Skip to content

Commit

Permalink
Updated-5142082-B2-Repo-Health
Browse files Browse the repository at this point in the history
Articles updated to resolve Suggestions.
  • Loading branch information
v-jmathew committed Jul 1, 2021
1 parent d1aedd4 commit b3adef6
Show file tree
Hide file tree
Showing 20 changed files with 179 additions and 174 deletions.
2 changes: 1 addition & 1 deletion hololens/hololens-cellular.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ USB-C tethering can provide lower latency for advanced workloads that need it. [

A limited number of devices that present themselves as an ethernet adaptor can be used with Windows Holographic version 2004 and later.

Devices that do not present themselves as an ethernet adapter must support the generic Microsoft [RNDIS](https://docs.microsoft.com/windows-hardware/drivers/network/overview-of-remote-ndis--rndis-) driver. But, only a limited number of those devices are compatible with HoloLens 2. Please consult your device's manufacturer for details on whether it supports the generic Microsoft RNDIS driver.
Devices that do not present themselves as an ethernet adapter must support the generic Microsoft [RNDIS](/windows-hardware/drivers/network/overview-of-remote-ndis--rndis-) driver. But, only a limited number of those devices are compatible with HoloLens 2. Please consult your device's manufacturer for details on whether it supports the generic Microsoft RNDIS driver.

Devices that are not RNDIS compatible, or require a driver or application to be installed, are not supported.

Expand Down
20 changes: 10 additions & 10 deletions hololens/hololens2-cloud-connected-prepare.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,31 +29,31 @@ For both personal and corporate deployment scenarios, an MDM system is the essen
Azure AD is a cloud-based directory service that provides identity and access management. Organizations that use Microsoft Office 365 or Intune are already using Azure AD, which has three editions: Free, Premium P1, and Premium P2 (see [Azure Active Directory editions](https://azure.microsoft.com/documentation/articles/active-directory-editions).) All editions support Azure AD device registration, but Premium P1 is required to enable MDM auto-enrollment which we will be using in this guide later.

> [!IMPORTANT]
> It is essential to have an Azure Active Directory as HoloLens devices do not support on-premises AD join. If you don't already have an Azure Active Directory set up follow the instructions in this link to get started and [Create a new tenant in Azure Active Directory](https://docs.microsoft.com/azure/active-directory/fundamentals/active-directory-access-create-new-tenant).
> It is essential to have an Azure Active Directory as HoloLens devices do not support on-premises AD join. If you don't already have an Azure Active Directory set up follow the instructions in this link to get started and [Create a new tenant in Azure Active Directory](/azure/active-directory/fundamentals/active-directory-access-create-new-tenant).
## Identity Management

Employees can use only one account to initialize a device so it's imperative that your organization controls which account is enabled first. The account chosen will determine who controls the device and influence your management capabilities.

In this guide we have chosen that for the [Identity](https://docs.microsoft.com/hololens/hololens-identity) used we will use Azure AD accounts, or Azure Active Directory accounts. There are several benefits to Azure AD accounts we would like to use, such as:
In this guide we have chosen that for the [Identity](/hololens/hololens-identity) used we will use Azure AD accounts, or Azure Active Directory accounts. There are several benefits to Azure AD accounts we would like to use, such as:

- Employees use their Azure AD account to register the device in Azure AD and automatically enroll it with the organization's MDM solution (Azure AD+MDM – requires Azure AD Premium).
- Azure AD accounts support [Single Sign On](https://docs.microsoft.com/azure/active-directory/manage-apps/what-is-single-sign-on). When a user signs into Remote Assist, their Identity from the signed in Azure AD user will be recognized and the user will be signed into the app for a streamlined experience.
- Azure AD accounts have additional [authentication options](https://docs.microsoft.com/hololens/hololens-identity) via [Windows Hello for Business](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-identity-verification). In addition to Iris log-in users can sign in from another device or use FIDO security keys.
- Azure AD accounts support [Single Sign On](/azure/active-directory/manage-apps/what-is-single-sign-on). When a user signs into Remote Assist, their Identity from the signed in Azure AD user will be recognized and the user will be signed into the app for a streamlined experience.
- Azure AD accounts have additional [authentication options](/hololens/hololens-identity) via [Windows Hello for Business](/windows/security/identity-protection/hello-for-business/hello-identity-verification). In addition to Iris log-in users can sign in from another device or use FIDO security keys.

