├── CA └── DU8_Deploy_ConditionalAccessRules.ps1 ├── DU ├── ADMX │ ├── Office_OutlookSSO │ │ └── _outlooksso.json │ ├── Office_Security │ │ ├── _Microsoft Excel 2016_Excel Options_Save_Default file format.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Force file extension to match file type.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Scan encrypted macros in Excel Open XML workbooks.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_Block macros from running in Office files from the Internet.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Dif and Sylk files.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 2 macrosheets and add-in files.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 2 worksheets.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 3 macrosheets and add-in files.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 3 worksheets.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 4 macrosheets and add-in files.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 4 workbooks.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 4 worksheets.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 95 workbooks.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 95-97 workbooks and templates.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Microsoft Office query files.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Set default file block behavior.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Web pages and Excel 2003 XML spreadsheets.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_dBase III _ IV files.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_Protected View_Do not open files from the Internet zone in Protected View.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_Protected View_Do not open files in unsafe locations in Protected View.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_Protected View_Set document behavior if file validation fails.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_Protected View_Turn off Protected View for attachments opened from Outlook.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_Require that application add-ins are signed by Trusted Publisher.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_Trust access to Visual Basic Project.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Trust Center_VBA Macro Notification Settings.json │ │ ├── _Microsoft Excel 2016_Excel Options_Security_Turn off file validation.json │ │ ├── _Microsoft Office 2016_Security Settings_Disable VBA for Office applications.json │ │ ├── _Microsoft Outlook 2016_Security_Trust Center_Allow hyperlinks in suspected phishing e-mail messages.json │ │ ├── _Microsoft PowerPoint 2016_PowerPoint Options_Security_Make hidden markup visible.json │ │ ├── _Microsoft PowerPoint 2016_PowerPoint Options_Security_Run Programs.json │ │ ├── _Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_Block macros from running in Office files from the Internet.json │ │ ├── _Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_File Block Settings_PowerPoint 97-2003.json │ │ ├── _Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_Protected View_Set document behavior if file validation fails.json │ │ ├── _Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_Protected View_Turn off Protected.json │ │ ├── _Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_Trust access to Visual Basic Project.json │ │ ├── _Microsoft PowerPoint 2016_PowerPoint Options_Security_Turn off file validation.json │ │ ├── _Microsoft Visio 2016_Visio Options_Security_Trust Center_File Block Settings_Visio 2000-2002 Binary Drawings, Templates and Stencils.json │ │ ├── _Microsoft Visio 2016_Visio Options_Security_Trust Center_File Block Settings_Visio 2003-2010 Binary Drawings, Templates and Stencils.json │ │ ├── _Microsoft Word 2016_Word Options_Save_Default file format.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Make hidden markup visible.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_Block macros from running in Office files from the Internet.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Set default file block behavior.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2 and earlier binary documents and templates.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2000 binary documents and templates.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2003 and plain XML documents.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2003 binary documents and templates.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2007 and later binary documents and templates.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 6.0 binary documents and templates.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 95 binary documents and templates.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 97 binary documents and templates.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word XP binary documents and templates.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_Trust access to Visual Basic Project.json │ │ ├── _Microsoft Word 2016_Word Options_Security_Trust Center_VBA Macro Notification Settings.json │ │ └── _Microsoft Word 2016_Word Options_Security_Turn off file validation.json │ ├── Windows10_Edge_Settings │ │ ├── _Microsoft Edge - Default Settings (users can override)_Default search provider_Default search provider name.json │ │ ├── _Microsoft Edge - Default Settings (users can override)_Default search provider_Default search provider search URL.json │ │ ├── _Microsoft Edge_Allow users to proceed from the HTTPS warning page.json │ │ ├── _Microsoft Edge_Automatically import another browser's data and settings at first run.json │ │ ├── _Microsoft Edge_Browser sign-in settings.json │ │ ├── _Microsoft Edge_Content settings_Default Adobe Flash setting.json │ │ ├── _Microsoft Edge_Content settings_Default notification setting.json │ │ ├── _Microsoft Edge_Default search provider_Enable the default search provider.json │ │ ├── _Microsoft Edge_Enable site isolation for every site.json │ │ ├── _Microsoft Edge_Force synchronization of browser data and do not show the sync consent prompt.json │ │ ├── _Microsoft Edge_Hide the First-run experience and splash screen.json │ │ ├── _Microsoft Edge_Minimum TLS version enabled.json │ │ ├── _Microsoft Edge_Native Messaging_Allow user-level native messaging hosts (installed without admin permissions).json │ │ ├── _Microsoft Edge_Password manager and protection_Enable saving passwords to the password manager.json │ │ ├── _Microsoft Edge_SmartScreen settings_Configure Microsoft Defender SmartScreen to block potentially unwanted apps.json │ │ └── _Microsoft Edge_SmartScreen settings_Prevent bypassing Microsoft Defender SmartScreen prompts for sites.json │ ├── Windows10_Eventlog │ │ ├── _Windows Components_Event Log Service_Application_Specify the maximum log file size (KB).json │ │ ├── _Windows Components_Event Log Service_Security_Specify the maximum log file size (KB).json │ │ └── _Windows Components_Event Log Service_System_Specify the maximum log file size (KB).json │ ├── Windows10_Onedrive │ │ ├── _OneDrive_Coauthor and share in Office desktop apps.json │ │ ├── _OneDrive_Configure team site libraries to sync automatically.json │ │ ├── _OneDrive_Disable the tutorial that appears at the end of OneDrive Setup.json │ │ ├── _OneDrive_Prevent users from redirecting their Windows known folders to their PC.json │ │ ├── _OneDrive_Require users to confirm large delete operations.json │ │ ├── _OneDrive_Set the sync app update ring.json │ │ ├── _OneDrive_Silently move Windows known folders to OneDrive.json │ │ ├── _OneDrive_Silently sign in users to the OneDrive sync app with their Windows credentials.json │ │ └── _OneDrive_Use OneDrive Files On-Demand.json │ └── chromeadmx.xml ├── DU2a_Create_Dynamic_Groups.ps1 ├── DU2b_Create_Autopilot_Profiles.ps1 ├── DU2c_Autopilot_profile_assignment.ps1 ├── DU2d_Link_license_to_Group.ps1 ├── DU2e_Set_Intune_As_MDMAuthority.ps1 ├── DU2f_Config_Apple_MDM.ps1 ├── DU2g_Assign_Google_Apps.ps1 ├── DU2h_AppProtectionPolicyManagedDevices.ps1 ├── DU2h_AppProtectionPolicyUnmanagedDevices.ps1 ├── DU2i_Create_Enrollment_Restrictions.ps1 ├── DU3b_Chocolatey_Assign_Basic_Apps.ps1 ├── DU3b_Chocolatey_Assign_Large_Icons.ps1 ├── DU3b_Chocolatey_Upload_Basic_Apps.ps1 ├── DU3b_Edge_Upload_App.ps1 ├── DU3b_Office365_Upload_Apps.ps1 ├── DU3b_Windows10_Assign_Basic_Apps.ps1 ├── DU3b_Windows10_Upload_Basic_Apps.ps1 ├── DU3b_iOS_Assign_Basic_Apps.ps1 ├── DU3b_iOS_Upload_Basic_Apps.ps1 ├── DU3c_Config_Enrollment_Status_Page.ps1 ├── DU4a_DeviceConfigurationADMX_Assignment.ps1 ├── DU4a_DeviceConfigurationADMX_Import_FromJSON.ps1 ├── DU4b_AppConfigurationPolicy_Assignment.ps1 ├── DU4b_AppConfigurationPolicy_ImportFromJSON.ps1 ├── DU4b_Windows10_ImportAllDeviceConfigs.ps1 ├── DU4c_Enroll_Windows10_Powershellscripts.ps1 ├── DU4d_Windows10_firewallRules.ps1 ├── DU5_Import_Compliance_Policies.ps1 ├── DU6_Config_WindowsUpdate.ps1 ├── DU7_Config_WindowsHello.ps1 ├── JSON │ ├── Android_Device_Restrictions.json │ ├── Android_compliance_RequireDeviceHealth.json │ ├── Android_compliance_RequireDeviceSecurity.json │ ├── Android_compliance_RequireOSVersion.json │ ├── AzureAd_AllowPasswordreset.json │ ├── IOS_Device_Restrictions.json │ ├── IOS_IntuneMAMUpn_Excel_11-03-2021-9-51-461.json │ ├── IOS_IntuneMAMUpn_Office_11-03-2021-9-51-481.json │ ├── IOS_IntuneMAMUpn_Onedrive_10-03-2021-16-42-521.json │ ├── IOS_IntuneMAMUpn_Outlook_10-03-2021-16-42-531.json │ ├── IOS_IntuneMAMUpn_Teams_10-03-2021-16-42-561.json │ ├── IOS_IntuneMAMUpn_Word_10-03-2021-16-42-551.json │ ├── Ios_Compliance_RequireDeviceHealth.json │ ├── Ios_Compliance_RequireDeviceSecurity.json │ ├── Ios_Compliance_RequireOSVersion.json │ ├── Mac_Compliance.json │ ├── WIndows10_Applocker.json │ ├── WIndows10_DisableInternetExplorer.json │ ├── WIndows10_EnableBitlocker.json │ ├── WIndows10_LockDownURL.json │ ├── WIndows_Compliance_RequireDeviceHealth.json │ ├── WIndows_Compliance_RequireDeviceSecurity.json │ ├── WIndows_Compliance_RequireOSVersion.json │ ├── Windows10_Audit.json │ ├── Windows10_ChromeSettings.json │ ├── Windows10_Create_admin_user.json │ ├── Windows10_Defender.json │ ├── Windows10_Defender_ASR.json │ ├── Windows10_Defender_notifications.json │ ├── Windows10_DeliveryOptimization.json │ ├── Windows10_EdgeSettings.json │ ├── Windows10_PowerSettings.json │ ├── Windows10_PreventAppInstall_Nonadmin.json │ ├── Windows10_RequireBitlockerKey_10FailedLogins.json │ ├── Windows10_RestrictedGroups.json │ ├── Windows10_SettingsMenu.json │ ├── Windows10_Settings_Menu.json │ ├── Windows10_Skip_user_status_page.json │ ├── Windows10_Storagesense.json │ ├── Windows10_TimeZone.json │ └── Windows10_Update.json ├── Packages │ ├── Bitlocker │ │ ├── Windows10_enablebitlocker.intunewin │ │ ├── Windows10_enablebitlocker.ps1 │ │ ├── detection.xml │ │ ├── install.cmd │ │ └── uninstall.cmd │ ├── Chocolatey │ │ ├── Windows10_Chocolatey.intunewin │ │ ├── Windows10_Chocolatey.ps1 │ │ ├── detection.xml │ │ ├── install.cmd │ │ └── uninstall.cmd │ ├── ChocolateyAppsInstall │ │ ├── 7zip │ │ │ ├── 7zip.intunewin │ │ │ ├── 7zip.jpg │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ └── uninstall.ps1 │ │ ├── Adobe Reader │ │ │ ├── adobereader.intunewin │ │ │ ├── adobereader.jpg │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ └── uninstall.ps1 │ │ ├── Dymo │ │ │ ├── detection.xml │ │ │ ├── dymo.intunewin │ │ │ ├── dymolabel.png │ │ │ ├── install.ps1 │ │ │ └── uninstall.ps1 │ │ ├── Firefox │ │ │ ├── detection.xml │ │ │ ├── firefox.intunewin │ │ │ ├── firefox.jpg │ │ │ ├── firefox.png │ │ │ ├── install.ps1 │ │ │ └── uninstall.ps1 │ │ ├── Notepad++ │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ ├── notepad++.intunewin │ │ │ ├── notepad++.jpg │ │ │ └── uninstall.ps1 │ │ ├── SynologyDrive │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ ├── synology.intunewin │ │ │ ├── synology.jpg │ │ │ └── uninstall.ps1 │ │ ├── chrome │ │ │ ├── chrome.jpg │ │ │ ├── detection.xml │ │ │ ├── googlechromenew.intunewin │ │ │ ├── install.ps1 │ │ │ ├── uninstall.ps1 │ │ │ └── win32 │ │ │ │ └── install.intunewin │ │ ├── citrix │ │ │ ├── citrix.intunewin │ │ │ ├── citrix.jpg │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ └── uninstall.ps1 │ │ ├── cutepdf │ │ │ ├── cutepdf.intunewin │ │ │ ├── cutepdf.jpg │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ └── uninstall.ps1 │ │ ├── filezilla │ │ │ ├── detection.xml │ │ │ ├── filezilla.intunewin │ │ │ ├── filezilla.jpg │ │ │ ├── install.ps1 │ │ │ └── uninstall.ps1 │ │ ├── gotomeeting │ │ │ ├── detection.xml │ │ │ ├── gotomeeting.intunewin │ │ │ ├── gotomeeting.jpg │ │ │ ├── install.ps1 │ │ │ └── uninstall.ps1 │ │ ├── icloud │ │ │ ├── detection.xml │ │ │ ├── icloud.intunewin │ │ │ ├── install.ps1 │ │ │ └── uninstall.ps1 │ │ ├── java │ │ │ ├── detection.xml │ │ │ ├── install.intunewin │ │ │ ├── install.ps1 │ │ │ ├── java.intunewin │ │ │ ├── java.jpg │ │ │ └── uninstall.ps1 │ │ ├── keepass │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ ├── keepass.intunewin │ │ │ ├── keepass.png │ │ │ └── uninstall.ps1 │ │ ├── silverlight │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ ├── silverlight.intunewin │ │ │ ├── silverlight.jpg │ │ │ └── uninstall.ps1 │ │ ├── skype │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ ├── skype.intunewin │ │ │ ├── skype.jpg │ │ │ └── uninstall.ps1 │ │ ├── vcredist140 │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ ├── uninstall.ps1 │ │ │ ├── vcredist140.intunewin │ │ │ └── vcredist140.jpg │ │ ├── vlc │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ ├── uninstall.ps1 │ │ │ ├── vlc.intunewin │ │ │ └── vlc.jpg │ │ └── zoom │ │ │ ├── detection.xml │ │ │ ├── install.ps1 │ │ │ ├── uninstall.ps1 │ │ │ ├── zoom.intunewin │ │ │ └── zoom.jpg │ ├── DCLAPS │ │ ├── Windows10_rotate.intunewin │ │ ├── Windows10_rotate.ps1 │ │ ├── detection.xml │ │ ├── install.cmd │ │ └── uninstall.cmd │ ├── OneDriveSilent │ │ ├── Windows10_OnedriveSilent.intunewin │ │ ├── Windows10_OnedriveSilent.ps1 │ │ ├── detection.xml │ │ ├── install.cmd │ │ └── uninstall.cmd │ ├── Onedrive │ │ ├── detection.xml │ │ └── onedrivesetup.intunewin │ ├── OnedriveConfig │ │ ├── Windows10_Onedrive.intunewin │ │ ├── Windows10_Onedrive.ps1 │ │ ├── detection.xml │ │ ├── install.cmd │ │ └── uninstall.cmd │ ├── PowerOptions │ │ ├── Windows10_PowerOptions.intunewin │ │ ├── Windows10_PowerOptions.ps1 │ │ ├── detection.xml │ │ ├── install.cmd │ │ ├── install.intunewin │ │ └── uninstall.cmd │ ├── Quickassist │ │ ├── Windows10_Quickassist.ps1 │ │ ├── Windows10_quickassist.intunewin │ │ ├── detection.xml │ │ ├── install.cmd │ │ ├── intune.ico │ │ └── uninstall.cmd │ ├── RemoveAdmin │ │ ├── Windows10_RemoveAdmin.intunewin │ │ ├── Windows10_RemoveAdmin.ps1 │ │ ├── detection.xml │ │ ├── install.cmd │ │ └── uninstall.cmd │ ├── RestartService │ │ ├── Windows10_Restartservice.intunewin │ │ ├── Windows10_Restartservice.ps1 │ │ ├── detection.xml │ │ ├── install.cmd │ │ └── uninstall.cmd │ ├── Windows10_AllowPrinterInstallation │ │ ├── WIndows10_Allowprinterinstallation.intunewin │ │ └── detection.xml │ └── readme └── scripts │ ├── Windows10_ChangePublicDesktopPermissions.ps1 │ ├── Windows10_Hardening.ps1 │ ├── Windows10_Hiberboot.ps1 │ └── Windows10_TimeService.ps1 ├── Default_Enrollment.ps1 ├── Readme.md ├── SL1 ├── SL1_1.ps1 ├── SL1_2.ps1 ├── SL1_3.ps1 ├── SL1_4.ps1 └── readme └── functions └── Test-JSON.ps1 /DU/ADMX/Office_OutlookSSO/_outlooksso.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('7ab3839d-2ea4-413c-93bd-ed0143133b70')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Save_Default file format.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('f2ac971b-e0bf-46b0-bf45-72715e8d9f5e')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "51", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('f2ac971b-e0bf-46b0-bf45-72715e8d9f5e')/presentations('c82dd53b-8380-4dcf-b84b-4241098bcea1')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Force file extension to match file type.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('38de8259-2314-491b-9b8e-8c9cccb36d73')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "1", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('38de8259-2314-491b-9b8e-8c9cccb36d73')/presentations('ca5bc481-a497-439c-b87b-0cea7ceec5bf')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Scan encrypted macros in Excel Open XML workbooks.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('b84e93f5-187a-441e-b63e-fdddf2bdd780')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "0", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('b84e93f5-187a-441e-b63e-fdddf2bdd780')/presentations('b6733f16-0416-4107-b5d3-7b8556f23415')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_Block macros from running in Office files from the Internet.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('614bb3e1-f51b-4622-baa5-dbfd257818d1')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Dif and Sylk files.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('7bce0994-f770-4759-801b-1ba596f56901')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('7bce0994-f770-4759-801b-1ba596f56901')/presentations('d2553a0f-c2e6-46fc-9894-4490554c59c5')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 2 macrosheets and add-in files.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('6a4c8d66-139f-4fc8-be10-c6e6a8d90dd8')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('6a4c8d66-139f-4fc8-be10-c6e6a8d90dd8')/presentations('f9413893-eeec-42fa-a09c-a854d67dddd3')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 2 worksheets.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('63f5fb57-4740-4019-83a9-28d6c06c58e4')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('63f5fb57-4740-4019-83a9-28d6c06c58e4')/presentations('e768431c-fe29-472d-b3ea-b707c405ec19')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 3 macrosheets and add-in files.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('df930f9b-5805-4462-8479-416bfb69da0b')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('df930f9b-5805-4462-8479-416bfb69da0b')/presentations('c091d69c-e0c1-43aa-a2b7-07b245eafcab')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 3 worksheets.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('f28e75e1-fed9-4da4-964f-771e7befd004')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('f28e75e1-fed9-4da4-964f-771e7befd004')/presentations('7b66d90d-7306-4cfc-af89-af9cf7b3e210')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 4 macrosheets and add-in files.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('1211efcc-3987-4d49-912c-6f218f74b611')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('1211efcc-3987-4d49-912c-6f218f74b611')/presentations('52efb481-14ba-4d1b-8b03-73b933919059')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 4 workbooks.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('49741913-dc82-472e-a831-f8b9cebcfb3b')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('49741913-dc82-472e-a831-f8b9cebcfb3b')/presentations('2efec34c-2a2c-4926-8a37-40e0538e2d39')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 4 worksheets.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('74ad65e8-6df4-4194-98a5-cd1c66e461e5')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('74ad65e8-6df4-4194-98a5-cd1c66e461e5')/presentations('e607ed2f-e3b9-4478-8bd3-335233d758ff')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 95 workbooks.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('e289061c-539c-47e7-bba4-609bfccc5be7')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "5", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('e289061c-539c-47e7-bba4-609bfccc5be7')/presentations('75f83dbf-8ec0-4dab-ac9d-45cb395c35fd')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Excel 95-97 workbooks and templates.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('dbc94d34-6c08-4459-ba14-c91e5ed20184')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "5", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('dbc94d34-6c08-4459-ba14-c91e5ed20184')/presentations('1ec7cf4b-5cff-429c-ae81-3d19d372d094')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Microsoft Office query files.