it shows&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; the following configuration:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Virtual Machine Scale Set&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;VMSS&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; configuratio&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;n includes &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;the number of &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;i&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;nstances, their state, the operating system, and extensions like PowerShell DSC. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Although &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;VMSS supports &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;uto&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;caling&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; which includes&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; adding or removing &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;v&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;irtual &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;m&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;achines based on usage&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, this isn’t supported by ConfigMgr.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;This is because&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;onfiguration changes made outside of the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ConfigMgr&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; API aren't supported, as &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ConfigMgr&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; isn't aware of such changes, potentially leading to issues.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With the creation of the VMSS, an Enterprise Application Managed Identity is also created for accessing the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;k&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ey&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; v&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ault.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Key Vault&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Inside the Key Vault&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; for the CMG’s VMSS&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;there are&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;two&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ecrets&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; stored&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;T&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;he Storage Connection String (in case the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; is configured to act as a Distribution Point)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;T&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;he &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;local &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Administrator &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;assword for the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;v&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;irtual &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;m&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;achines inside the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;cale &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;et.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Additionally, we store the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ertificate for the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;By default, only two &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;pplications have access to the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;key v&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ault: our WebApp and the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;m&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;anaged &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;i&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;dentity of the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;cale &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;et.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Load Balancer&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The Load Balancer distributes traffic among multiple virtual machine instances &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;within&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. It’s configured with &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a f&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ront&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; end&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; IP &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;onfiguration linked to the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ublic &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ddress and three rules:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;One load balancer rule for the HTTPS-Traffic which is used for the backend pools and the HealthProbe&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Two Inbound NAT Rules for each VMSS-Instance&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE data-tablestyle="MsoTableGrid" data-tablelook="1184" aria-rowcount="3"&gt;
&lt;TBODY&gt;
&lt;TR aria-rowindex="1"&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Front End Port&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Back End Port&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Service&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR aria-rowindex="2"&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;50000&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;3389&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;RDP&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR aria-rowindex="3"&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;10124&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;8443&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Custom / CMG-Channel-Traffic&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The Remote Desktop Protocol is pre-created and used in combination with &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;an &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Azure Bastion avoiding external port exposure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;One of our peers in Ireland wrote one article specific to this Port 8443 – which you will also find in the Network Security Groups&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;: &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/cloud-management-gateway-inbound-rule-for-port-8443/ba-p/3833139" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Cloud Management Gateway - Inbound Rule for Port 8443 - Microsoft Community Hub&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Network Security Groups&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apart from Default Rules for Inbound/Outbound Security, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;there are&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; two &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;llow &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;r&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ules for &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;i&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;nbound&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; traffic&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE data-tablestyle="MsoTableGrid" data-tablelook="1184" aria-rowcount="3"&gt;
&lt;TBODY&gt;
&lt;TR aria-rowindex="1"&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Name&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Port&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Protocol&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Source&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Destination&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Action&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR aria-rowindex="2"&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;webHttpsRule&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;443&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;TCP&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;INTERNET&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;10.0.0.0/24&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Allow&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR aria-rowindex="3"&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;webHttps8443Rule&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;8443&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;TCP&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;INTERNET&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;10.0.0.0/24&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD data-celllook="0"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Allow&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;v&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;irtual &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ubnet is solely associated with this &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;r&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;esource &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;g&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;roup&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;’s &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Network Security Group&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; (NSG)&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Public IP Adress&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The Public IP Address serves its obvious purpose. Notably, the IP Address Assignment is static, ensuring the IP Address is retained unless this Resource is deleted.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; For details on Azure public IP addresses, see &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/virtual-network/ip-services/virtual-network-public-ip-address" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Create, change, or delete an Azure public IP address - Azure Virtual Network | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Virtual Network&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As outlined &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;above&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;there is&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; a single IP-Subnet 10.0.0.0/24 associated with the Scale Set NSG.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Storage Account&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Here we upload&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; and store all ConfigMgr &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;content &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;distributed to the CMG’s cloud storage &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;to &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Azure&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;b&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;lo&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;b s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;torage. &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We also create &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;t&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ables &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;within Azure the Azure storage account &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;for &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG l&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ogging, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;udit and &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;onfiguration &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;urpose&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;s&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Defender for Cloud Recommendations&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Security is vital for organizations – and of course we need to address those concerns. For Instance, if you use at the Defender for Cloud &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;r&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ecommendations you will see the following advices for &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;As mentioned earlier, the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; is a SaaS utilizing PaaS components, and modifications are not supported outside the Configuration Manager API.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; The following comments address each of the items called out in the screenshot above.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;A Log Analytics Agent or Azure Monitoring Agent is not necessary for this service.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;The entire content workflow is based on a Shared Key Access. Modifying this would break the content download. Additionally, this Secret Key is stored in the Key Vault.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;By default, when you create a new key vault, the Azure Key Vault firewall is disabled. All applications and Azure services can access the key vault and send requests to it. However, this configuration does not mean that any user will be able to perform operations on your key vault. The key vault still restricts access to secrets, keys, and certificates stored within it by requiring Microsoft Entra authentication and &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;enforcing &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;access policy permissions. In our case, only the WebApp and the Managed Identity of the VMSS have access to the Key Vault.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Restrict the Storage Account access to specific virtual networks or private link connections. In this case, the service itself is designed to manage devices regardless of their location without requiring a VPN.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Purge Protection helps in case of malicious deletion of a key vault, which could lead to permanent data loss. However, the risk for this scenario is low regarding data loss because, in the worst case, you would rebuild your CMG and upload your on-premises content again.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We hope this Blogpost provides a better understanding of the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, assisting &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ConfigMgr&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Admins in addressing queries from their Azure &amp;amp; Security Teams.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Disclaimer&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;The sample scripts are not supported under any Microsoft standard support program or service. The sample scripts are provided AS IS without warranty of any kind. Microsoft further disclaims all implied warranties including, without limitation, any implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample scripts and documentation remains with you. In no event shall Microsoft, its authors, or anyone else involved in the creation, production, or delivery of the scripts be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample scripts or documentation, even if Microsoft has been advised of the possibility of such damages.&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 04:41:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/a-deep-dive-look-into-cmg-cloud-components-part-2/ba-p/4080963</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2024-03-11T04:41:15Z</dc:date>
    </item>
    <item>
      <title>A Deep Dive look into CMG App-Registrations (Part 1)</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/a-deep-dive-look-into-cmg-app-registrations-part-1/ba-p/4080948</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this&amp;nbsp;&lt;STRONG&gt;comprehensive guide&lt;/STRONG&gt;, we delve into the&amp;nbsp;&lt;STRONG&gt;Cloud Management Gateway (CMG)&lt;/STRONG&gt;&amp;nbsp;within&amp;nbsp;&lt;STRONG&gt;Microsoft Configuration Manager (ConfigMgr)&lt;/STRONG&gt;. Our goal is to empower ConfigMgr administrators by providing insights and practical instructions for understanding and configuring CMG effectively. &lt;STRONG&gt;CMG&lt;/STRONG&gt;&amp;nbsp;acts as a gateway for internet clients to communicate with on-premises Configuration Manager infrastructure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The series is a collaborative effort between&amp;nbsp;&lt;STRONG&gt;Herbert Fuchs&lt;/STRONG&gt;, a&amp;nbsp;&lt;STRONG&gt;Cloud Solution Architect&lt;/STRONG&gt;, and&amp;nbsp;&lt;STRONG&gt;Beatriz Moran Serrano&lt;/STRONG&gt;, an experienced&amp;nbsp;&lt;STRONG&gt;Escalation Engineer&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before we embark, here's a quick reminder: the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; operates as Software as a Service (SaaS), leveraging Platform as a Service (PaaS) components. It's crucial to note that any modifications to this service outside the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ConfigMgr&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; API are not supported.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/manage/cmg/cloud-management-gateway-faq" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;CMG FAQ - Configuration Manager | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This feature and its requirements are extensively documented and can be found here:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/manage/cmg/overview" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Cloud management gateway overview - Configuration Manager | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Entra Application Registration&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before setting up a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, it's imperative to configure an Azure service for cloud management:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;During this process, you'll need to configure two Azure Application Registrations. You can opt to create these through the user interface or have an Azure administrator set them up beforehand &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;by&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; provid&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ing them&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; the necessary details&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; at &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/manage/cmg/manually-register-azure-ad-apps" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Manually register Microsoft Entra apps - Configuration Manager | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In either scenario, possessing the privileges of a Global Administrator is essential for creation, which is a one-time requirement &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;at the time the application registrations are created&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. Over the years, I've encountered amusing scenarios like Teams calls routed through multiple servers just to access the ConfigMgr server, highlighting the importance of proper administrative access. If you've experienced similar challenges, I recommend exploring Privileged Identity Management (PIM).&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/privileged-identity-management/pim-configure" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;What is Privileged Identity Management? - Microsoft Entra ID Governance | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;The WebApp Application Configuration&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Regardless of the method chosen, you'll end up with two Application Registrations: one for the web app and another for the client app.