{ "AndroidForWorkAppPermissions": { "Action": { "autoDeny": "Auto deny", "autoGrant": "Auto grant", "prompt": "Prompt" }, "addButtonLabel": "+Add", "addPermissionsTitle": "Add permissions", "addPermissionTableDescription": "Specify permissions you want to override. If they are not chosen/specified explicitly, then the default behavior will apply.", "learnMoreLink": "https://go.microsoft.com/fwlink/?linkid=850320", "learnMoreText": "Learn more about Android runtime permissions", "Permissions": { "accessBackgroundLocation": "Location access (background)", "accessCoarseLocation": "Location access (coarse)", "accessFineLocation": "Location access (fine)", "addVoicemail": "Add voicemail", "bluetoothConnect": "Bluetooth connect", "bodySensors": "Allow body sensor data", "bodySensorsBackground": "Allow background body sensor data", "callPhone": "Make phone calls", "camera": "Camera", "getAccounts": "Get accounts", "nearbyDevices": "Nearby Devices", "nearbyWifiDevices": "Nearby Wifi Devices", "postNotifications": "Post notifications", "processOutgoingCalls": "Process outgoing calls", "readCalendar": "Calendar (read)", "readCallLog": "Call log (read)", "readContacts": "Contacts (read)", "readExternalStorage": "External storage (read)", "readMediaAudio": "Media Audio (read)", "readMediaImages": "Media Images (read)", "readMediaVideo": "Media Video (read)", "readPhoneState": "Phone state (read)", "readSMS": "SMS (read)", "receiveMMS": "MMS (receive)", "receiveSMS": "SMS (receive)", "receiveWAPPush": "WAP push messages (receive)", "recordAudio": "Record audio", "sendSMS": "SMS (send)", "useSIP": "Use SIP service", "writeCalendar": "Calendar (write)", "writeCallLog": "Call log (write)", "writeContacts": "Contacts (write)", "writeExternalStorage": "External storage (write)" }, "permissionsTitle": "Permissions", "permissionTableDescription": "Permissions granted here will override the “Default app permissions” policy for the selected apps.", "RemoveDialog": { "description": "Are you sure you want to remove the permission?", "title": "Remove" }, "TableHeader": { "permission": "Permission", "permissionGroup": "Permission group", "permissionName": "Permission name", "permissionState": "Permission state" } }, "AppCategories": { "microsoftDefenderATP": "Microsoft Defender for Endpoint", "microsoftEdge": "Microsoft Edge, version 77 and later", "office365Suite": "Microsoft 365 Apps", "other": "Other", "storeApp": "Store app", "webApplication": "Web Application" }, "AppGroupType": { "allApps": "All Apps", "allMicrosoftApps": "All Microsoft Apps", "coreMicrosoftApps": "Core Microsoft Apps", "selectedPublicApps": "Selected apps" }, "AppInfoBalloonText": { "appInstallContext": "This specifies the install context to be associated with this app. For dual mode apps, select the desired context for this app. For all other apps, this is pre-selected based on the package and cannot be modified.", "autoUpdateMode": "Configure the update priority for the app. Select Default to require the device to be connected to WiFi, to be charging, and not to be actively in use before updating the app. Select High Priority to update the app as soon as the developer has published the app, regardless of charge status, WiFi capability, or end user activity on the device. Select Postponed to forgo app updates for up to 90 days. High priority and postponed will only take effect on DO devices.", "Certificate": { "customSubjectName": "CN={{UserName}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US\nor\nCN={{AAD_Device_ID}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US", "keySize": "Select the number of bits contained in the key.", "keyUsage": "Specify the cryptographic action that is required to exchange the certificate’s public key.", "renewalThreshold": "Enter the percentage (between 1 and 99 percent) of remaining certificate lifetime that is allowed before a device can request renewal of the certificate. The recommended amount in Intune is 20%. (1-99)", "rootCert": "Choose a previously configured and assigned root CA certificate profile. The CA certificate must match the root certificate of the CA that is issuing the certificate for this profile (the one you are currently configuring).", "scepServerUrl": "Enter a URL for the NDES Server that issues certificates through SCEP (Must be HTTPS). e.g. https://contoso.com/certsrv/mscep/mscep.dll", "scepServerUrls": "Add one or more URLs for the NDES Server that issues certificates through SCEP (Must be HTTPS). e.g. https://contoso.com/certsrv/mscep/mscep.dll", "subjectAlternativeName": "Subject alternative name", "subjectNameFormat": "Subject name format", "validityPeriod": "The amount of time remaining before the certificate expires. Enter a value that is equal to or lower than the validity period shown in the certificate template. Default is set at one year." }, "configurationSettingsFormat": "Configuration settings format text", "ignoreVersionDetection": "Set this to “Yes” for apps that are automatically updated by the app developer (such as Google Chrome).", "ignoreVersionDetectionMacOSLobApp": "Select \"Yes\" for apps that are automatically updated by app developer or to only check for app bundleID before installation. Select \"No\" to check for app bundleID and version number before installation.", "installAsManagedMacOSLobApp": "This setting only applies to macOS 11 and higher. The app will be installed but not managed on macOS 10.15 and lower.", "installContextDropdown": "Select the appropriate install context. User context will install the app only for the targeted user while device context will install the app for all users on the device.", "ldapUrl": "This is the LDAP hostname where clients can get the public encryption keys for email recipients. Emails will be encrypted when a key is available. Supported formats:
To deploy this profile to a device, you must assign the device a Resource account. Select one device at a time to assign an existing Resource account or to create a new one. Learn more about Resource Accounts
", "assignedDevicesResourceAccountStatusBarMessage": "This table only lists the Surface Hub 2 devices that have been assigned this profile.", "assignFailedDescription": "Failed to update assignments for {0}.", "assignFailedTitle": "Failed to update Autopilot profile assignments.", "assigningDescription": "Updating assignments for {0}.", "assigningTitle": "Updating Autopilot profile assignments.", "AssignResourceAccount": { "createNewCommandMenu": "Create new", "createNewResourceAccountInfo": "\nCreate a new resource account during enrollment. The Resource account will be added to the Resource account table right away, but won't be active until the device is enrolled, and the Surface Hub subscription is verified. Learn more about Resource Accounts
\n ", "createNewResourceTitle": "Create new resource account", "deviceNameInvalid": "Device name is in an invalid format", "deviceNameRequired": "A device name is required", "editResourceAccountLabel": "Edit", "selectExistingCommandMenu": "Select existing" }, "assignSuccessDescription": "Successfully updated assignments for {0}.", "assignSuccessTitle": "Successfully updated Autopilot profile assignments.", "assignSufaceHub2ProfileNextStep": "Next steps for this deployment", "assignSurfaceHub2ProfileToDeviceGroup": "1. Assign this profile to at least one device group", "assignSurfaceHub2ProfileToResourceAccount": "2. Assign a resource account to each Surface Hub device to which you deploy this profile", "autoremediationContext": "We've detected a hardware change on this device. We're trying to automatically register the new hardware. You don't need to do anything now; the status will be updated at the next check in with the result. Learn more about resetting the profile.", "autoremediationTitle": "Device {0} has a fix pending", "cannotDeleteMessage": "This profile is assigned to groups. You must unassign all groups from this profile before you can delete it.", "cannotDeleteTitle": "Cannot delete {0}", "createdDateTime": "Created", "deleteMessage": "If you delete this Autopilot profile, any devices assigned to this profile will display Unassigned.", "deleteMessageWithPolicySet": "{0} is included in one or more policy sets. If you delete {0}, you'll no longer be able to assign it via these policy sets.", "deleteTitle": "Are you sure you want to delete this profile?", "description": "Description", "Device": { "ComputerName": { "validFormat": "Names must be 15 characters or less, and can contain letters (a-z, A-Z), numbers (0-9), and hyphens. Names must not contain only numbers. Names cannot include a blank space." }, "Header": { "addressableUserName": "User friendly name", "azureADDevice": "Associated Microsoft Entra device", "batch": "Group tag", "dateAssigned": "Date assigned", "deviceAccountPwd": "Device account password", "deviceAccountUpn": "Device account", "deviceDisplayName": "Device name", "deviceFriendlyName": "Device friendly name", "deviceName": "Device name", "deviceUseType": "Device-use type", "enrollmentState": "Enrollment state", "intuneDevice": "Associated Intune device", "lastContacted": "Last contacted", "make": "Manufacturer", "model": "Model", "profile": "Assigned profile", "profileStatus": "Profile status", "purchaseOrderId": "Purchase order", "resourceAccount": "Resource