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('613f015c-6cca-4bb2-bc6d-772a89eccdc5')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('613f015c-6cca-4bb2-bc6d-772a89eccdc5')/presentations('b2d505b3-f4ba-441e-98ab-3d1034d0ecc7')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Set default file block behavior.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('705795de-23e0-45af-bb36-575a2d880ee2')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "0", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('705795de-23e0-45af-bb36-575a2d880ee2')/presentations('893ae763-f785-4f74-ba49-64c759911e1a')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_Web pages and Excel 2003 XML spreadsheets.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('115c0206-3952-47a8-a0fe-05455b0a93e4')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('115c0206-3952-47a8-a0fe-05455b0a93e4')/presentations('fb6ad578-11ce-42db-abd4-4d7eb5247db6')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_File Block Settings_dBase III _ IV files.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('af226178-7706-4463-8279-195d057da473')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('af226178-7706-4463-8279-195d057da473')/presentations('44f83e1d-ec41-401f-8663-fa49bf9d42c9')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_Protected View_Do not open files from the Internet zone in Protected View.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('a7df08c0-4e3e-40a0-bd4a-321579eb05ba')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_Protected View_Do not open files in unsafe locations in Protected View.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('686f6f27-ca3e-49c1-a622-debf103e4c85')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_Protected View_Set document behavior if file validation fails.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('17162938-080e-4dad-973a-f040636346d5')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_Protected View_Turn off Protected View for attachments opened from Outlook.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('73d52afc-3218-4933-8072-c33bf5d1bb84')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_Require that application add-ins are signed by Trusted Publisher.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('4f9a7958-5466-47ec-a76d-a7dd0e43f6f0')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_Trust access to Visual Basic Project.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('28970d0e-7673-45f7-999c-e564d58e2d64')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Trust Center_VBA Macro Notification Settings.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('6769129c-b98c-4ddb-8cb2-0b4c55f9ebeb')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "3", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('6769129c-b98c-4ddb-8cb2-0b4c55f9ebeb')/presentations('9f2c5355-b699-401c-818e-ffb83507245a')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Excel 2016_Excel Options_Security_Turn off file validation.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('3bf9f9df-ee3a-446f-b53e-243798b20b5b')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Office 2016_Security Settings_Disable VBA for Office applications.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('3aab9919-b73b-4f2b-8a60-77c2c348e825')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Outlook 2016_Security_Trust Center_Allow hyperlinks in suspected phishing e-mail messages.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('eaca8635-cefd-4f22-8a04-26a3007b2336')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft PowerPoint 2016_PowerPoint Options_Security_Make hidden markup visible.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('30162fb6-600d-467d-9dbd-40cea95ecb5b')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft PowerPoint 2016_PowerPoint Options_Security_Run Programs.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('aa6eca64-45f5-4abf-97da-c76a78563600')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "0", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('aa6eca64-45f5-4abf-97da-c76a78563600')/presentations('afb344b3-2512-4e9d-b1cd-68854f4e8638')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_Block macros from running in Office files from the Internet.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('cd880aae-d675-4484-9e37-ddfe518352cf')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_File Block Settings_PowerPoint 97-2003.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('d2514b82-0147-4efb-ad17-ebd261a1a201')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "4", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('d2514b82-0147-4efb-ad17-ebd261a1a201')/presentations('cf3a43ee-4545-4132-ad0d-84ddd7022ec1')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_Protected View_Set document behavior if file validation fails.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('c2fcfa44-294e-4641-a9c2-fee770c626b6')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueBoolean", 7 | "value": false, 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('c2fcfa44-294e-4641-a9c2-fee770c626b6')/presentations('339e9b46-d360-4036-89f5-3545289e3015')" 9 | }, 10 | { 11 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 12 | "value": "0", 13 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('c2fcfa44-294e-4641-a9c2-fee770c626b6')/presentations('450eb463-ca98-4cd4-8ff1-c1d42426cc7d')" 14 | } 15 | ] 16 | } 17 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_Protected View_Turn off Protected.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('ba45be03-e632-408a-bc4d-f2df8f7caa37')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft PowerPoint 2016_PowerPoint Options_Security_Trust Center_Trust access to Visual Basic Project.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('9a744c46-d4fa-49aa-acf5-c674b79719b2')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft PowerPoint 2016_PowerPoint Options_Security_Turn off file validation.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('9cf92212-f1b2-4966-b1b4-d094e6818982')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Visio 2016_Visio Options_Security_Trust Center_File Block Settings_Visio 2000-2002 Binary Drawings, Templates and Stencils.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('e5445c75-65be-4066-b80e-42b213463c66')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('e5445c75-65be-4066-b80e-42b213463c66')/presentations('27b2e6d4-15f5-4f18-9637-ba5cc0071408')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Visio 2016_Visio Options_Security_Trust Center_File Block Settings_Visio 2003-2010 Binary Drawings, Templates and Stencils.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('bd3551d6-c190-42af-8246-dcadc4466b7b')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('bd3551d6-c190-42af-8246-dcadc4466b7b')/presentations('2bb94a14-cb54-47a0-9fb5-99ecf17e3e2c')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Save_Default file format.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('ed2a5416-d394-4310-a143-63ad0ab42147')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Make hidden markup visible.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('7bd6026e-db6e-4993-a127-6249bdc59a4d')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_Block macros from running in Office files from the Internet.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('3894d7d1-f892-4bff-b3ab-910e8c81b6d5')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Set default file block behavior.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('435352ce-9db0-41de-a3fc-2c9cac5ec435')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "0", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('435352ce-9db0-41de-a3fc-2c9cac5ec435')/presentations('ec01185d-07ab-41e2-b950-58ce66e8321c')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2 and earlier binary documents and templates.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('d95e9464-5f1c-4008-9fe7-d8f78641a18c')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('d95e9464-5f1c-4008-9fe7-d8f78641a18c')/presentations('02523e21-292e-493b-a712-eb7dffc20a4f')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2000 binary documents and templates.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('097c6a0b-d0ee-4664-9d11-179eb42dc7da')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('097c6a0b-d0ee-4664-9d11-179eb42dc7da')/presentations('e60ef3aa-0fb6-44dc-bbe0-e9ca307b3dff')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2003 and plain XML documents.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('775dae9b-b762-42e0-b14e-d082bbe4c87a')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('775dae9b-b762-42e0-b14e-d082bbe4c87a')/presentations('b9c1a5ab-8531-4096-809d-1c5263bcfe33')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2003 binary documents and templates.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('b26ecded-1043-45e6-a05d-792240b00d91')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('b26ecded-1043-45e6-a05d-792240b00d91')/presentations('d1c4898f-54e8-4c89-8698-3b3fc4fa833f')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 2007 and later binary documents and templates.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('55e70618-bb12-42f1-ad3e-f4c7a2869f83')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "4", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('55e70618-bb12-42f1-ad3e-f4c7a2869f83')/presentations('9dc627f4-5cff-4a24-ab06-e07e3ce2015f')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 6.0 binary documents and templates.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('a23ee300-d990-48af-a795-abb935d172a3')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('a23ee300-d990-48af-a795-abb935d172a3')/presentations('2d42bc12-b367-4a11-a73b-3e19f690a1df')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 95 binary documents and templates.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('668b1418-6eec-4b53-83dd-ca1261ee0906')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('668b1418-6eec-4b53-83dd-ca1261ee0906')/presentations('20633dc2-f608-4eaa-848c-bf183d2c8eba')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word 97 binary documents and templates.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('480a31af-b36a-48a6-b590-c2b918360380')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('480a31af-b36a-48a6-b590-c2b918360380')/presentations('c57e1883-25da-44e3-a810-90e983ddd8dd')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_File Block Settings_Word XP binary documents and templates.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2fe179a6-2d0f-4354-8469-5daf324db2db')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2fe179a6-2d0f-4354-8469-5daf324db2db')/presentations('20241533-5b33-4d02-ac79-8bacb8eec4fb')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_Trust access to Visual Basic Project.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('9b3b3720-08eb-4a60-b7a5-ce2330e8eb78')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Trust Center_VBA Macro Notification Settings.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('e92ea21b-8d97-4cc3-80c9-dd396c3d61e4')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "3", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('e92ea21b-8d97-4cc3-80c9-dd396c3d61e4')/presentations('e3040ad3-0f64-4b3b-8a39-20cca3793183')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Office_Security/_Microsoft Word 2016_Word Options_Security_Turn off file validation.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('268af92f-8689-455e-b177-7dd2bc97fd43')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge - Default Settings (users can override)_Default search provider_Default search provider name.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2e7068be-919a-4f6f-8f65-f9b0ec7a92ef')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "Google", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2e7068be-919a-4f6f-8f65-f9b0ec7a92ef')/presentations('0b60bb93-8648-4997-b9e1-5ca4bedfac9c')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge - Default Settings (users can override)_Default search provider_Default search provider search URL.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2b2fd6a8-1846-451f-89cd-5bcf6cd6359a')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "{google:baseURL}search?q={searchTerms}\u0026{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2b2fd6a8-1846-451f-89cd-5bcf6cd6359a')/presentations('c40aca27-bdc8-43a1-831f-5620acb8025f')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Allow users to proceed from the HTTPS warning page.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('3d8b4372-f547-44c9-bfd0-c61b39f830cf')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Automatically import another browser's data and settings at first run.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('b8d52fe3-72e5-45cb-806b-f748e6f5a3d7')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "0", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('b8d52fe3-72e5-45cb-806b-f748e6f5a3d7')/presentations('112c452a-d8d1-4f0f-bbcf-0dbce06a4bf0')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Browser sign-in settings.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('871d5363-4bc6-478a-9f75-2a38e4f44cd6')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('871d5363-4bc6-478a-9f75-2a38e4f44cd6')/presentations('74b35a93-4b39-4584-b386-47b9951f31bf')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Content settings_Default Adobe Flash setting.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2c83dff3-5232-4dd9-976e-a1320e4e05b7')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "3", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2c83dff3-5232-4dd9-976e-a1320e4e05b7')/presentations('7af61699-62f2-4aa4-8ebe-94a0f3a78e60')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Content settings_Default notification setting.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('bf2be6ff-9820-4815-8e4e-dfffef518a04')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('bf2be6ff-9820-4815-8e4e-dfffef518a04')/presentations('f03ca5da-054b-49bd-847c-be5ef4061e5b')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Default search provider_Enable the default search provider.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('51cbefd5-a214-4b1f-8163-1473dbcf41ef')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Enable site isolation for every site.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('eefc04b9-c246-4c3d-83fd-0c2bb7376be9')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Force synchronization of browser data and do not show the sync consent prompt.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('c8cf2942-4a84-475d-a967-021a98a026a1')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Hide the First-run experience and splash screen.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('50dfaaa3-c402-4dde-ae57-22e691e24906')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Minimum TLS version enabled.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('9e4c321f-1e99-4d06-a34f-514b6cf81d6f')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "tls1.2", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('9e4c321f-1e99-4d06-a34f-514b6cf81d6f')/presentations('7b5221d6-d817-4b02-8a1d-cc04d61f49e5')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Native Messaging_Allow user-level native messaging hosts (installed without admin permissions).json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('74b526f5-8ec5-46d0-ba8c-35e453608ee1')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_Password manager and protection_Enable saving passwords to the password manager.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2eea8708-ab5c-47ae-b91a-142a071013a5')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_SmartScreen settings_Configure Microsoft Defender SmartScreen to block potentially unwanted apps.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('c406f8cd-1937-4c9c-95af-acbea4309a91')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Edge_Settings/_Microsoft Edge_SmartScreen settings_Prevent bypassing Microsoft Defender SmartScreen prompts for sites.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('a6d684c3-a656-4515-bec3-eee2e5c903c2')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Eventlog/_Windows Components_Event Log Service_Application_Specify the maximum log file size (KB).json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('9c9f7914-04b2-4fd0-9d45-0ce4005fd681')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueDecimal", 7 | "value": 500480, 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('9c9f7914-04b2-4fd0-9d45-0ce4005fd681')/presentations('f64d5399-b62c-41c2-9a1c-05f8826bb225')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Eventlog/_Windows Components_Event Log Service_Security_Specify the maximum log file size (KB).json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2aab8c95-553b-4534-94ef-a0b5f6fe8156')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueDecimal", 7 | "value": 500480, 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2aab8c95-553b-4534-94ef-a0b5f6fe8156')/presentations('c8c0ee63-bb3a-4fa3-b34d-ab4212ae07ed')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Eventlog/_Windows Components_Event Log Service_System_Specify the maximum log file size (KB).json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('98d69f26-2201-4aed-8927-d20c29b24ed5')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueDecimal", 7 | "value": 500480, 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('98d69f26-2201-4aed-8927-d20c29b24ed5')/presentations('5c8d10ad-8a28-4fe2-bd16-170d88dceb82')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Onedrive/_OneDrive_Coauthor and share in Office desktop apps.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2daec783-9596-4947-8592-87deff63d3fa')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Onedrive/_OneDrive_Configure team site libraries to sync automatically.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('f2e9d965-39e3-4efa-8d25-e11e8ff5ef57')", 3 | "enabled": "false" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Onedrive/_OneDrive_Disable the tutorial that appears at the end of OneDrive Setup.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('9a4db949-29e4-4e31-a129-bf2b88d8fa1b')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Onedrive/_OneDrive_Prevent users from redirecting their Windows known folders to their PC.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('2ce2f507-aae8-49a1-98ce-dc3faafcd331')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Onedrive/_OneDrive_Require users to confirm large delete operations.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('8cbfae18-90d8-467f-8b46-8180010bbece')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Onedrive/_OneDrive_Set the sync app update ring.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('120400ba-f245-46c6-9f84-c91b1500d706')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "0", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('120400ba-f245-46c6-9f84-c91b1500d706')/presentations('03081a27-07d6-4982-b31d-0937259d64a0')" 9 | } 10 | ] 11 | } 12 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Onedrive/_OneDrive_Silently move Windows known folders to OneDrive.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('39147fa2-6c5e-437b-8264-19b50b891709')", 3 | "enabled": "true", 4 | "presentationValues": [ 5 | { 6 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 7 | "value": "7bc939ad-dfe4-497e-95da-e083bc73d5a4", 8 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('39147fa2-6c5e-437b-8264-19b50b891709')/presentations('fbefbbdf-5382-477c-8b6c-71f4a06e2805')" 9 | }, 10 | { 11 | "@odata.type": "#microsoft.graph.groupPolicyPresentationValueText", 12 | "value": "0", 13 | "presentation@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('39147fa2-6c5e-437b-8264-19b50b891709')/presentations('35c82072-a93b-4022-be14-8684c2f6fcc2')" 14 | } 15 | ] 16 | } 17 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Onedrive/_OneDrive_Silently sign in users to the OneDrive sync app with their Windows credentials.