设置注册状态页Set up the Enrollment Status Page

注册状态页 (ESP) 显示注册新设备后以及新用户登录该设备时的预配过程。The Enrollment Status Page (ESP) displays provisioning progress after a new device is enrolled, as well as when new users sign into the device. 这使 IT 管理员能够选择性地阻止对设备的访问,直到设备完全预配,同时向用户提供有关预配过程中剩余任务的信息。This enables IT administrators to optionally prevent (block) access to the device until it has been fully provisioned, while at the same time giving users information about the tasks remaining in the provisioning process.

ESP 可以作为任何 Windows Autopilot 预配方案的一部分使用,也可以作为 Azure AD 联接的默认开箱即用体验 (OOBE) 的一部分与 Windows Autopilot 分开使用,对首次登录设备的任何新用户也适用。The ESP can be used as part of any Windows Autopilot provisioning scenario, and can also be used separately from Windows Autopilot as part of the default out-of-box experience (OOBE) for Azure AD Join, as well as for any new users signing into the device for the first time.

可以创建具有不同配置的多个注册状态页配置文件,以指定以下内容:You can create multiple Enrollment Status Page profiles with different configurations that specify:

  • 显示安装进度Showing installation progress
  • 阻止访问,直到完成预配过程Blocking access until the provisioning process is completed
  • 时间限制Time limits
  • 允许的故障排除操作Allowed troubleshooting operations

这些配置文件按优先级顺序指定;将使用适用的最高优先级。These profiles are specified in a priority order; the highest priority that is applicable will be used. 每个 ESP 配置文件都可以针对包含设备或用户的组。Each ESP profile can be targeted to groups containing devices or users. 确定要使用的配置文件时,请遵循以下标准:When determining which profile to use, the following criteria will be followed:

  • 将首先使用针对设备的最高优先级配置文件。The highest-priority profile targeted to the device will be used first.
  • 如果没有针对设备的配置文件,则将使用针对当前用户的最高优先级配置文件。If there are no profiles targeted to the device, the highest priority profile targeted to the current user will be used. (这仅适用于存在用户的情况。(This only applies in scenarios where there is a user. 在白手套和自部署情景中,只能使用设备目标。)In white glove and self-deploying scenarios, only device targeting can be used.)
  • 如果没有针对特定组的配置文件,则将使用默认 ESP 配置文件。If there are no profiles targeted to specific groups, then the default ESP profile will be used.

可用设置Available settings

可以配置以下设置,以自定义注册状态页的行为:The following settings can be configured to customize behavior of the Enrollment Status page:

设置SettingYesNo
显示应用和配置文件安装进度Show app and profile installation progress显示注册状态页。The enrollment status page is displayed.不显示注册状态页。The enrollment status page isn't displayed.
在安装所有应用和配置文件之前阻止设备使用Block device use until all apps and profiles are installed可以使用此表中的设置自定义注册状态页的行为,以便用户可以解决潜在的安装问题。The settings in this table are made available to customize behavior of the enrollment status page, so that the user can address potential installation issues. 显示注册状态页,其中不包含可解决安装故障的其他选项。The enrollment status page is displayed with no additional options to address installation failures.
出现安装错误时允许用户重置设备Allow users to reset device if installation error occurs出现安装故障时显示“重置设备”按钮。A Reset device button is displayed if there's an installation failure.出现安装故障时不显示“重置设备”按钮。The Reset device button isn't displayed if there's an installation failure.
出现安装错误时允许用户使用设备Allow users to use device if installation error occurs出现安装故障时显示“仍然继续”按钮。A Continue anyway button is displayed if there's an installation failure.出现安装故障时不显示“仍然继续”按钮。The Continue anyway button isn't displayed if there's an installation failure.
安装时间超出指定的分钟数时显示超时错误Show timeout error when installation takes longer than specified number of minutes指定等待安装完成所需的分钟数。Specify the number of minutes to wait for installation to complete. 将输入默认值 60 分钟。A default value of 60 minutes is entered.
出现错误时显示自定义消息Show custom message when an error occurs提供一个文本框,可以在其中指定出现安装错误时要显示的自定义消息。A text box is provided where you can specify a custom message to display if an installation error occurs.显示默认的消息:The default message is displayed:
安装超出组织设置的时间限制。Installation exceeded the time limit set by your organization. 请重试,也可联系你的 IT 支持人员以获取帮助。 Try again or contact your IT support person for help.
允许用户收集与安装错误有关的日志Allow users to collect logs about installation errors若出现安装错误,将显示“收集日志”按钮。If there's an installation error, a Collect logs button is displayed.
若用户单击此按钮,将要求他们选择一个位置,以用于保存日志文件“MDMDiagReport.cab”If the user clicks this button, they're asked to choose a location to save the log file MDMDiagReport.cab
出现安装错误时不显示“收集日志”按钮。The Collect logs button isn't displayed if there's an installation error.
如果这些所需应用已分配给用户/设备,则在安装这些应用之前阻止设备使用Block device use until these required apps are installed if they're assigned to the user/device选择“全部”或“已选择”。Choose All or Selected.