account", "serialNumber": "Serial number", "userPrincipalName": "User" }, "SurfaceHub": { "friendlyNameRequired": "A friendly name is required", "pwdRequired": "A password is required", "pwdValidFormat": "Unable to update the password. The value provided for the new password does not meet the lenght or complexity requirements of the domain.", "upnRequired": "A device account is required", "upnValidFormat": "Values can contain letters (a-z, A-Z), numbers (0-9), and hyphens. Values cannot include a blank space." } }, "Devices": { "featureDescription": "Windows Autopilot lets you customize the out-of-box experience (OOBE) for your users.", "importErrorStatus": "Some devices were not imported. Click here for more information.", "importPendingStatus": "Import in progress. Elapsed time: {0} min. This process can take up to {1} min." }, "deviceType": "Device type", "deviceUse": "Device use", "DeviceUseType": { "meetingAndPresentation": "Meeting and presentation", "teamCollaboration": "Team collaboration" }, "DirectoryService": { "activeDirectoryAD": "Microsoft Entra hybrid joined", "activeDirectoryADLabel": "Microsoft Entra hybrid join with Autopilot", "azureAD": "Microsoft Entra joined", "unknownType": "Unknown Type" }, "directoryServiceHintForSurfaceHub2": "\n Autopilot only supports Microsoft Entra Joined for Surface Hub 2 devices. Specify how devices join Active Directory (AD) in your organization.\n
\n\n Specify how devices join Active Directory (AD) in your organization:\n
\n\nConfigure the out-of-box experience for your Autopilot devices\n
", "ConfigureComputerNameTemplate": { "description": "Create a unique name for your devices. Names must be 15 characters or less, and can contain letters (a-z, A-Z), numbers (0-9), and hyphens. Names must not contain only numbers. Names cannot include a blank space. Use the %SERIAL% macro to add a hardware-specific serial number. Alternatively, use the %RAND:x% macro to add a random string of numbers, where x equals the number of digits to add." }, "configureDevice": "Deployment mode", "configureDeviceHintForSurfaceHub2": "Autopilot only supports self-deploying mode for Surface Hub 2. This mode doesn't associate the user with the enrolled device, so it doesn't require user credentials.", "configureDeviceHintForWindowsPC": "\n Deployment mode controls if a user needs to provide credentials in order to provision the device.\n
\n\nThe following options are automatically enabled for Autopilot devices in self-deploying mode:\n
\nNotes:
\nNotes:
\nLow
\nMedium
\nHigh
\nI need to add my own line-of-business app
", "guidedTemplate2": "We’ll ask you which protection level you would like to deploy to your users. For more information, see Data protection framework with app protection policies. ", "guidExample": "e.g. 782AFCFC-7CAA-436C-8BF0-78CD0FFBD4AF", "healthCheck": "Health Checks", "healthMonCustomScope": "Enter a custom scope", "healthMonCustomScopeDescription": "Custom event sets", "healthMonEnablement": "Health monitoring", "healthMonEnablementDescription": "Enables event collection from devices running Windows 10 or later.", "healthmonEnablementDisabledOption": "Disable", "healthmonEnablementEnabledOption": "Enable", "healthMonHeader": "Proactively monitor device health by tracking device events. Health monitoring is available for devices running Windows 10, version 1903 and later, or Windows 11.", "healthMonScope": "Scope", "healthMonScopeBasic": "Basic", "healthMonScopeBootPerf": "Endpoint analytics", "healthMonScopeDescription": "The Windows events you want to collect.", "healthMonScopeWindowsUpdates": "Windows updates", "helpAndSupport": "Help and support", "hibernate": "Hibernate", "hide": "Hide", "hideAppsList": "Hidden apps", "hideOption": "Hide", "hideOverrides": "Hide Overrides", "high": "High", "highDataProtectionGuidedString": "High data protection – expand upon the settings defined in enhanced data protection by introducing more complex access requirements settings (e.g., disables simple PIN), data protection settings (for example, disabling third-party keyboards).", "highOption": "High", "highSeverity": "High severity", "holoLensSharedPCAccountDeletion": "Account Deletion(HoloLens)", "holoLensSharedPCAccountDiskSpaceLeftBeforeDeletion": "Delete oldest accounts when free disk space drops below(HoloLens)", "holoLensSharedPCAccountManager": "Account management(HoloLens)", "holoLensSharedPCDaysBeforeInactive": "Number of days an account is unused before it's considered inactive(HoloLens)", "holoLensSharedPCDiskSpaceLeftCached": "Stop account deletion when percentage storage/disk space is(HoloLens)", "homeButtonOnlySystemNavigationOption": "Home button only", "homepagesColumn": "e.g. https://co.com/sites.xml", "homeScreenLayoutAppAndFolderTableName": "Apps and folders", "homeScreenLayoutAppAndFolderTableNameTooltip": "The list of apps and folders to add.", "homeScreenLayoutDockDescription": "Apps and folders you select will be placed on the dock of end user's iOS devices that you assign this policy to. Items are added from left to right in the order you give them. You can select up to 6 items.", "homeScreenLayoutDockHeader": "Select the apps or folders that you want to add to the dock. Apps and folders that you select will be placed on the dock for devices that have this policy assigned to them. Items will be added from left to right in the order that you add them.\nIf you defer software updates, newly released updates won't become visible to users until after the deferral period (which you'll configure in the next settings). Deferring software updates doesn't impact scheduled updates.
OS-related updates can be deferred on devices running macOS 10.13 or later; non OS-related updates (such as Safari updates) can be deferred on devices running macOS 11 or later.
", "updateDelayPolicyName": "Defer software updates", "updateEveryWeek": "Every week", "updateFirstWeekOfMonth": "First week of the month", "updateFourthWeekOfMonth": "Fourth week of the month", "updateNotificationLevelDescription": "Specifies what Windows Update notifications users see.", "updateNotificationLevelName": "Change notification update level", "updatesClassificationName": "Minimum classification of updates to install automatically", "updateSecondWeekOfMonth": "Second week of the month", "updateSettingsName": "Update settings", "updateThirdWeekOfMonth": "Third week of the month", "uploadResult": "File contents", "upperIPv4AddressName": "Upper IPv4 address", "upperPortName": "Upper port", "url": "URL", "urlPathHashOption": "Hash", "uSBOption": "USB", "usbTypeAPortName": "USB type A", "usbTypeCPortName": "USB Type C", "useDeadlineSettingsDescription": "Allows user to use deadline settings", "useDeadlineSettingsName": "Use deadline settings", "useInternalSubnetName": "Use IPv4/IPv6 internal subnet attributes", "useOAuth": "OAuth", "useOAuthDescription": "Specifies whether the connection should use OAuth for authentication.", "usePACName": "Use (PAC)", "userAccountControlDescription": "How is user notified about device changes (recommend Always notify).", "userAccountControlName": "User Account Control", "userApprovedAndAutomatedDeviceEnrollmentHeaderDescriptionMac": "These settings work for devices that were enrolled in Intune with user approval, and for devices enrolled using Apple School Manager or Apple Business Manager with automated device enrollment (formerly DEP). This includes all supervised devices.", "userApprovedAndAutomatedDeviceEnrollmentHeaderNameMac": "User approved and automated device enrollment", "userAuthentication": "User authentication", "userCanConfigure": "User can configure", "userCheckInPerAppGridTitle": "User check-in per app", "userColumnLabel": "User", "userConfigReport": "User configuration report", "userControlOption": "User in control", "userCustomDomainDescription": "The value Intune uses for the user domain name that will be used by this profile e.g. contoso.com or contoso.", "userCustomDomainName": "Custom domain name to use", "userCustomDomainNameExample": "e.g. contoso.com", "userDefined": "User defined", "userDomainAADAttributeDescription": "The attribute Intune gets from Microsoft Entra ID to dynamically generate the user domain name that will be used by this profile e.g. contoso.com (full domain name) or contoso (NetBIOS name).", "userDomainAADAttributeLinkText": "Learn more about Microsoft Entra attributes for email profiles.", "userDomainAADAttributeName": "User domain name attribute from Microsoft Entra ID", "userEmail": "User email", "userExperienceSettingsName": "User experience settings", "userGroupAddErrorNotificationTitle": "Error adding one or more user groups to policy", "userGroupIsNotTargetedText": "No", "userGroupIsTargetedText": "Yes", "userGroupNameColumnLabel": "User group", "userHasNotReceivedAppConfigurations": "The user has not received any app configurations", "userId": "User ID", "userImpact": "User impact", "userImpactTextDetails": "Assigned iOS and Android users must enter a PIN or use biometrics to access work or school content after a period of inactivity. After 5 failed PIN attempts, user must reset their PIN.If advanced data protection controls are enforced, users will not be able to share work or school content with personal apps or personal accounts and will be required to use Microsoft Edge.