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity-platform/quickstart-register-app" target="_self"&gt;&lt;SPAN&gt;Quickstart: Register an app in the Microsoft identity platform - Microsoft identity platform | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The WebApp application is an integral part of the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; setup. It comes equipped with a Client Secret, Application ID URI, and strict restrictions against public client flows. This information is securely stored within the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ConfigMgr&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Database, including the secret.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; To view these details stored in the ConfigMgr database, use the following example SQL query:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;SELECT&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;*&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;FROM&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; AAD_Tenant_Ex tenant&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;INNER&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;JOIN&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; AAD_Application_Ex app &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;ON&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; tenant&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;ID &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;=&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; app&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;TenantDB_ID &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;AND&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; app&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;IsClientApp &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;=&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; 0&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;INNER&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;JOIN&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; AAD_CloudServiceApplicationRelations asso &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;ON&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; asso&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;AADApplicationID &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;=&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; app&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;ID&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;INNER&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;JOIN&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; Azure_CloudService &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;service&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;ON&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;service&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;ID &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;=&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; asso&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;ID&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;WHERE&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;service&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;ServiceType &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;=&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; 3&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These configurations facilitate authentication to Azure and enable automated processes such as the CMG ARM Template deployment. The acquisition of the authorization token follows the OAuth 2.0 authorization code flow model.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; See &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/entra/identity-platform/v2-oauth2-auth-code-flow" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft identity platform and OAuth 2.0 authorization code flow - Microsoft identity platform | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt; &lt;SPAN data-contrast="auto"&gt;for a deeper look at OAuth in Azure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With only one API permission configured, namely Directory.Read.All, the WebApp is granted access to read user, group, and device resources within Azure. This permission can only be granted by a Global Administrator.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; See &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/graph/permissions-reference" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Graph permissions reference - Microsoft Graph | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for complete deletes on Graph permissions.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Additionally, the WebApp exposes the API to a custom scope to restrict access to data and functionality protected by the API. Creating a scope here only grants delegated permissions, particularly for the Client-App.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Client&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;App Functionality&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;lient&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;pp serves as the service principal facilitating communication with the server app. While the server app exposes the API, the client app enables seamless interaction with the exposed API. It holds permission to access the API exposed by the server app.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For security reasons, the server app cannot be implemented on clients. Instead, clients utilize the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;client app&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; without storing any secrets, allowing them to request access to &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Entra ID&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; and delegate permissions &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;from&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; the server app. When the ConfigMgr client initiates a request to Azure for a token, it utilizes the Native App ID alongside the server app URI.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;[Example: Getting AAD (device) token with: ClientId = a0cf002e-40bf-4327-9caf-b59cc916ba6e, ResourceUrl = api://a8d6314d-b475-4f0b-a5da-2a768405e86a/955bc496-6637-4de9-8777-9689914b23e1, AccountId = &lt;A href="https://login.microsoftonline.com/" target="_blank" rel="noopener"&gt;https://login.microsoftonline.com/&lt;/A&gt;, Null parent window handle = true]&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This process is only triggered if the device is in an &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Entra or Entra hybrid &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;joined state. In cases where HTTPS-Only mode is enabled, authentication is facilitated through the client certificate. However, it's crucial to note the limitations of this setup; for instance, deploying applications to users &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;is&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; feasible without a hybrid or modern &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;device &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;identity configuration.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Also&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, it is&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; important to note &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;that &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;redentials provided for the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;pp&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; r&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;egistration information create an association to your &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Entra ID&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Tenant.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;The Cloud Management Installation&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We've completed the initial prerequisites with the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;pp &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;r&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;egistrations in Entra. However, to utilize and install the Cloud Management Gateway, we also require an Azure Subscription. Configuring Resource Providers is crucial for enabling this feature&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; as called out at &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/manage/cmg/configure-azure-ad#configure-azure-resource-providers" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Configure Microsoft Entra ID for CMG - Configuration Manager | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; these include the following:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft.KeyVault&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft.Storage&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft.Network&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft.Compute&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When initiating the Installation &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;w&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;izard for the Cloud Management Gateway &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;using&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ConfigMgr console&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, you'll encounter a list of configured Azure Active Directory Tenants and their associated WebApps. To select a Subscription, you must provide User Credentials with Owner Privileges at the Subscription Level. This role is essential as it's the only one capable of assigning RBAC Permissions. This privilege is only necessary once. As soon the Installation of the Cloud Management Gateway &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;is&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; successful you can remove this privilege.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; See &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/role-based-access-control/built-in-roles#owner" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Azure built-in roles - Azure RBAC | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for more info.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Attention: Our Support Teams also faced situations, because of Azure-Policy-Restrictions where it was necessary to assign the classic Co-Administrator. However, keep in mind that classic resources and administrators will retire soon&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; as called out at &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/role-based-access-control/classic-administrators" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Azure classic subscription administrators | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Within the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;wizard&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;you&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; also specify the new or existing &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Azure &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Resource Group in which the Cloud Management Gateway &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;will&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; be configured. On this Resource Group, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;the wizard sets&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; the Contributor Permission for &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; pre-configured Web Application.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;It's important to note that when using a Subscription with numerous Resource Groups, the Wizard might not display all Resource Groups in the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;d&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;rop-&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;d&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;own &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;list&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. In such cases, you have two options: create a new Resource Group via the User Interface Wizard or utilize Configuration Manager &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;mdlets to set up the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; The following example PowerShell snippet is for this latter option:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;$PW&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;=&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;ConvertTo-SecureString&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-AsPlainText&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;'PFX-Password'&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-Force&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;New-CMCloudManagementGateway&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-GroupName&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;'FOXWORKS-CMG'&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-ServerAppClientId&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;'xxxxxxx-89aa-4e89-bc3b-21390772d7e9'&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-ServiceCertPath&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;"C:\Certs\CMG\CMG.pfx"&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-ServiceCertPassword&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;$PW&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-SubscriptionId&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;'xxxxxx-b5e2-485a-ab19-edfd79b58fe1'&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-VMSSVMSize&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;StandardB2S&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-VMInstanceCount&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;1&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-EnableCloudDPFunction&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;$True&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-CheckClientCertRevocation&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;$false&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;-Region&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;WestEurope&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Our next key element in the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;w&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;izard is the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ertificate bound to the WebServers in the Virtual Machine Scale Se&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;t (VMSS) which a CMG is built from. This is&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; crucial for the Service&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; n&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ame and Deployment&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; n&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ame.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;It's recommended to use a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ublic &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ertificate. The Deployment&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; n&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ame is always linked to an Azure&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; r&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;egion. Since you cannot issue a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ertificate f&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;or a&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; cloudapp.azure.com&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; domain&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, configuring your DNS&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Servers (&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;i&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;nternal&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; and e&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;xternal) to redirect a request &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;for&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; the Service&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; n&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ame to the Deployment&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; n&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ame. While a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ublic &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ertificate incurs additional cost, it eliminates concerns &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;and issues with certificate trust&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; as th&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;is is&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; already available by default on Windows Systems&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; for certificates issued from public authorities&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. For customers who previously used a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ublic &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ertificate for their Classic &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, migrating to a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;VMSS&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; simplifies the process. Otherwise, setting up an additional &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;CMG&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; and &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;c&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;onnector is required, followed by monitoring,&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; and &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;reporting to ensure all clients receive updated &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;olicies.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;This blog post enhances understanding of CMG, helping ConfigMgr Admins address Azure and Security Teams’ queries about App Registrations. Continue learning in &lt;STRONG&gt;&lt;A href="https://techcommunity.microsoft.com/t5/configuration-manager-blog/a-deep-dive-look-into-cmg-cloud-components-part-2/ba-p/4080963" target="_self"&gt;Part 2&lt;/A&gt;&lt;/STRONG&gt; of the series.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Disclaimer&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;The sample scripts are not supported under any Microsoft standard support program or service. The sample scripts are provided AS IS without warranty of any kind. Microsoft further disclaims all implied warranties including, without limitation, any implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample scripts and documentation remains with you. In no event shall Microsoft, its authors, or anyone else involved in the creation, production, or delivery of the scripts be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample scripts or documentation, even if Microsoft has been advised of the possibility of such damages.&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 04:45:05 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/a-deep-dive-look-into-cmg-app-registrations-part-1/ba-p/4080948</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2024-03-11T04:45:05Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager technical preview version 2401</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2401/ba-p/4042177</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_DiagDash" class="heading-anchor"&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Automated diagnostic Dashboard for Software Update Issues&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;A new dashboard is added to the console under monitoring workspace which shows the diagnosis of the software update issues in your environment. You can fix software update issues based on CM troubleshooting documentation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorBala_Delli_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;Support for ARM64 Operating System Deployment&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configuration Manager now extends its operating system deployment capabilities to Windows 11 ARM64 devices. This includes the integration of features such as boot image import, driver import, and pull distribution point, enhancing the deployment experience in addition to the existing 2311tp feature.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Introducing Centralized Search box: Effortlessly Find What You Need in the Console!&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Users can now use the global search box in CM console which streamlines the search experience and centralizes access to information. This enhances the overall usability, productivity and effectiveness of CM. Users no longer need to navigate through multiple nodes or sections/ folders to find information they require, saving valuable time and effort.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorBala_Delli_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Microsoft Azure Active Directory rebranded to Microsoft Entra ID&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting Configuration Manager version 2403, Microsoft Azure Active Directory is renamed to Microsoft Entra ID within Configuration Manager.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_TSVar" class="heading-anchor"&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Enhancement in Deploying Software Packages with Dynamic Variables&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;With the introduction of retry count in UI administrators while deploying the "Install Software Package" via Dynamic variable with "Continue on error" unchecked to clients, won't be notified with task sequence failures even if package versions on the distribution point are updated.&lt;/P&gt;
