Manage connections from Windows 10 and Windows 11 operating system components to Microsoft services using Microsoft Intune MDM Server

Applies to

  • Windows 11
  • Windows 10 Enterprise 1903 version and newer

This article describes the network connections that Windows 10 and Windows 11 components make to Microsoft and the Mobile Device Management/Configuration Service Provider (MDM/CSP) and custom Open Mobile Alliance Uniform Resource Identifier (OMA URI) policies available to IT Professionals using Microsoft Intune to help manage the data shared with Microsoft. If you want to minimize connections from Windows to Microsoft services, or configure privacy settings, there are a number of settings for consideration. For example, you can configure diagnostic data to the lowest level for your edition of Windows and evaluate other connections Windows makes to Microsoft services you want to turn off using the instructions in this article. While it is possible to minimize network connections to Microsoft, there are many reasons why these communications are enabled by default, such as updating malware definitions and maintaining current certificate revocation lists. This data helps us deliver a secure, reliable, and up-to-date experience.

Important

  • The Allowed Traffic endpoints for an MDM configuration are here: Allowed Traffic
    • CRL (Certificate Revocation List) and OCSP (Online Certificate Status Protocol) network traffic cannot be disabled and will still show up in network traces. CRL and OCSP checks are made to the issuing certificate authorities. Microsoft is one of these authorities. There are many others such as DigiCert, Thawte, Google, Symantec, and VeriSign.
    • There is some traffic which is specifically required for the Microsoft Intune based management of Windows 10 and Windows 11 devices. This traffic includes Windows Notifications Service (WNS), Automatic Root Certificates Update (ARCU), and some Windows Update related traffic. The aforementioned traffic comprises the Allowed Traffic for Microsoft Intune MDM Server to manage Windows 10 and Windows 11 devices.
  • For security reasons, it is important to take care in deciding which settings to configure as some of them may result in a less secure device. Examples of settings that can lead to a less secure device configuration include: disabling Windows Update, disabling Automatic Root Certificates Update, and disabling Windows Defender. Accordingly, we do not recommend disabling any of these features.
  • To ensure CSPs take priority over Group Policies in case of conflicts, use the ControlPolicyConflict policy.
  • The Get Help and Give us Feedback links in Windows may no longer work after applying some or all of the MDM/CSP settings.

Warning

If a user executes the "Reset this PC" command (Settings -> Update & Security -> Recovery) with the "Remove Everything" option the >Windows Restricted Traffic Limited Functionality settings will need to be re-applied in order re-restrict the device's egress traffic. >To do this the client must be re-enrolled to the Microsoft Intune service. Egress traffic may occur during the period prior to the re->application of the Restricted Traffic Limited Functionality settings. If the user executes a "Reset this PC" with the "Keep my files" >option the Restricted Traffic Limited Functionality settings are retained on the device, and therefore the client will remain in a >Restricted Traffic configuration during and after the "Keep my files" reset, and no re-enrollment is required.

For more information on Microsoft Intune please see Transform IT service delivery for your modern workplace and Microsoft Intune documentation.

For detailed information about managing network connections to Microsoft services using Windows Settings, Group Policies and Registry settings see Manage connections from Windows operating system components to Microsoft services.

We are always striving to improve our documentation and welcome your feedback. You can provide feedback by sending email to telmhelp@microsoft.com.

Settings for Windows 10 Enterprise edition 1903 and later and Windows 11

The following table lists management options for each setting.

For Windows 10 and Windows 11, the following MDM policies are available in the Policy CSP.

  1. Automatic Root Certificates Update

    1. MDM Policy: There is intentionally no MDM available for Automatic Root Certificate Update. This MDM does not exist since it would prevent the operation and management of MDM management of devices.
  2. Cortana and Search

    1. MDM Policy: Experience/AllowCortana. Choose whether to let Cortana install and run on the device. Set to 0 (zero)
    2. MDM Policy: Search/AllowSearchToUseLocation. Choose whether Cortana and Search can provide location-aware search results. Set to 0 (zero)
  3. Date & Time

    1. MDM Policy: Settings/AllowDateTime. Allows the user to change date and time settings. Set to 0 (zero)
  4. Device metadata retrieval

    1. MDM Policy: DeviceInstallation/PreventDeviceMetadataFromNetwork. Choose whether to prevent Windows from retrieving device metadata from the Internet. Set to Enabled
  5. Find My Device