### Mobile Device Management

Microsoft [Intune](https://docs.microsoft.com/mem/intune/fundamentals/what-is-intune), part of the Enterprise Mobility + Security, is a cloud-based MDM system that manages devices connected to your tenant. Like Office 365, Intune uses Azure AD for identity management, so employees use the same credentials to enroll devices in Intune that they use to sign into Office 365. Intune also supports devices that run other operating systems, such as iOS and Android, to provide a complete MDM solution. For the purposes of this guide, we'll be focusing on using Intune for enabling a cloud deployment at scale with HoloLens 2.
Microsoft [Intune](/mem/intune/fundamentals/what-is-intune), part of the Enterprise Mobility + Security, is a cloud-based MDM system that manages devices connected to your tenant. Like Office 365, Intune uses Azure AD for identity management, so employees use the same credentials to enroll devices in Intune that they use to sign into Office 365. Intune also supports devices that run other operating systems, such as iOS and Android, to provide a complete MDM solution. For the purposes of this guide, we'll be focusing on using Intune for enabling a cloud deployment at scale with HoloLens 2.

> [!IMPORTANT]
> It is essential to have Mobile Device Management. If you don't already have it set up follow this guide and [Get started with Intune](https://docs.microsoft.com/mem/intune/fundamentals/free-trial-sign-up).
> It is essential to have Mobile Device Management. If you don't already have it set up follow this guide and [Get started with Intune](/mem/intune/fundamentals/free-trial-sign-up).
> [!NOTE]
> Multiple MDM systems support Windows 10 and most support personal and corporate device deployment scenarios. MDM providers that support Windows 10 Holographic currently include: AirWatch, MobileIron, and others. Most industry-leading MDM vendors already support integration with Azure AD. You can find the MDM vendors that support Azure AD in [Azure Marketplace](https://azure.microsoft.com/marketplace/).
## Network

In this setup, we anticipate HoloLens 2 devices connecting to the Internet from any available open Wi-Fi network. Since a user could need to change the network connection based on location, they should learn how to [connect HoloLens devices to Wi-Fi.](https://docs.microsoft.com/hololens/hololens-network)
In this setup, we anticipate HoloLens 2 devices connecting to the Internet from any available open Wi-Fi network. Since a user could need to change the network connection based on location, they should learn how to [connect HoloLens devices to Wi-Fi.](/hololens/hololens-network)

For Dynamics 365 Remote Assist there are a variety of network conditions, including bandwidth, latency, jitter, and packet loss, that can impact your video calling experience. Although audio and video calls might be possible in environments with reduced bandwidth, you might experience feature degradation. When using Dynamics 365 Remote Assist on HoloLens here are the network requirements to keep in mind:

Expand All @@ -63,12 +63,12 @@ For Dynamics 365 Remote Assist there are a variety of network conditions, includ

More information:

- [Network requirements](https://docs.microsoft.com/dynamics365/mixed-reality/remote-assist/requirements#network-requirements)
- [Network optimization recommendations](https://docs.microsoft.com/dynamics365/mixed-reality/remote-assist/requirements#dynamics-365-remote-assist-hololens)
- [Network requirements](/dynamics365/mixed-reality/remote-assist/requirements#network-requirements)
- [Network optimization recommendations](/dynamics365/mixed-reality/remote-assist/requirements#dynamics-365-remote-assist-hololens)

### Optional: Connect your HoloLens to VPN

The devices being connected into this guide are going to connect to the network via and external cloud network. It may be that to access company resources you'll need to connect your devices via VPN. There are several different ways to connect your devices to VPN, both where the end user can connect via using the device UI, or the devices can be managed and receive the VPN profile from either a PPKG or MDM. How to set up VPN won't be covered in this article, so if you'd like to learn more about the different VPN protocols or ways to manage VPN visit [these guides for information on HoloLens and VPN.](https://docs.microsoft.com/hololens/hololens-network#vpn)
The devices being connected into this guide are going to connect to the network via and external cloud network. It may be that to access company resources you'll need to connect your devices via VPN. There are several different ways to connect your devices to VPN, both where the end user can connect via using the device UI, or the devices can be managed and receive the VPN profile from either a PPKG or MDM. How to set up VPN won't be covered in this article, so if you'd like to learn more about the different VPN protocols or ways to manage VPN visit [these guides for information on HoloLens and VPN.](/hololens/hololens-network#vpn)