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('81c07ba0-7512-402d-b1f6-00856975cfab')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/ADMX/Windows10_Onedrive/_OneDrive_Use OneDrive Files On-Demand.json: -------------------------------------------------------------------------------- 1 | { 2 | "definition@odata.bind": "https://graph.microsoft.com/beta/deviceManagement/groupPolicyDefinitions('61b07a01-7e60-4127-b086-f6b32458a5c5')", 3 | "enabled": "true" 4 | } 5 | -------------------------------------------------------------------------------- /DU/DU2b_Create_Autopilot_Profiles.ps1: -------------------------------------------------------------------------------- 1 | ########################################################################### 2 | # Versie: 1.0 (07-04-2021) 3 | # Script: DU.1B 4 | # Autopilot profielen aanmaken # 5 | ########################################################################### 6 | 7 | 8 | $Body = @{ 9 | "@odata.type" = "#microsoft.graph.azureADWindowsAutopilotDeploymentProfile" 10 | displayName = "Autopilot Default Profile" 11 | description = "Autopilot Default Profile" 12 | language = 'os-default' 13 | extractHardwareHash = $false 14 | enableWhiteGlove = $true 15 | outOfBoxExperienceSettings = @{ 16 | "@odata.type" = "microsoft.graph.outOfBoxExperienceSettings" 17 | hidePrivacySettings = $true 18 | hideEULA = $true 19 | userType = 'Standard' 20 | deviceUsageType = 'singleuser' 21 | skipKeyboardSelectionPage = $false 22 | hideEscapeLink = $true 23 | } 24 | enrollmentStatusScreenSettings = @{ 25 | '@odata.type' = "microsoft.graph.windowsEnrollmentStatusScreenSettings" 26 | hideInstallationProgress = $true 27 | allowDeviceUseBeforeProfileAndAppInstallComplete = $true 28 | blockDeviceSetupRetryByUser = $false 29 | allowLogCollectionOnInstallFailure = $true 30 | customErrorMessage = "An error has occured. Please contact your IT Administrator" 31 | installProgressTimeoutInMinutes = "45" 32 | allowDeviceUseOnInstallFailure = $true 33 | } 34 | } | ConvertTo-Json 35 | 36 | 37 | $apiurl = "https://graph.microsoft.com/beta/deviceManagement/windowsAutopilotDeploymentProfiles" 38 | $Data = Invoke-RestMethod -Headers @{Authorization = "Bearer $($accessToken1b)"} -Uri $apiUrl -Body $body -Method Post -ContentType 'application/json' 39 | -------------------------------------------------------------------------------- /DU/DU2c_Autopilot_profile_assignment.ps1: -------------------------------------------------------------------------------- 1 | ########################################################################### 2 | # Versie: 1.0 (07-04-2021) 3 | # Script: DU.1d 4 | # Autopilot profile assigment 5 | ########################################################################### 6 | #Autopilot profile assigment 7 | 8 | $autopilotprofile = Get-autopilotprofile 9 | $autopilotprofileid1 = $autopilotprofile[0].id 10 | 11 | 12 | $body = @" 13 | {"target":{"@odata.type":"#microsoft.graph.groupAssignmentTarget","groupId":"$autopilotstaticgroupid"}} 14 | "@ 15 | $apiurl = 16 | "https://graph.microsoft.com/beta/deviceManagement/windowsAutopilotDeploymentProfiles/$autopilotprofileid1/assignments" 17 | $Data = Invoke-RestMethod -Headers @{Authorization = "Bearer $($accessToken1b)"} -Uri $apiUrl -Body $body -Method Post -ContentType 'application/json' 18 | 19 | -------------------------------------------------------------------------------- /DU/DU2d_Link_license_to_Group.ps1: -------------------------------------------------------------------------------- 1 | ########################################################################### 2 | # Versie: 1.0 (07-04-2021) 3 | # Script: DU.1e 4 | # Licentie aan groep koppelen 5 | ########################################################################### 6 | 7 | 8 | $body = @{ 9 | addLicenses = @( 10 | @{ 11 | skuId = 'cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46' 12 | } 13 | ) 14 | removeLicenses = @() 15 | } | ConvertTo-Json -Depth 3 16 | 17 | $content = $body 18 | $url = -join ('https://graph.microsoft.com/v1.0/groups/',$ms365licensegroupid,'/assignLicense') 19 | $Data = Invoke-RestMethod -Headers @{Authorization = "Bearer $($accessToken1e)"} -Uri $Url -Body $body -Method Post -ContentType 'application/json' 20 | -------------------------------------------------------------------------------- /DU/DU2e_Set_Intune_As_MDMAuthority.ps1: -------------------------------------------------------------------------------- 1 | ########################################################################### 2 | # Versie: 1.22 (06-09-2021) 3 | # Script: DU.2A 4 | # Intune Instellen als MDM Authority # 5 | ########################################################################### 6 | 7 | # Connecten naar msgraph (install-module microsoft.graph.intune) 8 | 9 | $mdmAuth = (Invoke-MSGraphRequest -Url "https://graph.microsoft.com/beta/organization('$OrgId')?`$select=mobiledevicemanagementauthority" -HttpMethod Get -ErrorAction Stop).mobileDeviceManagementAuthority 10 | 11 | 12 | if($mdmAuth -notlike "intune") 13 | { 14 | $OrgID = (Invoke-MSGraphRequest -Url "https://graph.microsoft.com/v1.0/organization" -HttpMethod Get -ErrorAction Stop).value.id 15 | Invoke-MSGraphRequest -Url "https://graph.microsoft.com/v1.0/organization/$OrgID/setMobileDeviceManagementAuthority" -HttpMethod Post -ErrorAction Stop 16 | } 17 | 18 | 19 | 20 | $url = "https://main.iam.ad.ext.azure.com/api/MdmApplications" 21 | $mdmapp= Invoke-RestMethod –Uri $url –Headers $headersazurerm –Method get 22 | $mdmapp = $mdmapp | Where-Object {$_.appDisplayName -eq "Microsoft Intune"} 23 | $mdmappid = $mdmapp.objectId 24 | 25 | $url = -join ('https://main.iam.ad.ext.azure.com/api/MdmApplications/',$mdmappid,'?mdmAppliesToChanged=true&mamAppliesToChanged=true') 26 | 27 | $contentpart1 = -join ('{"objectId":"',$mdmappid,'","appId":"0000000a-0000-0000-c000-000000000000","appDisplayName":"Microsoft Intune","appCategory":"Mdm","logoUrl":null,"isOnPrem":false,"appData":{"mamEnrollmentUrl":"https://wip.mam.manage.microsoft.com/Enroll","mamComplianceUrl":"","mamTermsOfUseUrl":"","enrollmentUrl":"https://enrollment.manage.microsoft.com/enrollmentserver/discovery.svc","complianceUrl":"https://portal.manage.microsoft.com/?portalAction=Compliance","termsOfUseUrl":"https://portal.manage.microsoft.com/TermsofUse.aspx"},"originalAppData":{"mamEnrollmentUrl":"https://wip.mam.manage.microsoft.com/Enroll","mamComplianceUrl":"","mamTermsOfUseUrl":"","enrollmentUrl":"https://enrollment.manage.microsoft.com/enrollmentserver/discovery.svc","complianceUrl":"https://portal.manage.microsoft.com/?portalAction=Compliance","termsOfUseUrl":"https://portal.manage.microsoft.com/TermsofUse.aspx"},"mdmAppliesTo":1,"mamAppliesTo":2,"mdmAppliesToGroups":[{"objectId":"',$ms365licensegroupid,'","displayName":"MS365BusinessLicences ","dirSyncEnabled":null,"groupTypes":null,"securityEnabled":null,"mailEnabled":null}],"mamAppliesToGroups":[]}') 28 | $content = $contentpart1 29 | 30 | Invoke-RestMethod –Uri $url –Headers $headersazurerm –Method PUT -Body $content -ErrorAction Stop 31 | 32 | ############################################################################### 33 | #Enable Continuous access evaluation V1.2.2 34 | ################################################################################ 35 | 36 | $url = "https://main.iam.ad.ext.azure.com/api/SmartSession/Config" 37 | $content = '{"state":1,"groupsToInclude":[],"usersToInclude":[],"isStrictLocationEnforcementEnabled":false}' 38 | Invoke-RestMethod –Uri $url –Headers $headersazurerm –Method Put -Body $content -ErrorAction Stop 39 | 40 | 41 | ############################################################################### 42 | #Enable new mfa experience V1.2.2 43 | ################################################################################ 44 | 45 | $url = "https://main.iam.ad.ext.azure.com/api/Directories/FeatureSettingsProperties" 46 | $contentpart1 = '{"convergedUXV2FeatureValue":"2"}' 47 | $content = $contentpart1 48 | Invoke-RestMethod –Uri $url –Headers $headersazurerm –Method Put -Body $content -ErrorAction Stop 49 | 50 | ############################################################################### 51 | #Enable / configure password reset V1.2.2 52 | ################################################################################ 53 | 54 | $url = "https://main.iam.ad.ext.azure.com/api/PasswordReset/PasswordResetPolicies" 55 | $contentpart1 = -join ('{"objectId":"default","enablementType":1,"numberOfAuthenticationMethodsRequired":1,"emailOptionEnabled":true,"mobilePhoneOptionEnabled":true,"officePhoneOptionEnabled":false,"securityQuestionsOptionEnabled":false,"mobileAppNotificationEnabled":false,"mobileAppCodeEnabled":false,"numberOfQuestionsToRegister":5,"numberOfQuestionsToReset":3,"registrationRequiredOnSignIn":true,"registrationReconfirmIntevalInDays":180,"skipRegistrationAllowed":true,"skipRegistrationMaxAllowedDays":7,"customizeHelpdeskLink":false,"customHelpdeskEmailOrUrl":"","notifyUsersOnPasswordReset":true,"notifyOnAdminPasswordReset":false,"passwordResetEnabledGroupIds":["',$ms365licensegroupid,'"],"passwordResetEnabledGroupName":"MS365BusinessLicences ","securityQuestions":[],"registrationConditionalAccessPolicies":[],"emailOptionAllowed":true,"mobilePhoneOptionAllowed":true,"officePhoneOptionAllowed":true,"securityQuestionsOptionAllowed":true,"mobileAppNotificationOptionAllowed":true,"mobileAppCodeOptionAllowed":true}') 56 | $content = $contentpart1 57 | Invoke-RestMethod –Uri $url –Headers $headersazurerm –Method Put -Body $content -ErrorAction Stop 58 | 59 | -------------------------------------------------------------------------------- /DU/DU2f_Config_Apple_MDM.ps1: -------------------------------------------------------------------------------- 1 | ########################################################################### 2 | # Versie: 1.0 (07-04-2021) 3 | # Script: DU.2C 4 | # Apple MDM configureren # 5 | ########################################################################### 6 | 7 | #IOS_UserEnrollmentCOnfigureren 8 | 9 | $body = @" 10 | {"id":"74bff598-526e-40b5-95e0-2ca176acc8dc","displayName":"IOS_UserEnrollment","description":"","priority":0,"platform":"iOS","createdDateTime":"2021-03-25T09:36:38.7935651Z","lastModifiedDateTime":"2021-03-25T09:57:22Z","defaultEnrollmentType":"device","availableEnrollmentTypeOptions":[]} 11 | "@ 12 | $apiurl = “ 13 | https://graph.microsoft.com/beta/deviceManagement/appleUserInitiatedEnrollmentProfiles” 14 | 15 | $Data = Invoke-RestMethod -Headers @{Authorization = "Bearer $($accessToken1b)"} -Uri $apiUrl -Body $body -Method Post -ContentType 'application/json' 16 | 17 | #assignment maken 18 | 19 | $Data = Invoke-RestMethod -Headers @{Authorization = "Bearer $($accessToken1b)"} -Uri $apiUrl -Method get 20 | $id = $data.value.id 21 | 22 | $apiurl = “https://graph.microsoft.com/beta/deviceManagement/appleUserInitiatedEnrollmentProfiles/$id/assignments” 23 | 24 | $body = @" 25 | {"target":{"@odata.type":"#microsoft.graph.allLicensedUsersAssignmentTarget"}} 26 | "@ 27 | $Data = Invoke-RestMethod -Headers @{Authorization = "Bearer $($accessToken1b)"} -Uri $apiUrl -Body $body -Method Post -ContentType 'application/json' 28 | -------------------------------------------------------------------------------- /DU/DU2g_Assign_Google_Apps.ps1: -------------------------------------------------------------------------------- 1 | Function Get-IntuneApplication(){ 2 | 3 | <# 4 | #> 5 | 6 | [cmdletbinding()] 7 | 8 | $graphApiVersion = "Beta" 9 | $Resource = "deviceAppManagement/mobileApps" 10 | 11 | try { 12 | 13 | $uri = "https://graph.microsoft.com/$graphApiVersion/$($Resource)" 14 | #(Invoke-RestMethod -Uri $uri –Headers $authToken –Method Get).Value | ? { (!($_.'@odata.type').Contains("managed")) } 15 | (Invoke-RestMethod -Uri $uri –Headers @{Authorization = "Bearer $($accessToken1b)"} –Method Get).Value | ? { (!($_.'@odata.type').Contains("managed")) } 16 | 17 | } 18 | 19 | catch { 20 | 21 | $ex = $_.Exception 22 | Write-Host "Request to $Uri failed with HTTP Status $([int]$ex.Response.StatusCode) $($ex.Response.StatusDescription)" -f Red 23 | $errorResponse = $ex.Response.GetResponseStream() 24 | $reader = New-Object System.IO.StreamReader($errorResponse) 25 | $reader.BaseStream.Position = 0 26 | $reader.DiscardBufferedData() 27 | $responseBody = $reader.ReadToEnd(); 28 | Write-Host "Response content:`n$responseBody" -f Red 29 | Write-Error "Request to $Uri failed with HTTP Status $($ex.Response.StatusCode) $($ex.Response.StatusDescription)" 30 | write-host 31 | break 32 | } 33 | } 34 | 35 | ######################## 36 | # get all android apps # 37 | ########################### 38 | 39 | $mobileApps = Get-IntuneApplication -All | Select-Object displayName, id, '@odata.type' | ? { $_.'@odata.type' -eq "#microsoft.graph.androidManagedStoreApp" } 40 | foreach ($mobileApp in $mobileApps) { 41 | $applicationid = $mobileapp.id 42 | $applicationuri = "https://graph.microsoft.com/beta/deviceAppManagement/mobileApps/$applicationid/assignments" 43 | Invoke-RestMethod -Uri $applicationuri –Headers @{Authorization = "Bearer $($accessToken1b)"} –Method Get 44 | $contentpart1 = '{"intent":"required","source": "direct","sourceId": null,"target": {"@odata.type": "#microsoft.graph.allDevicesAssignmentTarget"}}' 45 | $content = $contentpart1 46 | Invoke-RestMethod -Headers @{Authorization = "Bearer $($accessToken1b)"} -Uri $applicationuri -Body $content -Method Post -ContentType 'application/json' 47 | } 48 | -------------------------------------------------------------------------------- /DU/DU3b_iOS_Assign_Basic_Apps.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/DU3b_iOS_Assign_Basic_Apps.ps1 -------------------------------------------------------------------------------- /DU/DU3b_iOS_Upload_Basic_Apps.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/DU3b_iOS_Upload_Basic_Apps.ps1 -------------------------------------------------------------------------------- /DU/DU3c_Config_Enrollment_Status_Page.ps1: -------------------------------------------------------------------------------- 1 | 2 | 3 | #################################################### 4 | 5 | #$authResult = Get-MsalToken -ClientId 'd1ddf0e4-d672-4dae-b554-9d5bdfd93547' -Scopes 'https://graph.microsoft.com/.default' 6 | #$headers1b = @{ 7 | # 'Content-Type'='application/json' 8 | # 'Authorization'="Bearer " + $authResult.AccessToken 9 | # 'ExpiresOn'=$authResult.ExpiresOn 10 | # } 11 | 12 | #################################################### 13 | 14 | Function Get-DeviceEnrollmentConfigurations(){ 15 | 16 | [cmdletbinding()] 17 | 18 | $graphApiVersion = "Beta" 19 | $Resource = "deviceManagement/deviceEnrollmentConfigurations" 20 | 21 | try { 22 | 23 | $uri = "https://graph.microsoft.com/$graphApiVersion/$($Resource)" 24 | (Invoke-RestMethod -Uri $uri -Headers $headers1b -Method Get).Value 25 | 26 | } 27 | 28 | catch { 29 | 30 | $ex = $_.Exception 31 | $errorResponse = $ex.Response.GetResponseStream() 32 | $reader = New-Object System.IO.StreamReader($errorResponse) 33 | $reader.BaseStream.Position = 0 34 | $reader.DiscardBufferedData() 35 | $responseBody = $reader.ReadToEnd(); 36 | Write-Host "Response content:`n$responseBody" -f Red 37 | Write-Error "Request to $Uri failed with HTTP Status $($ex.Response.StatusCode) $($ex.Response.StatusDescription)" 38 | write-host 39 | break 40 | 41 | } 42 | 43 | } 44 | 45 | #################################################### 46 | 47 | Function Set-DeviceEnrollmentConfiguration(){ 48 | 49 | 50 | [cmdletbinding()] 51 | 52 | param 53 | ( 54 | $JSON, 55 | $DEC_Id 56 | ) 57 | 58 | $graphApiVersion = "Beta" 59 | $App_resource = "deviceManagement/deviceEnrollmentConfigurations" 60 | 61 | try { 62 | 63 | if(!$JSON){ 64 | 65 | write-host "No JSON was passed to the function, provide a JSON variable" -f Red 66 | break 67 | 68 | } 69 | 70 | elseif(!$DEC_Id){ 71 | 72 | write-host "No Device Enrollment Configuration ID was passed to the function, provide a Device Enrollment Configuration ID" -f Red 73 | break 74 | 75 | } 76 | 77 | else { 78 | 79 | Test-JSON -JSON $JSON 80 | 81 | $uri = "https://graph.microsoft.com/$graphApiVersion/$($App_resource)/$DEC_Id" 82 | Invoke-RestMethod -Uri $uri -Method Patch -ContentType "application/json" -Body $JSON -Headers $headers1b 83 | 84 | } 85 | 86 | } 87 | 88 | catch { 89 | 90 | $ex = $_.Exception 91 | $errorResponse = $ex.Response.GetResponseStream() 92 | $reader = New-Object System.IO.StreamReader($errorResponse) 93 | $reader.BaseStream.Position = 0 94 | $reader.DiscardBufferedData() 95 | $responseBody = $reader.ReadToEnd(); 96 | Write-Host "Response content:`n$responseBody" -f Red 97 | Write-Error "Request to $Uri failed with HTTP Status $($ex.Response.StatusCode) $($ex.Response.StatusDescription)" 98 | write-host 99 | break 100 | 101 | } 102 | 103 | } 104 | 105 | #################################################### 106 | 107 | Function Test-JSON(){ 108 | 109 | param ( 110 | 111 | $JSON 112 | 113 | ) 114 | 115 | try { 116 | 117 | $TestJSON = ConvertFrom-Json $JSON -ErrorAction Stop 118 | $validJson = $true 119 | 120 | } 121 | 122 | catch { 123 | 124 | $validJson = $false 125 | $_.Exception 126 | 127 | } 128 | 129 | if (!