    1. MDM Policy: Experience/AllowFindMyDevice. This policy turns on Find My Device. Set to 0 (zero)
  6. Font streaming

    1. MDM Policy: System/AllowFontProviders. Setting that determines whether Windows is allowed to download fonts and font catalog data from an online font provider. Set to 0 (zero)
  7. Insider Preview builds

    1. MDM Policy: System/AllowBuildPreview. This policy setting determines whether users can access the Insider build controls in the Advanced Options for Windows Update. Set to 0 (zero)
  8. Internet Explorer The following Microsoft Internet Explorer MDM policies are available in the Internet Explorer CSP

    1. MDM Policy: InternetExplorer/AllowSuggestedSites. Recommends websites based on the user’s browsing activity. Set to Disabled
    2. MDM Policy: InternetExplorer/PreventManagingSmartScreenFilter. Prevents the user from managing Windows Defender SmartScreen, which warns the user if the website being visited is known for fraudulent attempts to gather personal information through "phishing," or is known to host malware. Set to String with Value:
      1. <enabled/><data id=”IE9SafetyFilterOptions” value=”1”/>
    3. MDM Policy: InternetExplorer/DisableFlipAheadFeature. Determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website. Set to Enabled
    4. MDM Policy: InternetExplorer/DisableHomePageChange. Determines whether users can change the default Home Page or not. Set to String with Value:
      1. <enabled/><data id=”EnterHomePagePrompt” value=”Start Page”/>
    5. MDM Policy: InternetExplorer/DisableFirstRunWizard. Prevents Internet Explorer from running the First Run wizard the first time a user starts the browser after installing Internet Explorer or Windows. Set to String with Value:
      1. <enabled/><data id=”FirstRunOptions” value=”1”/>
  9. Live Tiles

    1. MDM Policy: Notifications/DisallowTileNotification. This policy setting turns off tile notifications. If you enable this policy setting applications and system features will not be able to update their tiles and tile badges in the Start screen. Integer value 1
  10. Mail synchronization

    1. MDM Policy: Accounts/AllowMicrosoftAccountConnection. Specifies whether the user is allowed to use an Microsoft account for non-email related connection authentication and services. Set to 0 (zero)
  11. Microsoft Account

    1. MDM Policy: Accounts/AllowMicrosoftAccountSignInAssistant. Disable the Microsoft Account Sign-In Assistant. Set to 0 (zero)
  12. Microsoft Edge The following Microsoft Edge MDM policies are available in the Policy CSP. For a complete list of the Microsoft Edge policies, see Available policies for Microsoft Edge.

    1. MDM Policy: Browser/AllowAutoFill. Choose whether employees can use autofill on websites. Set to 0 (zero)
    2. MDM Policy: Browser/AllowDoNotTrack. Choose whether employees can send Do Not Track headers. Set to 0 (zero)
    3. MDM Policy: Browser/AllowMicrosoftCompatbilityList. Specify the Microsoft compatibility list in Microsoft Edge. Set to 0 (zero)
    4. MDM Policy: Browser/AllowPasswordManager. Choose whether employees can save passwords locally on their devices. Set to 0 (zero)
    5. MDM Policy: Browser/AllowSearchSuggestionsinAddressBar. Choose whether the Address Bar shows search suggestions. Set to 0 (zero)
    6. MDM Policy: Browser/AllowSmartScreen. Choose whether Windows Defender SmartScreen is turned on or off. Set to 0 (zero)
  13. Network Connection Status Indicator

    1. Connectivity/DisallowNetworkConnectivityActiveTests. Note: After you apply this policy you must restart the device for the policy setting to take effect. Set to 1 (one)
  14. Offline maps

    1. MDM Policy: AllowOfflineMapsDownloadOverMeteredConnection. Allows the download and update of map data over metered connections.
      Set to 0 (zero)
    2. MDM Policy: EnableOfflineMapsAutoUpdate. Disables the automatic download and update of map data. Set to 0 (zero)
  15. OneDrive

