使用 Windows 10 模板在 Microsoft Intune 中配置组策略设置Use Windows 10 templates to configure group policy settings in Microsoft Intune

管理组织中的设备时,你希望创建几组应用于不同设备组的设置。When managing devices in your organization, you want to create groups of settings that apply to different device groups. 例如,你有多个设备组。For example, you have several device groups. 对于 GroupA,要分配一组特定设置。For GroupA, you want to assign a specific set of settings. 对于 GroupB,要分配另一组设置。For GroupB, you want to assign a different set of settings. 此外,还需要可配置设置的简单视图。You also want a simple view of the settings you can configure.

可以使用 Microsoft Intune 中的“管理模板”完成此任务。You can complete this task using Administrative Templates in Microsoft Intune. 管理模板包括数千个设置,这些设置可控制 Microsoft Edge 77 及更高版本、Internet Explorer、Microsoft Office 程序、远程桌面、OneDrive 中的功能,以及密码和 PIN 等等。The administrative templates include thousands of settings that control features in Microsoft Edge version 77 and later, Internet Explorer, Microsoft Office programs, remote desktop, OneDrive, passwords, PINs, and more. 这些设置允许组管理员使用云来管理组策略。These settings allow group administrators to manage group policies using the cloud.

此功能适用于:This feature applies to:

  • Windows 10 及更高版本Windows 10 and newer

Windows 设置类似于 Active Directory (AD) 中的组策略 (GPO) 设置。The Windows settings are similar to group policy (GPO) settings in Active Directory (AD). 这些设置内置于 Windows 中,是使用 XML 的支持 ADMX 的设置These settings are built in to Windows, and are ADMX-backed settings that use XML. Office 和 Microsoft Edge 设置为 ADMX 引入的设置,并使用 Office 管理模板文件Microsoft Edge 管理模板文件中的 ADMX 设置。The Office and Microsoft Edge settings are ADMX-ingested, and use the ADMX settings in Office administrative template files and Microsoft Edge administrative template files. Intune 模板 100% 基于云。And, the Intune templates are 100% cloud-based. 它们提供简单和直接的方法来配置设置,并可查找所需设置。They offer a simple and straight-forward way to configure the settings, and find the settings you want.

“管理模板”内置于 Intune 中,不需要任何自定义(包括使用 OMA-URI)。Administrative Templates are built in to Intune, and don't require any customizations, including using OMA-URI. 作为移动设备管理 (MDM) 解决方案的一部分,请将这些模板设置用作一站式服务,以管理 Windows 10 设备。As part of your mobile device management (MDM) solution, use these template settings as a one-stop shop to manage your Windows 10 devices.

本文列出为 Windows 10 设备创建模板的步骤,并演示如何筛选 Intune 中的所有可用设置。This article lists the steps to create a template for Windows 10 devices, and shows how to filter all the available settings in Intune. 创建模板时,模板会创建设备配置配置文件。When you create the template, it creates a device configuration profile. 然后,可以将此配置文件分配或部署到贵组织中的 Windows 10 设备。You can then assign or deploy this profile to Windows 10 devices in your organization.

在开始之前Before you begin

  • 其中一些设置从 Windows 10 版本 1709(RS2/内部版本 15063)开始提供。Some of these settings are available starting with Windows 10 version 1709 (RS2/build 15063). 所有 Windows 版本中均不包含某些设置。Some settings aren't included in all the Windows editions. 为获得最佳体验,建议使用 Windows 10 企业版 1903(19H1/内部版本 18362)及更高版本。For the best experience, it's suggested to use Windows 10 Enterprise version 1903 (19H1/build 18362) and newer.

  • Windows 设置使用 Windows 策略 CSPThe Windows settings use Windows policy CSPs. CSP 适用于不同版本的 Windows,例如家庭版、专业版和企业版等。The CSPs work on different editions of Windows, such as Home, Professional, Enterprise, and so on. 要查看 CSP 是否适用于特定版本,请转到 Windows 策略 CSPTo see if a CSP works on a specific edition, go to Windows policy CSPs.

创建模板Create the template

  1. 登录到 Microsoft 终结点管理器管理中心Sign in to the Microsoft Endpoint Manager admin center.

  2. 选择“设备” > “配置文件” > “创建配置文件”。Select Devices > Configuration profiles > Create profile.

  3. 输入以下属性:Enter the following properties:

    • 平台:选择“Windows 10 及更高版本”。Platform: Select Windows 10 and later.
    • 配置文件:选择“管理模板”。Profile: Select Administrative Templates.
  4. 选择“创建”。Select Create.