若选择了“已选择”,将显示“所选应用”按钮,以允许你选择启用设备前必须安装的应用。If Selected is chosen, a Select apps button appears that lets you choose which apps must be installed before enabling the device.

为所有用户启用默认注册状态页Turn on default Enrollment Status Page for all users

若要启用注册状态页,请执行以下步骤。To turn on the Enrollment Status Page, follow the steps below.

  1. Microsoft Endpoint Manager 管理中心中,选择“设备” > “Windows” > “Windows 注册” > “注册状态页” 。In the Microsoft Endpoint Manager admin center, choose Devices > Windows > Windows enrollment > Enrollment Status Page.
  2. 在“注册状态页”边栏选项卡中,选择“默认” > “设置” 。In the Enrollment Status Page blade, choose Default > Settings.
  3. 有关“显示应用和配置文件安装进度”,请选择“是” 。For Show app and profile installation progress, choose Yes.
  4. 选择要打开的其他设置,然后选择“保存”。Choose the other settings that you want to turn on and then choose Save.

创建注册状态页配置文件并将其分配到组Create Enrollment Status Page profile and assign to a group

  1. Microsoft Endpoint Manager 管理中心中,选择“设备” > “Windows” > “Windows 注册” > “注册状态页” > “创建配置文件” 。In the Microsoft Endpoint Manager admin center, choose Devices > Windows > Windows enrollment > Enrollment Status Page > Create profile.
  2. 提供名称和说明 。Provide a Name and Description.
  3. 选择“创建”。Choose Create.
  4. 在“注册状态页”列表中选择新配置文件。Choose the new profile in the Enrollment Status Page list.
  5. 选择“分配” > “选择组”> 选择要采用此配置文件的组 >“选择” > “保存” 。Choose Assignments > Select groups > choose the groups that you want to adopt this profile > Select > Save.
  6. 选择“设置”> 选择要应用于此配置文件的设置 >“保存” 。Choose Settings > choose the settings you want to apply to this profile > Save.

设置注册状态页的优先级Set the enrollment status page priority

设备或用户可以处于多个组中,并且具有多个注册状态页配置文件作为目标。A device or user can be in many groups and have multiple Enrollment Status Page profiles targeted. 若要控制首先考虑哪些配置文件,可以为每个配置文件设置优先级;优先级较高的配置文件将首先考虑。To control which profiles are considered first, you can set the priorities for each profile; those with higher priorities are considered first.