    1. MDM Policy: DisableOneDriveFileSync. Allows IT Admins to prevent apps and features from working with files on OneDrive. Set to 1 (one)
    2. Ingest the ADMX - To get the latest OneDrive ADMX file you need an up-to-date Windows 10 or Windows 11 client. The ADMX files are located under the following path: %LocalAppData%\Microsoft\OneDrive\ there's a folder with the current OneDrive build (e.g. "18.162.0812.0001"). There is a folder named "adm" which contains the admx and adml policy definition files.
    3. MDM Policy: Prevent Network Traffic before User SignIn. PreventNetworkTrafficPreUserSignIn. The OMA-URI value is: ./Device/Vendor/MSFT/Policy/Config/OneDriveNGSC~Policy~OneDriveNGSC/PreventNetworkTrafficPreUserSignIn, Data type: String, Value: <enabled/>
  16. Privacy settings Except for the Feedback & Diagnostics page, these settings must be configured for every user account that signs into the PC.

    1. General - TextInput/AllowLinguisticDataCollection. This policy setting controls the ability to send inking and typing data to Microsoft. Set to 0 (zero)
    2. Location - System/AllowLocation. Specifies whether to allow app access to the Location service. Set to 0 (zero)
    3. Camera - Camera/AllowCamera. Disables or enables the camera. Set to 0 (zero)
    4. Microphone - Privacy/LetAppsAccessMicrophone. Specifies whether Windows apps can access the microphone. Set to 2 (two)
    5. Notifications - Privacy/LetAppsAccessNotifications. Specifies whether Windows apps can access notifications. Set to 2 (two)
    6. Notifications - Settings/AllowOnlineTips. Enables or disables the retrieval of online tips and help for the Settings app. Integer value 0
    7. Speech, Inking, & Typing - Privacy/AllowInputPersonalization. This policy specifies whether users on the device have the option to enable online speech recognition. Set to 0 (zero)
    8. Speech, Inking, & Typing - TextInput/AllowLinguisticDataCollection. This policy setting controls the ability to send inking and typing data to Microsoft Set to 0 (zero)
    9. Account info - Privacy/LetAppsAccessAccountInfo. Specifies whether Windows apps can access account information. Set to 2 (two)
    10. Contacts - Privacy/LetAppsAccessContacts. Specifies whether Windows apps can access contacts. Set to 2 (two)
    11. Calendar - Privacy/LetAppsAccessCalendar. Specifies whether Windows apps can access the calendar. Set to 2 (two)
    12. Call history - Privacy/LetAppsAccessCallHistory. Specifies whether Windows apps can access account information. Set to 2 (two)
    13. Email - Privacy/LetAppsAccessEmail. Specifies whether Windows apps can access email. Set to 2 (two)
    14. Messaging - Privacy/LetAppsAccessMessaging. Specifies whether Windows apps can read or send messages (text or MMS). Set to 2 (two)
    15. Phone calls - Privacy/LetAppsAccessPhone. Specifies whether Windows apps can make phone calls. Set to 2 (two)
    16. Radios - Privacy/LetAppsAccessRadios. Specifies whether Windows apps have access to control radios. Set to 2 (two)
    17. Other devices - Privacy/LetAppsSyncWithDevices. Specifies whether Windows apps can sync with devices. Set to 2 (two)
    18. Other devices - Privacy/LetAppsAccessTrustedDevices. Specifies whether Windows apps can access trusted devices. Set to 2 (two)
    19. Feedback & diagnostics - System/AllowTelemetry. Allow the device to send diagnostic and usage telemetry data, such as Watson. Set to 0 (zero)
    20. Feedback & diagnostics - Experience/DoNotShowFeedbackNotifications. Prevents devices from showing feedback questions from Microsoft. Set to 1 (one)
    21. Background apps - Privacy/LetAppsRunInBackground. Specifies whether Windows apps can run in the background. Set to 2 (two)
    22. Motion - Privacy/LetAppsAccessMotion. Specifies whether Windows apps can access motion data. Set to 2 (two)
    23. Tasks - Privacy/LetAppsAccessTasks. Turn off the ability to choose which apps have access to tasks. Set to 2 (two)
    24. App Diagnostics - Privacy/LetAppsGetDiagnosticInfo. Force allow, force deny or give user control of apps that can get diagnostic information about other running apps. Set to 2 (two)
  17. Software Protection Platform - Licensing/DisallowKMSClientOnlineAVSValidation. Opt out of sending KMS client activation data to Microsoft automatically. Set to 1 (one)

  18. Storage Health - Storage/AllowDiskHealthModelUpdates. Allows disk health model updates. Set to 0 (zero)

  19. Sync your settings - Experience/AllowSyncMySettings. Control whether your settings are synchronized. Set to 0 (zero)

  20. Teredo - No MDM needed. Teredo is Off by default. Delivery Optimization (DO) can turn on Teredo, but DO itself is turned Off via MDM.