$validJson){ 130 | 131 | Write-Host "Provided JSON isn't in valid JSON format" -f Red 132 | break 133 | 134 | } 135 | 136 | } 137 | 138 | 139 | #################################################### 140 | 141 | $JSON = @" 142 | 143 | { 144 | "@odata.context": "https://graph.microsoft.com/beta/$metadata#deviceManagement/deviceEnrollmentConfigurations/$entity", 145 | "@odata.type": "#microsoft.graph.windows10EnrollmentCompletionPageConfiguration", 146 | "id": "942bf267-8ce1-4d12-8691-163ea8c6b54b_DefaultWindows10EnrollmentCompletionPageConfiguration", 147 | "displayName": "All users and all devices", 148 | "description": "This is the default enrollment status screen configuration applied with the lowest priority to all users and all devices regardless of group membership.", 149 | "priority": 0, 150 | "createdDateTime": "2020-03-12T19:50:28.1782346Z", 151 | "lastModifiedDateTime": "2020-03-12T19:50:28.1782346Z", 152 | "version": 0, 153 | "showInstallationProgress": true, 154 | "blockDeviceSetupRetryByUser": false, 155 | "allowDeviceResetOnInstallFailure": true, 156 | "allowLogCollectionOnInstallFailure": true, 157 | "customErrorMessage": "", 158 | "installProgressTimeoutInMinutes": 90, 159 | "allowDeviceUseOnInstallFailure": true, 160 | "selectedMobileAppIds": [ 161 | "cd961d45-9f46-42e8-ae06-9a430387863c", 162 | "8a042df1-da0b-435f-ab1b-1640e629d5bf", 163 | "322879a6-3864-4d94-a6de-88a577c9d3fd" 164 | ], 165 | "trackInstallProgressForAutopilotOnly": true, 166 | "disableUserStatusTrackingAfterFirstUser": true 167 | } 168 | 169 | "@ 170 | 171 | #################################################### 172 | 173 | $DeviceEnrollmentConfigurations = Get-DeviceEnrollmentConfigurations 174 | 175 | $PlatformRestrictions = ($DeviceEnrollmentConfigurations | Where-Object { ($_.id).contains("DefaultWindows10EnrollmentCompletionPageConfiguration") }).id 176 | 177 | Set-DeviceEnrollmentConfiguration -DEC_Id $PlatformRestrictions -JSON $JSON 178 | -------------------------------------------------------------------------------- /DU/DU4a_DeviceConfigurationADMX_Assignment.ps1: -------------------------------------------------------------------------------- 1 | 2 | #################################################### 3 | 4 | #$authResult = Get-MsalToken -ClientId 'd1ddf0e4-d672-4dae-b554-9d5bdfd93547' -Scopes 'https://graph.microsoft.com/.default' 5 | #$headers1b = @{ 6 | # 'Content-Type'='application/json' 7 | # 'Authorization'="Bearer " + $authResult.AccessToken 8 | # 'ExpiresOn'=$authResult.ExpiresOn 9 | # } 10 | 11 | #################################################### 12 | 13 | Function Get-IntuneApplication(){ 14 | 15 | [cmdletbinding()] 16 | 17 | $graphApiVersion = "Beta" 18 | $Resource = "deviceManagement/groupPolicyConfigurations" 19 | $uri = "https://graph.microsoft.com/$graphApiVersion/$($resource)" 20 | (Invoke-RestMethod -Uri $uri -Headers $headers1b -Method Get).Value 21 | 22 | 23 | } 24 | 25 | # 26 | 27 | #################################################### 28 | 29 | #################################################### 30 | ####Windows10_Onedrive_assignments #### 31 | #################################################### 32 | $ApplicationName = "Windows10_Onedrive" 33 | $Application = Get-IntuneApplication | ? { $_.displayName -eq "$ApplicationName" } 34 | $solarwindsid = $application.id 35 | $solarwindsuri = "https://graph.microsoft.com/beta/deviceManagement/groupPolicyConfigurations('$solarwindsid')/assign" 36 | $contentpart1 = '{"assignments":[{"id":"","target":{"@odata.type":"#microsoft.graph.allLicensedUsersAssignmentTarget"}},{"id":"","target":{"@odata.type":"#microsoft.graph.allDevicesAssignmentTarget"}}]}' 37 | $content = $contentpart1 38 | Invoke-RestMethod -Uri $solarwindsuri -Headers $headers1b -Method Post -Body $content -ErrorAction Stop -ContentType 'application/json' 39 | 40 | #################################################### 41 | ####Office_OutlookSSO_assignments #### 42 | #################################################### 43 | $ApplicationName = "Office_outlooksso" 44 | $Application = Get-IntuneApplication | ? { $_.displayName -eq "$ApplicationName" } 45 | $solarwindsid = $application.id 46 | $solarwindsuri = "https://graph.microsoft.com/beta/deviceManagement/groupPolicyConfigurations('$solarwindsid')/assign" 47 | $contentpart1 = '{"assignments":[{"id":"","target":{"@odata.type":"#microsoft.graph.allLicensedUsersAssignmentTarget"}},{"id":"","target":{"@odata.type":"#microsoft.graph.allDevicesAssignmentTarget"}}]}' 48 | $content = $contentpart1 49 | Invoke-RestMethod -Uri $solarwindsuri -Headers $headers1b -Method Post -Body $content -ErrorAction Stop -ContentType 'application/json' 50 | 51 | #################################################### 52 | ####Office_security_assignments #### 53 | #################################################### 54 | $ApplicationName = "Office_Security" 55 | $Application = Get-IntuneApplication | ? { $_.displayName -eq "$ApplicationName" } 56 | $solarwindsid = $application.id 57 | $solarwindsuri = "https://graph.microsoft.com/beta/deviceManagement/groupPolicyConfigurations('$solarwindsid')/assign" 58 | $contentpart1 = '{"assignments":[{"id":"","target":{"@odata.type":"#microsoft.graph.allLicensedUsersAssignmentTarget"}},{"id":"","target":{"@odata.type":"#microsoft.graph.allDevicesAssignmentTarget"}}]}' 59 | $content = $contentpart1 60 | Invoke-RestMethod -Uri $solarwindsuri -Headers $headers1b -Method Post -Body $content -ErrorAction Stop -ContentType 'application/json' 61 | 62 | #################################################### 63 | ####Windows10_Edge_Settings1_assignments #### 64 | #################################################### 65 | $ApplicationName = "Windows10_Edge_Settings" 66 | $Application = Get-IntuneApplication | ? { $_.displayName -eq "$ApplicationName" } 67 | $solarwindsid = $application.id 68 | $solarwindsuri = "https://graph.microsoft.com/beta/deviceManagement/groupPolicyConfigurations('$solarwindsid')/assign" 69 | $contentpart1 = '{"assignments":[{"id":"","target":{"@odata.type":"#microsoft.graph.allLicensedUsersAssignmentTarget"}},{"id":"","target":{"@odata.type":"#microsoft.graph.allDevicesAssignmentTarget"}}]}' 70 | $content = $contentpart1 71 | Invoke-RestMethod -Uri $solarwindsuri -Headers $headers1b -Method Post -Body $content -ErrorAction Stop -ContentType 'application/json' 72 | #################################################### 73 | ####Windows10_Eventlog_assignments #### 74 | #################################################### 75 | $ApplicationName = "Windows10_Eventlog" 76 | $Application = Get-IntuneApplication | ? { $_.displayName -eq "$ApplicationName" } 77 | $solarwindsid = $application.id 78 | $solarwindsuri = "https://graph.microsoft.com/beta/deviceManagement/groupPolicyConfigurations('$solarwindsid')/assign" 79 | $contentpart1 = '{"assignments":[{"id":"","target":{"@odata.type":"#microsoft.graph.allLicensedUsersAssignmentTarget"}},{"id":"","target":{"@odata.type":"#microsoft.graph.allDevicesAssignmentTarget"}}]}' 80 | $content = $contentpart1 81 | Invoke-RestMethod -Uri $solarwindsuri -Headers $headers1b -Method Post -Body $content -ErrorAction Stop -ContentType 'application/json' 82 | 83 | -------------------------------------------------------------------------------- /DU/DU4b_AppConfigurationPolicy_Assignment.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/DU4b_AppConfigurationPolicy_Assignment.ps1 -------------------------------------------------------------------------------- /DU/DU7_Config_WindowsHello.ps1: -------------------------------------------------------------------------------- 1 | #################################################### 2 | 3 | #$authResult = Get-MsalToken -ClientId 'd1ddf0e4-d672-4dae-b554-9d5bdfd93547' -Scopes 'https://graph.microsoft.com/.default' 4 | #$headers1b = @{ 5 | # 'Content-Type'='application/json' 6 | # 'Authorization'="Bearer " + $authResult.AccessToken 7 | # 'ExpiresOn'=$authResult.ExpiresOn 8 | # } 9 | 10 | #################################################### 11 | 12 | Function Get-DeviceEnrollmentConfigurations(){ 13 | 14 | 15 | [cmdletbinding()] 16 | 17 | $graphApiVersion = "Beta" 18 | $Resource = "deviceManagement/deviceEnrollmentConfigurations" 19 | 20 | try { 21 | 22 | $uri = "https://graph.microsoft.com/$graphApiVersion/$($Resource)" 23 | (Invoke-RestMethod -Uri $uri -Headers $headers1b -Method Get).Value 24 | 25 | } 26 | 27 | catch { 28 | 29 | $ex = $_.Exception 30 | $errorResponse = $ex.Response.GetResponseStream() 31 | $reader = New-Object System.IO.StreamReader($errorResponse) 32 | $reader.BaseStream.Position = 0 33 | $reader.DiscardBufferedData() 34 | $responseBody = $reader.ReadToEnd(); 35 | Write-Host "Response content:`n$responseBody" -f Red 36 | Write-Error "Request to $Uri failed with HTTP Status $($ex.Response.StatusCode) $($ex.Response.StatusDescription)" 37 | write-host 38 | break 39 | 40 | } 41 | 42 | } 43 | 44 | #################################################### 45 | 46 | Function Set-DeviceEnrollmentConfiguration(){ 47 | 48 | 49 | [cmdletbinding()] 50 | 51 | param 52 | ( 53 | $JSON, 54 | $DEC_Id 55 | ) 56 | 57 | $graphApiVersion = "Beta" 58 | $App_resource = "deviceManagement/deviceEnrollmentConfigurations" 59 | 60 | try { 61 | 62 | if(!$JSON){ 63 | 64 | write-host "No JSON was passed to the function, provide a JSON variable" -f Red 65 | break 66 | 67 | } 68 | 69 | elseif(!$DEC_Id){ 70 | 71 | write-host "No Device Enrollment Configuration ID was passed to the function, provide a Device Enrollment Configuration ID" -f Red 72 | break 73 | 74 | } 75 | 76 | else { 77 | 78 | Test-JSON -JSON $JSON 79 | 80 | $uri = "https://graph.microsoft.com/$graphApiVersion/$($App_resource)/$DEC_Id" 81 | Invoke-RestMethod -Uri $uri -Method Patch -ContentType "application/json" -Body $JSON -Headers $headers1b 82 | 83 | } 84 | 85 | } 86 | 87 | catch { 88 | 89 | $ex = $_.Exception 90 | $errorResponse = $ex.Response.GetResponseStream() 91 | $reader = New-Object System.IO.StreamReader($errorResponse) 92 | $reader.BaseStream.Position = 0 93 | $reader.DiscardBufferedData() 94 | $responseBody = $reader.ReadToEnd(); 95 | Write-Host "Response content:`n$responseBody" -f Red 96 | Write-Error "Request to $Uri failed with HTTP Status $($ex.Response.StatusCode) $($ex.Response.StatusDescription)" 97 | write-host 98 | break 99 | 100 | } 101 | 102 | } 103 | 104 | #################################################### 105 | 106 | Function Test-JSON(){ 107 | 108 | param ( 109 | 110 | $JSON 111 | 112 | ) 113 | 114 | try { 115 | 116 | $TestJSON = ConvertFrom-Json $JSON -ErrorAction Stop 117 | $validJson = $true 118 | 119 | } 120 | 121 | catch { 122 | 123 | $validJson = $false 124 | $_.Exception 125 | 126 | } 127 | 128 | if (!$validJson){ 129 | 130 | Write-Host "Provided JSON isn't in valid JSON format" -f Red 131 | break 132 | 133 | } 134 | 135 | } 136 | 137 | #################################################### 138 | 139 | 140 | #################################################### 141 | 142 | $JSON = @" 143 | 144 | { 145 | "@odata.context": "https://graph.microsoft.com/beta/$metadata#deviceManagement/deviceEnrollmentConfigurations/$entity", 146 | "@odata.type": "#microsoft.graph.deviceEnrollmentWindowsHelloForBusinessConfiguration", 147 | "id": "4349e3f2-787b-4fb4-87d7-c191e84d4614_DefaultWindowsHelloForBusiness", 148 | "displayName": "All users and all devices", 149 | "description": "This is the default Windows Hello for Business configuration applied with the lowest priority to all users regardless of group membership.", 150 | "priority": 0, 151 | "createdDateTime": "2020-03-12T19:50:28.1782346Z", 152 | "lastModifiedDateTime": "2020-03-12T19:50:28.1782346Z", 153 | "version": 0, 154 | "pinMinimumLength": 6, 155 | "pinMaximumLength": 127, 156 | "pinUppercaseCharactersUsage": "allowed", 157 | "pinLowercaseCharactersUsage": "allowed", 158 | "pinSpecialCharactersUsage": "allowed", 159 | "state": "enabled", 160 | "securityDeviceRequired": false, 161 | "unlockWithBiometricsEnabled": true, 162 | "remotePassportEnabled": true, 163 | "pinPreviousBlockCount": 0, 164 | "pinExpirationInDays": 120, 165 | "enhancedBiometricsState": "notConfigured", 166 | "securityKeyForSignIn": "notConfigured" 167 | } 168 | 169 | "@ 170 | 171 | #################################################### 172 | 173 | $DeviceEnrollmentConfigurations = Get-DeviceEnrollmentConfigurations 174 | 175 | $PlatformRestrictions = ($DeviceEnrollmentConfigurations | Where-Object { ($_.id).contains("DefaultWindowsHelloForBusiness") }).id 176 | 177 | Set-DeviceEnrollmentConfiguration -DEC_Id $PlatformRestrictions -JSON $JSON 178 | -------------------------------------------------------------------------------- /DU/JSON/Android_Device_Restrictions.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.androidWorkProfileGeneralDeviceConfiguration", 3 | "id": "15b785e8-add8-4523-9ce2-b7191557a919", 4 | "lastModifiedDateTime": "\/Date(1593526672700)\/", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "\/Date(1586354389999)\/", 13 | "description": "", 14 | "displayName": "Android_Device_Restrictions", 15 | "version": 3, 16 | "passwordBlockFaceUnlock": false, 17 | "passwordBlockFingerprintUnlock": false, 18 | "passwordBlockIrisUnlock": false, 19 | "passwordBlockTrustAgents": false, 20 | "passwordExpirationDays": null, 21 | "passwordMinimumLength": null, 22 | "passwordMinutesOfInactivityBeforeScreenTimeout": null, 23 | "passwordPreviousPasswordBlockCount": null, 24 | "passwordSignInFailureCountBeforeFactoryReset": null, 25 | "passwordRequiredType": "atLeastNumeric", 26 | "workProfileDataSharingType": "deviceDefault", 27 | "workProfileBlockNotificationsWhileDeviceLocked": false, 28 | "workProfileBlockAddingAccounts": false, 29 | "workProfileBluetoothEnableContactSharing": true, 30 | "workProfileBlockScreenCapture": true, 31 | "workProfileBlockCrossProfileCallerId": false, 32 | "workProfileBlockCamera": false, 33 | "workProfileBlockCrossProfileContactsSearch": false, 34 | "workProfileBlockCrossProfileCopyPaste": true, 35 | "workProfileDefaultAppPermissionPolicy": "deviceDefault", 36 | "workProfilePasswordBlockFaceUnlock": false, 37 | "workProfilePasswordBlockFingerprintUnlock": false, 38 | "workProfilePasswordBlockIrisUnlock": false, 39 | "workProfilePasswordBlockTrustAgents": false, 40 | "workProfilePasswordExpirationDays": null, 41 | "workProfilePasswordMinimumLength": null, 42 | "workProfilePasswordMinNumericCharacters": null, 43 | "workProfilePasswordMinNonLetterCharacters": null, 44 | "workProfilePasswordMinLetterCharacters": null, 45 | "workProfilePasswordMinLowerCaseCharacters": null, 46 | "workProfilePasswordMinUpperCaseCharacters": null, 47 | "workProfilePasswordMinSymbolCharacters": null, 48 | "workProfilePasswordMinutesOfInactivityBeforeScreenTimeout": null, 49 | "workProfilePasswordPreviousPasswordBlockCount": null, 50 | "workProfilePasswordSignInFailureCountBeforeFactoryReset": null, 51 | "workProfilePasswordRequiredType": "atLeastNumeric", 52 | "workProfileRequirePassword": true, 53 | "securityRequireVerifyApps": true, 54 | "vpnAlwaysOnPackageIdentifier": null, 55 | "vpnEnableAlwaysOnLockdownMode": false, 56 | "workProfileAllowWidgets": false, 57 | "workProfileBlockPersonalAppInstallsFromUnknownSources": true 58 | } -------------------------------------------------------------------------------- /DU/JSON/Android_compliance_RequireDeviceHealth.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Android_compliance_RequireDeviceHealth.json -------------------------------------------------------------------------------- /DU/JSON/Android_compliance_RequireDeviceSecurity.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Android_compliance_RequireDeviceSecurity.json -------------------------------------------------------------------------------- /DU/JSON/Android_compliance_RequireOSVersion.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Android_compliance_RequireOSVersion.json -------------------------------------------------------------------------------- /DU/JSON/AzureAd_AllowPasswordreset.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windows10CustomConfiguration", 3 | "id": "6704766a-6c6a-4d9c-b89d-ca45c9037039", 4 | "lastModifiedDateTime": "2020-03-12T19:50:28.1782346Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-03-12T19:50:28.1782346Z", 13 | "description": "", 14 | "displayName": "AzureAd_AllowPasswordreset", 15 | "version": 1, 16 | "omaSettings": [ 17 | { 18 | "@odata.type": "#microsoft.graph.omaSettingInteger", 19 | "displayName": "ResetPasswordLink", 20 | "description": null, 21 | "omaUri": "./Vendor/MSFT/Policy/Config/Authentication/AllowAadPasswordReset", 22 | "value": 1, 23 | "isReadOnly": false 24 | } 25 | ] 26 | } 27 | -------------------------------------------------------------------------------- /DU/JSON/IOS_IntuneMAMUpn_Excel_11-03-2021-9-51-461.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.iosMobileAppConfiguration", 3 | "createdDateTime": "2021-03-11T08:50:36.7907688Z", 4 | "description": "", 5 | "displayName": "IOS_IntuneMAMUpn_Excel", 6 | "encodedSettingXml": null, 7 | "id": "c2e1922d-19af-4045-80e4-4cd42aab646e", 8 | "lastModifiedDateTime": "2021-03-11T08:50:36.7907688Z", 9 | "roleScopeTagIds": [ 10 | "0" 11 | ], 12 | "settings": [ 13 | { 14 | "appConfigKey": "IntuneMAMUpn", 15 | "appConfigKeyType": "stringType", 16 | "appConfigKeyValue": "{{UserPrincipalName}}" 17 | } 18 | ], 19 | "targetedMobileApps": [ 20 | "6e57f71e-0a47-49dd-8c6c-181303286278" 21 | ], 22 | "version": 1, 23 | "bundleID": "com.microsoft.Office.Excel" 24 | } 25 | -------------------------------------------------------------------------------- /DU/JSON/IOS_IntuneMAMUpn_Office_11-03-2021-9-51-481.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.iosMobileAppConfiguration", 3 | "createdDateTime": "2021-03-11T08:13:24.8387972Z", 4 | "description": "", 5 | "displayName": "IOS_IntuneMAMUpn_Office", 6 | "encodedSettingXml": null, 7 | "id": "c859faac-8947-446d-8123-9e1878e9b6cf", 8 | "lastModifiedDateTime": "2021-03-11T08:13:24.8387972Z", 9 | "roleScopeTagIds": [ 10 | "0" 11 | ], 12 | "settings": [ 13 | { 14 | "appConfigKey": "IntuneMAMUPN", 15 | "appConfigKeyType": "stringType", 16 | "appConfigKeyValue": "{{UserPrincipalName}}" 17 | } 18 | ], 19 | "targetedMobileApps": [ 20 | "80cfa83a-dd4a-4aaa-9107-66c85679ba07" 21 | ], 22 | "version": 1, 23 | "bundleID": "com.microsoft.officemobile" 24 | } 25 | -------------------------------------------------------------------------------- /DU/JSON/IOS_IntuneMAMUpn_Onedrive_10-03-2021-16-42-521.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.iosMobileAppConfiguration", 3 | "createdDateTime": "2021-03-10T15:36:45.147439Z", 4 | "description": "", 5 | "displayName": "IOS_IntuneMAMUpn_Onedrive", 6 | "encodedSettingXml": null, 7 | "id": "05145a7f-1457-4191-a17f-d4056a417a01", 8 | "lastModifiedDateTime": "2021-03-10T15:36:45.147439Z", 9 | "roleScopeTagIds": [ 10 | "0" 11 | ], 12 | "settings": [ 13 | { 14 | "appConfigKey": "IntuneMAMUPN", 15 | "appConfigKeyType": "stringType", 16 | "appConfigKeyValue": "{{UserPrincipalName}}" 17 | } 18 | ], 19 | "targetedMobileApps": [ 20 | "ae00b519-86e3-43b0-ad07-9ed29bef6ce7" 21 | ], 22 | "version": 1, 23 | "bundleID": "com.microsoft.skydrive" 24 | } 25 | -------------------------------------------------------------------------------- /DU/JSON/IOS_IntuneMAMUpn_Outlook_10-03-2021-16-42-531.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.iosMobileAppConfiguration", 3 | "createdDateTime": "2021-03-10T15:33:13.4264328Z", 4 | "description": "", 5 | "displayName": "IOS_IntuneMAMUpn_Outlook", 6 | "encodedSettingXml": null, 7 | "id": "2e44e76c-2c48-47a3-826a-81dce7107905", 8 | "lastModifiedDateTime": "2021-03-10T15:33:13.4264328Z", 9 | "roleScopeTagIds": [ 10 | "0" 11 | ], 12 | "settings": [ 13 | { 14 | "appConfigKey": "IntuneMAMUPN", 15 | "appConfigKeyType": "stringType", 16 | "appConfigKeyValue": "{{UserPrincipalName}}" 17 | } 18 | ], 19 | "targetedMobileApps": [ 20 | "96001ddf-4759-48dc-8548-0f28778cd4c5" 21 | ], 22 | "version": 1, 23 | "bundleID": "com.microsoft.Office.Outlook" 24 | } 25 | -------------------------------------------------------------------------------- /DU/JSON/IOS_IntuneMAMUpn_Teams_10-03-2021-16-42-561.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.iosMobileAppConfiguration", 3 | "createdDateTime": "2021-03-10T15:39:46.6958665Z", 4 | "description": "", 5 | "displayName": "IOS_IntuneMAMUpn_Teams", 6 | "encodedSettingXml": null, 7 | "id": "e9b993cb-d6c9-42a1-868d-dc2e06bb660a", 8 | "lastModifiedDateTime": "2021-03-10T15:39:46.6958665Z", 9 | "roleScopeTagIds": [ 10 | "0" 11 | ], 12 | "settings": [ 13 | { 14 | "appConfigKey": "IntuneMAMUPN", 15 | "appConfigKeyType": "stringType", 16 | "appConfigKeyValue": "{{UserPrincipalName}}" 17 | } 18 | ], 19 | "targetedMobileApps": [ 20 | "044d2356-a900-457d-b439-49000d6d8199" 21 | ], 22 | "version": 1, 23 | "bundleID": "com.microsoft.skype.teams" 24 | } 25 | -------------------------------------------------------------------------------- /DU/JSON/IOS_IntuneMAMUpn_Word_10-03-2021-16-42-551.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.iosMobileAppConfiguration", 3 | "createdDateTime": "2021-03-10T15:37:34.0588526Z", 4 | "description": "", 5 | "displayName": "IOS_IntuneMAMUpn_Word", 6 | "encodedSettingXml": null, 7 | "id": "33364478-6166-4cb7-aebe-b6caad982648", 8 | "lastModifiedDateTime": "2021-03-10T15:37:34.0588526Z", 9 | "roleScopeTagIds": [ 10 | "0" 11 | ], 12 | "settings": [ 13 | { 14 | "appConfigKey": "IntuneMAMUpn", 15 | "appConfigKeyType": "stringType", 16 | "appConfigKeyValue": "{{UserPrincipalName}}" 17 | } 18 | ], 19 | "targetedMobileApps": [ 20 | "f24d444b-7bc3-47ef-b721-326e8c8577a8" 21 | ], 22 | "version": 1, 23 | "bundleID": "com.microsoft.Office.Word" 24 | } 25 | -------------------------------------------------------------------------------- /DU/JSON/Ios_Compliance_RequireDeviceHealth.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Ios_Compliance_RequireDeviceHealth.json -------------------------------------------------------------------------------- /DU/JSON/Ios_Compliance_RequireDeviceSecurity.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Ios_Compliance_RequireDeviceSecurity.json -------------------------------------------------------------------------------- /DU/JSON/Ios_Compliance_RequireOSVersion.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Ios_Compliance_RequireOSVersion.json -------------------------------------------------------------------------------- /DU/JSON/Mac_Compliance.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Mac_Compliance.json -------------------------------------------------------------------------------- /DU/JSON/WIndows10_Applocker.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/WIndows10_Applocker.json -------------------------------------------------------------------------------- /DU/JSON/WIndows10_DisableInternetExplorer.