25.07.2017 Views

MICROSOFT_PRESS_EBOOK_INTRODUCING_WINDOWS_10

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

FIGURE 15-1 Use Group Policy to enable the Windows Update for Business features, which you can use to delay the<br />

installation of updates and full upgrades.<br />

Note that these settings don’t apply if you deliver updates using a tool other than the public Windows<br />

Update servers, such as a Windows Server Update Services (WSUS) server on your network. In<br />

addition, if the Allow Telemetry policy is enabled and set to 0 on a PC running Windows <strong>10</strong> Enterprise,<br />

Windows Update is effectively disabled and the Windows Update for Business settings have no effect.<br />

Device Guard<br />

Device Guard, another new feature available only in Windows <strong>10</strong> Enterprise, offers IT pros the capability<br />

to lock down a device so that it runs only applications from an approved list. Credential Guard, a related<br />

enterprise-security feature, uses hardware virtualization to secure credentials.<br />

Deploying Device Guard, with or without Credential Guard, is a complex process that involves enabling<br />

hardware-security features, creating a code-integrity policy, and then applying that policy to individual<br />

devices. Two Group Policy settings represent a small but critical part of this deployment process. These<br />

settings, shown in Figures 15-2 and 15-3, are located under Computer Configuration > Administrative<br />

Templates > System > Device Guard.<br />

178 CHAPTER 15 What’s new in Group Policy in Windows <strong>10</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!