  1. Microsoft Endpoint Manager 管理中心中,选择“设备” > “Windows” > “Windows 注册” > “注册状态页” 。In the Microsoft Endpoint Manager admin center, choose Devices > Windows > Windows enrollment > Enrollment Status Page.
  2. 将鼠标悬停在列表中的配置文件上。Hover over the profile in the list.
  3. 使用三个垂直点,将该配置文件拖到列表中的所需位置。Using the three vertical dots, drag the profile to the desired position on the list.

在安装特定应用程序之前阻止访问设备Block access to a device until a specific application is installed

你可以指定在注册状态页 (ESP) 完成之前必须安装的应用。You can specify which apps must be installed before the Enrollment Status Page (ESP) completes.

  1. Microsoft Endpoint Manager 管理中心中,选择“设备” > “Windows” > “Windows 注册” > “注册状态页” 。In the Microsoft Endpoint Manager admin center, choose Devices > Windows > Windows enrollment > Enrollment Status Page.
  2. 选择配置文件 >“设置”。Choose a profile > Settings.
  3. 有关“显示应用和配置文件安装进度”,请选择“是” 。Choose Yes for Show app and profile installation progress.
  4. 有关“在安装所有应用和配置文件之前阻止设备使用”,请选择“是” 。Choose Yes for Block device use until all apps and profiles are installed.
  5. 有关“如果这些所需应用已分配给用户/设备,则在安装这些应用之前阻止设备使用”,请选择“已选择” 。Choose Selected for Block device use until these required apps are installed if they're assigned to the user/device.
  6. 选择“选择应用”> 选择应用 >“选择” > “保存”。Choose Select apps > choose the apps > Select > Save.

Intune 使用此列表中包含的应用来筛选应被视为要阻止的列表。The apps that are included in this list are used by Intune to filter the list that should be considered blocking. 它并未指定应安装的应用。It does not specify what apps should be installed. 例如,如果将此列表配置为包含“应用 1”、“应用 2”和“应用 3”,并且“应用 3”和“应用 4”定向于设备或用户,则注册状态页将仅跟踪“应用 3”。For example, if you configure this list to include "App 1," "App 2," and "App 3" and "App 3" and "App 4" are targeted to the device or user, the Enrollment Status Page will track only "App 3." 仍将安装“应用 4”,但注册状态页不会等待它完成。"App 4" will still be installed, but the Enrollment Status Page will not wait for it to complete.

最多可指定 100 个应用。A maximum of 100 apps can be specified.

注册状态页跟踪信息Enrollment Status Page tracking information

注册状态页跟踪以下三个阶段的信息:设备准备、设备设置和帐户设置。There are three phases where the Enrollment Status Page tracks information for; device preparation, device setup, and account setup.

设备准备Device preparation

对于设备准备,注册状态页跟踪以下内容:For device preparation, the enrollment status page tracks:

  • 受信任的平台模块 (TPM) 密钥证明(适用时)Trusted Platform Module (TPM) key attestation (when applicable)
  • Azure Active Directory 联接过程Azure Active Directory join process
  • Intune (MDM) 注册Intune (MDM) enrollment
  • 安装 Intune 管理扩展(用于安装 Win32 应用)Installation of the Intune Management Extensions (used to install Win32 apps)

设备设置Device setup

注册状态页跟踪以下设备设置项目:The Enrollment Status Page tracks the following device setup items:

  • 安全策略Security policies
    • 目前跟踪 Microsoft Edge、分配的访问权限和展台浏览器策略。Microsoft Edge, Assigned Access, and Kiosk Browser policies are presently tracked.
    • 不会跟踪其他策略。Other policies are not tracked.
  • 应用程序Applications
    • 每台计算机业务线 (LoB) MSI 应用。Per machine Line-of-business (LoB) MSI apps.
    • LoB 应用商店应用(安装上下文为设备)。LoB store apps with installation context = Device.
    • 离线应用商店和 LoB 应用商店应用(安装上下文为设备)。Offline store and LoB store apps with installation context = Device.
    • Win32 应用程序(仅 Windows 10 版本 1903 及更高版本)Win32 applications (Windows 10 version 1903 and newer only)
  • 连接性配置文件Connectivity profiles
    • 为“所有设备”或注册设备是成员的设备组分配 VPN 或 Wi-Fi 配置文件,但仅适用于 Autopilot 设备VPN or Wi-Fi profiles that are assigned to All Devices or a device group in which the enrolling device is a member, but only for Autopilot devices
  • 为“所有设备”或注册设备是成员的设备组分配证书配置文件,但仅适用于 Autopilot 设备Certificate profiles that are assigned to All Devices or a device group in which the enrolling device is a member, but only for Autopilot devices