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/WIndows10_DisableInternetExplorer.json -------------------------------------------------------------------------------- /DU/JSON/WIndows10_EnableBitlocker.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/WIndows10_EnableBitlocker.json -------------------------------------------------------------------------------- /DU/JSON/WIndows_Compliance_RequireDeviceHealth.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/WIndows_Compliance_RequireDeviceHealth.json -------------------------------------------------------------------------------- /DU/JSON/WIndows_Compliance_RequireDeviceSecurity.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/WIndows_Compliance_RequireDeviceSecurity.json -------------------------------------------------------------------------------- /DU/JSON/WIndows_Compliance_RequireOSVersion.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/WIndows_Compliance_RequireOSVersion.json -------------------------------------------------------------------------------- /DU/JSON/Windows10_Audit.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windows10CustomConfiguration", 3 | "id": "45f29357-e94b-4bf4-a0ac-78489a6f6549", 4 | "lastModifiedDateTime": "2020-03-06T08:56:47.3226358Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-03-06T08:56:47.3226358Z", 13 | "description": "", 14 | "displayName": "Windows10_Audit", 15 | "version": 1, 16 | "omaSettings": [ 17 | { 18 | "@odata.type": "#microsoft.graph.omaSettingInteger", 19 | "displayName": "Audit User Account Management", 20 | "description": null, 21 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/AccountManagement_AuditUserAccountManagement", 22 | "value": 3, 23 | "isReadOnly": false 24 | }, 25 | { 26 | "@odata.type": "#microsoft.graph.omaSettingInteger", 27 | "displayName": "Audit Other Object Access Events", 28 | "description": null, 29 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/ObjectAccess_AuditOtherObjectAccessEvents", 30 | "value": 3, 31 | "isReadOnly": false 32 | }, 33 | { 34 | "@odata.type": "#microsoft.graph.omaSettingInteger", 35 | "displayName": "Audit Other System Events", 36 | "description": null, 37 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/System_AuditOtherSystemEvents", 38 | "value": 3, 39 | "isReadOnly": false 40 | }, 41 | { 42 | "@odata.type": "#microsoft.graph.omaSettingInteger", 43 | "displayName": "Audit Security Group Management", 44 | "description": null, 45 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/AccountManagement_AuditSecurityGroupManagement", 46 | "value": 1, 47 | "isReadOnly": false 48 | }, 49 | { 50 | "@odata.type": "#microsoft.graph.omaSettingInteger", 51 | "displayName": "Audit Process Creation", 52 | "description": null, 53 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/DetailedTracking_AuditProcessCreation", 54 | "value": 1, 55 | "isReadOnly": false 56 | }, 57 | { 58 | "@odata.type": "#microsoft.graph.omaSettingInteger", 59 | "displayName": "Audit Logon", 60 | "description": null, 61 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/AccountLogonLogoff_AuditLogon", 62 | "value": 3, 63 | "isReadOnly": false 64 | }, 65 | { 66 | "@odata.type": "#microsoft.graph.omaSettingInteger", 67 | "displayName": "Audit Other Logon/Logoff Events", 68 | "description": null, 69 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/AccountLogonLogoff_AuditOtherLogonLogoffEvents", 70 | "value": 3, 71 | "isReadOnly": false 72 | }, 73 | { 74 | "@odata.type": "#microsoft.graph.omaSettingInteger", 75 | "displayName": "Audit Audit Policy Change", 76 | "description": null, 77 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/PolicyChange_AuditPolicyChange", 78 | "value": 1, 79 | "isReadOnly": false 80 | }, 81 | { 82 | "@odata.type": "#microsoft.graph.omaSettingInteger", 83 | "displayName": "Audit Sensitive Privilege Use", 84 | "description": null, 85 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/PrivilegeUse_AuditSensitivePrivilegeUse", 86 | "value": 3, 87 | "isReadOnly": false 88 | }, 89 | { 90 | "@odata.type": "#microsoft.graph.omaSettingInteger", 91 | "displayName": "Audit Special Logon", 92 | "description": null, 93 | "omaUri": "./Vendor/MSFT/Policy/Config/Audit/AccountLogonLogoff_AuditSpecialLogon", 94 | "value": 1, 95 | "isReadOnly": false 96 | } 97 | ] 98 | } 99 | -------------------------------------------------------------------------------- /DU/JSON/Windows10_Create_admin_user.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windows10CustomConfiguration", 3 | "id": "59a9a954-11e4-4b78-8acf-ff92e0cdba0d", 4 | "lastModifiedDateTime": "2020-03-06T08:56:48.4540006Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-03-06T08:56:48.4540006Z", 13 | "description": "", 14 | "displayName": "Windows10_Create_admin_user", 15 | "version": 1, 16 | "omaSettings": [ 17 | { 18 | "@odata.type": "#microsoft.graph.omaSettingString", 19 | "displayName": "Password", 20 | "description": "Create user and password", 21 | "omaUri": "./Device/Vendor/MSFT/Accounts/Users/admin/Password", 22 | "value": "<<>>" 23 | }, 24 | { 25 | "@odata.type": "#microsoft.graph.omaSettingInteger", 26 | "displayName": "AccountType", 27 | "description": "Lid van admin maken", 28 | "omaUri": "./Device/Vendor/MSFT/Accounts/Users/admin/LocalUserGroup", 29 | "value": 2, 30 | "isReadOnly": false 31 | } 32 | ] 33 | } 34 | -------------------------------------------------------------------------------- /DU/JSON/Windows10_Defender_notifications.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Windows10_Defender_notifications.json -------------------------------------------------------------------------------- /DU/JSON/Windows10_DeliveryOptimization.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windowsDeliveryOptimizationConfiguration", 3 | "id": "69be558b-28a7-4e62-8075-4f8651305725", 4 | "lastModifiedDateTime": "2020-03-16T07:51:26.8361354Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-03-06T08:56:52.5137485Z", 13 | "description": "", 14 | "displayName": "Windows10_DeliveryOptimization", 15 | "version": 2, 16 | "deliveryOptimizationMode": "httpWithPeeringNat", 17 | "restrictPeerSelectionBy": "subnetMask", 18 | "groupIdSource": null, 19 | "backgroundDownloadFromHttpDelayInSeconds": 60, 20 | "foregroundDownloadFromHttpDelayInSeconds": 60, 21 | "minimumRamAllowedToPeerInGigabytes": 4, 22 | "minimumDiskSizeAllowedToPeerInGigabytes": 32, 23 | "minimumFileSizeToCacheInMegabytes": 10, 24 | "minimumBatteryPercentageAllowedToUpload": 40, 25 | "modifyCacheLocation": null, 26 | "maximumCacheAgeInDays": 7, 27 | "vpnPeerCaching": "disabled", 28 | "cacheServerHostNames": [ 29 | 30 | ], 31 | "cacheServerForegroundDownloadFallbackToHttpDelayInSeconds": 0, 32 | "cacheServerBackgroundDownloadFallbackToHttpDelayInSeconds": 0, 33 | "bandwidthMode": { 34 | "@odata.type": "#microsoft.graph.deliveryOptimizationBandwidthHoursWithPercentage", 35 | "bandwidthBackgroundPercentageHours": { 36 | "bandwidthBeginBusinessHours": 8, 37 | "bandwidthEndBusinessHours": 18, 38 | "bandwidthPercentageDuringBusinessHours": 30, 39 | "bandwidthPercentageOutsideBusinessHours": 70 40 | }, 41 | "bandwidthForegroundPercentageHours": { 42 | "bandwidthBeginBusinessHours": 8, 43 | "bandwidthEndBusinessHours": 18, 44 | "bandwidthPercentageDuringBusinessHours": 30, 45 | "bandwidthPercentageOutsideBusinessHours": 70 46 | } 47 | }, 48 | "maximumCacheSize": { 49 | "@odata.type": "#microsoft.graph.deliveryOptimizationMaxCacheSizePercentage", 50 | "maximumCacheSizePercentage": 10 51 | } 52 | } 53 | -------------------------------------------------------------------------------- /DU/JSON/Windows10_EdgeSettings.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Windows10_EdgeSettings.json -------------------------------------------------------------------------------- /DU/JSON/Windows10_PreventAppInstall_Nonadmin.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/JSON/Windows10_PreventAppInstall_Nonadmin.json -------------------------------------------------------------------------------- /DU/JSON/Windows10_RequireBitlockerKey_10FailedLogins.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windows10CustomConfiguration", 3 | "id": "351f460a-5a22-4b2c-8c80-1bf01707fab8", 4 | "lastModifiedDateTime": "2020-03-06T08:56:55.8951656Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-03-06T08:56:55.8951656Z", 13 | "description": "", 14 | "displayName": "Windows10_RequireBitlockerKey_10FailedLogins", 15 | "version": 1, 16 | "omaSettings": [ 17 | { 18 | "@odata.type": "#microsoft.graph.omaSettingInteger", 19 | "displayName": "RequireBitlockerkey_failedlogins", 20 | "description": null, 21 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/DeviceLock/MaxDevicePasswordFailedAttempts", 22 | "value": 10, 23 | "isReadOnly": false 24 | } 25 | ] 26 | } 27 | -------------------------------------------------------------------------------- /DU/JSON/Windows10_RestrictedGroups.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windows10CustomConfiguration", 3 | "id": "190aed16-3b06-4dae-bcec-d9e41a0180bf", 4 | "lastModifiedDateTime": "2020-04-04T09:41:54.3495944Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-04-04T09:41:54.3495944Z", 13 | "description": "", 14 | "displayName": "Windows10_RestrictedGroups", 15 | "version": 1, 16 | "omaSettings": [ 17 | { 18 | "@odata.type": "#microsoft.graph.omaSettingString", 19 | "displayName": "RestrictedGroupsMembership", 20 | "description": null, 21 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/RestrictedGroups/ConfigureGroupMembership", 22 | "value": "\u003caccessgroup desc = \"Administrators\"\u003e\n \u003cmember name = \"Administrator\" /\u003e\n \u003cmember name = \"deltacom\" /\u003e\n \u003cmember name = \"admin\" /\u003e\n\u003c/accessgroup\u003e" 23 | } 24 | ] 25 | } 26 | -------------------------------------------------------------------------------- /DU/JSON/Windows10_Skip_user_status_page.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windows10CustomConfiguration", 3 | "id": "832fd11e-e0ab-4281-b724-f571835b3921", 4 | "lastModifiedDateTime": "2020-03-06T08:56:56.6247424Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-03-06T08:56:56.6247424Z", 13 | "description": "Skipuserstatuspage", 14 | "displayName": "Windows10_Skip_user_status_page", 15 | "version": 1, 16 | "omaSettings": [ 17 | { 18 | "@odata.type": "#microsoft.graph.omaSettingInteger", 19 | "displayName": "EnableFirstLogonAnimation", 20 | "description": null, 21 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/WindowsLogon/EnableFirstLogonAnimation", 22 | "secretReferenceValueId": null, 23 | "isEncrypted": false, 24 | "value": 0, 25 | "isReadOnly": false 26 | }, 27 | { 28 | "@odata.type": "#microsoft.graph.omaSettingBoolean", 29 | "displayName": "./Device/Vendor/MSFT/DMClient/Provider/MS DM Server/FirstSyncStatus/SkipUserStatusPage", 30 | "description": null, 31 | "omaUri": "./Device/Vendor/MSFT/DMClient/Provider/MS DM Server/FirstSyncStatus/SkipUserStatusPage", 32 | "secretReferenceValueId": null, 33 | "isEncrypted": false, 34 | "value": true 35 | } 36 | ] 37 | } -------------------------------------------------------------------------------- /DU/JSON/Windows10_Storagesense.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windows10CustomConfiguration", 3 | "id": "49c99821-eef6-48bf-a94f-115cf4d31b9c", 4 | "lastModifiedDateTime": "2020-03-06T08:58:37.2515647Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-03-06T08:58:37.2515647Z", 13 | "description": "", 14 | "displayName": "Windows10_Storagesense", 15 | "version": 1, 16 | "omaSettings": [ 17 | { 18 | "@odata.type": "#microsoft.graph.omaSettingInteger", 19 | "displayName": "Enable_storagesense", 20 | "description": null, 21 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/Storage/AllowStorageSenseGlobal", 22 | "value": 1, 23 | "isReadOnly": false 24 | }, 25 | { 26 | "@odata.type": "#microsoft.graph.omaSettingInteger", 27 | "displayName": "AllowStorageSenseTemporaryFilesCleanup", 28 | "description": null, 29 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/Storage/AllowStorageSenseTemporaryFilesCleanup", 30 | "value": 1, 31 | "isReadOnly": false 32 | }, 33 | { 34 | "@odata.type": "#microsoft.graph.omaSettingInteger", 35 | "displayName": "ConfigStorageSenseCloudContentDehydrationThreshold", 36 | "description": null, 37 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/Storage/ConfigStorageSenseCloudContentDehydrationThreshold", 38 | "value": 30, 39 | "isReadOnly": false 40 | }, 41 | { 42 | "@odata.type": "#microsoft.graph.omaSettingInteger", 43 | "displayName": "ConfigStorageSenseDownloadsCleanupThreshold", 44 | "description": null, 45 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/Storage/ConfigStorageSenseDownloadsCleanupThreshold", 46 | "value": 90, 47 | "isReadOnly": false 48 | }, 49 | { 50 | "@odata.type": "#microsoft.graph.omaSettingInteger", 51 | "displayName": "ConfigStorageSenseRecycleBinCleanupThreshold", 52 | "description": null, 53 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/Storage/ConfigStorageSenseRecycleBinCleanupThreshold", 54 | "value": 7, 55 | "isReadOnly": false 56 | }, 57 | { 58 | "@odata.type": "#microsoft.graph.omaSettingInteger", 59 | "displayName": "ConfigStorageSenseGlobalCadence", 60 | "description": null, 61 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/Storage/ConfigStorageSenseGlobalCadence", 62 | "value": 7, 63 | "isReadOnly": false 64 | } 65 | ] 66 | } 67 | -------------------------------------------------------------------------------- /DU/JSON/Windows10_TimeZone.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windows10CustomConfiguration", 3 | "id": "832fd11e-e0ab-4281-b724-f571835b3921", 4 | "lastModifiedDateTime": "2020-03-06T08:56:56.6247424Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-03-06T08:56:56.6247424Z", 13 | "description": "Windows10_ConfigureTimeZone", 14 | "displayName": "Windows10_ConfigureTimeZone", 15 | "version": 1, 16 | "omaSettings": [ 17 | { 18 | "@odata.type": "#microsoft.graph.omaSettingString", 19 | "displayName": "Configure Time Zone", 20 | "description": null, 21 | "omaUri": "./Device/Vendor/MSFT/Policy/Config/TimeLanguageSettings/ConfigureTimeZone", 22 | "value": "W. Europe Standard Time" 23 | } 24 | ] 25 | } 26 | -------------------------------------------------------------------------------- /DU/JSON/Windows10_Update.json: -------------------------------------------------------------------------------- 1 | { 2 | "@odata.type": "#microsoft.graph.windowsUpdateForBusinessConfiguration", 3 | "id": "1406604d-d53f-4e80-82b6-8679d57ce618", 4 | "lastModifiedDateTime": "2020-04-08T08:06:23.182386Z", 5 | "roleScopeTagIds": [ 6 | "0" 7 | ], 8 | "supportsScopeTags": true, 9 | "deviceManagementApplicabilityRuleOsEdition": null, 10 | "deviceManagementApplicabilityRuleOsVersion": null, 11 | "deviceManagementApplicabilityRuleDeviceMode": null, 12 | "createdDateTime": "2020-03-06T08:58:38.7221367Z", 13 | "description": "", 14 | "displayName": "Windows10_Update", 15 | "version": 2, 16 | "deliveryOptimizationMode": "userDefined", 17 | "prereleaseFeatures": "userDefined", 18 | "automaticUpdateMode": "autoInstallAtMaintenanceTime", 19 | "microsoftUpdateServiceAllowed": true, 20 | "driversExcluded": true, 21 | "qualityUpdatesDeferralPeriodInDays": 0, 22 | "featureUpdatesDeferralPeriodInDays": 0, 23 | "qualityUpdatesPaused": false, 24 | "featureUpdatesPaused": false, 25 | "qualityUpdatesPauseExpiryDateTime": "0001-01-01T00:00:00Z", 26 | "featureUpdatesPauseExpiryDateTime": "0001-01-01T00:00:00Z", 27 | "businessReadyUpdatesOnly": "businessReadyOnly", 28 | "skipChecksBeforeRestart": false, 29 | "updateWeeks": null, 30 | "qualityUpdatesPauseStartDate": null, 31 | "featureUpdatesPauseStartDate": null, 32 | "featureUpdatesRollbackWindowInDays": 10, 33 | "qualityUpdatesWillBeRolledBack": false, 34 | "featureUpdatesWillBeRolledBack": false, 35 | "qualityUpdatesRollbackStartDateTime": "0001-01-01T00:00:00Z", 36 | "featureUpdatesRollbackStartDateTime": "0001-01-01T00:00:00Z", 37 | "engagedRestartDeadlineInDays": null, 38 | "engagedRestartSnoozeScheduleInDays": null, 39 | "engagedRestartTransitionScheduleInDays": null, 40 | "deadlineForFeatureUpdatesInDays": 7, 41 | "deadlineForQualityUpdatesInDays": 3, 42 | "deadlineGracePeriodInDays": 2, 43 | "postponeRebootUntilAfterDeadline": true, 44 | "autoRestartNotificationDismissal": "notConfigured", 45 | "scheduleRestartWarningInHours": 4, 46 | "scheduleImminentRestartWarningInMinutes": 60, 47 | "userPauseAccess": "disabled", 48 | "userWindowsUpdateScanAccess": "enabled", 49 | "updateNotificationLevel": "restartWarningsOnly", 50 | "installationSchedule": { 51 | "@odata.type": "#microsoft.graph.windowsUpdateActiveHoursInstall", 52 | "activeHoursStart": "08:00:00.0000000", 53 | "activeHoursEnd": "17:00:00.0000000" 54 | }, 55 | "assignments@odata.context": "https://graph.microsoft.com/beta/$metadata#deviceManagement/deviceConfigurations(\u002795db6c26-08b7-4140-ad78-f18b50624491\u0027)/microsoft.graph.windows10CustomConfiguration/assignments", 56 | "assignments": [ 57 | { 58 | "id": "95db6c26-08b7-4140-ad78-f18b50624491_adadadad-808e-44e2-905a-0b7873a8a531", 59 | "source": "direct", 60 | "sourceId": "95db6c26-08b7-4140-ad78-f18b50624491", 61 | "target": { 62 | "@odata.type": "#microsoft.graph.allDevicesAssignmentTarget" 63 | } 64 | } 65 | ] 66 | } 67 | -------------------------------------------------------------------------------- /DU/Packages/Bitlocker/Windows10_enablebitlocker.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/Bitlocker/Windows10_enablebitlocker.intunewin -------------------------------------------------------------------------------- /DU/Packages/Bitlocker/Windows10_enablebitlocker.ps1: -------------------------------------------------------------------------------- 1 | ########################## 2 | # create bitlocker.ps### 3 | ############################ 4 | $content = @' 5 | $BLinfo = Get-Bitlockervolume 6 | if($BLinfo.EncryptionPercentage -ne '100' -and $BLinfo.EncryptionPercentage -ne '0'){ 7 | Resume-BitLocker -MountPoint "C:" 8 | $BLV = Get-BitLockerVolume -MountPoint "C:" | select * 9 | BackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $BLV.KeyProtector[1].KeyProtectorId 10 | } 11 | if($BLinfo.VolumeStatus -eq 'FullyEncrypted' -and $BLinfo.ProtectionStatus -eq 'Off'){ 12 | Resume-BitLocker -MountPoint "C:" 13 | $BLV = Get-BitLockerVolume -MountPoint "C:" | select * 14 | BackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $BLV.KeyProtector[1].KeyProtectorId 15 | } 16 | if($BLinfo.EncryptionPercentage -eq '0'){ 17 | Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -SkipHardwareTest -RecoveryPasswordProtector 18 | $BLV = Get-BitLockerVolume -MountPoint "C:" | select * 19 | BackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $BLV.KeyProtector[1].KeyProtectorId 20 | } 21 | if($BLinfo.EncryptionPercentage -eq '100'){ 22 | $BLV = Get-BitLockerVolume -MountPoint "C:" | select * 23 | BackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $BLV.KeyProtector[1].KeyProtectorId 24 | } 25 | '@ 26 | 27 | ########################## 28 | # output content to file # 29 | ########################## 30 | $path = $(Join-Path $env:ProgramData CustomScripts) 31 | if (!