## Next step

Expand Down
34 changes: 17 additions & 17 deletions hololens/hololens2-compliance.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,45 +18,45 @@ appliesto:

# HoloLens 2 Privacy Statement

One of the core elements of the GDPR is ‘data protection by design’. This concept especially applies to mobile devices, like the HoloLens 2, because of their portability, unlimited internet connections and open communication channels. Resultingly, the HoloLens 2’s [security](https://docs.microsoft.com/hololens/security-architecture) has been redesigned to provide advanced, innovative security and privacy protection, end-to-end, incorporating both Microsoft’s approach to [privacy and GDPR regulations](https://privacy.microsoft.com/).
One of the core elements of the GDPR is ‘data protection by design’. This concept especially applies to mobile devices, like the HoloLens 2, because of their portability, unlimited internet connections and open communication channels. Resultingly, the HoloLens 2’s [security](/hololens/security-architecture) has been redesigned to provide advanced, innovative security and privacy protection, end-to-end, incorporating both Microsoft’s approach to [privacy and GDPR regulations](https://privacy.microsoft.com/).

>[!NOTE]
> This document does not apply to HoloLens (1st gen).
## Privacy Overview

HoloLens 2 is a self-contained Windows computer, running Windows Holographic, that runs apps and solutions in an immersive mixed reality environment. It can be used as a secure offline device or deployed as a [managed device](https://docs.microsoft.com/mem/intune/fundamentals/windows-holographic-for-business) within your organization. See the following links to understand how the HoloLens 2 and Microsoft uses and protects your data:
HoloLens 2 is a self-contained Windows computer, running Windows Holographic, that runs apps and solutions in an immersive mixed reality environment. It can be used as a secure offline device or deployed as a [managed device](/mem/intune/fundamentals/windows-holographic-for-business) within your organization. See the following links to understand how the HoloLens 2 and Microsoft uses and protects your data:

1. [Microsoft Privacy Statement - HoloLens](https://privacy.microsoft.com/privacystatement) – expand the **Enterprise and developer** section in the left navigation menu and select **Enterprise and developer software and appliances**. Go to the **HoloLens** section.
2. [Windows 10 and your online services](https://privacy.microsoft.com/windows10privacy)
3. [Windows 10 & Privacy Compliance Guide](https://docs.microsoft.com/windows/privacy/windows-10-and-privacy-compliance)
4. [Privacy and personal data in Intune](https://docs.microsoft.com/mem/intune/protect/privacy-personal-data)
2. [Windows 10 and your online services](https://privacy.microsoft.com/windows10privacy)
3. [Windows 10 & Privacy Compliance Guide](/windows/privacy/windows-10-and-privacy-compliance)
4. [Privacy and personal data in Intune](/mem/intune/protect/privacy-personal-data)

## Network Security
Following the HoloLens 2 [Common Deployment Scenarios](https://docs.microsoft.com/hololens/common-scenarios), your data will be protected by [Azure’s world-class compliance](https://docs.microsoft.com/azure/compliance/) along with legal/regulatory standards integration. If you are new to Azure AD and Dynamics 365 Remote Assist, reference the [Azure and Dynamics 365 accountability readiness checklist for the GDPR](https://docs.microsoft.com/compliance/regulatory/gdpr-arc-azure-dynamics).
Following the HoloLens 2 [Common Deployment Scenarios](/hololens/common-scenarios), your data will be protected by [Azure’s world-class compliance](/azure/compliance/) along with legal/regulatory standards integration. If you are new to Azure AD and Dynamics 365 Remote Assist, reference the [Azure and Dynamics 365 accountability readiness checklist for the GDPR](/compliance/regulatory/gdpr-arc-azure-dynamics).

Furthermore, Windows Defender Firewall delivers critical functionality to secure device connectivity. With HoloLens 2, the firewall is always enabled and there are no ways to disable it programmatically or through the UI. When the HoloLens 2 is deployed as a managed device using [Intune](https://docs.microsoft.com/mem/intune/protect/device-compliance-get-started), more compliance functionality is available with integration for [Endpoint with Microsoft Intune](https://docs.microsoft.com/mem/intune/protect/advanced-threat-protection) as a Mobile Threat Defense solution.
Furthermore, Windows Defender Firewall delivers critical functionality to secure device connectivity. With HoloLens 2, the firewall is always enabled and there are no ways to disable it programmatically or through the UI. When the HoloLens 2 is deployed as a managed device using [Intune](/mem/intune/protect/device-compliance-get-started), more compliance functionality is available with integration for [Endpoint with Microsoft Intune](/mem/intune/protect/advanced-threat-protection) as a Mobile Threat Defense solution.