&lt;DIV id="tinyMceEditorBala_Delli_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 id="bkmk_CMGVMSS" class="heading-anchor"&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Enabling Auto-Image Patching for CMG Virtual Machine Scale Set&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;With this version of CM Configuration Manager Cloud Management Gateway (CMG) Virtual Machine Scale introduces enabling of Auto-Image Patching for seamless and automated updates to ensure your environment stays current and secure with this efficient solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_win23H2" class="heading-anchor"&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Window 11 Readiness dashboard to support Windows 23H2&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;With this version of Configuration Manager, the Windows 11 readiness dashboard will show charts for Windows 23H2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_EHTTP" class="heading-anchor"&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;HTTPS or Enhanced HTTP should be enabled for client communication from this version of Configuration Manager&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;HTTP-only communication is deprecated, and support is removed from this version of Configuration Manager. Please enable HTTPS or Enhanced HTTP for client communication.&lt;/P&gt;
&lt;DIV id="tinyMceEditorBala_Delli_3" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 id="bkmk_CMgclassic" class="heading-anchor"&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Upgrade to CM 2403 is blocked if CMG V1 is running as a cloud service (classic)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;The option to upgrade Configuration Manager 2403 is blocked if you're running cloud management gateway V1 (CMG) as a cloud service (classic).All CMG deployments should use a virtual machine scale set.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_ServerS" class="heading-anchor"&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Windows Server 2012/2012 R2 operating system site system roles aren't supported from this version of Configuration Manager&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting 2403, Windows Server 2012/2012 R2 operating system site system roles aren't supported in any CB releases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Improvements to Bitlocker&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;This release includes the following improvements to Bitlocker:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Based on your feedback, this feature ensures proper verification of key escrow and prevents message drops. We now validate whether the key is successfully escrowed to the database, and only on successful escrow we add the key protector.&lt;/LI&gt;
&lt;LI&gt;This feature prevents a potential data loss scenario where BitLocker is protecting the volumes with keys that are never backed up to the database, in any failures to escrow happens.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Known issue&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Upgrading from TP 2311 to 2401, you will not be able to upgrade If Resource access slider is already in Intune. This is a regression caused from previous TP, please move any other slider (Apps/ End point) to CM or Intune then choose to apply&amp;nbsp;--&amp;gt; Ok. After this try upgrading the site to TP 2401 once done you can revert back (Apps/ End &lt;/FONT&gt;point) to old settings. This is already fixed in our code.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;Update 2401 for Technical Preview Branch is available in the Microsoft Configuration Manager Technical Preview console. For new installations, the 2401 baseline version of Microsoft Configuration Manager Technical Preview Branch is&amp;nbsp;available on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/MECM2206TP-Baseline" target="_self" rel="noreferrer"&gt;CM2401TP-Baseline&lt;/A&gt;&amp;nbsp;or from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager-technical-preview" target="_self" rel="noreferrer noopener"&gt;Eval center&lt;/A&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Technical Preview Branch releases give you an opportunity to try out new Configuration Manager features in a test environment before they are made generally available.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;We would love to hear your thoughts about the latest Technical Preview! Send us&amp;nbsp;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;feedback&lt;/A&gt;&amp;nbsp;directly from the console.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Thanks,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;The Configuration Manager team&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Configuration Manager Resources:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/core/get-started/technical-preview" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager Technical Previews&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-system-center-configuration-manager-and-endpoint-protection-technical-preview" target="_blank" rel="noopener noreferrer"&gt;Try the Configuration Manager Technical Preview Branch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Forums&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 03:30:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2401/ba-p/4042177</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2024-02-07T03:30:16Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager technical preview version 2311</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2311/ba-p/3991736</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_Folderscript" class="heading-anchor"&gt;&lt;FONT size="6"&gt;Folder support for Scripts node in Software Library&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;FONT size="4"&gt;You can now organize scripts by using folders. This change allows for better categorization and management of scripts. Full Administrator and Operations Administrator roles can manage the folders&lt;/FONT&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorBala_Delli_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;FONT size="6"&gt;&lt;STRONG&gt;New parameter SoftwareUpdateO365Language is added to Save-CMSoftwareUpdate cmdlet&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;A new parameter&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SoftwareUpdateO365Language&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is now added to Powershell Save-CMSoftwareUpdate cmdlet. Customers now don't, have to check a specific language in the SUP Properties (causing a metadata download for that language for all updates).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;PowerShell Commandlet:&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Save-CMSoftwareUpdate – SoftwareUpdateO365Language &amp;lt;language name&amp;gt; (&amp;lt;region name&amp;gt;)"&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="alert is-info"&gt;
&lt;P class="alert-title"&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Note: Languages need to be in O365 format to be consistent with Admin Console UI e.g. "Hungarian (Hungary)"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="6"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Support for Arm64 Operating System Deployment&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Configuration Manager operating system deployment support is now added on Windows 11 Arm64 devices. Currently Importing and customizing Arm64 boot images, Wipe and load Task Sequence, Media creation Task sequence and WDS PXE for Arm64 is supported.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_RAblock" class="heading-anchor"&gt;&lt;FONT size="6"&gt;Resource access profiles and deployments will block Configuration manager upgrade&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Any configured Resource access profiles and associated deployments will block the Configuration manager upgrade. Please consider deleting them and moving the co-management workload for Resource Access (if co-managed) to Intune.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_DGEP" class="heading-anchor"&gt;&lt;FONT size="6"&gt;WildCard Support added in Defender Exploit Guard policy for Controlled Folders&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Defender Exploit Guards policy for Controlled Folder now accepts Regex in the file path for apps.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;E.g. [C:\Folder\Subfolder\app?.exe] [C:\Folder1\Sub*Name]&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="6"&gt;&lt;STRONG&gt;Other Updates&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="6"&gt;&lt;STRONG&gt;Troubleshooting Dashboard for Software Update Issues (Teaser)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;A new dashboard is added to the console under monitoring workspace which will diagnose software update issue in your environment. You can fix these issues based on troubleshooting documentations. Future release will have more common errors, automated troubleshooting and remediation added.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;Update 2311 for Technical Preview Branch is available in the Microsoft Configuration Manager Technical Preview console. For new installations, the 2311 baseline version of Microsoft Configuration Manager Technical Preview Branch is&amp;nbsp;available on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/MECM2206TP-Baseline" target="_self" rel="noreferrer"&gt;CM2311TP-Baseline&lt;/A&gt;&amp;nbsp;or from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager-technical-preview" target="_self" rel="noreferrer noopener"&gt;Eval center&lt;/A&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Technical Preview Branch releases give you an opportunity to try out new Configuration Manager features in a test environment before they are made generally available.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;We would love to hear your thoughts about the latest Technical Preview! Send us&amp;nbsp;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;feedback&lt;/A&gt;&amp;nbsp;directly from the console.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Thanks,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;The Configuration Manager team&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Configuration Manager Resources:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/core/get-started/technical-preview" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager Technical Previews&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-system-center-configuration-manager-and-endpoint-protection-technical-preview" target="_blank" rel="noopener noreferrer"&gt;Try the Configuration Manager Technical Preview Branch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Forums&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 18:54:25 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2311/ba-p/3991736</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-11-27T18:54:25Z</dc:date>
    </item>
    <item>
      <title>Update 2309 for Microsoft Configuration Manager current branch is now available.</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2309-for-microsoft-configuration-manager-current-branch/ba-p/3928963</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Site infrastructure&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="introducing-sql-odbc-driver-support-for-configuration-manager" class="heading-anchor"&gt;&lt;FONT size="5"&gt;Introducing SQL ODBC driver support for Configuration Manager&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Starting with Configuration Manager 2309 release, Configuration Manager requires the installation of the ODBC driver for SQL server 18.1.0 or later as a prerequisite, &lt;A href="https://learn.microsoft.com/sql/connect/odbc/download-odbc-driver-for-sql-server?view=sql-server-ver16" target="_self"&gt;SQL ODBC Download&lt;/A&gt;. This prerequisite is required when you create a new site or update an existing one and on all remote roles.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="alert is-primary"&gt;
&lt;P class="alert-title"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Important&lt;/P&gt;
&lt;P&gt;Microsoft ODBC Driver for SQL Server 18.1.0 or later needs to be installed on Site Servers and site system roles before upgrading to 2309 version. Do not uninstall SQL native client 11 until we call out in further communications. Configuration Manager doesn't manage the updates for the ODBC driver, ensure that this component is up to date.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/configs/site-and-site-system-prerequisites#sql-odbc-driver-for-the-site-server" target="_self" data-linktype="relative-path"&gt;SQL ODBC driver for the site server&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;SPAN&gt;Option to schedule Scripts execution time&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting in Configuration Manager current branch version 2309, you can now schedule scripts' runtime in UTC. The run Script Wizard now offers a scheduling option that enables administrators to schedule the execution of scripts. It provides a convenient way to automate the running of scripts on managed devices according to specified schedules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information, see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/apps/deploy-use/create-deploy-scripts#schedule-scripts-runtime" target="_self" data-linktype="relative-path"&gt;Schedule scripts' runtime&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="external-service-notification-run-details-from-azure-logic-application" class="heading-anchor"&gt;&lt;FONT size="5"&gt;External service notification Run details from Azure Logic application. &lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;Starting in Configuration Manager current branch version 2309, when Azure Logic App generates notifications related to specific events, CM can now capture and display these notifications. This integration enables the monitoring of Azure Logic App notifications directly within the MCM console, providing a centralized location for tracking critical events, taking appropriate actions and maintains a high level of operational efficiency.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information, see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/manage/external-notifications#monitor-the-workflow" target="_self" data-linktype="relative-path"&gt;External service notification&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="new-site-maintenance-task-delete-aged-task-execution-status-messages-is-now-available-on-primary-servers-to-clean-up-data-older-than-30-days-or-configured-number-of-days" class="heading-anchor"&gt;&lt;FONT size="5"&gt;New Site Maintenance task “Delete Aged Task Execution Status Messages” is now available on primary servers to clean up data older than 30 days or configured number of days&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting in Configuration Manager current branch version 2309, you can now enable this feature by utilizing the Site Maintenance Window or using PowerShell Commandlet. By default, it has been set to run on Saturday and delete the data older than 30 days. It does so by cleaning up [dbo].TaskExecutionStatus Table &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example : PowerShell Commandlet:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#000000"&gt;&lt;CODE&gt;Set-CMSiteMaintenanceTask -Sitecode "XXX" -MaintenanceTaskName "Delete Aged Task Execution Status Messages" -DaysOfWeek Friday&lt;/CODE&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/manage/reference-for-maintenance-tasks#delete-aged-task-execution-status-messages" target="_self" data-linktype="relative-path"&gt;Delete Aged Task Execution Status Messages&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="software-updates" class="heading-anchor"&gt;&lt;FONT size="5"&gt;Software updates&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="update-orchestrator-service-uso-for-windows-11-22h2-or-later-with-windows-native-reboot-experience" class="heading-anchor"&gt;&lt;FONT size="5"&gt;Update Orchestrator Service (USO) for Windows 11 22H2 or later with windows native reboot experience &lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;In Configuration Manager current branch version 2309, when installing software updates from Configuration Manager, administrators can now choose to use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;native Windows Update restart&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;experience. To use this feature, client devices must be running Windows build 22H2 or later. From the Computer Restart client device settings, ensure that Windows is selected as the restart experience. Branding information is included in the Windows restart notification for updates that require restart. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/deploy/device-restart-notifications#device-restart-notifications-in-configuration-manager" target="_self" data-linktype="relative-path"&gt;Device restart notifications&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="maintenance-window-creation-using-ps-cmdlet" class="heading-anchor"&gt;&lt;FONT size="5"&gt;Maintenance window creation using PS cmdlet &lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;We've extended the Offset parameter for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Maintenance&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;windows. The&lt;/STRONG&gt;&amp;nbsp;cmdlet New-CMMaintenanceWindow is used to create a maintenance window for a collection. Earlier the Offset parameter could be set only between 0 and 4. Now it has been extended between 0 to 7.