(Test-Path $path)) 32 | { 33 | New-Item -Path $path -ItemType Directory -Force -Confirm:$false 34 | } 35 | Out-File -FilePath $(Join-Path $env:ProgramData CustomScripts\enablebitlocker.ps1) -Encoding unicode -Force -InputObject $content -Confirm:$false 36 | 37 | ########################################################### 38 | # register script as scheduled task to run at each logon # 39 | ########################################################### 40 | 41 | $Time = New-ScheduledTaskTrigger -AtLogOn 42 | $User = "SYSTEM" 43 | $Action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-ex bypass -file `"C:\ProgramData\CustomScripts\enablebitlocker.ps1`"" 44 | Register-ScheduledTask -TaskName "EnableBitlocker" -Trigger $Time -User $User -Action $Action -Force 45 | 46 | ################################ 47 | ###Create Bitlocker Policies ### 48 | ################################ 49 | 50 | $BitLockerRegLoc = 'HKLM:\SOFTWARE\Policies\Microsoft' 51 | New-Item -Path "$BitLockerRegLoc" -Name 'FVE' 52 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'ActiveDirectoryBackup' -Value '00000001' -PropertyType DWORD 53 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'RequireActiveDirectoryBackup' -Value '00000001' -PropertyType DWORD 54 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'OSRequireActiveDirectoryBackup' -Value '00000001' -PropertyType DWORD 55 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'OSRecovery' -Value '00000001' -PropertyType DWORD 56 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'OSManageDRA' -Value '00000001' -PropertyType DWORD 57 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'OSActiveDirectoryBackup' -Value '00000001' -PropertyType DWORD 58 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'FDVRecovery' -Value '00000001' -PropertyType DWORD 59 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'FDVManageDRA' -Value '00000000' -PropertyType DWORD 60 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'FDVRecoveryPassword' -Value '00000002' -PropertyType DWORD 61 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'FDVRecoveryKey' -Value '00000002' -PropertyType DWORD 62 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'FDVActiveDirectoryBackup' -Value '00000001' -PropertyType DWORD 63 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'FDVRequireActiveDirectoryBackup' -Value '00000001' -PropertyType DWORD 64 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'OSActiveDirectoryInfoToStore' -Value '00000002' -PropertyType DWORD 65 | New-ItemProperty -Path "$BitLockerRegLoc\FVE" -Name 'FDVActiveDirectoryInfoToStore' -Value '00000002' -PropertyType DWORD 66 | 67 | ############################################ 68 | ###Eject all Media before bitlocker ### 69 | ############################################ 70 | 71 | #$Diskmaster = New-Object -ComObject IMAPI2.MsftDiscMaster2 72 | #$DiskRecorder = New-Object -ComObject IMAPI2.MsftDiscRecorder2 73 | #$DiskRecorder.InitializeDiscRecorder($DiskMaster) 74 | #$DiskRecorder.EjectMedia() 75 | 76 | $volumes = get-wmiobject -Class Win32_Volume | where{$_.drivetype -eq '2'} 77 | foreach($volume in $volumes){ 78 | $ejectCmd = New-Object -comObject Shell.Application 79 | $ejectCmd.NameSpace(17).ParseName($volume.driveletter).InvokeVerb("Eject") 80 | } 81 | ################################ 82 | ###Start bitlocker encryption### 83 | ################################ 84 | 85 | Start-ScheduledTask -TaskName "EnableBitlocker" 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | -------------------------------------------------------------------------------- /DU/Packages/Bitlocker/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | Windows10_enablebitlocker.intunewin 3 | 1967 4 | Windows10_enablebitlocker.intunewin 5 | Windows10_enablebitlocker.ps1 6 | 7 | 00rX6tWfng+0kYnfo+2hyrVKb4UGigOktndPivANbZ8= 8 | azSGzSfk0N/hGPeu5OT9bxTLR7nBjmBizzXrRjVcSE8= 9 | L7nP0/9haSCpIvppyjo3XQ== 10 | dL/3FXpStsTMdwrkdRjMo9sPdNffTtAJIMYZVIwcu2s= 11 | ProfileVersion1 12 | scXmdJB4aTsJhi8UmWBYR844I1TI8yXp8e2iImhcUnk= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/Bitlocker/install.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_enablebitlocker.ps1'" -------------------------------------------------------------------------------- /DU/Packages/Bitlocker/uninstall.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_enablebitlocker.ps1' remove-item" -------------------------------------------------------------------------------- /DU/Packages/Chocolatey/Windows10_Chocolatey.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/Chocolatey/Windows10_Chocolatey.intunewin -------------------------------------------------------------------------------- /DU/Packages/Chocolatey/Windows10_Chocolatey.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/Chocolatey/Windows10_Chocolatey.ps1 -------------------------------------------------------------------------------- /DU/Packages/Chocolatey/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | Windows10_Chocolatey.intunewin 3 | 1774 4 | Windows10_Chocolatey.intunewin 5 | Windows10_Chocolatey.ps1 6 | 7 | r+gl07zTNK92/HQMoYCVkSAWYDGn0qH8AHL3VMYYGDQ= 8 | ECUsshLfZOq4d87RDWjpHhrqaCqDFENEnu3PanYZBsA= 9 | fPJcykuQpIFtQcBA+tPWYw== 10 | vycwVQ/rJXko7fLC2HWtzxPdLUoKv1MXkF/NfRwLU68= 11 | ProfileVersion1 12 | /PQ0br/idHzhUBew9o3DUx66gBOlhHZ6pQPQOMUoTPM= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/Chocolatey/install.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_chocolatey.ps1'" -------------------------------------------------------------------------------- /DU/Packages/Chocolatey/uninstall.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_removeadmin.ps1' remove-item" -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/7zip/7zip.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/7zip/7zip.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/7zip/7zip.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/7zip/7zip.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/7zip/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 4984 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | SHGCxHXDF6hDXn5DPphF9Kxdrn0U6yEtPTiFNHuiYwo= 8 | /ICNFc36ffk/U3rqc/R269EpPY7YKxU0XZd2MQZwHCA= 9 | QgfFSmey2g/tYJYLBtqc2Q== 10 | VuoUib4KI9LZu8puUKArQdt8PKYOFaknSOjuOAdmrj0= 11 | ProfileVersion1 12 | WHHo6tsZi0dGBoWTaXyN3h4CAsfAnKfmjbfCxie+WIk= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/7zip/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/7zip/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/7zip/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall 7zip -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Adobe Reader/adobereader.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Adobe Reader/adobereader.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Adobe Reader/adobereader.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Adobe Reader/adobereader.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Adobe Reader/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.intunewin 3 | 7348 4 | install.intunewin 5 | install.ps1 6 | 7 | 56WxgbbCVz3oRrH3sEgiUvaIkYFMmCYclkFfxkEqJ7g= 8 | jBF4ALOq6lpI91y+0LG7rgHvJWAwmXU4wfdzeutQK/E= 9 | vUbMKZrDC7kUDgODi0Zdzw== 10 | 0IHFlaUVA5rSjzJWkAfBp3/2wBabIogDZGTjuHiQxgw= 11 | ProfileVersion1 12 | ZSVVOdLhbC0knSXCEbPywSROWBv4v6cdxZI65OYGilM= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Adobe Reader/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Adobe Reader/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Adobe Reader/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall adobereader -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Dymo/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 29484 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | 9sPVd08QEg8A1fZOmdmNYbue1uBECFUjtHlTTt652IM= 8 | Gcoqbgn+/QBd6GLLD4Ocq8y4Aw7iRgKVUJZciK738/M= 9 | f7dBzSXNtsp6ylUF82FG7w== 10 | hs12uWqbI8TC3vKWY02uONrcRX6+2G+Xy7gXEW6U3WY= 11 | ProfileVersion1 12 | SdSxLL4bjdEwAS4oxqcOU1ENAyZplEQ0BiffTkeoIOw= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Dymo/dymo.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Dymo/dymo.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Dymo/dymolabel.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Dymo/dymolabel.png -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Dymo/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Dymo/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Dymo/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall dymo-label -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Firefox/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 10908 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | kuvJnXZZCjkkQrT0Wgk5Uw1YrWimMJSgNeGlUFN26rI= 8 | sz1Dv10PNAraG3NjYASOXxErU2/lZhIbl7pGq/nWLls= 9 | 8xdv/VnFl4x4vPBi5ForvA== 10 | eaxh3TIa3ewEi9AydLhzG89vnmbzBG++v4oOynAld8E= 11 | ProfileVersion1 12 | N48Ud8OCTRRE/NGkLCZbXaKny5nn3FNjxOVTTZV2Tz0= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Firefox/firefox.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Firefox/firefox.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Firefox/firefox.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Firefox/firefox.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Firefox/firefox.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Firefox/firefox.png -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Firefox/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Firefox/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Firefox/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall firefox -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Notepad++/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 7742 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | H69IhwhPqe7ArBX058PW86dZe2bOJWbcXQfL9lXfsoo= 8 | 6M0Xh5uagfUghY/g+raROCLlhe8Ktwak4g5V5mLf8GA= 9 | MEPOcm8Mk+2CM5VbY5y+fA== 10 | PyZlOGGdjUw0jIwbWcyjAtO1Ttxvl7dXijXapBN6JI0= 11 | ProfileVersion1 12 | DFx7v8CZHJdc2kLDnnp2bqvGxABjqsYML7+NY6QqCP8= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Notepad++/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Notepad++/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Notepad++/notepad++.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Notepad++/notepad++.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Notepad++/notepad++.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/Notepad++/notepad++.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/Notepad++/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall notepadplusplus.install -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/SynologyDrive/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 19578 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | 4KeIpgvr1SiiHrtOc+QLJofkYhIOs0F97/r7qHZjZN8= 8 | J+3TzK/52MJHYTLKouCVr9eN1gbhXw3xK+vYbYJSiVk= 9 | sFD7syq3FSddV6Znfgt68Q== 10 | 4DzS8x739/oVlTzxwFeUa7pkzg98z0sFtUuQ9Uhf+IM= 11 | ProfileVersion1 12 | SS3hppmFW9mychDQmq05eDWf+nDqXwZ0GGaRwhIjZ0I= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/SynologyDrive/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/SynologyDrive/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/SynologyDrive/synology.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/SynologyDrive/synology.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/SynologyDrive/synology.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/SynologyDrive/synology.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/SynologyDrive/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall cloudstation -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/chrome/chrome.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/chrome/chrome.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/chrome/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.intunewin 3 | 5027 4 | install.intunewin 5 | install.ps1 6 | 7 | WUfPbVl9TgpzrbuaZQ6JglZKTr7AWwVMv/qnpnZA2ZE= 8 | pTuAzxqugPxiXPpY0AoQkdaAGXoArbFhs6hR3Hw+Uos= 9 | IuIkikAe9j+8V1EaYS6bsQ== 10 | LNFwchg47V/6Yk5QuhEJnGZU2iFUnUcIlj1SiA+yADg= 11 | ProfileVersion1 12 | XqV1mGKoDetFD97I67LV0Wa1AaSmQs6hd8KaXUJPRVc= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/chrome/googlechromenew.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/chrome/googlechromenew.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/chrome/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/chrome/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/chrome/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall googlechrome -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/chrome/win32/install.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/chrome/win32/install.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/citrix/citrix.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/citrix/citrix.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/citrix/citrix.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/citrix/citrix.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/citrix/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 17155 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | Y9GR52mzDbQrC1DJIy8Tt+ZMgjzMVfSrkjw8H8GpoNs= 8 | nMk6+1o/B3tyCwPJf0cjPLGSolVL/8cMp64cHc3muMY= 9 | w/8j2aBCSGw4+jaTnADz4A== 10 | CPS718YdGWVK5N7mGBhyiz2rVKe/QjRnPtfzGBjwhys= 11 | ProfileVersion1 12 | ebqUZ2yboT/mDWYAbDwy79Xv+8QtgsTSyryThiY4J9w= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/citrix/install.ps1: -------------------------------------------------------------------------------- 1 | if (!(Test-Path -Path "$env:ProgramData\Chocolatey")) { 2 | Invoke-Expression((New-Object System.Net.WebClient).DownloadString('https://chocolatey.org/install.ps1')) 3 | } 4 | 5 | start-process -wait -filepath "c:\programdata\chocolatey\choco.exe"-argumentlist "install citrix-workspace -force -y" 6 | 7 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/citrix/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall citrix-workspace -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/cutepdf/cutepdf.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/cutepdf/cutepdf.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/cutepdf/cutepdf.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/cutepdf/cutepdf.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/cutepdf/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 5578 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | QqlfLw7HmyhtI9S1q0h+IJmgNTNAFSc/ynyk2wCMZEk= 8 | gMIsQXzysaZsz7QHFiWUl0ACBfJfhxybJlRt9SznURY= 9 | XVAeChrxDL5ImHjRmaYhNA== 10 | HgtEzcC+qzZ0sYe82/cDh0Yzmj2ZOErkP7oqR14E+eg= 11 | ProfileVersion1 12 | /QbfUuFDxnSGUXaf0dhgENmyrVYSW69r3zQ0+CWgSic= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/cutepdf/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/cutepdf/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/cutepdf/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall cutepdf -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/filezilla/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 5907 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | iPhmUp7AybVUjw3xKp+WbZ9tjvAnBfjedkcveEyQIcI= 8 | 8e0FLG80kG1IIFc8jRXdFsSwF4uFYcWEeRzP+7cIxaI= 9 | 1HKRc1PNDUEOSCRPcmC/Zg== 10 | YRp5VHcb+LP5f8wQD+/faC1xpyrTCZgIzgFvm0KgcSE= 11 | ProfileVersion1 12 | yLyS6w4/LecdjkJlRJy1LCS7HmK5TnQdq1qGqpjBqeA= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/filezilla/filezilla.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/filezilla/filezilla.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/filezilla/filezilla.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/filezilla/filezilla.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/filezilla/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/filezilla/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/filezilla/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall filezilla -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/gotomeeting/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 10518 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | BKvq2ZjPTI6pydrOmWYJzmIo4x/wHp0zodqxOTZRr2A= 8 | KkXND3sTLxHF3iICn5N4eOCShhmrUeL0tK0ifhmfaU0= 9 | mKPpj63kMoyrMhgNeV0jlg== 10 | Owk8K1a8fDQIeAPEMgAdvVOv5ISMeqc68gPLoGB5n10= 11 | ProfileVersion1 12 | 1Ntw3BWKXbjx5/5/H6RI3mqU7wxa1dBZy5PDs0As1aY= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/gotomeeting/gotomeeting.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/gotomeeting/gotomeeting.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/gotomeeting/gotomeeting.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/gotomeeting/gotomeeting.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/gotomeeting/install.ps1: -------------------------------------------------------------------------------- 1 | if (!(Test-Path -Path "$env:ProgramData\Chocolatey")) { 2 | Invoke-Expression((New-Object System.Net.WebClient).DownloadString('https://chocolatey.org/install.ps1')) | out-null 3 | } 4 | 5 | start-process -wait -filepath "c:\programdata\chocolatey\choco.exe" -argumentlist "install gotomeeting -y" -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/gotomeeting/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall gotomeeting -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/icloud/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 1329 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | H17u0+hIy1w+H4litys/z0ER23ZNBUl80QPSx1HP9JA= 8 | rV5Jxn5g7DeqN0PI9xN5Lv79auYNDFg0xzbMdfIS2go= 9 | 3wVn5jAtkCdNqAoBUQ1leg== 10 | iC7AH4AqHJcPlclzKPVEDUP+V7g0fy58HDMiPpTBzF8= 11 | ProfileVersion1 12 | Nnb6L4dX5I0wjK5d1uf6+hbIEt1gKfY6fq6Q+3sX5gY= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/icloud/icloud.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/icloud/icloud.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/icloud/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/icloud/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/icloud/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall zoom -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/java/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 6841 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | yf+OK9ojol3TeCvQay1YzVIqvAHElSHxA8lek+t7ZDg= 8 | YlF8CHseeo15wIa516d6jYzOar8CtGJI+hGgIl3lekE= 9 | eNusqKyxI3cFsBMDf1KWMg== 10 | x1k04kijndCYOQhxQi1qZei6JfjMhoaKGxwHtjQmxqU= 11 | ProfileVersion1 12 | v9jpKCNel4jw9XM5PvroHSgwoSQYcfV5XtCGpF7ETTc= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/java/install.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/java/install.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/java/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/java/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/java/java.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/java/java.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/java/java.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/java/java.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/java/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall jre8 -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/keepass/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 42087 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | asyV3ex82QRUoldGw32Q3b910hOdQrWJYVr9G45e6U0= 8 | GLz4syEnRonuDIebeadwtOtXg5NTuMYcdFbftm1jzxQ= 9 | 7DxRQeLgjT/QLL+3/hdDjw== 10 | ZoxqJVaVxbD5+BeW5bHbp5srF4yNWEVYFUl7I3HWm9M= 11 | ProfileVersion1 12 | xz3/+YT4YHWjG0uqasjYek1VYzzXXVBT37AtObJwFBE= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/keepass/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/keepass/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/keepass/keepass.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/keepass/keepass.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/keepass/keepass.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/keepass/keepass.png -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/keepass/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall keepass -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/silverlight/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 7994 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | YJ/k05NCj5DTI7LQ1JhJSZobAMz+MjObcOUWHceLKe4= 8 | 8QdtG4GZuxMweW5dpMVDV4IzfEum0YVoH1iZQeGKCKQ= 9 | QdGBPqQsYIWnQYuw+GGo5g== 10 | AOoeubsSnsPOrJ7ulG9yft7yE4cUvf0F5iUDCXuRT3E= 11 | ProfileVersion1 12 | HT6kAlaI6z6G7srVQTWdIUWDACzrlMGYvih5aButnbY= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/silverlight/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/silverlight/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/silverlight/silverlight.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/silverlight/silverlight.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/silverlight/silverlight.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/silverlight/silverlight.