", "userIsBlocked": "This user is blocked by user-level wipe.", "userIsLicensedIntune": "User is licensed for Microsoft Intune.", "userIsLicensedO365": "User is licensed for Office 365.", "userIsNotLicensedIntune": "User is not licensed for Microsoft Intune. Click here to learn more.", "userIsNotLicensedIntuneNoLink": "User is not licensed for Microsoft Intune. Click here to learn more.", "userIsNotLicensedO365": "User is not licensed for Office 365. Click here to learn more.", "userIsNotLicensedO365NoLink": "User is not licensed for Office 365. Click here to learn more.", "userLevelWipe": "User-Level Wipe", "userLicensingUnknownIntune": "Unable to determine if a Microsoft Intune license is assigned to this user. Click here to learn more.", "userLicensingUnknownIntuneNoLink": "Unable to determine if a Microsoft Intune license is assigned to this user. Click here to learn more.", "userLicensingUnknownO365": "Unable to determine if an Office 365 license is assigned to this user. Click here to learn more.", "userLicensingUnknownO365NoLink": "Unable to determine if an Office 365 license is assigned to this user. Click here to learn more.", "userName": "User name", "usernameAndPasswordOption": "Username and password", "usernameFormat": "Username format:", "usernameFormatDescription": "Username format example - abcd{{WifiMacAddress}}", "userNameOption": "User name", "userNameTypeDescription": " The attribute Intune gets from Microsoft Entra ID to dynamically generate the username that will be used by this profile e.g. MyName@contoso.com (UPN) or MyName (username).", "userNameTypeLinkText": "Learn more about Microsoft Entra attributes for Email profiles.", "userNameTypeName": "Username attribute from Microsoft Entra ID", "userNotFound": "User not found", "userNotLicensed": "This user is not licensed for Microsoft Intune.", "userNotTargetedForAppPolicies": "This user is not targeted for any app policies", "userPauseAccessDescription": "An option in Windows Update that, when enabled, lets device users pause updates for a certain number of days.", "userPauseAccessName": "Option to pause Windows updates", "userPrincipalName": "User principal name", "userPrincipalNameOption": "User principal name", "userReport": "User report", "userRightsAccessCredentialManagerAsTrustedCallerDesc": "This user right is used by Credential Manager during Backup/Restore. Users' saved credentials might be compromised if this privilege is given to other entities. ", "userRightsAccessCredentialManagerAsTrustedCallerName": "Access Credential Manager as trusted caller", "userRightsActAsPartOfTheOperatingSystemDesc": "This user right allows a process to impersonate any user without authentication. ", "userRightsActAsPartOfTheOperatingSystemName": "Act As Part Of The OS", "userRightsAddSidBladeTitle": "Other local users or groups", "userRightsAddSidBladeTitleName": "Add local users or groups by SID", "userRightsAddSidTableDescriptionDesc": "Admin’s description of this local user or group.", "userRightsAddSidTableDescriptionName": "Description", "userRightsAddSidTableNameDesc": "The name of this local user or group.", "userRightsAddSidTableNameName": "Name", "userRightsAddSidTableSidDesc": "The security identifier of this local user or group (e.g. *S-1-5-32-544).", "userRightsAddSidTableSidName": "SID", "userRightsAdministratorsName": "Administrators", "userRightsAllowAccessFromNetworkDesc": "This user right determines which users and groups are allowed to connect to the computer over the network. ", "userRightsAllowAccessFromNetworkName": "Allow Access From Network", "userRightsAllowLocalLogOnDesc": "This user right determines which users can log on to the computer.", "userRightsAllowLocalLogOnName": "Allow local log on", "userRightsAuthenticatedUsersName": "Authenticated users", "userRightsBackupFilesAndDirectoriesDesc": "This user right determines which users can bypass file, directory, registry, and other persistent objects permissions when backing up files and directories.", "userRightsBackupFilesAndDirectoriesName": "Backup files and directories", "userRightsBlockAccessFromNetworkDesc": "This user right determines which users are prevented from accessing a computer over the network.", "userRightsBlockAccessFromNetworkName": "Deny Access From Network", "userRightsChangeSystemTimeDesc": "This user right determines which users and groups can change the time and date on the internal clock of the computer.", "userRightsChangeSystemTimeName": "Change the system time", "userRightsCreateGlobalObjectsDesc": "This security setting determines whether users can create global objects that are available to all sessions. Users who can create global objects could affect processes that run under other users' sessions, which could lead to application failure or data corruption.", "userRightsCreateGlobalObjectsName": "Create global objects", "userRightsCreatePageFileDesc": "This user right determines which users and groups can call an internal API to create and change the size of a page file.", "userRightsCreatePageFileName": "Create pagefile", "userRightsCreatePermanentSharedObjectsDesc": "This user right determines which accounts can be used by processes to create a directory object using the object manager.", "userRightsCreatePermanentSharedObjectsName": "Create permanent shared objects", "userRightsCreateSymbolicLinksDesc": "This user right determines if the user can create a symbolic link from the computer to which they are logged on.", "userRightsCreateSymbolicLinksName": "Create symbolic links", "userRightsCreateTokenDesc": "This user right determines which users/groups can be used by processes to create a token that can then be used to get access to any local resources when the process uses an internal API to create an access token.", "userRightsCreateTokenName": "Create tokens", "userRightsDebugProgramsDesc": "This user right determines which users can attach a debugger to any process or to the kernel.", "userRightsDebugProgramsName": "Debug programs", "userRightsDelegationDesc": "This user right determines which users can set the Trusted for Delegation setting on a user or computer object.", "userRightsDelegationName": "Enable delegation", "userRightsDenyLocalLogOnDesc": "This security setting determines which service accounts are prevented from registering a process as a service.", "userRightsDenyLocalLogOnName": "Deny local log on name", "userRightsDescriptionExample": "(BUILTIN\\Event Log Readers)", "userRightsGenerateSecurityAuditsDesc": "This user right determines which accounts can be used by a process to add entries to the security log. The security log is used to trace unauthorized system access.", "userRightsGenerateSecurityAuditsName": "Generate security audits", "userRightsGuestsName": "Guests", "userRightsImpersonateClientDesc": "Assigning this user right to a user allows programs running on behalf of that user to impersonate a client. Requiring this user right for this kind of impersonation prevents an unauthorized user from convincing a client to connect to a service that they have created and then impersonating that client, which can elevate the unauthorized user's permissions to administrative or system levels.", "userRightsImpersonateClientName": "Impersonate a client", "userRightsIncreaseSchedulingPriorityDesc": "This user right determines which accounts can use a process with Write Property access to another process to increase the execution priority assigned to the other process", "userRightsIncreaseSchedulingPriorityName": "Increase scheduling priority", "userRightsLoadUnloadDriversDesc": "This user right determines which users can dynamically load and unload device drivers