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example : PowerShell Commandlet:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;New-CMSchedule -Start (Get-Date) -DayOfWeek Monday -WeekOrder Second -RecurCount 1 -OffSetDay 6&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;OS deployment&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="osd-preferred-mp-option-for-pxe-boot-scenario" class="heading-anchor"&gt;&lt;FONT size="5"&gt;OSD preferred MP option for PXE boot scenario &lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting in Configuration Manager current branch version 2309, Preferred Management Point (MP) option will now allow&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;PXE clients&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to communicate to an initial lookup MP and receive the list of MP(s) to be used for further communication. When the option is enabled, it allows an MP to redirect the PXE client to another MP, based on the client location in the site boundaries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information, see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/configure/install-and-configure-distribution-points" target="_self" data-linktype="relative-path"&gt;Install-and-configure-distribution-points&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;Enable Bitlocker through ProvisionTS &lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;In Configuration Manager current branch version 2309, Escrowing recovery key to Config Manager Database is now supported using ProvisionTS. ProvisionTS is the task sequence that is executed at the time of provisioning. As a result, device can escrow the key to Config Manager Database instantly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/osd/deploy-use/preprovision-bitlocker-in-windows-pe" target="_self" data-linktype="relative-path"&gt;Preprovision-BitLocker-in-Windows-PE&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="windows-11-edition-upgrade-using-cm-policy-settings" class="heading-anchor"&gt;&lt;FONT size="5"&gt;Windows 11 Edition Upgrade using CM Policy settings &lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting in Configuration Manager current branch version 2309, administrator can now create a policy using edition upgrade in Configuration Manager to update the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Windows 11 edition&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information, see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/compliance/deploy-use/upgrade-windows-version" target="_self" data-linktype="relative-path"&gt;Upgrade Windows devices to a new edition&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="windows-11-upgrade-readiness-dashboard" class="heading-anchor"&gt;&lt;FONT size="5"&gt;Windows 11 Upgrade Readiness Dashboard &lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting in Configuration Manager current branch version 2309, administrators can use this dashboard to devise their windows 11 upgrade strategy and discover the devices in the organization, which are ready for Windows 11 Upgrade. This Dashboard also provides a count by installed Feature update version and a view of all Windows devices inside the organization. Administrators can create a collection of Windows 11 ready for upgrading devices and roll out feature updates to them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information, see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/osd/deploy-use/manage-windows-11-readiness-dashboard" target="_self" data-linktype="relative-path"&gt;Manage Windows 11 readiness dashboard ,&lt;/A&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;For Co-managed devices, see &lt;A href="https://learn.microsoft.com/en-us/mem/intune/protect/windows-update-compatibility-reports#use-the-windows-feature-update-device-readiness-report" target="_self"&gt;Use Windows compatibility reports for Windows 10 and Windows 11 updates in Intune&lt;/A&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="cloud-attached-management" class="heading-anchor"&gt;Cloud-attached management&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;New Cloud Management Gateway (CMG) creation via Console &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting in Configuration Manager current branch version 2309, We have enhanced security of web (server) app for the creation of CMG. For new CMG creation, users can select tenant and the app name using the Azure AD tenant name. After selecting tenant and app name the sign-in button appears, follow rest of the process as per the setup CMG.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="alert-title"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Note&lt;/P&gt;
&lt;P&gt;Pre existing CMG customers must update their web server app by navigating to Azure Active Directory Tenants node --&amp;gt; select the tenant --&amp;gt; select the server app --&amp;gt; click on "update application settings".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information, see&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://learn.microsoft.com/en-us/mem/configmgr/core/clients/manage/cmg/configure-azure-ad" target="_self" data-linktype="relative-path"&gt;Configure Azure Active Directory for CMG&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="new-cloud-management-gateway-cmg-creation-via-powershell" class="heading-anchor"&gt;&lt;FONT size="5"&gt;New Cloud Management Gateway (CMG) creation via PowerShell &lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;You can now create CMG Server app via PowerShell cmdlet, you need to specify TenantID in the argument:&lt;/P&gt;
&lt;P&gt;PowerShell Commandlet:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Set-UpdateServerApplication – 'TenantID'&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;If you try to create the CMG before updating RedirectUrl, you get an error "Your server Application needs to be updated".&lt;/P&gt;
&lt;P&gt;PowerShell command: &lt;CODE&gt;Set-UpdateServerApplication&lt;/CODE&gt; to update your App, and then try again to create CMG.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="alert is-info"&gt;
&lt;P class="alert-title"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Note&lt;/P&gt;
&lt;P&gt;For new customers, before creating CMG, create Azure AD web server app and execute the new PowerShell commandlet script.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="alert is-info"&gt;
&lt;P&gt;&lt;FONT size="6"&gt;&lt;SPAN&gt;Deprecated features&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Configured resource access policies will block Configuration Manager 2403 upgrade, remove existing policies and move the slider to Intune. Please action before January 2024, read the &lt;A href="https://learn.microsoft.com/mem/configmgr/protect/plan-design/resource-access-deprecation-faq#what-happens-when-you-upgrade-to-cm-2403--" target="_self"&gt;FAQ.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/deprecated/removed-and-deprecated-cmfeatures" target="_self" data-linktype="relative-path"&gt;Removed and deprecated features for Configuration Manager&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;For more details and to view the full list of new features in this update, check out our&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/whats-new-in-version-2309" target="_blank" rel="noopener noreferrer"&gt;What’s new in version 2309 of Microsoft Configuration Manager&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;documentation.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="6"&gt;&lt;SPAN&gt;Other updates&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Patching guidance for MCM customers migrating to Azure&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN data-contrast="auto"&gt;Migrating to Azure? Managing your on-prem infrastructure through &lt;/SPAN&gt;&lt;SPAN&gt;Microsoft Configuration Manager (MCM)&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN data-contrast="auto"&gt;? Have you figured out how you would patch your infrastructure on Azure? This article provides steps that you can follow to patch your migrated virtual machines on Azure.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Note: MCM manages both devices and servers. This blog provides guidance for servers migrating to Azure. For devices, please refer to &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-in/security/business/endpoint-management/microsoft-intune?rtc=1%22%20HYPERLINK%20%22https://www.microsoft.com/en-in/security/business/endpoint-management/microsoft-intune?rtc=1%22%20HYPERLINK%20%22https://www.microsoft.com/en-in/security/business/endpoint-management/microsoft-intune?rtc=1" target="_self"&gt;&lt;SPAN&gt;Microsoft Intune￼&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/mem/configmgr/core/support/azure-migration-tool" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Azure Migration tool&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; has been &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;helping you to programmatically create Azure virtual machines (VMs) for Configuration Manager and install the different site roles with default settings. Validation of the new roles, followed by removal of the on-premises site system role enables MCM in Azure, provides you all the on-premises capabilities and experiences in Azure.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Additionally, you can leverage native &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/update-center/overview?tabs=azure-vms" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Azure Update Manager&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; to &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;manage and govern&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; update compliance for Windows and Linux machines across your deployments in Azure, on-premises, and on the other cloud platforms from a single dashboard, with no operational cost for managing the patching infrastructure. Azure Update Manager shares similarities with the update management component of MCM, designed as a standalone Azure service to provide SaaS experience on Azure to manage hybrid environments.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Both MCM in Azure and Azure Update Manager can fulfil your patching requirements and the ultimate choice depends on your specific needs and preferences.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;MCM in Azure would allow you to continue using existing investments in Microsoft Configuration Manager and familiar processes for &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;maintaining &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;the patch update management cycle for Windows virtual machines.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;On the other hand, through Azure Update Manager, you can achieve consistent management of VMs and operating system updates across your cloud and hybrid environment. Moreover, you would not need to maintain Azure virtual machines for hosting the different Configuration Manager roles and would not need a MCM license, hence reducing the total cost for maintaining the patch update management cycle for all machines in your environment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;For more details, please refer the actual &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/understand/configuration-manager-on-azure" target="_self"&gt;CM on Azure FAQ&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;For assistance with the upgrade process, please post your questions in the Site and Client Deployment forum&lt;/SPAN&gt;.&amp;nbsp;&lt;SPAN&gt;Send us your Configuration Manager feedback through&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Feedback&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;in the Configuration Manager console.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Continue to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/configmgrsuggestions" target="_blank" rel="noopener noreferrer"&gt;share and vote on ideas&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;about new features in Configuration Manager.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Configuration Manager team&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Additional resources:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/whats-new-incremental-versions" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;What’s New in Configuration Manager&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbdocs" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Documentation for Configuration Manager&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/CMAnnounce" target="_blank" rel="noopener noreferrer"&gt;Microsoft Configuration Manager announcement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/MEMVisionPaper" target="_blank" rel="noopener noreferrer"&gt;Microsoft Configuration Manager vision statement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/get-started/evaluate-with-lab-environment" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Evaluate Configuration Manager in a lab&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/upgrade-to-configuration-manager" target="_blank" rel="noopener noreferrer"&gt;Upgrade to Configuration Manager&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Configuration Manager Forums&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Configuration Manager Support&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Report an issue&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/configmgrsuggestions" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Provide suggestions&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 15 Nov 2023 09:18:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2309-for-microsoft-configuration-manager-current-branch/ba-p/3928963</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-11-15T09:18:08Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager technical preview version 2307</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2307/ba-p/3886631</link>
      <description>&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 id="bkmk_Editionupgrade" class="heading-anchor"&gt;Windows 11 Edition Upgrade using Configuration Manager policy settings.&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Administrator can now create a policy using edition upgrade in Configuration Manager to update the Windows 11 edition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 id="bkmk_Win11dashboard" class="heading-anchor"&gt;Windows 11 Upgrade Readiness Dashboard&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Administrators can use this dashboard to devise their Windows 11 upgrade strategy and discover the devices in the organization, which are ready for Windows 11 Upgrade. This Dashboard also provides a count by installed Feature update version and a view of all Windows devices inside the organization. Administrators can create a collection of Windows 11 ready for upgrading devices and roll out feature updates to them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;img /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Following four charts are offered in this dashboard:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows Device Information- Shows count of Windows 7, 8, 10 and 11 devices in your organization.&lt;/LI&gt;
&lt;LI&gt;Feature Update Version – Shows count of each feature update Version in your organization.&lt;/LI&gt;
&lt;LI&gt;Upgrade Experience Indicators – Shows information for each device, which can be in any of these states:
&lt;UL&gt;
&lt;LI&gt;Cannot Upgrade (Red Color) devices that cannot be upgraded to windows 11.&lt;/LI&gt;
&lt;LI&gt;App Upgrade/Uninstall required (Yellow Color) devices that need an application update or uninstall before upgrading to Windows 11.&lt;/LI&gt;
&lt;LI&gt;App/Driver upgrade required (Orange Color) devices that need application upgrade to windows 11.&lt;/LI&gt;
&lt;LI&gt;Ready for Upgrade (Green Color) devices that are capable of Windows 11 upgrade.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Windows 11 Minimum Hardware Requirement – Showcases the minimum hardware and software requirements needed to support Windows 11.&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 id="bkmk_Schedulescript" class="heading-anchor"&gt;Option to schedule scripts' runtime&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;The Run Script wizard now offers a scheduling option which enables administrators to schedule the future execution time of the scripts. It provides a convenient way to automate the running of scripts on managed devices according to specified schedules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_Externalnotification" class="heading-anchor"&gt;External service notification Run details from Azure Logic application.&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;This integration enables the monitoring and management of Azure Logic App notifications directly within the Configuration Manager console, providing a centralized location for tracking critical events, taking appropriate actions and maintains a high level of operational efficiency.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="alert is-info"&gt;
&lt;P class="alert-title"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To use this feature a valid Azure AD web app is required. Please deploy the Azure services for Administration service management under \Administration\Overview\Cloud Services\Azure Services. If the service is already deployed, admin can use the existing web application to view Run details from Azure logic app.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;View Status wizard&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Known issue&lt;/STRONG&gt; :- An unexpected error can occur while configuring the Azure service web app for Administration service management which can be ignored as it does not affect the service creation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_PSMW" class="heading-anchor"&gt;Maintenance window creation using PS cmdlet.&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Maintenance windows are recurring periods of time when the Configuration Manager client can run tasks.&lt;/P&gt;
&lt;P&gt;PowerShell Commandlet:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;New-CMMaintenanceWindow&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/CODE&gt;is used to create a maintenance window for a collection. Earlier the Offset parameter could be set only between 0 and 4. Now it has been extended between 0 to 7.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_USOreboot" class="heading-anchor"&gt;Update Orchestrator Service (USO) for Windows 11 22H2 or later with windows native reboot experience&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;When installing software updates from Configuration Manager, administrators can now choose to use the native Windows Update restart experience. To use this feature, client devices must be running Windows build 22H2 or later. From the Computer Restart client device settings, ensure that Windows is selected as the restart experience. Branding information will be included in the Windows restart notification for updates that require restart.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Steps to enable Client settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reboot Notification&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;img /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Update 2307 for Technical Preview Branch is available in the Microsoft Configuration Manager Technical Preview console. For new installations, the 2307 baseline version of Microsoft Configuration Manager Technical Preview Branch is&amp;nbsp;available on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/MECM2206TP-Baseline" target="_self" rel="noreferrer noopener"&gt;CM2307TP-Baseline&lt;/A&gt;&amp;nbsp;or from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager-technical-preview" target="_self" rel="noreferrer noopener"&gt;Eval center&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Technical Preview Branch releases give you an opportunity to try out new Configuration Manager features in a test environment before they are made generally available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would love to hear your thoughts about the latest Technical Preview! Send us&amp;nbsp;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;feedback&lt;/A&gt;&amp;nbsp;directly from the console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;The Configuration Manager team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Configuration Manager Resources:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/core/get-started/technical-preview" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager Technical Previews&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-system-center-configuration-manager-and-endpoint-protection-technical-preview" target="_blank" rel="noopener noreferrer"&gt;Try the Configuration Manager Technical Preview Branch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Forums&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 03:41:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2307/ba-p/3886631</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-08-02T03:41:09Z</dc:date>