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/silverlight/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall silverlight -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/skype/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 7574 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | 7oKJOhtduZZ7CN0l8sxUCeyFOHMHiGPYnkNXAIGCXN0= 8 | 9zW5s1BNyj4mgFoIQhPll9c5QORV18SzJfCzgQeqHGM= 9 | h+qwSMePnbq/ousmVIme/A== 10 | dikpcx8zZl49AnjUmmhftz/fHihY9d+Yo37fs13WnOM= 11 | ProfileVersion1 12 | Ch4GkED5F2mj8X5jDxLmMImKcFv1zfAbT4UmEpmTawg= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/skype/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/skype/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/skype/skype.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/skype/skype.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/skype/skype.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/skype/skype.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/skype/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall skype -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vcredist140/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 5560 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | pQlqSRZnWVBWXmunzYlHuntLImKFLi0IHawlV6huTzg= 8 | fQZu/vLdwZV7wu32TQhR/SOT9tAAee8L1c6rVjgE2eo= 9 | +Rm2S2pcF1sGccRYliLiwA== 10 | IV/BI8PT55OxpYS6KnjD+DiEdE7pPgYc5d6DNKtmw0c= 11 | ProfileVersion1 12 | Ml7f+189oqB83Hhk25XOmNMGxVayHa4+wNKn17wziN8= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vcredist140/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/vcredist140/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vcredist140/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall vcredist140 -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vcredist140/vcredist140.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/vcredist140/vcredist140.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vcredist140/vcredist140.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/vcredist140/vcredist140.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vlc/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 6141 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | 1bR21hlEhfFqMmueqAVIC1NFZjzMV5uIcY3kzit5DDg= 8 | xDWnN+38o4pJYahdMBPpcssrZ3jff+6HHy5H83GuGRo= 9 | s41CwAVZ0JxYZOHwoSd6NA== 10 | ErAj2Ajq+3jh1bSP4RgxMJKtC8K7Tv7kiizMIi36TgM= 11 | ProfileVersion1 12 | 8+rd5SjtDRvgMLDTIdyBbni60VAMNHrnbZszFd+61xU= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vlc/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/vlc/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vlc/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall vlc -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vlc/vlc.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/vlc/vlc.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/vlc/vlc.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/vlc/vlc.jpg -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/zoom/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.ps1 3 | 5172 4 | IntunePackage.intunewin 5 | install.ps1 6 | 7 | pcmiK9luRkqvSe+M9+VwM8sROagX2UHepe+pxa7mCZM= 8 | VFrsz1taN4/+k1XehdCiaeldwov0M6+AHpgUJo80/ng= 9 | OwQJ93sKFdF+vTcbVLAlOA== 10 | kebWIxlYwsZ5SAwt2UHJ8bMiX2h2ODYMNUNVmzckor8= 11 | ProfileVersion1 12 | HMgZfioZgCPjYe4XhHrHepkx2PHBTa8QEGwImJhD+uw= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/zoom/install.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/zoom/install.ps1 -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/zoom/uninstall.ps1: -------------------------------------------------------------------------------- 1 | choco uninstall zoom -y -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/zoom/zoom.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/zoom/zoom.intunewin -------------------------------------------------------------------------------- /DU/Packages/ChocolateyAppsInstall/zoom/zoom.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/ChocolateyAppsInstall/zoom/zoom.jpg -------------------------------------------------------------------------------- /DU/Packages/DCLAPS/Windows10_rotate.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/DCLAPS/Windows10_rotate.intunewin -------------------------------------------------------------------------------- /DU/Packages/DCLAPS/Windows10_rotate.ps1: -------------------------------------------------------------------------------- 1 | $content = @' 2 | function Get-RandomCharacters($length, $characters) { 3 | $random = 1..$length | ForEach-Object { Get-Random -Maximum $characters.length } 4 | $private:ofs="" 5 | return [String]$characters[$random] 6 | } 7 | 8 | function Scramble-String([string]$inputString){ 9 | $characterArray = $inputString.ToCharArray() 10 | $scrambledStringArray = $characterArray | Get-Random -Count $characterArray.Length 11 | $outputString = -join $scrambledStringArray 12 | return $outputString 13 | } 14 | $password = Get-RandomCharacters -length 8 -characters 'abcdefghiklmnoprstuvwxyz' 15 | $password += Get-RandomCharacters -length 2 -characters 'ABCDEFGHKLMNOPRSTUVWXYZ' 16 | $password += Get-RandomCharacters -length 3 -characters '1234567890' 17 | $password += Get-RandomCharacters -length 1 -characters '!$%&/()=?@#*+' 18 | net user admin $password 19 | $registryPath = "HKLM:\SOFTWARE\Microsoft\DCLAPS" 20 | New-Item -Path $registryPath 21 | $name = "lapsww" 22 | $value = $password 23 | New-ItemProperty -Path $registryPath -Name $name -Value $value -Force | Out-Null 24 | 25 | #Change Register permissions 26 | $path = 'HKLM:\software\microsoft\dclaps' 27 | #breaks inheritens. 28 | $acl = (Get-Item $path).GetAccessControl('Access') 29 | $acl.SetAccessRuleProtection($true,$true) 30 | set-acl $path -AclObject $acl 31 | #removes all access rules based on 'BUILTIN\Users' 32 | $acl = (Get-Item $path).GetAccessControl('Access') 33 | $acl.Access |where {$_.IdentityReference -eq 'INGEBOUWD\Gebruikers'} |%{$acl.RemoveAccessRule($_)} 34 | set-acl $path -AclObject $acl 35 | '@ 36 | 37 | # create custom folder and write PS script 38 | $path = $(Join-Path $env:ProgramData CustomScripts) 39 | if (!(Test-Path $path)) 40 | { 41 | New-Item -Path $path -ItemType Directory -Force -Confirm:$false 42 | } 43 | Out-File -FilePath $(Join-Path $env:ProgramData CustomScripts\rotate.ps1) -Encoding unicode -Force -InputObject $content -Confirm:$false 44 | 45 | # register script as scheduled task 46 | $Time = New-ScheduledTaskTrigger -At 11:00AM -Weekly -WeeksInterval 4 -DaysOfWeek Monday 47 | $User = "SYSTEM" 48 | $Action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-ex bypass -file `"C:\ProgramData\CustomScripts\rotate.ps1`"" 49 | Register-ScheduledTask -TaskName "Rotate" -Trigger $Time -User $User -Action $Action -Force 50 | Set-ScheduledTask -taskname "Rotate" -Settings $(New-ScheduledTaskSettingsSet -StartWhenAvailable -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries) 51 | Start-ScheduledTask -TaskName "Rotate" 52 | 53 | -------------------------------------------------------------------------------- /DU/Packages/DCLAPS/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | Windows10_rotate.intunewin 3 | 2381 4 | Windows10_rotate.intunewin 5 | Windows10_rotate.ps1 6 | 7 | AeBy3NzE7UlPwVC+65hHdNrMU+qDBqPfLe+cl2BjBNU= 8 | N5ZTiDe+/xs16IvbGmdnpGyLUsKVoOI48ftAdOb2Ld4= 9 | s+H3hbTE/5ENKa5SKUK0xA== 10 | VOJZT6LN+xb50U034fO0RpvuBCJC5uqawcv4yQCQ7pE= 11 | ProfileVersion1 12 | DLWHwyUi0jwPmruYgJ02D20/gz6xjVbRHijcbk4yhzM= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/DCLAPS/install.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_rotate.ps1'" -------------------------------------------------------------------------------- /DU/Packages/DCLAPS/uninstall.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_rotate.ps1' remove-item" -------------------------------------------------------------------------------- /DU/Packages/OneDriveSilent/Windows10_OnedriveSilent.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/OneDriveSilent/Windows10_OnedriveSilent.intunewin -------------------------------------------------------------------------------- /DU/Packages/OneDriveSilent/Windows10_OnedriveSilent.ps1: -------------------------------------------------------------------------------- 1 | $content = @' 2 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\OneDrive" 3 | $Name1 = "SilentAccountConfig" 4 | New-ItemProperty -Path $registryPath -Name $name1 -Value 1 -PropertyType DWord -Force 5 | gpupdate /force 6 | '@ 7 | 8 | Out-File -FilePath $(Join-Path $env:ProgramData CustomScripts\onedrivesilent.ps1) -Encoding unicode -Force -InputObject $content -Confirm:$false 9 | 10 | New-Item -Path "c:\" -Name "temp" -ItemType "directory" -force 11 | $path = "c:\temp" 12 | New-Item -path $path -name "onedrivesilent.txt" -ItemType file -force 13 | 14 | # register script as scheduled task 15 | $Time = New-ScheduledTaskTrigger -AtLogOn 16 | $User = "SYSTEM" 17 | $Action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-ex bypass -file `"C:\ProgramData\CustomScripts\onedrivesilent.ps1`" -Verb RunAs" 18 | Register-ScheduledTask -TaskName "onedrivesilent" -Trigger $Time -User $User -Action $Action -Force 19 | Start-ScheduledTask -TaskName "onedrivesilent" -------------------------------------------------------------------------------- /DU/Packages/OneDriveSilent/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | Windows10_OnedriveSilent.intunewin 3 | 1783 4 | Windows10_OnedriveSilent.intunewin 5 | Windows10_OnedriveSilent.ps1 6 | 7 | WWk6JG++OtzQ5ATkJpjsmlaGp4eKYR/RBdfWo+FjQNg= 8 | UXAUoEuDih82H0grc/raeN+ZMthQ1Bybm5Wfte1lYpw= 9 | e9TU99VS0zu93Mh8lALvEA== 10 | WfhNHOOdfnzRfHomLXrExAqM/mZXrwMvfvvBiO7Mv5M= 11 | ProfileVersion1 12 | OZO2LS23LDRjRxrLnJLFsqzTEEe6OK8DtenlBWNrNtY= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/OneDriveSilent/install.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_onedrivesilent.ps1'" -------------------------------------------------------------------------------- /DU/Packages/OneDriveSilent/uninstall.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_onedrivesilent.ps1' 0" -------------------------------------------------------------------------------- /DU/Packages/Onedrive/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | onedrivesetup.intunewin 3 | 30874783 4 | onedrivesetup.intunewin 5 | onedrivesetup.exe 6 | 7 | SjKUhJjjEpDr5i1EZ6TqlIHVgu771a+9ahJwtdCKrgs= 8 | 2lIoVIUuzze1m2EFwZt1FVWh9Yplc9dHQH7G60SvXag= 9 | QHqkefbgsRtCAc8HMOoQ7g== 10 | C2eodn/PnxGdeK/1GGsw+BAW8d0uTRjLv1j33ogYgyA= 11 | ProfileVersion1 12 | evTEPqkXbQZrdGeIILGrHQKv9nkrcKEg9Bx/iuvWZZ4= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/Onedrive/onedrivesetup.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/Onedrive/onedrivesetup.intunewin -------------------------------------------------------------------------------- /DU/Packages/OnedriveConfig/Windows10_Onedrive.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/OnedriveConfig/Windows10_Onedrive.intunewin -------------------------------------------------------------------------------- /DU/Packages/OnedriveConfig/Windows10_Onedrive.ps1: -------------------------------------------------------------------------------- 1 | $content = @' 2 | Windows Registry Editor Version 5.00 3 | [HKEY_CURRENT_USER\Software\Microsoft\OneDrive] 4 | "SilentBusinessConfigCompleted"="0" 5 | "EnableAdal"=dword:00000001 6 | "EnableTeamTier_Internal"=dword:00000001 7 | [HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Business1] 8 | "EnableADALForSilentBusinessConfig"=dword:00000001 9 | "TimerAutoMount"=hex(b):01,00,00,00,00,00,00,00 10 | [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Identity] 11 | "EnableAdal"=dword:00000001 12 | [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Licensing] 13 | "EulasSetAccepted"="16.0," 14 | '@ 15 | 16 | 17 | # create custom folder and write PS script 18 | $path = $(Join-Path $env:ProgramData CustomScripts) 19 | if (!(Test-Path $path)) 20 | { 21 | New-Item -Path $path -ItemType Directory -Force -Confirm:$false 22 | } 23 | Out-File -FilePath $(Join-Path $env:ProgramData CustomScripts\onedrive.reg) -Encoding unicode -Force -InputObject $content -Confirm:$false 24 | 25 | # register script as scheduled task 26 | $WshShell = New-Object -comObject WScript.Shell 27 | $Shortcut = $WshShell.CreateShortcut("$env:ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\config.lnk") 28 | $Shortcut.TargetPath = '"c:\windows\System32\reg.exe"' 29 | $Shortcut.Arguments = "import c:\programdata\CustomScripts\onedrive.reg" 30 | $Shortcut.WorkingDirectory = '"c:\programdata\CustomScripts\"' 31 | $Shortcut.Save() -------------------------------------------------------------------------------- /DU/Packages/OnedriveConfig/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | Windows10_Onedrive.intunewin 3 | 1916 4 | Windows10_Onedrive.intunewin 5 | Windows10_Onedrive.ps1 6 | 7 | 9GEQu25/F9af76fE9W0JH5zYVZiyYAkhm/yWkLUt1Dk= 8 | vggkd05sbqIMwq0FXHQSpu/+R/68aL/p2YcLjfOQ8zQ= 9 | MLYXw01R0wKqO+qL3xzSTg== 10 | 2iJ5q3hJaWr9HkzDW9HFPbUja3UB/5EcFEViQpkjTXY= 11 | ProfileVersion1 12 | 0t+ToY05mn+0c3k27B1vaBFHnbq2pCO4F4g/2Hg0/HU= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/OnedriveConfig/install.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_Onedrive.ps1'" -------------------------------------------------------------------------------- /DU/Packages/OnedriveConfig/uninstall.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_Onedrive.ps1'" -------------------------------------------------------------------------------- /DU/Packages/PowerOptions/Windows10_PowerOptions.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/PowerOptions/Windows10_PowerOptions.intunewin -------------------------------------------------------------------------------- /DU/Packages/PowerOptions/Windows10_PowerOptions.ps1: -------------------------------------------------------------------------------- 1 | New-Item -Path "c:\" -Name "temp" -ItemType "directory" -force 2 | $path = "c:\temp" 3 | New-Item -path $path -name "poweropties.txt" -ItemType file -force 4 | powercfg -setdcvalueindex SCHEME_CURRENT 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0 5 | powercfg -setacvalueindex SCHEME_CURRENT 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0 6 | powercfg.exe -x -standby-timeout-ac 0 7 | powercfg.exe -x -standby-timeout-dc 0 8 | powercfg.exe -x -hibernate-timeout-ac 0 9 | powercfg.exe -x -hibernate-timeout-dc 0 10 | powercfg.exe -x -monitor-timeout-ac 0 11 | powercfg.exe -x -monitor-timeout-dc 0 12 | powercfg.exe -x -disk-timeout-ac 0 13 | powercfg.exe -x -disk-timeout-dc 0 14 | -------------------------------------------------------------------------------- /DU/Packages/PowerOptions/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | Windows10_PowerOptions.intunewin 3 | 917 4 | Windows10_PowerOptions.intunewin 5 | Windows10_PowerOptions.ps1 6 | 7 | Heh/Fj3YeuHsj+UT2xbtTWSKJ8isRct27mpu2Png5JU= 8 | s78UcUhkM7myC1AktAMd/ntZsLvWxzw9Bx1lwUqkeYQ= 9 | /IKfFkhixKhFVF+Xnz4TDQ== 10 | 1WIJ2+X6uo6o4g1UtJUdpjFPOQ2QoAc+AWtOkcnL+G8= 11 | ProfileVersion1 12 | 1afhAkOOb/qcZ/bj16ybbdX4QO1tkIScVJh/+mw68n8= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/PowerOptions/install.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_PowerOptions.ps1'" -------------------------------------------------------------------------------- /DU/Packages/PowerOptions/install.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/PowerOptions/install.intunewin -------------------------------------------------------------------------------- /DU/Packages/PowerOptions/uninstall.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_PowerOptions.ps1'" -------------------------------------------------------------------------------- /DU/Packages/Quickassist/Windows10_Quickassist.ps1: -------------------------------------------------------------------------------- 1 | md "c:\program files (x86)\ico" 2 | copy .\intune.ico "c:\program files (x86)\ico\deltacom.ico" 3 | 4 | #Create Shortcut Desktops 5 | if (-not (Test-Path "C:\Users\Public\Desktop\Deltacom-Helpdesk.url")) 6 | { 7 | $null = $WshShell = New-Object -comObject WScript.Shell 8 | $path = "C:\Users\Public\Desktop\Deltacom-Helpdesk.url" 9 | $targetpath = "c:\windows\system32\quickassist.exe" 10 | $iconlocation = "c:\program files (x86)\ico\deltacom.ico" 11 | $iconfile = "IconFile=" + $iconlocation 12 | $Shortcut = $WshShell.CreateShortcut($path) 13 | $Shortcut.TargetPath = $targetpath 14 | $Shortcut.Save() 15 | 16 | Add-Content $path "HotKey=0" 17 | Add-Content $path "$iconfile" 18 | Add-Content $path "IconIndex=0" 19 | } 20 | 21 | -------------------------------------------------------------------------------- /DU/Packages/Quickassist/Windows10_quickassist.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/Quickassist/Windows10_quickassist.intunewin -------------------------------------------------------------------------------- /DU/Packages/Quickassist/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | install.cmd 3 | 42305 4 | IntunePackage.intunewin 5 | install.cmd 6 | 7 | tXZKZEUAUif+zJqMyXm3hrub/1BVYPI/3vknbtGA32o= 8 | oH4ey3BGBNU+vN1/C52Hrr5c6xtLUdElakJ8F9+DoVY= 9 | u7UgOBjIQfANsPz0w85kZw== 10 | hN5kb2GLvuBH4xOhrQlXT+Ax81J+hvCTTtl1K7BL4so= 11 | ProfileVersion1 12 | Z/eJww8xyTPPhO0E5Nj7cqFHgrYvdfPvvFD0zRjQVuc= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/Quickassist/install.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_quickassist.ps1'" -------------------------------------------------------------------------------- /DU/Packages/Quickassist/intune.ico: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/Quickassist/intune.ico -------------------------------------------------------------------------------- /DU/Packages/Quickassist/uninstall.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_removeadmin.ps1' remove-item" -------------------------------------------------------------------------------- /DU/Packages/RemoveAdmin/Windows10_RemoveAdmin.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/RemoveAdmin/Windows10_RemoveAdmin.intunewin -------------------------------------------------------------------------------- /DU/Packages/RemoveAdmin/Windows10_RemoveAdmin.ps1: -------------------------------------------------------------------------------- 1 | $content = @' 2 | $administrators = @( ([ADSI]"WinNT://./Administrators").psbase.Invoke('Members') | % { $_.GetType().InvokeMember('AdsPath','GetProperty',$null,$($_),$null) } ) -match '^WinNT'; 3 | $administrators = $administrators -replace "WinNT://","" 4 | foreach($administrator in $administrators) { if ($administrator -like "$env:COMPUTERNAME/administrator" -or $administrator -like "AzureAd/*" -or $administrator -like "$env:COMPUTERNAME/deltacom") { continue; } Remove-LocalGroupMember -group "administrators" -member $administrator } 5 | # get accounts to remove 6 | $remove = net localgroup administrators | select -skip 6 | ? {$_ -and $_ -notmatch 'De opdracht is voltooid.|^deltacom$|^administrator$|^admin$'} 7 | #remove the accounts 8 | foreach ($user in $remove) { 9 | net localgroup administrators "`"$user`"" /delete 10 | } 11 | $username = "deltacom" 12 | if ($(Get-LocalGroupMember -Group "Administrators").Name -notcontains "$env:ComputerName\$username") { 13 | remove-LocalGroupMember -Group "Administrators" -Member $username} 14 | $username = "admin" 15 | if ($(Get-LocalGroupMember -Group "Administrators").Name -notcontains "$env:ComputerName\$username") { 16 | Add-LocalGroupMember -Group "Administrators" -Member $username} 17 | get-localuser | Set-localUser -PasswordNeverExpires:$True 18 | '@ 19 | 20 | 21 | # create custom folder and write PS script 22 | $path = $(Join-Path $env:ProgramData CustomScripts) 23 | if (!(Test-Path $path)) 24 | { 25 | New-Item -Path $path -ItemType Directory -Force -Confirm:$false 26 | } 27 | Out-File -FilePath $(Join-Path $env:ProgramData CustomScripts\myScript.ps1) -Encoding unicode -Force -InputObject $content -Confirm:$false 28 | 29 | # register script as scheduled task 30 | $Time = New-ScheduledTaskTrigger -AtLogOn 31 | $User = "SYSTEM" 32 | $Action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-ex bypass -file `"C:\ProgramData\CustomScripts\myScript.ps1`"" 33 | Register-ScheduledTask -TaskName "RemoveAdmin" -Trigger $Time -User $User -Action $Action -Force 34 | Start-ScheduledTask -TaskName "RemoveAdmin" 35 | -------------------------------------------------------------------------------- /DU/Packages/RemoveAdmin/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | Windows10_RemoveAdmin.intunewin 3 | 1466 4 | Windows10_RemoveAdmin.intunewin 5 | Windows10_RemoveAdmin.ps1 6 | 7 | /09h9izLcpXRWKJUE3J3fgNHp58/fFTvNSvyfqYkngg= 8 | U0tgpKN6d6JdoTcZ0Yj0sGS8QM802S/QThqK5ae7nEA= 9 | 9L1z7C2KNth89DbRl4AsHQ== 10 | bcPYfZf1RpPUA0r64RCIwMiMOxHNFiw9xZE+X1iXpWM= 11 | ProfileVersion1 12 | AA1RgjEx6VeC8OrkZw3nqNcoAEXVY2PEomV2WJGYVYE= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/RemoveAdmin/install.