or other code in to kernel mode.", "userRightsLoadUnloadDriversName": "Load and unload device drivers", "userRightsLocalAccountAndMemberOfAdministratorsGroupName": "Local account and member of Administrators group", "userRightsLocalAccountName": "Local account", "userRightsLocalServicesName": "Local services", "userRightsLockMemoryDesc": "This user right determines which accounts can use a process to keep data in physical memory, which prevents the system from paging the data to virtual memory on disk.", "userRightsLockMemoryName": "Lock pages in memory", "userRightsManageAuditingAndSecurityLogsDesc": "This user right determines which users can specify object access auditing options for individual resources, such as files, Active Directory objects, and registry keys.", "userRightsManageAuditingAndSecurityLogsName": "Manage auditing and security log", "userRightsManageVolumesDesc": "This user right determines which users and groups can run maintenance tasks on a volume, such as remote defragmentation.", "userRightsManageVolumesName": "Perform volume maintenance tasks", "userRightsModifyFirmwareEnvironmentDesc": "This user right determines who can modify firmware environment values.", "userRightsModifyFirmwareEnvironmentName": "Modify firmware environment values", "userRightsModifyObjectLabelsDesc": "This user right determines which user accounts can modify the integrity label of objects, such as files, registry keys, or processes owned by other users.", "userRightsModifyObjectLabelsName": "Modify an object label", "userRightsNameExample": "Event Log Readers", "userRightsNetworkServicesName": "Network services", "userRightsProfileSingleProcessDesc": "This user right determines which users can use performance monitoring tools to monitor the performance of system processes.", "userRightsProfileSingleProcessName": "Profile single process", "userRightsRemoteDesktopServicesLogOnDesc": "This user right determines which users and groups are prohibited from logging on as a Remote Desktop Services client.", "userRightsRemoteDesktopServicesLogOnName": "Deny log on through Remote Desktop Services", "userRightsRemoteDesktopUsersName": "Remote desktop users", "userRightsRemoteShutdownDesc": "This user right determines which users are allowed to shut down a computer from a remote location on the network. Misuse of this user right can result in a denial of service.", "userRightsRemoteShutdownName": "Remote shutdown", "userRightsRestoreDataDesc": "This user right determines which users can bypass file, directory, registry, and other persistent objects permissions when restoring backed up files and directories, and determines which users can set any valid security principal as the owner of an object.", "userRightsRestoreDataName": "Restore files and directories", "userRightsServicesName": "Services", "userRightsSidDesc": "User or Group Sid", "userRightsSidExample": "*S-1-5-21-2146773085", "userRightsSidName": "SIDs", "userRightsTakeOwnershipDesc": "This user right determines which users can take ownership of any securable object in the system, including Active Directory objects, files and folders, printers, registry keys, processes, and threads.", "userRightsTakeOwnershipName": "Take ownership of files or objects", "userRightsUsersName": "Users", "users": "Users", "usersCheckedInTitle": "Users checked in", "userSelectorDisplayText": "{0} selected", "userSelectorLabel": "User", "userStatusesTableGroupingDropdownLabel": "Table grouping", "userStatusesTableGroupingDropdownTooltip": "Select a column to aggregate data by", "usersThatIDontInclude": "What happens to the users that I don't include?", "usersWithLicense": "Assigned and licensed", "usersWithoutLicense": "Assigned and not licensed", "usersWithPotentiallyHarmfulApps": "Users with potentially harmful apps", "userToggleEnabledName": "User to disable VPN configuration", "userToggleEnabledToolTip": "Unless allowed, users can’t turn off always-on VPN. The default value for this setting is the most secure option.", "userWindowsUpdateScanAccessDescription": "A button in Windows Update that, when enabled, lets device users check the update service for updates.", "userWindowsUpdateScanAccessName": "Option to check for Windows updates", "useWindows10ForcedUpdates": "Force restart apps on update failure", "useWindows10ForcedUpdatesTooltip": "To ensure apps are always up-to-date, use this setting to configure a recurring or one time date to restart apps whose update failed due to the app being in use.", "utcMinusEightOption": "UTC-8", "utcMinusElevenOption": "UTC-11", "utcMinusFiveOption": "UTC-5", "utcMinusFourOption": "UTC-4", "utcMinusNineOption": "UTC-9", "utcMinusNineThirtyOption": "UTC-9:30", "utcMinusOneOption": "UTC-1", "utcMinusSevenOption": "UTC-7", "utcMinusSixOption": "UTC-6", "utcMinusTenOption": "UTC-10", "utcMinusThreeOption": "UTC-3", "utcMinusThreeThirtyOption": "UTC-3:30", "utcMinusTwelveOption": "UTC-12", "utcMinusTwoOption": "UTC-2", "utcPlusEightFourtyFiveOption": "UTC+8:45", "utcPlusEightOption": "UTC+8", "utcPlusEightThirtyOption": "UTC+8:30", "utcPlusElevenOption": "UTC+11", "utcPlusFiveFourtyFiveOption": "UTC+5:45", "utcPlusFiveOption": "UTC+5", "utcPlusFiveThirtyOption": "UTC+5:30", "utcPlusFourOption": "UTC+4", "utcPlusFourteenOption": "UTC+14", "utcPlusFourThirtyOption": "UTC+4:30", "utcPlusNineOption": "UTC+9", "utcPlusOneOption": "UTC+1", "utcPlusSevenOption": "UTC+7", "utcPlusSixOption": "UTC+6", "utcPlusSixThirtyOption": "UTC+6:30", "utcPlusTenOption": "UTC+10", "utcPlusTenThirtyOption": "UTC+10:30", "utcPlusThirteenOption": "UTC+13", "utcPlusThreeOption": "UTC+3", "utcPlusThreeThirtyOption": "UTC+3:30", "utcPlusTwelveFourtyFiveOption": "UTC+12:45", "utcPlusTwelveOption": "UTC+12", "utcPlusTwoOption": "UTC+2", "utcZeroOption": "UTC±00", "validateFreezePeriodLength": "Freeze period cannot be longer than 90 days.", "validateFreezePeriodSeparation": "Freeze periods must be separated by at least 60 days.", "validateSingleSignOnMessage": "Property Single sign-on (SSO) must be set to Disable when Authentication Mode is set to Machine or Guest.", "validationResult": "Validation result", "validOperatingSystemBuildsDescription": "Valid operating system builds", "validOperatingSystemBuildsDescriptionName": "Description", "validOperatingSystemBuildsMaximumName": "Maximum", "validOperatingSystemBuildsMinimumName": "Minimum", "validOperatingSystemBuildsName": "Valid operating system builds", "validTLSVersion": "TLS Version must be one of the following values: 1.0, 1.1, 1.2", "value": "Value", "valueColumn": "Value", "valueColumnHeader": "Value", "valueInKilobytesPerSecondEmpty": "Enter value in KB/s", "valueMustNotContainCharsError": "Value must not contain the following characters: {0}", "valueName": "Value", "valueType": "Value type", "valueZeroNotLimitedEmpty": "Value 0 specifies not limited.", "version": "{0} ({1})", "versionAndroid4": "(This compliance check is supported for devices with OS versions Android 4.0 and above)", "versionAndroid4SamsungKStandard4": "(This compliance check is supported for devices with OS versions Android 4.0 and above, or KNOX 4.0 and above)", "versionIOS8": "(This compliance check is supported for devices with OS versions iOS 8.0 and above)", "versionValidationExample": "Format: [Major].[Minor] or [Major].[Minor].[Build].[Revision]
Example: 1.5 or 1.5.50.101
", "versionValidationWith2To5Segments": "Format: [Major].[Minor] or [Major].[Minor].[Build] or [Major].[Minor].[Build].[Revision]. For iOS, [Major].[Minor].[Build].[Revision].[RapidSecurityResponse] is also supported.
Note: Apps will not perform wipes for RapidSecurityResponse violations, only block or warn is supported.