  5. 在“基本信息”中,输入以下属性:In Basics, enter the following properties:

    • 名称:输入配置文件的描述性名称。Name: Enter a descriptive name for the profile. 为配置文件命名,以便稍后可以轻松地识别它们。Name your profiles so you can easily identify them later. 例如,配置文件名称最好是“管理模板:用于在 Microsoft Edge 中配置 xyz 设置的 Windows 10 管理模板”。For example, a good profile name is Admin template: Windows 10 admin template that configures xyz settings in Microsoft Edge.
    • 描述:输入配置文件的说明。Description: Enter a description for the profile. 此设置是可选的,但建议进行。This setting is optional, but recommended.
  6. 选择“下一步”。Select Next.

  7. 在“配置设置”中,选择“所有设置”,查看所有设置按字母顺序排序的列表 。In Configuration settings, select All settings to see an alphabetical list of all the settings. 或者,配置适用于设备的设置(“计算机配置”)和适用于用户的设置(“用户配置”) :Or, configure settings that apply to devices (Computer configuration), and settings that apply to users (User configuration):

    将 ADMX 模板设置应用于 Microsoft Intune 终结点管理器中的用户和设备Apply ADMX template settings to users and devices in Microsoft Intune Endpoint Manager

  8. 选择“所有设置”时,将列出所有设置。When you select All settings, every setting is listed. 向下滚动以使用上一个和下一个箭头查看更多设置:Scroll down to use the before and next arrows to see more settings:

    请查看设置的示例列表,并使用“上一页”和“下一页”按钮See a sample list of settings and use previous and next buttons

  9. 选择任意设置。Select any setting. 例如,在 Office 上筛选,然后选择“激活受限浏览”。For example, filter on Office, and select Activate Restricted Browsing. 列出设置的详细描述。A detailed description of the setting is shown. 选择“启用”、“禁用”或将设置保留为“未配置”(默认)。Choose Enabled, Disabled, or leave the setting as Not configured (default). 详细说明还会介绍选择“启用”、“禁用”或“未配置”时发生的情况。The detailed description also explains what happens when you choose Enabled, Disabled, or Not configured.

    提示

    Intune 中的 Windows 设置与你在本地组策略编辑器 (gpedit) 中看到的本地组策略路径相关The Windows settings in Intune correlate to the on-premises group policy path you see in Local Group Policy Editor (gpedit)

  10. 选择“计算机配置”或“用户配置”时,将显示设置类别 。When you select Computer configuration or User configuration, the setting categories are shown. 可以选择任何类别查看可用的设置。You can select any category to see the available settings.

    例如,依次选择“计算机配置” > “Windows 组件” > “Internet Explorer”即可查看适用于 Internet Explorer 的所有设备设置:For example, select Computer configuration > Windows components > Internet Explorer to see all the device settings that apply to Internet Explorer:

    在 Microsoft Intune 终结点管理器中查看适用于 Internet Explorer 的所有设备设置See all device settings that apply to Internet Explorer in Microsoft Intune Endpoint Manager

  11. 选择“确定”,保存所做更改。Select OK to save your changes.

    继续浏览设置列表,并在环境中配置所需设置。Continue to go through the list of settings, and configure the settings you want in your environment. 下面是一些示例:Here are some examples:

    • 使用“VBA 宏通知设置”设置,在不同的 Microsoft Office 程序(包括 Word 和 Excel)中处理 VBA 宏。Use the VBA Macro Notification Settings setting to handle VBA macros in different Microsoft Office programs, including Word and Excel.
    • 使用“允许文件下载”设置,允许或阻止从 Internet Explorer 下载。Use the Allow file downloads setting to allow or prevent downloads from Internet Explorer.
    • 使用“唤醒计算机时需要密码(接通电源)”,在从睡眠模式唤醒设备时提示用户输入密码。Use Require a password when a computer wakes (plugged in) to prompt users for a password when devices wake from sleep mode.
    • 使用“下载未签名的 ActiveX 控件”设置,阻止用户从 Internet Explorer 下载未签名的 ActiveX 控件。Use the Download unsigned ActiveX controls setting to block users from downloading unsigned ActiveX controls from Internet Explorer.
    • 使用“关闭系统还原”设置,许可或阻止用户在设备上运行系统还原。Use the Turn off System Restore setting to allow or prevent users from running a system restore on the device.
    • 使用“允许导入收藏夹”设置,允许或阻止用户将另一个浏览器中的收藏夹导入 Microsoft Edge。Use the Allow importing of favorites setting to allow or block users from importing favorites from another browser into Microsoft Edge.
    • 还有更多...And much more...
  12. 选择“下一步”。Select Next.