  21. Wi-Fi Sense - No MDM needed. Wi-Fi Sense is no longer available from Windows 10 version 1803 and later or Windows 11.

  22. Windows Defender

    1. Defender/AllowCloudProtection. Disconnect from the Microsoft Antimalware Protection Service. Set to 0 (zero)
    2. Defender/SubmitSamplesConsent. Stop sending file samples back to Microsoft. Set to 2 (two)
    3. Defender/EnableSmartScreenInShell. Turns off SmartScreen in Windows for app and file execution. Set to 0 (zero)
    4. Windows Defender SmartScreen - Browser/AllowSmartScreen. Disable Windows Defender SmartScreen. Set to 0 (zero)
    5. Windows Defender SmartScreen EnableAppInstallControl - SmartScreen/EnableAppInstallControl. Controls whether users are allowed to install apps from places other than the Microsoft Store. Set to 0 (zero)
    6. Windows Defender Potentially Unwanted Applications(PUA) Protection - Defender/PUAProtection. Specifies the level of detection for potentially unwanted applications (PUAs). Set to 1 (one)
    7. Defender/SignatureUpdateFallbackOrder. Allows you to define the order in which different definition update sources should be contacted. The OMA-URI for this is: ./Vendor/MSFT/Policy/Config/Defender/SignatureUpdateFallbackOrder, Data type: String, Value: FileShares
  23. Windows Spotlight - Experience/AllowWindowsSpotlight. Disable Windows Spotlight. Set to 0 (zero)

  24. Microsoft Store

    1. ApplicationManagement/DisableStoreOriginatedApps. Boolean value that disables the launch of all apps from Microsoft Store that came pre-installed or were downloaded. Set to 1 (one)
    2. ApplicationManagement/AllowAppStoreAutoUpdate. Specifies whether automatic update of apps from Microsoft Store are allowed. Set to 0 (zero)
  25. Apps for websites - ApplicationDefaults/EnableAppUriHandlers. This policy setting determines whether Windows supports web-to-app linking with app URI handlers. Set to 0 (zero)

  26. Windows Update Delivery Optimization - The following Delivery Optimization MDM policies are available in the Policy CSP.

    1. DeliveryOptimization/DODownloadMode. Let’s you choose where Delivery Optimization gets or sends updates and apps. Set to 99 (ninety-nine)
  27. Windows Update

    1. Update/AllowAutoUpdate. Control automatic updates. Set to 5 (five)
    2. Windows Update Allow Update Service - Update/AllowUpdateService. Specifies whether the device could use Microsoft Update, Windows Server Update Services (WSUS), or Microsoft Store. Set to 0 (zero)
    3. Windows Update Service URL - Update/UpdateServiceUrl. Allows the device to check for updates from a WSUS server instead of Microsoft Update. Set to String with the Value:
      1. <Replace><CmdID>$CmdID$<Item><Meta><Format>chr<Type>text/plain</Meta><Target> <LocURI>./Vendor/MSFT/Policy/Config/Update/UpdateServiceUrl</Target><Data>http://abcd-srv:8530</Item></Replace>
  28. Recommendations
    a. HideRecentJumplists setting in the Start Policy configuration service provider (CSP). To hide a list of recommended apps and files in the Recommended section on the Start menu.

Allowed traffic for Microsoft Intune / MDM configurations

Allowed traffic endpoints
activation-v2.sls.microsoft.com/*
cdn.onenote.net
client.wns.windows.com
crl.microsoft.com/pki/crl/*
ctldl.windowsupdate.com
*displaycatalog.mp.microsoft.com
dm3p.wns.windows.com
*microsoft.com/pkiops/*
ocsp.digicert.com/*
r.manage.microsoft.com
tile-service.weather.microsoft.com
settings-win.data.microsoft.com
msedge.api.cdp.microsoft.com
*.dl.delivery.mp.microsoft.com
edge.microsoft.com