    </item>
    <item>
      <title>Microsoft Configuration Manager 2309 - Press release</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/microsoft-configuration-manager-2309-press-release/ba-p/3886659</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;SPAN data-contrast="none"&gt;This article provides information about Microsoft Configuration Manager 2309 release. To learn about the Configuration Manager, see &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/understand/microsoft-endpoint-manager-faq" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Configuration Manager FAQ&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Configuration Manager 2309 release is planned for October 2023. With this release we are bringing in new features and additional enhancements to the existing feature set. Configuration Manager 2305 Technical Preview had new enhancements, likewise, 2307 Technical Preview will bring additional capabilities to customers. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;SPAN data-contrast="none"&gt;Here is the list of features that are being introduced during Configuration Manager 2307 TP and 2309 Current Branch focusing on key customer value/asks and delivering high quality product updates.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;SPAN data-contrast="none"&gt;Some of the key additions are 1) Operating system deployment support for Windows 23H2; 2) Customers can perform Windows 11 edition upgrade like they did for Windows 10 edition upgrade from Professional to Enterprise Operating System; 3) a Windows 11 readiness dashboard for administrators or management to decide on how many devices are ready to upgrade to latest Windows 11 operating system, 4) Script runtime can be scheduled with simple steps, and c&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;ustomers can schedule the scripts to run &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;on a particular time from the Primary Site time zone 5) Unified Service Orchestrator (USO) integration with Configuration Manager provides native windows update reboot experience( pre-release feature), and 6) Improvements in external notifications (Console Connectors).&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;SPAN data-contrast="none"&gt;Furthermore we added critical customer asks such as, 1) Operating Systems Deployment (OSD) Preferred MP options which enables IT admins to choose a preferred Management point for PXE boot scenario; 2) Task Execution Status messages can now be deleted from primary servers which are older than 30 days, or any configured number of days; 3) CMG creation using third party app via console or PowerShell instead of the first party app; 4) Attack Surface Reduction (ASR) capability now marks server SKU as compliant only after enforcement is completed successfully; 5) Enable BitLocker through provisionTS task sequence option available on CM console to save the recovery key on CM database; 6) Client certificate state in console (self-signed) will now match state in control panel (PKI) applet; 7) Discrepancy in App Summarization report in console is corrected; &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Synchronization of collection memberships to Azure AD groups now optimized to show the entire set of members; 9) Patch downloader log size increased for troubleshooting purposes.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;SPAN data-contrast="none"&gt;We value your feedback on the upcoming functionalities to be released as it will contribute greatly to the enhancement of the product.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Thanks,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;The Configuration Manager team&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Additional resources:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/whats-new-incremental-versions" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;What’s New in Configuration Manager&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/cmcbdocs" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Documentation for Configuration Manager&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/CMAnnounce" target="_blank" rel="noopener noreferrer"&gt;Microsoft Configuration Manager announcement&lt;/A&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/MEMVisionPaper" target="_blank" rel="noopener noreferrer"&gt;Microsoft Configuration Manager vision statement&lt;/A&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/get-started/evaluate-with-lab-environment" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Evaluate Configuration Manager in a lab&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/upgrade-to-configuration-manager" target="_blank" rel="noopener noreferrer"&gt;Upgrade to Configuration Manager&lt;/A&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Configuration Manager Forums&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Configuration Manager Support&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Report an issue&lt;/SPAN&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;A href="https://aka.ms/configmgrsuggestions" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Provide suggestions&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 28 Jul 2023 17:42:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/microsoft-configuration-manager-2309-press-release/ba-p/3886659</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-07-28T17:42:42Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager technical preview version 2305</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2305/ba-p/3832110</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="bkmk_OSDPXE" class="heading-anchor"&gt;OSD preferred MP option for PXE boot scenario&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Preferred Management Point (MP) option will now allow PXE clients to communicate to an initial lookup MP and receive the list of MP(s) to be used for further communication. When the option is enabled, it allows an MP to redirect the PXE client to another MP, based on the client location in the site boundaries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="bkmk_Task" class="heading-anchor"&gt;New Site Maintenance task “Delete Aged Task Execution Status Messages” is now available on primary servers to clean up data older than 30 days or configured number of days&lt;/H2&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;You can enable this feature by utilizing the Site Maintenance Window or using PowerShell Commandlet. By default, it has been set to run on Saturday and delete the data older than 30 days. It does so by cleaning up [dbo].TaskExecutionStatus Table&lt;/P&gt;
&lt;P&gt;Example : Set-CMSiteMaintenanceTask -Sitecode "XXX" -MaintenanceTaskName "Delete Aged Task Execution Status Messages" -DaysOfWeek Friday&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 id="bkmk_CMGC" class="heading-anchor"&gt;CMG creation using third PartyApp via Console&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;We have deprecated the use of first party app for the creation of CMG. Now, CMG uses a third party server app to get bearer tokens. For CMG creation, users can select tenant and the app name using the Azure AD tenant name. After selecting tenant and app name the sign-in button appears. Existing Customers, must update their server app as current version, doesn't have the Redirect to- "&lt;A href="http://localhost" target="_blank" rel="noopener"&gt;http://localhost&lt;/A&gt;"&lt;/P&gt;
&lt;P&gt;To update the server app, you can navigate to Azure Active Directory Tenants node --&amp;gt; select the tenant --&amp;gt; select the server app --&amp;gt; click on "update application settings".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_CMGP" class="heading-anchor"&gt;CMG creation using third Party ServerApp via PowerShell&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;To create CMG using third party Server app via PowerShell cmdlet, you need to specify TenantID in the argument:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PowerShell Commandlet:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Set-UpdateServerApplication – TenantID&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;If you're utilizing the existing Azure AD server app, when existing (nonupdated) Azure AD server app is used, ensure that the server app has RedirectUrl="&lt;A href="http://localhost”" target="_blank" rel="noopener"&gt;http://localhost”&lt;/A&gt; added in Azure portal and in TableAAD_Application_EX in Database.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you try to create the CMG before updating RedirectUrl, you get an error "Your server Application needs to be updated".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run this PowerShell command: &lt;CODE&gt;Set-UpdateServerApplication&lt;/CODE&gt; to update your App, and then try again to create CMG.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="alert-title"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Note&lt;/P&gt;
&lt;P&gt;For new customers, before creating CMG, create Azure AD server app that contains the RedirectUrl="&lt;A href="http://localhost”" target="_blank" rel="noopener"&gt;http://localhost”&lt;/A&gt; in your App. Once redirect URL and database settings are complete, you can execute the new PowerShell commandlet script.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_ASR" class="heading-anchor"&gt;Attack Surface Reduction (ASR) capability now marks Server SKU as compliant only after enforcement&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Prior to the Attack Surface Reduction capability in Windows Server, rules were marked compliant by default. As this rule setting becomes available to Server SKU, it's enforced through Config Manager. Now the Server SKU will be marked as compliant for an Attack Surface Reduction rule, only after enforcement of the rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_Notification" class="heading-anchor"&gt;Enhancing security for External service notifications URL&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;This feature avoids the risk of directing the subscription logic to an untrusted URL, resulting in information leakage. The upgrade prevents information from being sent to an HTTPS URL with an untrusted certificate. This method ensures that the data is protected by a trusted SSL certificate. For a secure connection, we recommend using SSL certificates from trusted Certification Authorities. This security feature only allows connections to URLs that have trusted certificates for enhanced security.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_Bitlocker" class="heading-anchor"&gt;Enable BitLocker through ProvisionTS&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;ProvisionTS is the task sequence that is executed at the time of provisioning the device. Escrowing recovery key to Config Manager Database is now supported using ProvisionTS. As a result, a device can escrow the key to Config Manager Database instantly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_PKICERT" class="heading-anchor"&gt;Client certificate state in console (self-signed) to match state in control panel (PKI)&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;For clients that have a PKI certificate, the Configuration Manager console displays the Client certificate property as self-signed. The client control panel Client certificate property shows PKI. After this release, Configuration Manager console and client control panel Client certificate will be in sync and shows same state.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Update 2305 for Technical Preview Branch is available in the Microsoft Configuration Manager Technical Preview console. For new installations, the 2305 baseline version of Microsoft Configuration Manager Technical Preview Branch is&amp;nbsp;available on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/MECM2206TP-Baseline" target="_self" rel="noreferrer"&gt;CM2305TP-Baseline&lt;/A&gt;&amp;nbsp;or from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager-technical-preview" target="_self" rel="noreferrer noopener"&gt;Eval center&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Technical Preview Branch releases give you an opportunity to try out new Configuration Manager features in a test environment before they are made generally available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would love to hear your thoughts about the latest Technical Preview! Send us&amp;nbsp;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;feedback&lt;/A&gt;&amp;nbsp;directly from the console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;The Configuration Manager team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Configuration Manager Resources:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/core/get-started/technical-preview" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager Technical Previews&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-system-center-configuration-manager-and-endpoint-protection-technical-preview" target="_blank" rel="noopener noreferrer"&gt;Try the Configuration Manager Technical Preview Branch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Forums&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 13:14:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2305/ba-p/3832110</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-05-26T13:14:11Z</dc:date>
    </item>
    <item>
      <title>Unified update platform (UUP) FAQ's</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/unified-update-platform-uup-faq-s/ba-p/3808697</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;After a month of UUP update release, sharing best practices based on our field and feedback through multiple channels.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;1. &lt;STRONG&gt;Will UUP patch work for CB 2111 and below?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;Our pre-req is Configuration Manager Version &lt;U&gt;2203 and above&lt;/U&gt; as per our release documents. For Configuration Manager Version 2111 (Lesser than this are unsupported now) to patch UUP updates for windows 11 22H2 seamlessly, enable &lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/deploy/about-client-settings#allow-clients-to-download-delta-content-when-available" target="_self"&gt;delta download&lt;/A&gt; setting using client settings in ConfigMgr.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;img /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px" style="margin: 0in; background: white;"&gt;&lt;SPAN&gt;When this option is set, delta download is used for all Windows update installation files, not just express installation files.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="3"&gt;2.&amp;nbsp;&lt;/FONT&gt;Please be sure to select the appropriate update classifications in your ADRs.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have ADRs configured to auto-approve Security Updates, be sure to specify the “Security Updates” classification in your ADR settings.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you would like to take advantage of all the great features of UUP and utilize UUP feature updates to upgrade endpoint clients to Windows 11 22H2, be sure to include the “&lt;STRONG&gt;Upgrades&lt;/STRONG&gt;” classification in your ADRs. This will ensure that as endpoint clients go through the OS upgrade they will receive the latest security updates as part of the upgrade and will only need to reboot once.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do not want to utilize UUP feature updates to upgrade endpoint clients right now, you will want to exclude the “&lt;STRONG&gt;Upgrades&lt;/STRONG&gt;” classification from your ADRs.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; &lt;/U&gt;The feature updates will be released every month but there will be sharing of content for the old files and the new content should be only a few hundred MBs between the month releases. See &lt;U&gt;&lt;STRONG&gt;Question 9&lt;/STRONG&gt;&lt;/U&gt; for more details on deduplication.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;3. &lt;STRONG&gt;ConfigMgr + Adaptiva integrated solutions&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;Adaptiva has released a patch for its customers to support the UUP. The public documentation can be found here: &lt;A href="https://adaptiva.com/blog/using-unified-update-platform-with-adaptiva-onesite" target="_blank" rel="noopener"&gt;https://adaptiva.com/blog/using-unified-update-platform-with-adaptiva-onesite&lt;/A&gt;. Note that Adaptiva has asked customers not to enable delta download from the client settings and this is our recommendation from ConfigMgr 2203+ onwards only (which is our recommended version as well but as mentioned before for UUP to work with ConfigMgr 2111 there is a requirement to enable delta download from client settings.)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;4. &lt;STRONG&gt;ConfigMgr console on Windows Server 2012 R2 cannot download the UUP Quality update fails to verify cert signature&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;U&gt;&lt;FONT size="3"&gt;PatchDownloader.log&lt;/FONT&gt;&lt;/U&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Verifying file trust C:\Users\admin\AppData\Local\Temp\2\CAB291B.tmp.wim Software Updates Patch Downloader&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Authentication of file C:\Users\admin\AppData\Local\Temp\2\CAB291B.tmp.wim failed, error 0x800b0004 Software Updates Patch Downloader&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Attempting to delete 0 byte tmp files from previous downloads Software Updates Patch Downloader&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;ERROR: DownloadUpdateContent() failed with hr=0x80073633 Software Updates Patch Downloader&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt; Patch the Windows Server 2012 R2 with 2023 4B (April CU) which then fixes this issue.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;5.&lt;STRONG&gt;&amp;nbsp;ConfigMgr Patchdownloader component&amp;nbsp;may fail to verify (*.psf files) if the UUP patches were synched before ConfigMgr 2111 version.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;The issue will persist even if ConfigMgr version is upgraded to ConfigMgr 2111+ if the updates were synched before ConfigMgr was on a lesser version than version 2111.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;&lt;BR /&gt;&amp;nbsp;Sample error in &lt;U&gt;&lt;STRONG&gt;PatchDownloader.log&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;Verifying file trust C:\WINDOWS\TEMP\CAB6062.tmp.&lt;STRONG&gt;psf&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Software Updates Patch Downloader&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;Authentication of file C:\WINDOWS\TEMP\CAB6062.tmp.&lt;STRONG&gt;psf&lt;/STRONG&gt; failed, error &lt;STRONG&gt;0x800b0004&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt; Software Updates Patch Downloader&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;Attempting to delete 0 byte tmp files from previous downloads&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Software Updates Patch Downloader&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;ERROR: DownloadUpdateContent() failed with hr=0x80073633&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Software Updates Patch Downloader&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;The below SQL query will help you identify the issue.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;-- Sample check for 2023-04 Cumulative Update for Windows 11 Version 22H2 for x64-based Systems (KB5025239).
-- Replace the unique update id below if you are searching for a different UUP update

IF EXISTS( select  all SMS_CIContentFiles.CI_UniqueID,SMS_CIContentFiles.Content_ID,SMS_CIContentFiles.FileName,SMS_CIContentFiles.FileSize,
SMS_CIContentFiles.IsSigned,SMS_CIContentFiles.SecuredTypeID,SMS_CIContentFiles.SourceURL from vSMS_CIContentFiles AS SMS_CIContentFiles
WHERE SMS_CIContentFiles.CI_UniqueID='3157dbaf-04f5-49fc-baef-300bbd6d121a' AND FileName like '%.psf' and isSigned= 1 )

PRINT 'UUP Updates likely synched before upgrading to 2111. This will need correction, Please call Microsoft support to correct this.'