帐户设置Account setup

对于帐户设置,注册状态页将跟踪以下各项(如果已将它们分配给当前登录的用户):For account setup, the Enrollment Status Page tracks the following items if they're assigned to the current logged in user:

  • 安全策略Security policies
    • 目前跟踪 Microsoft Edge、分配的访问权限和展台浏览器策略。Microsoft Edge, Assigned Access, and Kiosk Browser policies are presently tracked.
    • 不会跟踪其他策略。Other policies are not tracked.
  • 应用程序Applications
    • 为所有设备、所有用户或注册设备的用户所属的用户组分配的每个用户 LoB MSI 应用。Per user LoB MSI apps that are assigned to All Devices, All Users, or a user group in which the user enrolling the device is a member.
    • 为所有用户或注册设备的用户所属的用户组分配的每台计算机 LoB MSI 应用。Per machine LoB MSI apps that are assigned to All Users or a user group in which the user enrolling device is a member.
    • 分配到以下任一对象的 LoB 商店应用、在线商店应用和离线商店应用:LoB store apps, online store apps, and offline store apps that are assigned to any of the following objects:
      • 所有设备All Devices
      • 所有用户All Users
      • 用户组,其中注册设备的用户是安装上下文设置为 User 的成员。A user group in which the user enrolling the device is a member with installation context set to User.
    • Win32 应用程序(仅 Windows 10 版本 1903 及更高版本)Win32 applications (Windows 10 version 1903 and newer only)
  • 连接性配置文件Connectivity profiles
    • 为所有用户或注册设备的用户所属的用户组分配的 VPN 或 Wi-Fi 配置文件。VPN or Wi-Fi profiles that are assigned to All Users or a user group in which the user enrolling the device is a member.
  • 证书Certificates
    • 为所有用户或注册设备的用户所属的用户组分配的证书配置文件。Certificate profiles that are assigned to All Users or a user group in which the user enrolling the device is a member.

已知问题Known issues

以下是与“注册状态页”相关的已知问题。The following are known issues related to the Enrollment Status Page.

  • 禁用 ESP 配置文件无法从设备删除 ESP 策略,用户首次登录到设备时仍然获得 ESP。Disabling the ESP profile doesn't remove ESP policy from devices and users still get ESP when they log in to device for first time. 禁用 ESP 配置文件后未删除策略。The policy isn't removed when the ESP profile is disabled.

  • 设备设置期间重启将强制用户输入凭据才能过渡到帐户设置阶段。A reboot during Device setup will force the user to enter their credentials before transitioning to Account setup phase. 重启时不会保留用户凭据。User credentials aren't preserved during reboot. 用户输入凭据后,注册状态页可继续使用。Have the user enter their credentials then the Enrollment Status Page can continue.

  • 在 1903 之前的 Windows 10 版本上,执行添加工作和学校帐户注册时,注册状态页经常超时。Enrollment Status Page will always time out during an Add work and school account enrollment on Windows 10 versions less than 1903. 注册状态页将等待 Azure AD 注册完成。The Enrollment Status Page waits for Azure AD registration to complete. 已在 Windows 10 版本 1903 及更高版本中修复此问题。The issue is fixed in Windows 10 version 1903 and newer.