  13. 在“作用域标记”(可选)中,分配一个标记以将配置文件筛选到特定 IT 组(如 US-NC IT TeamJohnGlenn_ITDepartment)。In Scope tags (optional), assign a tag to filter the profile to specific IT groups, such as US-NC IT Team or JohnGlenn_ITDepartment. 有关范围标记的详细信息,请参阅将 RBAC 和范围标记用于分布式 ITFor more information about scope tags, see Use RBAC and scope tags for distributed IT.

    选择“下一步”。Select Next.

  14. 在“分配”中,选择将接收配置文件的用户或组。In Assignments, select the user or groups that will receive your profile. 有关分配配置文件的详细信息,请参阅分配用户和设备配置文件For more information on assigning profiles, see Assign user and device profiles.

    如果将配置文件分配给用户组,则配置的 ADMX 设置将应用于用户注册和登录的任何设备。If the profile is assigned to user groups, then configured ADMX settings apply to any device that the user enrolls, and signs in to. 如果将配置文件分配给设备组,则配置的 ADMX 设置将应用于登录该设备的任何用户。If the profile is assigned to device groups, then configured ADMX settings apply to any user that signs into that device. 如果 ADMX 设置是计算机配置 (HKEY_LOCAL_MACHINE) 或用户配置 (HKEY_CURRENT_USER),则会发生此分配。This assignment happens if the ADMX setting is a computer configuration (HKEY_LOCAL_MACHINE), or a user configuration (HKEY_CURRENT_USER). 对于某些设置,分配给用户的计算机设置还可能会影响该设备上其他用户的体验。With some settings, a computer setting assigned to a user may also impact the experience of other users on that device.

    有关详细信息,请参阅用户组与设备组For more information, see User groups vs. device groups.

    选择“下一步”。Select Next.

  15. 在“查看并创建”中查看设置。In Review + create, review your settings. 选择“创建”时,将保存所做的更改并分配配置文件。When you select Create, your changes are saved, and the profile is assigned. 该策略也会显示在配置文件列表中。The policy is also shown in the profiles list.

下次设备检查配置更新时,将应用你配置的设置。The next time the device checks for configuration updates, the settings you configured are applied.

查找某些设置Find some settings

这些模板提供数千个设置。There are thousands of settings available in these templates. 为了更容易查找特定设置,请使用内置功能:To make it easier to find specific settings, use the built-in features:

  • 在模板中,选择“设置”、“状态”、“设置类型”或“路径”列,对列表进行排序。In your template, select the Settings, State, Setting type, or Path columns to sort the list. 例如,选择“路径”列,然后使用下一个箭头查看 Microsoft Excel 路径中的设置。For example, select the Path column, and use the next arrow to see the settings in the Microsoft Excel path.

  • 在模板中,请使用“搜索”框查找特定设置。In your template, use the Search box to find specific settings. 可以通过设置或路径进行搜索。You can search by setting, or path. 例如,选择“所有设置”,然后搜索 copyFor example, select All settings, and search for copy. 具有 copy 的所有设置均会显示:All the settings with copy are shown:

    搜索 copy 以显示 Intune 管理模板中的所有设备设置Search for copy to show all the device settings in administrative templates in Intune

    在另一个示例中,搜索 microsoft wordIn another example, search for microsoft word. 随即便可看到可以为 Microsoft Word 程序设置的设置。You see the settings you can set for the Microsoft Word program. 搜索 explorer 查看可以添加到模板的 Internet Explorer 设置。Search for explorer to see the Internet Explorer settings you can add to your template.

  • 还可以通过仅选择“计算机配置”或“用户配置”来缩小搜索范围 。You can also narrow your search by only selecting Computer configuration or User configuration.

    例如,要查看所有可用的 Internet Explorer 用户设置,请选择“用户配置”,然后搜索 Internet ExplorerFor example, to see all the available Internet Explorer user settings, select User configuration, and search for Internet Explorer. 仅显示适用于用户的 IE 设置:Only the IE settings that apply to users are shown:

    在 ADMX 模板中,选择“用户配置”,然后在 Microsoft Intune 中搜索或筛选 Internet Explorer。

后续步骤Next steps

模板已创建,但它尚未起到任何作用。The template is created, but may not be doing anything yet. 接下来,分配模板(也称为配置文件)监视其状态Next, assign the template (also called a profile) and monitor its status.

使用管理模板更新 Microsoft 365Update Microsoft 365 using administrative templates.

教程:通过云使用 ADMX 模板和 Microsoft Intune 为 Windows 10 设备配置组策略Tutorial: Use the cloud to configure group policy on Windows 10 devices with ADMX templates and Microsoft Intune