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_removeadmin.ps1'" -------------------------------------------------------------------------------- /DU/Packages/RemoveAdmin/uninstall.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_removeadmin.ps1' remove-item" -------------------------------------------------------------------------------- /DU/Packages/RestartService/Windows10_Restartservice.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/RestartService/Windows10_Restartservice.intunewin -------------------------------------------------------------------------------- /DU/Packages/RestartService/Windows10_Restartservice.ps1: -------------------------------------------------------------------------------- 1 | $content = @' 2 | Get-Service -Name IntuneManagementExtension | Restart-Service 3 | '@ 4 | 5 | 6 | # create custom folder and write PS script 7 | $path = $(Join-Path $env:ProgramData CustomScripts) 8 | if (!(Test-Path $path)) 9 | { 10 | New-Item -Path $path -ItemType Directory -Force -Confirm:$false 11 | } 12 | Out-File -FilePath $(Join-Path $env:ProgramData CustomScripts\restartservice.ps1) -Encoding unicode -Force -InputObject $content -Confirm:$false 13 | 14 | 15 | $triggers = @() 16 | $triggers += New-ScheduledTaskTrigger -At (get-date) -Once -RepetitionInterval (New-TimeSpan -Minutes 30) 17 | $triggers += New-ScheduledTaskTrigger -AtLogOn 18 | $User = "SYSTEM" 19 | $Action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-ex bypass -file `"C:\ProgramData\CustomScripts\restartservice.ps1`"" 20 | Register-ScheduledTask -TaskName "Restartservice" -Trigger $triggers -User $User -Action $Action -Force 21 | 22 | -------------------------------------------------------------------------------- /DU/Packages/RestartService/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | Windows10_Restartservice.intunewin 3 | 1763 4 | Windows10_Restartservice.intunewin 5 | Windows10_Restartservice.ps1 6 | 7 | CmeCdUGcsP7imcUjzgrZgMM/dKyAzuixfzWIDqEdrqY= 8 | nm5NKWfn5yQqEkvz27/y30cgUSZJS60fMQ2+5ya2G8w= 9 | 8yAtWdn3sImiGfjI9LVPTA== 10 | LK0XshKL+VJlhCs6T+UwPEAv5MaqdlJErdJOm+PwpYI= 11 | ProfileVersion1 12 | c9eNcDJ0WbXHMzgRB8FmOja2NiBH3jBaIlI4mcJCcOI= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/RestartService/install.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_restartservice.ps1'" -------------------------------------------------------------------------------- /DU/Packages/RestartService/uninstall.cmd: -------------------------------------------------------------------------------- 1 | powershell.exe -executionpolicy bypass -command "& '.\Windows10_removeadmin.ps1' remove-item" -------------------------------------------------------------------------------- /DU/Packages/Windows10_AllowPrinterInstallation/WIndows10_Allowprinterinstallation.intunewin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Call4cloud/Enrollment/4440ce2045ae2d5278a6ed054e1f270e61e43fb9/DU/Packages/Windows10_AllowPrinterInstallation/WIndows10_Allowprinterinstallation.intunewin -------------------------------------------------------------------------------- /DU/Packages/Windows10_AllowPrinterInstallation/detection.xml: -------------------------------------------------------------------------------- 1 | 2 | AllowNon-AdministratorsToInstallPrinterDrivers.intunewin 3 | 1646 4 | AllowNon-AdministratorsToInstallPrinterDrivers.intunewin 5 | AllowNon-AdministratorsToInstallPrinterDrivers.ps1 6 | 7 | jhHE+VlzgwRTFJe/sf+TvBUEBS7xzeHkqXDoOm4DqcA= 8 | NP2j60iyW6kw1gWr/pFQxJdsGHR7TyXZyAa7uXV1M/k= 9 | qE/We/Ge4gKC4/0tvWoPCA== 10 | b5mFuYcOs3BAj3tO7xLwFn1xzXxiG0j2HNyH2jvhbpk= 11 | ProfileVersion1 12 | HghsEFlKmChqVJfGiPcG3T5Ipckt+yVRnemKXacHCiw= 13 | SHA256 14 | 15 | -------------------------------------------------------------------------------- /DU/Packages/readme: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /DU/scripts/Windows10_ChangePublicDesktopPermissions.ps1: -------------------------------------------------------------------------------- 1 | $acl = Get-ACL "C:\Users\Public\Desktop" 2 | $rule=new-object System.Security.AccessControl.FileSystemAccessRule ("iedereen","FullControl", "ContainerInherit,ObjectInherit", "None", "Allow") 3 | $acl.SetAccessRule($rule) 4 | Set-ACL "C:\Users\Public\Desktop" $acl 5 | -------------------------------------------------------------------------------- /DU/scripts/Windows10_Hardening.ps1: -------------------------------------------------------------------------------- 1 | #Register Changes 2 | reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" /v SafeDLLSearchMode /t REG_DWORD /d 1 /f 3 | 4 | #Harden lsass to help protect against credential dumping (mimikatz) and audit lsass access requests 5 | reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RunAsPPL /t REG_DWORD /d 00000001 /f 6 | reg add "HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest" /v UseLogonCredential /t REG_DWORD /d 0 /f 7 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation" /v AllowProtectedCreds /t REG_DWORD /d 1 /f 8 | reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LSASS.exe" /v AuditLevel /t REG_DWORD /d 00000008 /f 9 | 10 | #Disables DNS multicast 11 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" /v EnableMulticast /t REG_DWORD /d 0 /f 12 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" /v DisableSmartNameResolution /t REG_DWORD /d 1 /f 13 | 14 | #Disable anonymous access to named pipes/shared, anonymous enumeration of SAM accounts, non-admin remote access to SAM 15 | reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v TokenLeakDetectDelaySecs /t REG_DWORD /d 30 /f 16 | reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RestrictAnonymousSAM /t REG_DWORD /d 1 /f 17 | reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RestrictAnonymous /t REG_DWORD /d 1 /f 18 | reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RestrictRemoteSAM /t REG_SZ /d "O:BAG:BAD:(A;;RC;;;BA)" /f 19 | reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v LmCompatibilityLevel /t REG_DWORD /d 5 /f 20 | reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v LimitBlankPasswordUse /t REG_DWORD /d 1 /f 21 | 22 | #Enable PowerShell Logging 23 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" /v EnableScriptBlockLogging /t REG_DWORD /d 1 /f 24 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging" /v EnableModuleLogging /t REG_DWORD /d 1 /f 25 | 26 | #Disable Enumate Admin 27 | reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\CredUI" /v EnumerateAdministrators /t REG_DWORD /d 1 /f 28 | 29 | #Disable autorun/autoplay on all drives 30 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoAutoplayfornonVolume /t REG_DWORD /d 1 /f 31 | reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 255 /f 32 | reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoAutorun /t REG_DWORD /d 1 /f 33 | 34 | #UAC 35 | reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v ConsentPromptBehaviorUser /t REG_DWORD /d 0 /f 36 | 37 | #Disable Solicited Remote Assistance 38 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fAllowToGetHelp /t REG_DWORD /d 0 /f 39 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fAllowUnsolicited /t REG_DWORD /d 0 /f 40 | 41 | 42 | #winrm 43 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" /v AllowBasic /t REG_DWORD /d 0 /f 44 | reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Client" /v AllowBasic /t REG_DWORD /d 0 /f 45 | 46 | #DisableAutorun 47 | reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoAutorun /t REG_DWORD /d 1 /f 48 | reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 255 /f 49 | 50 | #Digital Sign Communication 51 | reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v RequireSecuritySignature /t REG_DWORD /d 1 /f 52 | 53 | #Disable IP source routing 54 | reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v DisableIPSourceRouting /t REG_DWORD /d 2 /f 55 | 56 | 57 | #disable java and flash inside adobe 58 | reg add "HKLM\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown" /v bDisableJavaScript /t REG_DWORD /d 2 /f 59 | reg add "HKLM\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown" /v bEnableFlash /t REG_DWORD /d 2 /f 60 | 61 | 62 | #defender updates configureren 63 | Set-MpPreference -SignatureScheduleDay 0 64 | Set-MpPreference -SignatureUpdateInterval 1 65 | 66 | 67 | 68 | -------------------------------------------------------------------------------- /DU/scripts/Windows10_Hiberboot.ps1: -------------------------------------------------------------------------------- 1 | $Path = "HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Power" 2 | $Name = "HiberbootEnabled" 3 | $value = "0" 4 | 5 | #Check if $Path exist. If not, create $Path and then add the item and set value. 6 | 7 | If (!(Test-Path $Path)) 8 | 9 | { 10 | New-Item -Path $Path -Force | Out-Null 11 | New-ItemProperty -Path $Path -Name $Name -Value $value -PropertyType DWORD -Force | Out-Null 12 | } 13 | 14 | ELSE 15 | { 16 | New-ItemProperty -Path $Path -Name $Name -Value $value -PropertyType DWORD -Force | Out-Null 17 | } -------------------------------------------------------------------------------- /DU/scripts/Windows10_TimeService.ps1: -------------------------------------------------------------------------------- 1 | Set-Service W32time -startuptype automatic 2 | Start-Service W32time -------------------------------------------------------------------------------- /SL1/SL1_2.ps1: -------------------------------------------------------------------------------- 1 | ###################################### 2 | ###Configure Exchange Online # 3 | ##################################### 4 | #Office365 Powershell sessie opbouwen 5 | Set-ExecutionPolicy RemoteSigned 6 | $UserCredential = Get-Credential 7 | $Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri https://outlook.office365.com/powershell-liveid/ -Credential $UserCredential -Authentication Basic -AllowRedirection 8 | 9 | Import-PSSession $Session -AllowClobber 10 | 11 | #Enable Organization Customization 12 | Enable-OrganizationCustomization 13 | 14 | #Default Sharing Policy Calendar 15 | Set-SharingPolicy -Identity "Default Sharing Policy" -Domains @{Remove="Anonymous:CalendarSharingFreeBusyReviewer", "Anonymous:CalendarSharingFreeBusySimple", "Anonymous:CalendarSharingFreeBusyDetail"} 16 | Set-SharingPolicy -Identity "Default Sharing Policy" -Domains "*:CalendarSharingFreeBusySimple" 17 | 18 | 19 | #Spamfiltersettings Office365 20 | Set-HostedContentFilterPolicy -Identity "Default" -SpamAction MoveToJmf -BulkSpamAction MoveToJmf -HighConfidenceSpamAction MoveToJmf -BulkThreshold 5 -IncreaseScoreWithBizOrInfoUrls On ` 21 | -IncreaseScoreWithImageLinks On -IncreaseScoreWithNumericIps On -IncreaseScoreWithRedirectToOtherPort On -MarkAsSpamBulkMail On -MarkAsSpamEmbedTagsInHtml On -MarkAsSpamEmptyMessages On ` 22 | -MarkAsSpamFormTagsInHtml On -MarkAsSpamFramesInHtml On -MarkAsSpamFromAddressAuthFail On -MarkAsSpamJavaScriptInHtml On -MarkAsSpamNdrBackscatter On -MarkAsSpamObjectTagsInHtml On ` 23 | -MarkAsSpamSpfRecordHardFail On -MarkAsSpamWebBugsInHtml On -MarkAsSpamSensitiveWordList On -TestModeAction AddXHeader 24 | 25 | #End user Spam Notificatie office365 26 | Set-HostedContentFilterPolicy -Identity "Default" -EnableEndUserSpamNotifications $true -endUserSpamNotificationLanguage dutch –EndUserSpamNotificationFrequency 1 27 | 28 | #Malwarefiltersettings Office365 29 | Set-MalwareFilterPolicy -Identity "Default" -Action DeleteAttachmentAndUseDefaultAlertText -EnableFileFilter $true -FileTypes ".cpl", ".ace", ".app",".docm",".exe",".jar",".reg",".scr",".vbe",".vbs",".bat",".msi", ` 30 | ".ani", ".dll", ".lnf", ".mdb", ".ws", ".cmd", ".com", ".crt", ".dos", ".lns", ".ps1", ".wsh", ".wsc" -EnableExternalSenderNotifications $true -EnableInternalSenderNotifications $true 31 | 32 | ####################### 33 | 34 | #Audit log aanzetten voor alle users 35 | Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true 36 | 37 | Get-Mailbox -ResultSize Unlimited -Filter {RecipientTypeDetails -eq "UserMailbox" -or RecipientTypeDetails -eq "SharedMailbox" -or RecipientTypeDetails -eq "RoomMailbox" -or RecipientTypeDetails -eq "DiscoveryMailbox"} ` 38 | | Set-Mailbox -AuditEnabled $true -AuditLogAgeLimit 180 -AuditAdmin Update, MoveToDeletedItems, SoftDelete, HardDelete, SendAs, SendOnBehalf, Create, UpdateFolderPermission ` 39 | -AuditDelegate Update, SoftDelete, HardDelete, SendAs, Create, UpdateFolderPermissions, MoveToDeletedItems, SendOnBehalf ` 40 | -AuditOwner UpdateFolderPermission, MailboxLogin, Create, SoftDelete, HardDelete, Update, MoveToDeletedItems 41 | 42 | Get-Mailbox -ResultSize Unlimited | Select Name, AuditEnabled, AuditLogAgeLimit | Out-Gridview 43 | 44 | Get-MailboxPlan | Set-MailboxPlan -RetainDeletedItemsFor 30 45 | Get-mailbox | set-mailbox -retaindeleteditems 30 46 | Get-mailbox | Set-Mailbox -SingleItemRecoveryEnabled $true 47 | 48 | #Imap en Pop uitschakelen (check van te voren in de sign in logging of dit gebruikt wordt!!) 49 | Get-CASMailboxPlan | Set-CASMailboxPlan -ImapEnabled $false -PopEnabled $false 50 | 51 | #Block Client Forwarding Rules 52 | 53 | $rejectMessageText= "Client Forwarding Rules To External Domains Are Not Permitted." 54 | New-TransportRule -name "Client Rules To External Block" -Priority 0 -SentToScope NotInOrganization -FromScope InOrganization -MessageTypeMatches AutoForward -RejectMessageEnhancedStatusCode 5.7.1 ` 55 | -RejectMessageReasonText $rejectMessageText 56 | Get-RemoteDomain | Set-RemoteDomain –AutoForwardEnabled $false 57 | 58 | #Mailboxen Nederlands taal 59 | Get-mailbox -ResultSize unlimited | Set-MailboxRegionalConfiguration -Language nl-NL -DateFormat “d-M-yyyy” -timezone “W. Europe Standard Time” -timeformat “HH:mm” -LocalizeDefaultFolderName:$true 60 | 61 | 62 | 63 | 64 | 65 | 66 | -------------------------------------------------------------------------------- /SL1/SL1_3.ps1: -------------------------------------------------------------------------------- 1 | ################# 2 | #install-module MSOnline 3 | #Uninstall-module azuread 4 | #Uninstall-module azureadpreview 5 | #install-module AzureAD 6 | #install-module AzureADPreview 7 | #import-module AzureADPreview 8 | import-module msonline 9 | 10 | connect-msolservice 11 | Set-MsolCompanySettings -UsersPermissionToReadOtherUsersEnabled $false 12 | Set-MsolCompanySettings -AllowAdHocSubscriptions $false 13 | Set-MsolCompanySettings -SelfServePasswordResetEnabled $true 14 | 15 | 16 | 17 | ###################################### 18 | # Change Sharepoint Settings # 19 | ###################################### 20 | 21 | $name = get-azureaddomain | where {($_.name -like '*.onmicrosoft.com') -and ($_.name -notlike '*.mail.onmicrosoft.com')} | select name 22 | $name.name 23 | $ShortName = $name.Name.Replace(".onmicrosoft.com","") 24 | $sharepointadmincenter = "https://"+$shortname+"-admin.sharepoint.com" 25 | 26 | Connect-SPOService -url $sharepointadmincenter 27 | Set-SPOTenantSyncClientRestriction -ExcludedFileExtensions "exe;bat;msi;dll;vbs;vbe" 28 | set-spotenant -sharingcapability externalusersharingonly 29 | set-spotenant -defaultsharinglinktype direct 30 | set-spotenant -LegacyAuthProtocolsEnabled $false 31 | set-spotenant -RequireAcceptingAccountMatchInvitedAccount $true 32 | Set-SPOBrowserIdleSignOut -Enabled $true -WarnAfter (New-TimeSpan -Seconds 2700) -SignOutAfter (New-TimeSpan -Seconds 3600) 33 | set-spotenant -PreventExternalUsersFromResharing $true 34 | set-spotenant -DisplayStartASiteOption $False 35 | set-spotenant -DisallowInfectedFileDownload $true 36 | set-spotenant -NotifyOwnersWhenItemsReshared $True 37 | set-spotenant -NotifyOwnersWhenInvitationsAccepted $True 38 | set-spotenant -OwnerAnonymousNotification $True 39 | set-spotenant -OneDriveForGuestsEnabled $false 40 | 41 | 42 | get-AzureADMSAuthorizationPolicy | Set-AzureADMSAuthorizationPolicy -GuestUserRoleId '2af84b1e-32c8-42b7-82bc-daa82404023b' 43 | 44 | Connect-IPPSSession 45 | Set-PolicyConfig -EnableLabelCoauth $True –EnableSpoAipMigration $True 46 | 47 | 48 | #################### 49 | New-AzureADPolicy -Type AuthenticatorAppSignInPolicy -Definition '{"AuthenticatorAppSignInPolicy":{"Enabled":true}}' -isOrganizationDefault $true -DisplayName AuthenticatorAppSignIn 50 | 51 | 52 | -------------------------------------------------------------------------------- /SL1/SL1_4.ps1: -------------------------------------------------------------------------------- 1 |  2 | ### Configuring TEAMS and Commerce Settings 3 | 4 | ##### PLEASE CHANGE THE GROUP CREATORS TO YOUR LIKING!!############# 5 | 6 | 7 | ############################################### 8 | # limited the group creaters for teams # 9 | ############################################# 10 | 11 | $GroupName = “Group_creators” 12 | $AllowGroupCreation = "False" 13 | 14 | #Connect-AzureAD 15 | 16 | $settingsObjectID = (Get-AzureADDirectorySetting | Where-object -Property Displayname -Value "Group.Unified" -EQ).id 17 | if(!$settingsObjectID) 18 | { 19 | $template = Get-AzureADDirectorySettingTemplate | Where-object {$_.displayname -eq "group.unified"} 20 | $settingsCopy = $template.CreateDirectorySetting() 21 | New-AzureADDirectorySetting -DirectorySetting $settingsCopy 22 | $settingsObjectID = (Get-AzureADDirectorySetting | Where-object -Property Displayname -Value "Group.Unified" -EQ).id 23 | } 24 | 25 | $settingsCopy = Get-AzureADDirectorySetting -Id $settingsObjectID 26 | $settingsCopy["EnableGroupCreation"] = $AllowGroupCreation 27 | 28 | if($GroupName) 29 | { 30 | $settingsCopy["GroupCreationAllowedGroupId"] = (Get-AzureADGroup -SearchString $GroupName).objectid 31 | } 32 | 33 | Set-AzureADDirectorySetting -Id $settingsObjectID -DirectorySetting $settingsCopy 34 | 35 | (Get-AzureADDirectorySetting -Id $settingsObjectID).Values 36 | 37 | ##################### 38 | #Install-module MicrosoftTeams 39 | import-module MicrosoftTeams 40 | Connect-MicrosoftTeams 41 | Set-CsTeamsClientConfiguration -AllowEgnyte $false 42 | set-CsTeamsClientConfiguration -allowbox $false 43 | set-CsTeamsClientConfiguration -allowdropbox $false 44 | set-CsTeamsClientConfiguration -allowgoogledrive $false 45 | set-CsTeamsClientConfiguration -allowsharefile $false 46 | set-CsTeamsClientConfiguration -AllowEmailIntoChannel $true 47 | set-CsTeamsClientConfiguration -AllowGuestUser $true 48 | set-CsTeamsAppPermissionPolicy -GlobalCatalogAppsType blockedapplist 49 | 50 | ################### 51 | Import-Module -Name MSCommerce 52 | Connect-MSCommerce 53 | Get-MSCommerceProductPolicies -PolicyId AllowSelfServicePurchase | Where { $_.PolicyValue -eq “Enabled”} | forEach { 54 | Update-MSCommerceProductPolicy -PolicyId AllowSelfServicePurchase -ProductId $_.ProductID -Enabled $false } -------------------------------------------------------------------------------- /SL1/readme: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /functions/Test-JSON.ps1: -------------------------------------------------------------------------------- 1 | Function Test-JSON(){ 2 | 3 | <# 4 | .SYNOPSIS 5 | This function is used to test if the JSON passed to a REST Post request is valid 6 | .DESCRIPTION 7 | The function tests if the JSON passed to the REST Post is valid 8 | .EXAMPLE 9 | Test-JSON -JSON $JSON 10 | Test if the JSON is valid before calling the Graph REST interface 11 | .NOTES 12 | NAME: Test-AuthHeader 13 | #> 14 | 15 | param ( 16 | 17 | $JSON 18 | 19 | ) 20 | 21 | try { 22 | 23 | $TestJSON = ConvertFrom-Json $JSON -ErrorAction Stop 24 | $validJson = $true 25 | 26 | } 27 | 28 | catch { 29 | 30 | $validJson = $false 31 | $_.Exception 32 | 33 | } 34 | 35 | if (!$validJson){ 36 | 37 | Write-Host "Provided JSON isn't in valid JSON format" -f Red 38 | break 39 | 40 | } 41 | 42 | } 43 | --------------------------------------------------------------------------------