  • 使用 ESP 执行混合 Azure AD Autopilot 部署所需的时间超出在 ESP 配置文件中输入的超时持续时间。Hybrid Azure AD Autopilot deployment with ESP takes longer than the timeout duration entered in the ESP profile. 在混合 Azure AD Autopilot 部署中,ESP 所需的时间比 ESP 配置文件设置的值超出 40 分钟。On Hybrid Azure AD Autopilot deployments, the ESP will take 40 minutes longer than the value set in the ESP profile. 例如,在配置文件中将超时持续时间设置为 30 分钟。For example, you set the timeout duration to 30 minutes in the profile. ESP 可能需要 30 分钟 + 40 分钟。The ESP can take 30 minutes + 40 minutes.

    此延迟为本地 AD 连接器创建 Azure AD 的新设备记录提供了时间。This delay gives time for the on-prem AD connector to create the new device record to Azure AD.

  • 在 Autopilot 用户驱动模式下,Windows 登录页未预填充用户名。Windows logon page isn't pre-populated with the username in Autopilot User Driven Mode. 如果在 ESP 的设备设置阶段出现重启:If there's a reboot during the Device Setup phase of ESP:

    • 不会保留用户凭据the user credentials aren't preserved
    • 用户必须先重新输入凭据,然后才可由设备设置阶段继续转到帐户设置阶段the user must enter the credentials again before proceeding from Device Setup phase to the Account setup phase
  • ESP 长时间停滞,或始终未完成“正在识别”阶段。ESP is stuck for a long time or never completes the "Identifying" phase. 在识别阶段期间,Intune 将计算 ESP 策略。Intune computes the ESP policies during the identifying phase. 若当前用户未分配 Intune 许可证,设备可能始终无法完成计算 ESP 策略。A device may never complete computing ESP policies if the current user doesn't have an Intune licensed assigned.

  • 配置 Microsoft Defender 应用程序控制会导致在 Autopilot 期间提示重启。Configuring Microsoft Defender Application Control causes a prompt to reboot during Autopilot. 配置 Microsoft Defender 应用程序 (AppLocker CSP) 需要重启。Configuring Microsoft Defender Application (AppLocker CSP) requires a reboot. 配置此策略后,可能会导致设备在 Autopilot 期间重启。When this policy is configured, it may cause a device to reboot during Autopilot. 目前无法取消或推迟此重启。Currently, there's no way to suppress or postpone the reboot.

  • 启用 DeviceLock 策略 (https://docs.microsoft.com/windows/client-management/mdm/policy-csp-devicelock) 做为 ESP 配置文件一部分时,OOBE 或用户桌面自动登录可能会出于两个原因而意外失败。When the DeviceLock policy (https://docs.microsoft.com/windows/client-management/mdm/policy-csp-devicelock) is enabled as part of an ESP profile, the OOBE or user desktop autologon could fail unexpectantly for two reasons.

    • 若设备在退出 ESP 设备设置阶段前未重启,可能会提示用户输入 Azure AD 凭据。If the device didn't reboot before exiting the ESP Device setup phase, the user may be prompted to enter their Azure AD credentials. 此提示将出现,而不会出现自动登录成功提示(成功时用户将看到 Windows 首次登录动画)。This prompt occurs instead of a successful autologon where the user sees the Windows first login animation.
    • 若设备在用户输入 Azure AD 凭据后和退出 ESP 设备设置阶段前重启,自动登录将失败。The autologon will fail if the device rebooted after the user entered their Azure AD credentials but before exiting the ESP Device setup phase. 因为 ESP 设备设置阶段始终未完成,因此会出现此故障。This failure occurs because the ESP Device setup phase never completed. 解决方法为重置设置。The workaround is to reset the device.

后续步骤Next steps

设置 Windows 注册页后,了解如何管理 Windows 设备After you set up Windows enrollment pages, learn how to manage Windows devices.

Windows 注册状态疑难解答页Troubleshoot the Windows Enrollment Status page