ELSE

PRINT 'You are not likely affected by the UUP PSF update signing issue'&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;BR /&gt;If you get the output of the above query as&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;'&lt;STRONG&gt;UUP Updates likely synched before upgrading to 2111. This will need correction, please&amp;nbsp;call Microsoft support to correct this.&lt;/STRONG&gt;' then likely you are affected and open a support case with Microsoft to correct the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;6. &lt;STRONG&gt;UUP updates installed as a part of OSD TS in "Install Software Updates" step (Fixed 2309 or later)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;There is a known issue that is currently investigated. The issue is the Delta Download component of CCMEXEC not starting on time and the updates timeout on the first scan, later scans are not impacted.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&amp;nbsp;Add a restart step in between two install software updates steps. This will allow UUP updates to be successfully downloaded and installed in the second attempt.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;: Upgrade to CB 2309 and upgrade the client. This issue is addressed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;7.&amp;nbsp;&lt;STRONG&gt;Does offline servicing work with UUP updates?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px" style="margin: 0in 0in 12.0pt 0in;"&gt;&lt;SPAN&gt;No. Offline servicing images with UUP QU updates from the ConfigMgr console is not supported.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 12.0pt 0in;"&gt;8&lt;STRONG&gt;.&amp;nbsp; Are&amp;nbsp;Delivery Optimization (DO) and Delta Download (DD) components different ? What is ConfigMgr dependency on DO?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px" style="margin: 0in 0in 12.0pt 0in;"&gt;Delivery Optimization is a Windows technology to deliver content in a smart way reducing internet bandwidth owned by the Windows team and Delta Download is a component which is an http listener for requests owned by the ConfigMgr team.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Delivery Optimization is a peer-to-peer distribution technology available in Windows 11 and Windows 10 that allows devices to share content, such as updates, that the devices have downloaded from Microsoft over the internet.&amp;nbsp;DO is a part of the Windows OS. Delta Download is a http listener and is a component of ConfigMgr.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px" style="margin: 0in 0in 12.0pt 0in;"&gt;ConfigMgr requires the DO client as it invokes the Delta download listener to download the content (as we configure the alternate content location URL in WUA policy to point to Delta Download Listener URL). The Invocation flow is WUA (Windows Update Agent) -&amp;gt; DO (Delivery Optimization) -&amp;gt; DD (Delta Download). Hence even if we don't enable DO, ConfigMgr would automatically enable DO by setting these two policies.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px" style="margin: 0in 0in 12.0pt 0in;"&gt;This is visible in the&amp;nbsp;&lt;STRONG&gt;UpdateDOGPO.log&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px" style="margin: 0in 0in 12.0pt 0in;"&gt;&lt;FONT size="2"&gt;SetDOGPOSettings: Set Windows DO group policy to DOGroupId =&amp;nbsp; DeliveryMode = group&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditorBala_Delli_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Customers should not create any GPO settings to disable these policies OR edit the registry to disable the&amp;nbsp;&lt;STRONG&gt;DOSVC&lt;/STRONG&gt;&amp;nbsp;service or from services console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;9.&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Update Supersedence changing to 6 months default for new installs. How does update supersedence affect UUP scenarios?&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Refer the &lt;A href="https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2303-for-microsoft-configuration-manager-current-branch/ba-p/3784175" target="_self"&gt;blog&lt;/A&gt;&amp;nbsp;for the announcement details for this change.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The default for expiring updates which are superseded will only change for the new installations and the existing ones will not be altered from whatever the current setting is.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;10&lt;STRONG&gt;. &lt;/STRONG&gt;&lt;STRONG&gt;Does ConfigMgr have deduplication of files at source and distribution&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;points?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Deduplication at the source in ConfigMgr&lt;/STRONG&gt;&amp;nbsp;: When PatchDownloader component downloads a file it checks if the file exists in the same share and creates a hard link for the already existing file instead of re-downloading it.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Scenario 1&lt;/STRONG&gt;&lt;BR /&gt;If the files/folders for previous UUP update source package are on the same volume but different share name, customers don't go into creating hard link path at all.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Scenario 2(a)&lt;/STRONG&gt;&lt;BR /&gt;If the Package path has a common share&amp;nbsp;\\machine\share&amp;nbsp;but different folders inside it (which is the normal case) like&amp;nbsp;&amp;nbsp;\\machine\share\jan&amp;nbsp;and&amp;nbsp;\\machine\share\feb&amp;nbsp;we go to the hard link and create the hard link for the file with the Patchdownloader.log entry&amp;nbsp;Content already downloaded. Created link for ContentID&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Scenario 2(b)&lt;/STRONG&gt;&lt;BR /&gt;Same scenario as 2(a) but the PatchDownloader here finds the same file present in a different share first apart from being present on the same share. Here the PatchDownloader doesn't go deep and check if the file is also present on the same share and fails to create the hard link. But here it doesn't download from internet again but copies the file from the other share to this share. Log entries fail to create hard link with error 17 (which is it thinks these are different drives).&amp;nbsp;Could not create hard link: \\MachineNetbios\UpdatesPackage\2302_Win11_21H2_UUP\b1e9d019-7dec-4eee-b7e4-9e8eae99d89b.1\19222DDC6156FBE5570C3A6DDF69759662F93AEE_FeatureOnDemand.wim -&amp;gt; \\ MachineNetbios\22-11-UUPWin11\bcb528ff-85c2-4372-8b91-20bd0c7fa1e4\19222DDC6156FBE5570C3A6DDF69759662F93AEE_FeatureOnDemand.wim. LastErr=17&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;It is recommended to have a single share for all the UUP monthly packages&amp;nbsp;\\machine\UUP&amp;nbsp;and then creating folders inside it for each months. for eg.. \\machine\share\jan&amp;nbsp;and&amp;nbsp;\\machine\share\feb . In this case ConfigMgr will create hard links instead of downloading the actual files again.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;BR /&gt;If you actually check the properties of the folder it will still show the size of the actual file and not hard link. Use&amp;nbsp;DU.exe&amp;nbsp;from sysinternals suite to find the actual size of a folder.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;E:\UpdatesPackage\2302_Win11_21H2_UUP&amp;gt;E:\DU\du.exe .&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;DU v1.62 - Directory disk usage reporter&lt;BR /&gt;Copyright (C) 2005-2018 Mark Russinovich&lt;BR /&gt;Sysinternals -&amp;nbsp;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.sysinternals.com%2F&amp;amp;data=05%7C01%7Cbaladell%40microsoft.com%7C79851f30961c476ac49108db48f320e4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638183981334224515%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;amp;sdata=jsU9srXCca70BEBOgFTYcE6WIli00KPwj7Iw5OV3IMM%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;www.sysinternals.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Files: 14&lt;BR /&gt;Directories: 2&lt;BR /&gt;Size: 9,675,198,236 bytes&lt;BR /&gt;Size on disk: 9,675,227,136 bytes&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;BR /&gt;To find all the hard link references to a file use the&amp;nbsp;fsutil&amp;nbsp;command.&lt;BR /&gt;fsutil harlink list &amp;lt;full_file_path&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;11. Why does ConfigMgr UUP On-Prem download a 3-5GB wim when I want to install a very small FOD/LP package?&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;This is an issue with the size attribute on the file as we don't download the full file for FOD/LP but only the needed byte ranges. Since we download the needed byte ranges only, the size that gets displayed for the file is the cumulative size of the file till that range. Meaning if the small FOD package is around 3035627519 of the byte range in the file, we will display the size of the file as around 2.82 GB. While in actuality we only downloaded the file ranges between&amp;nbsp;3034578944-3035627519 for the 1 MB FOD package. To confirm the actual size of the file on disk you can check the properties of the file and verify the "Size on disk".&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;12. Deduplication at the distribution points in ConfigMgr&lt;/STRONG&gt;&amp;nbsp;: Distribution Points in ConfigMgr are already designed to have a SIS (Single instance storage) in the form of Content Library. So we store any file only once no matter how many packages it is present in. More on ConfigMgr Content Library design&amp;nbsp;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fmem%2Fconfigmgr%2Fcore%2Fplan-design%2Fhierarchy%2Fthe-content-library&amp;amp;data=05%7C01%7Cbaladell%40microsoft.com%7C79851f30961c476ac49108db48f320e4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638183981334224515%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;amp;sdata=JctNVGP%2BNTgvAwdHJBxM2S5YoFdFfTjvbjbJX7zp5kM%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;here&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;For more details ref the actual &lt;A href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/what-s-uup-new-update-style-coming-next-week/ba-p/3773065" target="_self"&gt;windows&lt;/A&gt; blog and &lt;A href="https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2303-for-microsoft-configuration-manager-current-branch/ba-p/3784175" target="_self"&gt;Configuration&lt;/A&gt; blog.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="4"&gt;The Configuration Manager team&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 16:44:59 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/unified-update-platform-uup-faq-s/ba-p/3808697</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2024-03-12T16:44:59Z</dc:date>
    </item>
    <item>
      <title>Update 2303 for Microsoft Configuration Manager current branch is now available.</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2303-for-microsoft-configuration-manager-current-branch/ba-p/3784175</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="microsoft-configuration-manager-product-branding" class="heading-anchor"&gt;Microsoft Configuration Manager product branding&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting with Configuration Manager version 2303 Microsoft Endpoint Configuration Manager is now Microsoft Configuration Manager. Microsoft Configuration Manager is an integrated solution for managing all your devices. Microsoft brings together Configuration Manager and Intune, without a complex migration, and with simplified licensing. Continue to use your existing Configuration Manager investments, while taking advantage of the power of the Microsoft cloud at your own pace.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="cloud-attached-management" class="heading-anchor"&gt;Cloud-attached management&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="improvements-to-cloud-sync-collections-to-azure-active-directory-group-synchronization-feature" class="heading-anchor"&gt;Improvements to Cloud Sync (Collections to Azure Active Directory Group Synchronization) feature&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting with Configuration Manager version 2303 collection member sync status (Success, In Progress, Failed - with reason for failure) is available in the Collection Cloud Sync dashboard for the chosen collection on the bottom pane. Earlier with Configuration Manager version 2211, the scalability of this feature has been improved with better throttling and error handling. Additionally, dedicated dashboards for user collections and device collections are added in Monitoring workspace to show Cloud Sync status. The dashboard displays the Cloud Sync status per collection with the mapped Azure AD group, total member count, synced member count, status (success, failed, in progress) and last sync details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/manage/collections/synchronize-collections-aad-group" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Synchronize collections to Azure Active Directory Group&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="endpoint-security-reports-in-intune-admin-center-for-tenant-attached-devices" class="heading-anchor"&gt;Endpoint Security reports in Intune admin center for Tenant Attached devices&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting with Configuration Manager version 2303, you can now opt for Endpoint Security reports in Intune admin center for tenant attached devices.   Once you opt in, Unhealthy endpoints and Active malware operational reports under Endpoint security node in Intune admin center will start showing data from tenant attached devices. Also, Antivirus agent status and Detected malware organizational reports under Microsoft Defender Antivirus in Reports section will show data from tenant attached devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/tenant-attach/deploy-antivirus-policy" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Tenant attach - Create and deploy Antivirus policies from the admin center&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="site-infrastructure" class="heading-anchor"&gt;Site infrastructure&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="authorization-failure-message-in-admin-service-now-shown-in-status-message-viewer" class="heading-anchor"&gt;Authorization failure message in admin service now shown in Status message viewer&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;We have introduced audit messages about authorization failure in admin service. You can now view request details and status messages. These messages are shown in “All Status Message” at “Status Message Queries” in “Monitoring” ribbon. Previously these failures were logged in log files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the new audit messages, we intend to avoid the inconvenience of log files rollback. Details about the user, resource access attempts and the number of attempts for all the authorized requests made by user in a day will now be available. We are also auditing read operations for HTTPS requests and for cloud-initiated operations. This helps admins to scope permission and roles of users while also determining if there are any malicious users. All unauthorized requests are aggregated for 24 hours before being sent to the status message viewer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/develop/adminservice/overview" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Administration Service documentation&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="sql-server-2022-version-support-added-for-configuration-manager" class="heading-anchor"&gt;SQL Server 2022 version support added for Configuration Manager&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting with 2303, support is added for SQL server 2022 RTM version. You can use this version of SQL Server for the following sites:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A central administration site&lt;/LI&gt;
&lt;LI&gt;A primary site&lt;/LI&gt;
&lt;LI&gt;A secondary site&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The following table identifies the recommended compatibility levels for Configuration Manager site databases:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="has-inner-focus"&gt;
&lt;TABLE class="table table-sm" aria-label="Table 1"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;SQL Server version&lt;/TH&gt;
&lt;TH&gt;Supported compatibility levels&lt;/TH&gt;
&lt;TH&gt;Recommended level&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;SQL Server 2022&lt;/TD&gt;
&lt;TD&gt;150, 140, 130, 120, 110&lt;/TD&gt;
&lt;TD&gt;150&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/configs/support-for-sql-server-versions" target="_blank" rel="noopener" data-linktype="relative-path"&gt;support-for-sql-server-versions.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="software-updates" class="heading-anchor"&gt;Software updates&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="unified-update-platform-uup-ga-release" class="heading-anchor"&gt;Unified update platform (UUP) GA release&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;The Unified Update Platform (UUP) servicing is finally here for all Windows 11, version 22H2 updates delivered via Windows Server Update Services (WSUS) and Configuration Manager! Starting March 28, on-premises Windows 11, version 22H2 devices will receive quality updates via the Unified Update Platform (UUP). For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/what-s-uup-new-update-style-coming-next-week/ba-p/3773065" target="_blank" rel="noopener" data-linktype="external"&gt;What’s UUP? New update style!&lt;/A&gt;. The Unified Update Platform (UUP) is a single publishing, hosting, scan, and download model for OS quality and feature updates. It offers improved delivery technologies in response to IT admin requests for more seamless updates, more control over installation time, more battery life, and lighter download size.&lt;/P&gt;
&lt;DIV class="alert is-info"&gt;