Example: 1.5 or 1.5.50 or 1.5.50.101 or (for iOS) 1.5.50.101.a
", "versionValidationWithDateFormat": "Must be a valid date format (YYYY-MM-DD).", "versionWin10Desktop": "(This compliance check is supported for desktop devices running Windows 10 or later)", "virtualHomeButtonDescription": "Enable a soft-key button that returns users to the Managed Home Screen. Choose between a persistent, floating button or a button activated by a swipe-up gesture.", "virtualHomeButtonFloating": "Floating", "virtualHomeButtonName": "Virtual home button", "virtualHomeButtonNotConfigured": "Not configured", "virtualHomeButtonSwipeUp": "Swipe-up", "virtualizationBasedSecurityEnabledName": "Virtualization-based Security", "virtualizationOfCpuAndIOName": "CPU and IO virtualization", "visibleAppsListOptionsDescription": "Set whether the list is a list of apps to hide or a list of apps to make visible.", "visibleAppsListOptionsName": "Type of apps list", "voicemailExceptionName": "Voicemail", "voicemailExceptionToolTip": "Choose what happens with voicemail traffic when always-on VPN is enabled. The default value for this setting is the most secure option.", "volumeName": "Volume", "vpn": "Base VPN", "vPNAddressExample": "10.0.0.3, vpn.contoso.com", "vpnAlwaysOn": "Always-on VPN", "vpnApps": "Automatic VPN", "vPNAppsDescription": "When at least one app is selected, the VPN connection will be limited to the apps in the list.", "vpnAppsExample": "e.g. com.microsoft.emmx", "vPNAppsName": "Select apps that would be allowed to use this VPN connection", "vPNAuthMethodDescription": "Select how you want users to authenticate to the VPN server. Using certificate-based authentication provides enhanced capabilities such as zero-touch experience, on-demand VPN, and per-app VPN.", "vPNCitrixData": "Citrix data", "vPNCitrixDataDescription": "Enter key and value pairs for the Citrix VPN attributes.", "vPNConditionTypeColumnName": "Restrict to", "vPNConditionTypeName": "I want to restrict to", "vPNConnectionExample": "Contoso VPN", "vpnConnectivity": "Connectivity", "vPNCustomData": "Attributes for custom VPN", "vPNCustomDataDescription": "Enter key and value pairs for the custom VPN attributes.", "vPNCustomKeyExample": "SingleSignOn", "vPNCustomValueExample": "True", "vPNDnsAutoTriggerDescription": "Automatically connect to the VPN when the device connects to this domain", "vPNDnsAutoTriggerName": "Automatically Connect", "vPNDnsPersistentDescription": "Keep this rule active even when the VPN is not connected: Select Enable to keep this rule in the Name Resolution Policy table (NRPT) until the rule is manually removed from the device, even after the VPN is disconnected. By default, NRPT rules in the VPN profile are removed from the device when the VPN is disconnected.", "vPNDnsPersistentName": "Persistent", "vPNEAPXMLDescription": "Enter the extensible authentication protocol (EAP) configuration in XML format. ", "vPNEAPXMLHelpLinkDescription": "Learn more about creating an EAP configuration for your VPN profile.", "vPNFQDNExample": "vpn.contoso.com", "vPNIdentifier": "VPN identifier", "vPNIdentifierExample": "e.g. com.cisco.anyconnect.applevpn.plugin", "vpnIkev2": "IKEv2 settings", "vPNIKEv2RemoteIdentifierDescription": "Specify the address of the IKEv2 server. This is usually the same value used in the IP address or FQDN field under Base VPN. The address must be a FQDN, UserFQDN, network address, or ASN1DN.", "vPNIKEv2RemoteIdentifierName": "Remote identifier", "vPNNetMotionMobilityCustomData": "Attributes for NetMotion Mobility VPN", "vPNNetMotionMobilityCustomDataDescription": "Enter key and value pairs for the NetMotion Mobility VPN attributes.", "vpnOnDemand": "On-Demand VPN Rules", "vpnOverCellularName": "VPN over the cellular network", "vpnPerApp": "Per-app VPN", "vPNPerAppDescription": "When users start using the selected apps, traffic will automatically route through the VPN connection if the connection is configured to be Always On or if the connection has been manually started by the user.", "vPNPolicyAddressDescription": "Proxy server address (fully-qualified host, or IP address).", "vPNPolicyAddressName": "Address", "vPNPolicyAssociatedAppsDescription": "Apps added here will automatically start this VPN connection.", "vPNPolicyAssociatedAppsName": "Associated Apps", "vPNPolicyAssociatedDomainsUrlsDescription": "Associated domains require additional setup outside of this VPN profile. Learn more.Enter the protocol for a single unmanaged browser. Web content (http/s) from policy managed applications will open in any app that supports this protocol.
\n\nNote: Include only the protocol prefix. If your browser requires links of the form \"mybrowser://www.microsoft.com\", enter \"mybrowser\".
" }, "CustomDialerAppDisplayName": { "label": "Dialer App Name" }, "CustomDialerAppPackageId": { "label": "Dialer App Package ID" }, "CustomDialerAppProtocol": { "label": "Dialer App URL Scheme" }, "Cutcopypaste": { "label": "Restrict cut, copy, and paste between other apps", "tooltip": "Cut, copy, and paste data between your app and other approved apps installed on the device. Choose to block these actions completely between apps, allow these actions for use with any app, or restrict use to apps that your organization manages.
\n\nPolicy-managed apps with paste in gives you the option to accept incoming content pasted from another app. However, it blocks users from sharing content outwardly, unless sharing with a managed app.
" }, "DialerRestrictionLevel": { "iosTooltip": "Typically, when a user selects a hyperlinked phone number in an app, a dialer app will open with the phone number prepopulated and ready to call. For this setting, choose how to handle this type of content transfer when it's initiated from a policy-managed app. Additional steps may be necessary in order for this setting to take effect. First, verify that tel and telprompt have been removed from the Select apps to exempt list. Then, ensure the application is using a newer version of Intune SDK (Version 12.7.0+).", "label": "Transfer telecommunication data to", "tooltip": "Typically, when a user selects a hyperlinked phone number in an app, a dialer app will open with the phone number prepopulated and ready to call. For this setting, choose how to handle this type of content transfer when it's initiated from a policy-managed app." }, "EncryptData": { "label": "Encrypt org data", "link": "https://docs.microsoft.com/en-us/mem/intune/apps/app-protection-policy-settings-android#data-relocation-settings", "tooltip": "Select {0} to enforce encrypting org data with Intune app layer encryption.\nChoose Require to enable encryption of work or school data in this app. Intune uses a wolfSSL, 256-bit AES encryption scheme along with the Android Keystore system to securely encrypt app data. Data is encrypted synchronously during file I/O tasks. Content on the device storage is always encrypted. New files will be encrypted with 256-bit keys. Existing 128-bit encrypted files will undergo a migration attempt to 256-bit keys, but the process is not guaranteed. Files encrypted with 128-bit keys will remain readable.
\n\nThe encryption method is FIPS 140-2 compliant.
" }, "EncryptDataIos": { "tooltip1": "Choose Require to enable encryption of work or school data in this app. Intune enforces iOS/iPadOS device encryption to protect app data while the device is locked. Applications may optionally encrypt app data using Intune APP SDK encryption. Intune APP SDK uses iOS/iPadOS cryptography methods to apply 256-bit AES encryption to app data.", "tooltip2": "When you enable this setting, the user may be required to set up and use a PIN to access their device. If there's no device PIN and encryption is required, the user is prompted to set a PIN with the message \"Your organization has required you to first enable a device PIN to access this app.\"", "tooltip3": "Go to the official Apple documentation to see which iOS encryption modules are FIPS 140-2 compliant or pending FIPS 140-2 compliance." }, "EncryptDataOnEnrolledDevices": { "label": "Encrypt org data on enrolled devices", "tooltip": "Select {0} to enforce encrypting org data with Intune app layer encryption on all devices.Select one of the following options to specify how notifications for org accounts are shown for this app and any connected devices such as wearables:
\n{0}: Do not share notifications.
\n{1}: Do not share org data in notifications. If not supported by the application, notifications are blocked.
\n{2}: Share all notifications.
\nAndroid only:\n Note: This setting does not apply to all applications. For more information see {3}
\n\niOS only:\nNote: This setting does not apply to all applications. For more information see {4}
" }, "OpenLinksManagedBrowser": { "label": "Restrict web content transfer with other apps", "tooltip": "Select one of the following options to specify the apps that this app can open web content in:
\nMicrosoft Edge: Allow web content to open only in Microsoft Edge. Learn how Microsoft Edge protects your data.