Learn more about the HoloLens 2 [security and architecture](https://docs.microsoft.com/hololens/security-architecture).
Learn more about the HoloLens 2 [security and architecture](/hololens/security-architecture).

## OS Security
Updates are done automatically (by default) so your HoloLens 2 is always up to date with the latest release of Windows Holographic and any installed apps. See the following to understand more about how our OS is securely designed:
1. [State separation and isolation](https://docs.microsoft.com/hololens/security-state-separation-isolation)
1. [Admin-less operating system](https://docs.microsoft.com/hololens/security-adminless-os)
1. [Limiting password use](https://docs.microsoft.com/hololens/security-limiting-password-use)

1. [State separation and isolation](/hololens/security-state-separation-isolation)
1. [Admin-less operating system](/hololens/security-adminless-os)
1. [Limiting password use](/hololens/security-limiting-password-use)

## Physical Security
HoloLens 2 has flash memory that is protected by [BitLocker encryption](https://docs.microsoft.com/hololens/security-encryption-data-protection). Your device, and its local data, can be flashed offline using [Advanced Recovery Companion](https://www.microsoft.com/p/advanced-recovery-companion/9p74z35sfrs8#activetab=pivot:overviewtab) or remotely wiped via MDM if it has been deployed as a managed device.
HoloLens 2 has flash memory that is protected by [BitLocker encryption](/hololens/security-encryption-data-protection). Your device, and its local data, can be flashed offline using [Advanced Recovery Companion](https://www.microsoft.com/p/advanced-recovery-companion/9p74z35sfrs8#activetab=pivot:overviewtab) or remotely wiped via MDM if it has been deployed as a managed device.

## Data Protection
Windows updates are run automatically (by default) and [Azure integration](https://docs.microsoft.com/hololens/security-encryption-data-protection#Azure-integration) protects data traveling between itself and the cloud.
Windows updates are run automatically (by default) and [Azure integration](/hololens/security-encryption-data-protection#Azure-integration) protects data traveling between itself and the cloud.

When deploying HoloLens 2 to external clients, [Dynamics 365 Remote Assist](https://docs.microsoft.com/hololens/hololens2-deployment-guide) ensures your sensitive company data and resources are both separate and safe.
When deploying HoloLens 2 to external clients, [Dynamics 365 Remote Assist](/hololens/hololens2-deployment-guide) ensures your sensitive company data and resources are both separate and safe.

The sharing of diagnostic data with Microsoft can be manually configured by MDM or by the user during OOBE. There are two choices: Optional diagnostic data and Required diagnostic data. If your original diagnostic setting needs to be changed at a later time for troubleshooting purposes, it can be changed by the user in **Settings -> Privacy -> Diagnostics & Feedback** or the IT Admin (MDM) if is a managed device. See more about [Diagnostics, feedback, and privacy in Windows 10](https://support.microsoft.com/windows/diagnostics-feedback-and-privacy-in-windows-10-28808a2b-a31b-dd73-dcd3-4559a5199319).

> [!Important]
> Device diagnostic logs contain personally identifiable information (PII), such as about what processes or applications the user starts during typical operations. When multiple users share a HoloLens device (for example, users sign in to the same device by using different Microsoft Azure Active Directory (Azure AD) accounts) the diagnostic logs may contain PII information that applies to multiple users.


There are [several collection methods and data retention policies](https://docs.microsoft.com/hololens/hololens-diagnostic-logs) for gathering diagnostic data from the HoloLens 2. For more information about how Microsoft collects and uses diagnostic data, see [Microsoft Privacy Statement - Diagnostics](https://privacy.microsoft.com/privacystatement) - expand **Windows** in the left navigation menu and select **Diagnostics**. Go to the **Diagnostics** section.
There are [several collection methods and data retention policies](/hololens/hololens-diagnostic-logs) for gathering diagnostic data from the HoloLens 2. For more information about how Microsoft collects and uses diagnostic data, see [Microsoft Privacy Statement - Diagnostics](https://privacy.microsoft.com/privacystatement) - expand **Windows** in the left navigation menu and select **Diagnostics**. Go to the **Diagnostics** section.
Loading

0 comments on commit b3adef6

Please sign in to comment.