&lt;P class="alert-title"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="alert-title"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Note:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A one-time 10-GB download to distribution points with your first UUP update. UUP is becoming the default and only way to download quality updates. This means that you should plan for an extra 10GB download to distribution points (not endpoint clients) with the March 28th update. That's a one-time 10GB download for updates for Windows 11, version 22H2 per architecture (AMD64 and ARM64).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Let's look at the key benefits, version requirements.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Quality updates for Windows 11 22H2 and above&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Quality updates with the UUP continue to be cumulative and include all released Windows quality and security fixes.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;All of these new capabilities are brought to you by UUP on premises! If interested in learning more about these improvements, &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/faster-smaller-windows-11-version-22h2-update-fundamentals/ba-p/3631894" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;read Faster, Smaller. Windows 11, version 22H2 update fundamentals&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;UUP on premises unlocks some amazing benefits going forward:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Up to 30% smaller client downloads for monthly quality updates&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Cumulative update integration with feature updates (i.e., get current in one reboot)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Seamless retention of installed language packs and optional features on demand (FODs) during feature updates&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Reduced client downloads for feature updates (i.e., inbox app downloads are conditional)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Automatic OS healing during the update process1 that requires no action from the enterprise admins&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="15" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;End-user acquisition of language packs and FODs&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;Note:&amp;nbsp;&lt;/STRONG&gt;To receive quality updates on Windows 11, we recommend that the latest security updates be installed on your devices. Minimally, devices should be updated through Windows 11 22H2.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;To take advantage of UUP on premises, you must be using a supported platform:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Recommended version: 2203 Configuration Manager Current Branch and above&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Enable Software Update on client’s settings to Yes.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;For Client Operating Systems that can support delta download (Win 10 Version 10.0.16299 or up), delta download endpoint will always get turned on regardless of the Client Agent Settings, and the port number will be honored even if Delta downloads not enabled.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;I&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;f Delta Download disabled, only UUP update will do delta download, all other updates, regardless of if express or not, will all do full file download.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;If Delta Download enabled, all updates will go with delta download code path regardless of if express or not, unless the only DP available is cloud DP.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Any supported versions of &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/plan/plan-your-wsus-deployment#uup-considerations" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Windows Server Update Services (WSUS)&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Note&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;If you're a WSUS &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;Standalone admin, please apply the upcoming February and March updates promptly to ensure your readiness! And if you haven't yet, learn about &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/adding-file-types-for-unified-update-platform-on-premises/ba-p/3620876" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Adding file types for Unified Update Platform on premises&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; .&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 id="known-issue" class="heading-anchor"&gt;Known issue:&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;On newly installed CM client, Delta Download delays to start on.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Patchdownloader.log shows incorrect download percentage.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;WSUS Servers running on server 2022, 2019 or 2016 likely to break after Feb 2023 LCU if custom mime types are added at a subsite level in IIS.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="update-to-the-default-value-of-supersedence-age-in-months-for-software-updates" class="heading-anchor"&gt;Update to the default value of supersedence age in months for software updates&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;With Unified Update Platform (UUP) general availability release, the feature update and non-feature update supersedence should be greater than 3. For new software update role installations, we're updating this to 6, existing customers can review and update to 6.  Update to the default value of supersedence age in months for software updates. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h4"&gt;
&lt;H4 id="known-issue" class="heading-anchor"&gt;Known issue:&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Update to the default value of supersedence age in months for software updates will not impact existing configurations. Removing SUP role in Admin Console does not reset the supersedence age property in WMI. As a result, while reconfiguring the role, the previously configured value is shown in the configuration window. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="enable-windows-features-introduced-via-windows-servicing-that-are-off-by-default" class="heading-anchor"&gt;Enable Windows features introduced via Windows servicing that are off by default&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;The Commercial control for continuous innovation in Windows is now integrated with Configuration Manager 2303 release.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/commercial-control-for-continuous-innovation/ba-p/3737575" target="_blank" rel="noopener" data-linktype="external"&gt;Commercial control for continuous innovation (Windows 11)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/deploy/about-client-settings" target="_blank" rel="noopener" data-linktype="relative-path"&gt;client settings in Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="configuration-manager-console" class="heading-anchor"&gt;Configuration Manager console&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="dark-theme-extended-to-delete-secondary-site-wizard" class="heading-anchor"&gt;Dark theme extended to delete secondary site wizard&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;The Configuration Manager console now extends the dark theme for the delete secondary site wizard. This wizard will also have a new look for the normal theme. This is part of the ongoing effort to make dark theme and overall admin console experience better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To use the theme, select the arrow from the top left of the ribbon, then choose the Switch console theme. Select Switch console theme again to return to the light theme. For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/manage/admin-console#bkmk_dark" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Dark theme for the console&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="deprecated-features" class="heading-anchor"&gt;Deprecated features&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="removed-community-hub-service-and-integration-with-configmgr" class="heading-anchor"&gt;Removed Community hub service and integration with ConfigMgr&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Removed Community Hub configuration from Hierarchy settings and Community Hub service integration. Learn about support changes before they're implemented in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/deprecated/removed-and-deprecated-cmfeatures" target="_blank" rel="noopener" data-linktype="relative-path"&gt;removed and deprecated items&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="other-updates" class="heading-anchor"&gt;Other updates&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="maintenance-window-schedules" class="heading-anchor"&gt;Maintenance window schedules&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Offset for recurring monthly maintenance window schedules. Based upon your feedback, you can now offset monthly maintenance window schedules to better align deployments with the release of monthly security updates. For example, using a maximum offset of seven days after the second Tuesday of the month, sets the maintenance window for next Monday.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="removing-microsoft-store-for-business-and-education-new-config-capability" class="heading-anchor"&gt;Removing Microsoft Store for Business and Education new config capability&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;As part of Microsoft Store for Business deprecation, we are making these changes to the customer experience with using this feature:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Removing a user's ability to create new Microsoft Store for Business in Configuration Manager.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Display a warning message box when user triggers a sync from Microsoft Store for Business.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Display a warning in the Create Application Wizard when user attempts to create a new app from Store license information.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/deprecated/removed-and-deprecated-cmfeatures" target="_blank" rel="noopener" data-linktype="relative-path"&gt;removed and deprecated items&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more details and to view the full list of new features in this update, check out our&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/whats-new-in-version-2303" target="_blank" rel="noopener noreferrer"&gt;What’s new in version 2303 of Microsoft Configuration Manager&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;documentation.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;For assistance with the upgrade process, please post your questions in the Site and Client Deployment forum&lt;/SPAN&gt;.&amp;nbsp;&lt;SPAN&gt;Send us your Configuration Manager feedback through&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Feedback&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;in the Configuration Manager console.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Continue to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/configmgrsuggestions" target="_blank" rel="noopener noreferrer"&gt;share and vote on ideas&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;about new features in Configuration Manager.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Configuration Manager team&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Additional resources:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/whats-new-incremental-versions" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;What’s New in Configuration Manager&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbdocs" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Documentation for Configuration Manager&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/CMAnnounce" target="_blank" rel="noopener noreferrer"&gt;Microsoft Configuration Manager announcement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/MEMVisionPaper" target="_blank" rel="noopener noreferrer"&gt;Microsoft Configuration Manager vision statement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/get-started/evaluate-with-lab-environment" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Evaluate Configuration Manager in a lab&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/deploy/install/upgrade-to-configuration-manager" target="_blank" rel="noopener noreferrer"&gt;Upgrade to Configuration Manager&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Configuration Manager Forums&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Configuration Manager Support&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Report an issue&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/configmgrsuggestions" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;Provide suggestions&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 13 Apr 2023 00:40:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2303-for-microsoft-configuration-manager-current-branch/ba-p/3784175</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-04-13T00:40:01Z</dc:date>
    </item>
    <item>
      <title>Release Cadence Changes to Microsoft Configuration Manager</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/release-cadence-changes-to-microsoft-configuration-manager/ba-p/3785508</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;This article provides information about release-cadence changes for Microsoft Configuration Manager, introducing a new release cycle starting after the release of a Configuration Manager baseline version in 2303. To learn about the changes introduced in previous updates for Configuration Manager, branding, and baselines, see &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/plan-design/changes/whats-new-incremental-versions" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;What's new in Configuration Manager incremental versions&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/understand/microsoft-endpoint-manager-faq" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Configuration Manager FAQ&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, and, &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/servers/manage/updates#bkmk_Baselines" target="_self"&gt;&lt;SPAN data-contrast="none"&gt;Baseline and update versions&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;As Windows is moving to a once-a-year update model, Configuration Manager&amp;nbsp;will be better aligning to that cadence by &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;moving from three to two updates a year. &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;The next release of Microsoft Configuration Manager after 2303 will be in September 2023, version 2309. Effectively, the xx07 and xx11 updates are being merged into an xx09 update.&amp;nbsp; The consolidation of updates will roll up enhancements into this release; another outcome is reducing the number of deployments customers must manage annually&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Along with better alignment to the Windows cadence and reducing CM deployment management, this change will also allow Configuration Manager&amp;nbsp;to have a longer development cycle to address key customer feature asks while continuing to deliver high quality updates.&amp;nbsp; With this change and the longer development cycle, the Configuration Manager&amp;nbsp;2309 update will be able to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;address key customer asks around policy sync, software update troubleshooting, improved alerts, dashboarding, and more&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;.&amp;nbsp; Hotfix rollups and security updates will continue to be made available as necessary to address any critical bugs.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Cadence Change Summary:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:510,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Starting in the calendar year 2023 customers will now receive two releases of Configuration Manager, one in March (xx03), and another in September (xx09) rather than the previous release cadence of xx03, xx07, and xx11.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:510,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Baseline versions can be used to install a new Configuration Manager site and hierarchy, or to upgrade from a supported version of Configuration Manager. 2303, 2403… will be baseline releases.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:510,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;There will be four Technical Preview (TP) releases per year.&amp;nbsp; Two will be released before each production current branch release, and one of Technical Preview release would be a baseline release. (TP Baseline are 180 days evaluation)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:510,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;There is no change to current branch support cadence. Each current branch version remains in support for 18 months from its general availability release date. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/mem/configmgr/core/servers/manage/current-branch-versions-supported" data-linktype="relative-path" target="_blank"&gt;Support for Configuration Manager current branch versions&lt;/A&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:150,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:150,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 01:32:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/release-cadence-changes-to-microsoft-configuration-manager/ba-p/3785508</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-04-04T01:32:38Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager technical preview version 2303</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2303/ba-p/3780768</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_dark" class="heading-anchor"&gt;Dark theme extended to one customer voice (OCV) wizard&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;The Configuration Manager console now extends the dark theme for the one customer voice (OCV) wizards. All 'Send a smile' and 'Send a frown' wizards will adhere to dark theme starting in Technical Preview 2303. This is part of the ongoing effort to make dark theme and overall admin console experience better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To use the theme, select the arrow from the top left of the ribbon, then choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Switch console theme&lt;/STRONG&gt;. Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Switch console theme&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;again to return to the light theme.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="known-issue" class="heading-anchor"&gt;Known issue.&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Console restart is required on doing the theme switch, as the node navigation pane might not properly render when you move to a new workspace.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_SQl2022" class="heading-anchor"&gt;SQL Server 2022 version support added for Configuration Manager&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting with technical preview 2303, support is added for SQL server 2022 RTM version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use this version of SQL Server for the following sites:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A central administration site&lt;/LI&gt;
&lt;LI&gt;A primary site&lt;/LI&gt;
&lt;LI&gt;A secondary site&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The following table identifies the recommended compatibility levels for Configuration Manager site databases:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="has-inner-focus"&gt;
&lt;TABLE class="table table-sm" aria-label="Table 1"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;SQL Server version&lt;/TH&gt;
&lt;TH&gt;Supported compatibility levels&lt;/TH&gt;
&lt;TH&gt;Recommended level&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;SQL Server 2022&lt;/TD&gt;
&lt;TD&gt;150, 140, 130, 120, 110&lt;/TD&gt;