\nUnmanaged browser: Allow web content to open only in the unmanaged browser defined by \"Unmanaged browser protocol\" setting
\nAny app: Allow web links in any app
", "warning": "Please select \"Microsoft Edge\" to protect your originization data." }, "OverrideBiometric": { "tooltip": "If required, depending on the timeout (minutes of inactivity), a PIN prompt will override biometric prompts. If this timeout value is not met, the biometric prompt will continue to show. This timeout value should be greater than the value specified under 'Recheck the access requirements after (minutes of inactivity)'. " }, "PinAccess": { "label": "PIN for access", "tooltip": "If required, a PIN must be used to access the policy-managed app. Users must create an access PIN the first time that they open the app from a work or school account." }, "PinLength": { "label": "Select minimum PIN length", "tooltip": "This setting specifies the minimum number of digits of a PIN." }, "PinType": { "label": "PIN type", "tooltip": "Numeric PINs are made up of all numbers. Passcodes are made up of alphanumeric characters and special characters. " }, "Printing": { "label": "Printing org data", "tooltip": "If blocked, the app cannot print protected data." }, "ProtectedMessagingRedirectAppType": { "iosTooltip": "Typically, when a user selects a hyperlinked messaging link in an app, a messaging app will open with the phone number prepopulated and ready to send. For this setting, choose how to handle this type of content transfer when it's initiated from a policy-managed app. Additional steps may be necessary in order for this setting to take effect. First, verify that sms has been removed from the Select apps to exempt list. Then, ensure the application is using a newer version of Intune SDK (Version > 19.0.0).", "label": "Transfer messaging data to", "tooltip": "Typically, when a user selects a hyperlinked messaging link in an app, a messaging app will open with the phone number prepopulated and ready to send. For this setting, choose how to handle this type of content transfer when it's initiated from a policy-managed app." }, "purviewEvaluationLabel": "Require Microsoft Purview review before sharing organizational data", "ReceiveData": { "label": "Receive data from other apps", "tooltip": "Select one of the following options to specify the apps that this app can receive data from:Select Yes to disable the app PIN when a device lock is detected on an enrolled device.
", "targetAllApps1": "Use this option to target your policy to apps on devices of any management state.", "targetAllApps2": "During policy conflict resolution this setting will be superseded if a user has policy targeted for a specific management state.", "TouchId1": { "android": "On Android, you can allow using fingerprint identification instead of a PIN. Users are prompted to provide their fingerprints when they access this app with their work accounts.", "iOS": "On iOS/iPadOS devices, you can allow using fingerprint identification instead of a PIN. Users are prompted to provide their fingerprints when they access this app with their work accounts.", "mac": "On Mac devices, you can allow using fingerprint identification instead of a PIN. Users are prompted to provide their fingerprints when they access this app with their work accounts." }, "touchId2": "Select {0} to require fingerprint identity instead of a PIN for app access." }, "requireAppPin": "Select Yes to disable the app PIN when a device lock is detected on an enrolled device.
Note: Intune cannot detect device enrollment with a third-party EMM solution on iOS/iPadOS.
", "Tap": { "pinResetAfterNumberOfDays": "Specify the number of days that must pass before the user must reset the PIN.", "previousPinBlockCount": "This setting specifies the number of previous PINs that Intune will maintain. Any new PINs must be different from those that Intune is maintaining." }, "WipPolicySettings": { "25": "", "allowWindowsSearch": "This will allow Windows Search to continue to search through encrypted data.", "authoritativeIpRanges": "Enable this setting if you want to override Windows auto-detection of IP ranges.", "authoritativeProxyServers": "Enable this setting if you want to override Windows auto-detection of proxy servers.", "checkInput": "Check input for validity", "dataRecoveryCert": "A recovery certificate is a special Encrypting File System (EFS) certificate you can use to recover encrypted files if your encryption key is lost or damaged. You need to create the recovery certificate, and specify it here. More information is here", "enterpriseCloudResources": "Specify cloud resources to be treated as corporate and be protected with Windows Information Protection policy. Multiple resources can be specified by separating individual entries with the '|' character.
If you have a proxy configured in your company, then you can specify the proxy through which traffic to cloud resources you specified will be routed.
URL[,Proxy]|URL[,Proxy]
Without proxy: contoso.sharepoint.com|contoso.visualstudio.com
With proxy: contoso.sharepoint.com,proxy.contoso.com|contoso.visualstudio.com,proxy.contoso.com
If you have a proxy configured in your company, then you can specify the proxy through which traffic to cloud resources specified in the Enterprise Cloud Resources settings are to be routed.
Multiple values can be specified by separating individual entries with a semi-colon.
For example: contoso.internalproxy1.com;contoso.internalproxy2.com
", "enterpriseIPv4Ranges": "Specify the IPv4 ranges that form your corporate network. These are used in conjunction with the Enterprise Network Domain Names that you specify to define your corporate network boundary.
This setting is required to have Windows Information Protection enabled.
Multiple ranges can be specified by separating individual entries with a comma.
For example: 3.4.0.1-3.4.255.255,192.168.1.1-192.168.255.255
", "enterpriseIPv6Ranges": "Specify the IPv6 ranges that form your corporate network. These are used in conjunction with the Enterprise Network Domain Names that you specify to define your corporate network boundary.
Multiple ranges can be specified by separating individual entries with a comma.
For example: 2001:4898:dc05::-2001:4898:dc05:ffff:ffff:ffff:ffff:ffff,2a01:110::-2a01:110:7fff:ffff:ffff:ffff:ffff:ffff
", "enterpriseNetworkDomainNames": "Specify the DNS names that form your corporate network. These are used in conjunction with the IP ranges that you specify to define your corporate network boundary. Multiple values can be specified by separating individual entries with a comma.
This setting is required to have Windows Information Protection enabled.
For example: corp.contoso.com,region.contoso.com
", "enterpriseProtectedDomainNames": "Specify the DNS names that form your corporate network. These are used in conjunction with the IP ranges that you specify to define your corporate network boundary. Multiple values can be specified by separating individual entries with a '|'.
This setting is required to have Windows Information Protection enabled.
For example: corp.contoso.com|region.contoso.com
", "enterpriseProxyServers": "If you have external facing proxies in your corporate network, specify them here. When specifying a proxy server address, you should also specify the port through which traffic should be allowed and protected through Windows Information Protection.
Note: This list must not include servers in your Enterprise Internal Proxy Server list. Multiple values can be specified by separating individual entries with a semi-colon.
For example: proxy.contoso.com:80;proxy2.contoso.com:80
", "maxInactivityTime1": "Specifies the maximum amount of time (in minutes) allowed after the device is idle that will cause the device to become PIN or password locked. Users can select any existing timeout value less than the specified maximum time in the Settings app. Note the Lumia 950 and 950XL have a maximum timeout value of 5 minutes, regardless of the value set by this policy.", "maxInactivityTime2": "0 (default) - No timeout is defined. The default of '0' is interpreted as 'No timeout is defined.'", "maxPasswordAttempts1": "This policy has different behaviors on the mobile device and desktop.", "maxPasswordAttempts2": "On a mobile device, when the user reaches the value set by this policy, then the device is wiped.", "maxPasswordAttempts3": "On a desktop, when the user reaches the value set by this policy, it is not wiped.Instead, the desktop is put on BitLocker recovery mode, which makes the data inaccessible but recoverable.If BitLocker is not enabled, then the policy cannot be enforced.", "maxPasswordAttempts4": "Prior to reaching the failed attempts limit, the user is sent to the lock screen and warned that more failed attempts will lock their computer.When the user reaches the limit, the device automatically reboots and shows the BitLocker recovery page.This page prompts the user for the BitLocker recovery key.", "maxPasswordAttempts5": "0 (default) - The device is never wiped after an incorrect PIN or password is entered.", "maxPasswordAttempts6": "Most secure value is 0 if all policy values = 0; otherwise, Min policy value is the most secure value.", "mdmDiscoveryUrl": "Specify the URL for the MDM enrollment endpoint that users who enroll to MDM will use. By default, this is specified for Intune.", "minimumPinLength1": "Integer value that sets the minimum number of characters required for the PIN. Default value is 4. The lowest number you can configure for this policy setting is 4. The largest number you can configure must be less than the number configured in the Maximum PIN length policy setting or the number 127, whichever is the lowest.", "minimumPinLength2": "If you configure this policy setting, the PIN length must be greater than or equal to this number. If you disable or do not configure this policy setting, the PIN length must be greater than or equal to 4.", "name": "The name of this network boundary", "neutralResources": "If you have authentication redirection endpoints in your company, specify those here. The locations specified here are considered to be either personal or corporate depending on the context of the connection prior to the redirection.