&lt;TD&gt;150&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_SQlodbc" class="heading-anchor"&gt;Prerequisites for the site server roles now include ODBC driver for SQL Server&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting with technical preview 2303, Configuration Manager requires the installation of the ODBC driver for SQL server as a prerequisite. This prerequisite is required when you create a new site or update an existing one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configuration Manager doesn't manage the updates for the ODBC driver. Ensure that this component is up to date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;For more details and to view the full list of new features in this update, check out our&amp;nbsp;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/get-started/2023/technical-preview-2303" target="_self" rel="noreferrer"&gt;Features in Configuration Manager technical preview version 2303&lt;/A&gt;&amp;nbsp;documentation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Update 2303 for Technical Preview Branch is available in the Microsoft Configuration Manager Technical Preview console. For new installations, the 2302 baseline version of Microsoft Configuration Manager Technical Preview Branch is&amp;nbsp;available on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/MECM2206TP-Baseline" target="_self" rel="noreferrer noopener"&gt;CM2302TP-Baseline&lt;/A&gt;&amp;nbsp;or from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager-technical-preview" target="_self" rel="noreferrer noopener"&gt;Eval center&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Technical Preview Branch releases give you an opportunity to try out new Configuration Manager features in a test environment before they are made generally available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would love to hear your thoughts about the latest Technical Preview! Send us&amp;nbsp;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;feedback&lt;/A&gt;&amp;nbsp;directly from the console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;The Configuration Manager team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Configuration Manager Resources:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/core/get-started/technical-preview" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager Technical Previews&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-system-center-configuration-manager-and-endpoint-protection-technical-preview" target="_blank" rel="noopener noreferrer"&gt;Try the Configuration Manager Technical Preview Branch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Forums&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 17:50:29 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2303/ba-p/3780768</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-03-28T17:50:29Z</dc:date>
    </item>
    <item>
      <title>Recommendations and insights to enrich the Configuration Manager site health and device management</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/recommendations-and-insights-to-enrich-the-configuration-manager/ba-p/3747981</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;You can now use the Microsoft Intune admin center to view recommendations and insights for your Configuration Manager sites. These recommendations can help you improve the site health and infrastructure along with enriching the device management experience.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With so many features and updates available, implementing the right available resources for your infrastructure management is essential. You might be new to the management world, or even if you have been managing your company’s infrastructure for a long time, this feature will provide you with insights that can help you to level up.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We are currently providing recommendations that can help in following ways:&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Help you to simplify your infrastructure by reviewing your hierarchy.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Assist you to enhance device management through co-management enablement.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Refine gathering of device insights via endpoint analytics enablement.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Improve the health of the site by reviewing current peer cache and delivery optimization settings.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These recommendations will be based on your current site infrastructure and settings. Applying the recommendations is solely the admin’s discretion.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We have created recommendation for TA customer solely based on their Site Configuration without interfering customer's privacy. Each recommendation points out how customer is leveraging features provided in site configuration. Recommendations are derived from database. Each recommendation is evaluated and updated in the next cycle. Recommendation will not be visible in the next cycle if fully applied or recommendation insight will be changed if partially applied.&amp;nbsp; Every cycle we inspect the customer DB through static query and then flow this insight to cloud to show the recommendation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;How can you view the recommendations?&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A user with global admin rights will be able to view recommendations for configuration manager sites that are version 2211 or higher and tenant attached.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To view recommendations, open the Microsoft Endpoint Manager admin center, and go to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Tenant administration&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; &amp;gt; &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Connectors and tokens&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; &amp;gt; &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Endpoint Configuration Manager&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, and select a &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;site&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; to view recommendations for that site.&amp;nbsp; Once selected, you’ll find the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Recommendations&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; tab that displays each insight along with a &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Learn more&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; link that opens details on how to apply that recommendation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;img /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;We are open to adding more recommendations in future and would love to hear from you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 10:04:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/recommendations-and-insights-to-enrich-the-configuration-manager/ba-p/3747981</guid>
      <dc:creator>shsenthi</dc:creator>
      <dc:date>2023-02-22T10:04:15Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager technical preview version 2302</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2302/ba-p/3749283</link>
      <description>&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 id="bkmk_winfeatures" class="heading-anchor"&gt;Enable Windows features introduced via Windows servicing that are off by default&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;To learn more about the settings: “Enable Windows features introduced via Windows servicing that are off by default”, please read this&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/commercial-control-for-continuous-innovation/ba-p/3737575" target="_blank" rel="noopener" data-linktype="external"&gt;blog&lt;/A&gt;. The post describes the Commercial control for continuous innovation in Windows. The setting for this policy is now integrated with the Configuration Manager 2302 Technical Preview. More information on the Commercial control timeline and versions of Windows 11 supported by the setting can be found in the &lt;A href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/commercial-control-for-continuous-innovation/ba-p/3737575" target="_self"&gt;blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Windows features that the policy will control will be released in later part of 2023. This ConfigMgr Technical Preview feature is for awareness and not for testing in February 2023.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_dark" class="heading-anchor"&gt;Dark theme extended to delete secondary site wizard&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;The Configuration Manager console now extends the dark theme for the delete secondary site wizard. This wizard will also have a new look for the normal theme. This is part of the ongoing effort to make dark theme and overall admin console experience better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditorBala_Delli_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To use the theme, select the arrow from the top left of the ribbon, then choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Switch console theme&lt;/STRONG&gt;. Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Switch console theme&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;again to return to the light theme.&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 class="heading-anchor"&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3 id="known-issue" class="heading-anchor"&gt;Known issue.&lt;/H3&gt;
&lt;/DIV&gt;
&lt;P&gt;Console restart is required on doing the theme switch, as the node navigation pane might not properly render when you move to a new workspace.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;For more details and to view the full list of new features in this update, check out our&amp;nbsp;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/get-started/2023/technical-preview-2302" target="_self" rel="noreferrer"&gt;Features in Configuration Manager technical preview version 2302&lt;/A&gt;&amp;nbsp;documentation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Update 2302 for Technical Preview Branch is available in the Microsoft Configuration Manager Technical Preview console. For new installations, the 2302 baseline version of Microsoft Configuration Manager Technical Preview Branch is&amp;nbsp;available on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/MECM2206TP-Baseline" target="_self" rel="noreferrer"&gt;CM2302TP-Baseline&lt;/A&gt;&amp;nbsp;or from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager-technical-preview" target="_self" rel="noreferrer noopener"&gt;Eval center&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Technical Preview Branch releases give you an opportunity to try out new Configuration Manager features in a test environment before they are made generally available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would love to hear your thoughts about the latest Technical Preview! Send us&amp;nbsp;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;feedback&lt;/A&gt;&amp;nbsp;directly from the console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;The Configuration Manager team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Configuration Manager Resources:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/core/get-started/technical-preview" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager Technical Previews&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-system-center-configuration-manager-and-endpoint-protection-technical-preview" target="_blank" rel="noopener noreferrer"&gt;Try the Configuration Manager Technical Preview Branch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Forums&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 05:08:54 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2302/ba-p/3749283</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-02-22T05:08:54Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager technical preview version 2301</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2301/ba-p/3728568</link>
      <description>&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2 id="bkmk_branding" class="heading-anchor"&gt;Microsoft Configuration Manager product branding.&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting with Configuration Manager version 2301 technical preview Microsoft Endpoint Configuration Manager is now Microsoft Configuration Manager.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Microsoft Configuration Manager is an integrated solution for managing all your devices. Microsoft brings together Configuration Manager and Intune, without a complex migration, and with simplified licensing. Continue to leverage your existing Configuration Manager investments, while taking advantage of the power of the Microsoft cloud at your own pace.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_coll_aad_group_sync" class="heading-anchor"&gt;Improvements to Cloud Sync (Collections to Azure Active Directory Group Synchronization) feature.&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Starting this technical preview 2301 release user/device-based sync status (success, failure, in-progress, failure reason if any) will be available in the dashboard for the chosen collection. Earlier with Configuration Manager version 2211, the scalability of this feature has been improved with better throttling and error handling. Additionally, dedicated dashboards for user collections and device collections are added in Monitoring workspace to show Cloud Sync status. The dashboard displays the Cloud Sync status per collection with the mapped Azure AD group, total member count, synced member count, status (success, failed, in progress) and last sync details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information, see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/clients/manage/collections/synchronize-collections-aad-group" target="_self" data-linktype="relative-path"&gt;Synchronize collections to Azure Active Directory Group&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="bkmk_softwareupdates" class="heading-anchor"&gt;Update to the default value of supersedence age in months for software updates.&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;With Unified Update Platform (UUP) nearing general availability release, the feature update and non-feature update supersedense should be greater than 3. For new software update role installations, we're updating this to 6, existing customer can review and update to 6 when the feature is released during general availability.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Update to the default value of supersedence age in months for software updates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 id="general-known-issues" class="heading-anchor"&gt;General known issues&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Update to the default value of supersedence age in months for software updates.&lt;/P&gt;
&lt;P&gt;Removing SUP role in Admin Console does not reset the supersedence age property in WMI. As a result, while reconfiguring the role, the previously configured value is shown in the configuration window. This property needs to be reset to default value on role removal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="bkmk_msfb" class="heading-anchor"&gt;Removing Microsoft Store for Business and Education new config capability.&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;As part of Microsoft Store for Business deprecation, we are making these changes to the customer experience with using this feature:&lt;/P&gt;
&lt;P&gt;-Removing a user's ability to create new Microsoft Store for Business in Configuration Manager.&lt;/P&gt;
&lt;P&gt;-Display a warning message box when user triggers a sync from Microsoft Store for Business.&lt;/P&gt;
&lt;P&gt;-Display a warning in the Create Application Wizard when user attempts to create a new app from Store license information.&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;
&lt;H2 class="heading-anchor"&gt;&amp;nbsp;&lt;/H2&gt;
&lt;/DIV&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;SPAN&gt;Other Updates&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;SPAN&gt;Update to Offset for recurring monthly maintenance window&amp;nbsp;schedule.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;BR /&gt;Based upon your feedback, you can now offset monthly maintenance window schedules to better align deployments with the release of monthly security updates. For example, using a maximum offset of &lt;STRONG&gt;seven&lt;/STRONG&gt; days after the &lt;STRONG&gt;second Tuesday&lt;/STRONG&gt; of the month, sets the maintenance window for &lt;STRONG&gt;next Monday&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;For more details and to view the full list of new features in this update, check out our&amp;nbsp;&lt;A href="https://learn.microsoft.com/mem/configmgr/core/get-started/2023/technical-preview-2301" target="_self" rel="noreferrer"&gt;Features in Configuration Manager technical preview version 2301&lt;/A&gt;&amp;nbsp;documentation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Update 2210 for Technical Preview Branch is available in the Microsoft Endpoint Configuration Manager Technical Preview console. For new installations, the 2210 baseline version of Microsoft Endpoint Configuration Manager Technical Preview Branch is&amp;nbsp;available on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/MECM2206TP-Baseline" target="_self" rel="noreferrer noopener"&gt;MECM2210TP-Baseline&lt;/A&gt;&amp;nbsp;or from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-microsoft-endpoint-configuration-manager-technical-preview" target="_self" rel="noreferrer noopener"&gt;Eval center&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Technical Preview Branch releases give you an opportunity to try out new Configuration Manager features in a test environment before they are made generally available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would love to hear your thoughts about the latest Technical Preview! Send us&amp;nbsp;&lt;A href="https://aka.ms/configmgrfeedback" target="_blank" rel="noopener noreferrer"&gt;feedback&lt;/A&gt;&amp;nbsp;directly from the console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;The Configuration Manager team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Configuration Manager Resources:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/core/get-started/technical-preview" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager Technical Previews&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/evalcenter/evaluate-system-center-configuration-manager-and-endpoint-protection-technical-preview" target="_blank" rel="noopener noreferrer"&gt;Try the Configuration Manager Technical Preview Branch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/mem/configmgr/" target="_blank" rel="noopener noreferrer"&gt;Documentation for Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbforums" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Forums&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/cmcbsupport" target="_blank" rel="noopener noreferrer"&gt;Configuration Manager Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 16:59:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager-blog/configuration-manager-technical-preview-version-2301/ba-p/3728568</guid>
      <dc:creator>Bala_Delli</dc:creator>
      <dc:date>2023-02-02T16:59:53Z</dc:date>
    </item>
  </channel>
</rss>