Multiple values can be specified by separating individual entries with a comma.
For example: sts.contoso.com,sts.contoso2.com
", "passportForWork1": "Value that sets Windows Hello for Business as a method for signing into Windows.", "passportForWork2": "Default value is true.If you set this policy to false, the user cannot provision Windows Hello for Business except on Microsoft Entra joined mobile phones where provisioning is required.", "pinExpiration": "The largest number you can configure for this policy setting is 730. The lowest number you can configure for this policy setting is 0. If this policy is set to 0, then the user’s PIN will never expire.", "pinHistory1": "The largest number you can configure for this policy setting is 50. The lowest number you can configure for this policy setting is 0. If this policy is set to 0, then storage of previous PINs is not required.", "pinHistory2": "The current PIN of the user is included in the set of PINs associated with the user account. PIN history is not preserved through a PIN reset.", "protectionModeBlock": "Block: Blocks enterprise data from leaving protected apps.
", "protectionModeOff": "Off: User is free to relocate data off of protected apps. No actions are logged.
", "protectionModeOverride": "Allow overrides: User is prompted when attempting to relocate data from a protected to a non-protected app. If they choose to override this prompt, the action will be logged.
", "protectionModeSilent": "Silent: User is free to relocate data off of protected apps. These actions are logged.
", "protectUnderLock": "Protects app content while the device is in a locked state.", "required": "Required", "revokeOnMdmHandoff": "Added in Windows 10, version 1703. This policy controls whether to revoke the WIP keys when a device upgrades from MAM to MDM. If set to “Off”, the keys will not be revoked and the user will continue to have access to protected files after upgrade. This is recommended if the MDM service is configured with the same WIP EnterpriseID as the MAM service.", "revokeOnUnenroll": "This will cause encryption keys to be revoked when a device un-enrolls from this policy.", "rmsTemplateForEdp": "TemplateID GUID to use for RMS encryption. The Azure RMS template allows the IT admin to configure the details about who has access to RMS-protected file and how long they have access.", "showWipIcon": "This will let the user know when they are acting in a corporate context, by overlaying an icon.", "useRmsForWip": "Specifies whether to allow Azure RMS encryption for WIP." } }, "Wildcard": { "aadDeviceID": "Microsoft Entra device ID", "accountID": "Account ID", "accountName": "Account name", "deviceID": "Intune device ID", "deviceImei": "IMEI", "deviceName": "Device name", "employeeID": "Employee ID", "mail": "Mail", "mEID": "MEID", "partialUPN": "Partial UPN", "serialNumber": "Serial number", "serialNumberLast4Digits": "Last 4 digits of serial number", "userID": "User ID", "userName": "User name", "userPrincipalName": "User principal name (UPN)" }, "Win32Program": { "availableUninstall": "Allow available uninstall", "availableUninstallTooltip": "Select 'Yes' to provide the uninstall option for this app for users from the Company Portal. Select 'No' to prevent users from uninstalling the app from the Company Portal.", "bladeTitle": "Program", "CheckForRunningProcesses": { "addProcessAnnouncement": "Added process. Total: {0}", "addProcessButton": "+ Add process", "detectionActionDoNotTerminate": "Report an app enforcement failure and do not terminate the processes", "detectionActionLabel": "What should happen if processes are detected?", "detectionActionTerminate": "Terminate the processes before enforcing the app", "displayNameHeader": "Display name", "displayNameTooltip": "This name is shown to users when action is required.", "gridAriaLabel": "Processes to check before enforcement grid", "gridTitle": "Processes to check before enforcement", "label": "Check for running processes", "none": "Do not check for running processes", "processDeletedAnnouncement": "Process {0} deleted", "processNameHeader": "Process name", "specific": "Check for specific processes", "specificDescription": "You can configure deferrals and notifications in the assignment settings.", "Validation": { "atLeastOneProcess": "At least one process must be added when 'Check for specific processes' is selected", "displayNameMaxLength": "Display name must be less than {0} characters", "displayNameMaxLengthAnnouncement": "App in use detection Display name must be less than 1024 characters", "displayNameRequired": "Display name is required", "displayNameRequiredAnnouncement": "App in use detection Display name is required", "processNameInvalid": "Executable file name must end with .exe", "processNameInvalidAnnouncement": "App in use detection {0} Executable file name must end with .exe", "processNameMaxLength": "Executable file name must be less than {0} characters", "processNameMaxLengthAnnouncement": "App in use detection {0} Executable file name must be less than 1024 characters", "processNameRequired": "Executable file name is required", "processNameRequiredAnnouncement": "App in use detection Executable file name is required", "processNameUnique": "Executable file name must be unique", "processNameUniqueAnnouncement": "App in use detection {0} Executable file name must be unique" } }, "commandLineDropdownText": "Command line", "deviceRestartBehavior": "Device restart behavior", "DeviceRestartBehaviorOptions": { "allow": "App install may force a device restart", "basedOnReturnCode": "Determine behavior based on return codes", "force": "Intune will force a mandatory device restart", "suppress": "No specific action" }, "deviceRestartBehaviorTooltip": "Select the device restart behavior after the app has successfully installed. Select 'Determine behavior based on return codes' to restart the device based on the return codes configuration settings. Select 'No specific action' to suppress device restarts during the app install for MSI-based apps. Select 'App install may force a device restart' to allow the app install to complete without suppressing restarts. Select 'Intune will force a mandatory device restart' to always restart the device after successful app installation.", "header": "Specify the commands to install and uninstall this app:", "installCommand": "Install command", "installCommandMaxLengthErrorMessage": "Install command cannot exceed the maximum allowed length of 1024 characters.", "installCommandTooltip": "The complete installation command line used to install this app.", "installerTypeText": "Installer type", "InstallExperience": { "maxRunTimeInMinutes": "Installation time required (mins)", "maxRunTimeInMinutesToolTip": "The number of minutes the system will wait for install program to finish. Default value is 60 minutes." }, "installScript": "Install script", "installScriptErrorText": "An install script is required.", "installScriptsHeader": "Specify app Installation and Uninstallation settings, including whether to use a script or command line, time limits, restart behavior, and return codes.", "installScriptToolTip": "The PowerShell script file with installation commands used to install this app.", "runAs32Bit": "Run install and uninstall commands in a 32-bit process on 64-bit clients", "runAs32BitTooltip": "Select 'Yes' to install and uninstall the app in a 32-bit process on 64-bit clients. Select 'No' (default) to install and uninstall the app in a 64-bit process on 64-bit clients. 32-bit clients will always use a 32-bit process.", "runAsAccount": "Install behavior", "RunAsAccountOptions": { "system": "System", "user": "User" }, "runAsAccountTooltip": "Select 'System' to install this app for all users if supported. Select 'User' to install this app for the logged-in user on the device. For dual-purpose MSI apps, changes will prevent updates and uninstalls from successfully completing until the value applied to the device at the time of the original install is restored.", "scriptDropdownText": "PowerShell script", "scriptsErrorText": "An install and an uninstall script are required.", "selectCustomScript": "Select custom script", "selectedScriptLinkAriaText": "Script {0} selected. Opens context pane to edit or upload a new script.", "selectorLabel": "Program", "selectScriptLinkAriaText": "Select custom script, button. Opens context pane to upload a script", "selectScriptLinkText": "Select a script", "uninstallCommand": "Uninstall command", "uninstallCommandTooltip": "The complete uninstallation command line used to uninstall this app.", "uninstallerTypeText": "Uninstaller type", "uninstallScript": "Uninstall script", "uninstallScriptErrorText": "An uninstall script is required.", "uninstallScriptToolTip": "The PowerShell script file with uninstallation commands used to uninstall this app." }, "Win32Requirements": { "AdditionalRequirements": { "bladeTitle": "Add a Requirement rule", "createRequirementHeader": "Create a requirement.", "File": { "fileOrFolderToolTip": "The file or folder as the selected requirement.", "pathToolTip": "The complete path of the file or folder to detect.", "property": "Property", "valueToolTip": "Select a requirement value that matches the selected detection method. Date and time requirement should be entered in your local format." }, "GridColumns": { "pathOrScript": "Path/Script", "type": "Type" }, "header": "Configure additional requirement rules", "label": "Additional requirement rules", "noRequirementsSelectedPlaceholder": "No requirements are specified.", "Registry": { "keyPath": "Key path", "keyPathTooltip": "The full path of the registry entry containing the value as a requirement.", "operator": "Operator", "operatorTooltip": "Select the operator for the comparison.", "registryRequirement": "Registry key requirement", "registryRequirementTooltip": "Select the registry key requirement comparison.", "valueName": "Value name", "valueNameTooltip": "The name of the required registry value." }, "requirementType": "Requirement type", "RequirementTypeOptions": { "fileType": "File", "registry": "Registry", "script": "Script" }, "requirementTypeTooltip": "Choose the type of detection method used to determine how a requirement is validated.", "Script": { "duplicateName": "Script name {0} has already been used. Please enter a different name.", "enforceSignatureCheck": "Enforce script signature check", "enforceSignatureCheckTooltip": "Select ‘Yes’ to verify that the script is signed by a trusted publisher, which will allow the script to run without warnings or prompts. The script will run unblocked. Select ‘No’ (default) to run the script with end-user confirmation, but without signature verification.", "loggedOnCredentials": "Run this script using the logged on credentials", "loggedOnCredentialsTooltip": "Run script using the signed in device credentials.", "operatorTooltip": "Select the operator for the requirement comparison.", "requirementMethod": "Select output data type", "RequirementMethodOptions": { "boolean": "Boolean", "dateTime": "Date and Time", "float": "Floating Point", "integer": "Integer", "string": "String", "version": "Version" }, "requirementMethodTooltip": "Select the data type used when determining a detection match requirement.", "scriptContent": "Script content", "scriptFile": "Script file", "scriptFileTooltip": "Select a PowerShell script that will detect the presence of the app on the client. If the app is detected, the requirement process will provide a 0 value exit code and will write a string value to STDOUT.", "scriptName": "Script name", "value": "Value", "valueTooltip": "Select a requirement value that matches the selected detection method. Date and time requirement should be entered in your local format." } }, "allowedArchitectures": "Check operating system architecture", "allowedArchitecturesNoRadioButton": "No. Allow this app to be installed on all systems.", "allowedArchitecturesTooltip": "Select 'Yes' to specify the systems the app can be installed on. Select 'No' (default) to allow this app to be installed on all systems.", "allowedArchitecturesYesRadioButton": "Yes. Specify the systems the app can be installed on.", "architectures": "Operating system architecture", "architecturesTooltip": "Choose the architectures needed to install the app.", "bladeTitle": "Requirements", "diskSpace": "Disk space required (MB)", "diskSpaceTooltip": "Free disk space needed on the system drive to install the app.", "header": "Specify the requirements that devices must meet before the app is installed:", "maximumTextFieldValue": "The value must be at most {0}.", "minimumCpuSpeed": "Minimum CPU speed required (MHz)", "minimumCpuSpeedTooltip": "The minimum CPU speed required to install the app.", "minimumLogicalProcessors": "Minimum number of logical processors required", "minimumLogicalProcessorsTooltip": "The minimum number of logical processors required to install the app.", "minimumOperatingSystem": "Minimum operating system", "minimumOperatingSystemTooltip": "Select the minimum operating system needed to install the app.", "minumumTextFieldValue": "The value must be at least {0}.", "physicalMemory": "Physical memory required (MB)", "physicalMemoryTooltip": "Physical memory (RAM) required to install the app.", "selectorLabel": "Requirements", "validNumber": "Please enter a valid number." }, "Win32ReturnCodes": { "bladeTitle": "Return codes", "CodeTypes": { "failed": "Failed", "hardReboot": "Hard reboot", "retry": "Retry", "softReboot": "Soft reboot", "success": "Success" }, "Columns": { "codeType": "Code type", "returnCode": "Return code" }, "gridAriaLabel": "Return codes", "header": "Specify return codes to indicate post-installation behavior:", "onAddAnnounceMessage": "Return code added item {0} of {1}", "onDeleteSuccess": "Return code {0} deleted successfully", "returnCodeAlreadyUsedValidation": "Return code is already used.", "returnCodeMustBeIntegerValidation": "Return code should be an integer.", "returnCodeShouldBeAtLeast": "Return code should be at least {0}.", "returnCodeShouldBeAtMost": "Return code should be at most {0}.", "selectorLabel": "Return codes" }, "WindowsDriverUpdateProfile": { "ApprovalMethod": { "automatic": "Automatically approve all recommended driver updates", "manual": "Manually approve and deploy driver updates" }, "BulkActions": { "button": "Bulk actions" }, "Details": { "ApprovalMethod": { "label": "Approval method:" }, "availabilityDate": "Make available in Windows Update", "bladeTitle": "Driver updates Windows 10 and later (preview)", "DeploymentDeferralInDays": { "label": "Make updates available after", "units": "(days)", "value": "{0} days" }, "DriverAction": { "header": "Select an action below.", "label": "Driver action", "placeholder": "Select an action" }, "IncludedDrivers": { "label": "Included drivers" }, "lastSync": "Last sync:", "lastSyncDefaultText": "Pending initial inventory collection", "loadError": "Loading failed!", "SelectDrivers": { "header": "Select drivers to include in your bulk action" }, "SelectDriversToInclude": { "button": "Select drivers to include" }, "SelectedDrivers": { "label": "Selected drivers" }, "SelectLessDrivers": { "validation": "At most one hundred drivers can be selected" }, "SelectMoreDrivers": { "validation": "At least one driver should be selected" } }, "driverAddFilter": "Add filter", "driverApplicableDevices": "Applicable devices", "driverApprovalStatus": "Status", "driverBulkActions": "Bulk actions", "driverClass": "Driver class", "driverCount": "Showing {0} to {1} of {2} records", "driverFilterNoneSelected": "None selected", "driverManufacturer": "Manufacturer", "driverName": "Driver name", "driverNameLower": "windows driver update deployment", "driverNameUpper": "Windows driver update deployment", "driverRefresh": "Refresh", "driverReleaseDate": "Release date", "driverSearch": "Search", "driverSearchKeyword": "Enter search keyword", "DriverStatus": { "approved": "Approved", "declined": "Declined", "export": "Exporting recommended drivers", "needsReview": "Needs review", "paused": "Paused" }, "DriversToReview": { "text": "{0} to review" }, "driverVersion": "Version", "firstDeploymentDate": "First Deployment", "infoBoxText": "Inventory can take up to 24 hours to populate after a policy is assigned and created.", "Subtitle": { "automatic": "Automatic approval driver update policy", "manual": "Manual approval driver update policy" }, "SyncNotification": { "failure": "Unable to sync {0}", "failureDescription": "We encountered an error and were unable to complete the requested sync. Please try again.", "pending": "{0} sync in progress", "pendingDescription": "We are retrieving the most recent data. This process may take several minutes.", "success": "{0} sync complete", "successDescription": "Sync with WUfB service completed at {0}" }, "SyncSpinner": { "text": "A sync is in progress. This could take several minutes. Look for an alert or check back in a few minutes." }, "TabName": { "basics": "Basics", "driverUpdateSettings": "Settings", "otherDrivers": "Other drivers", "properties": "Properties", "recommendedDrivers": "Recommended drivers" }, "textBlockText": "Select your policy approval and deployment settings. Choose to set up a policy to approve and deploy updates automatically or manually. The approval method cannot be changed once a policy is created, but changes to individual driver approvals and deployment details will be possible once an inventory is built for assigned devices." }, "WindowsEdgeAppConfig": { "Homepage": { "header": "Default Homepage URL", "tooltip": "Configures the default home page URL in Microsoft Edge Learn more." }, "InternetExplorerLevel": { "eleven": "Internet Explorer 11", "header": "Internet Explorer integration level", "mode": "Internet Explorer Mode", "none": "None", "tooltip": "Configure Internet Explorer integration. Learn more." }, "InternetExplorerList": { "header": "Internet Explorer integration list", "tooltip": "Configure the Enterprise Mode Site List. Learn more." }, "ManagedFavorites": { "header": "Managed favorites", "tooltip": "Configures a list of managed favorites. Learn more." }, "RestrictCutCopyPaste": { "header": "Restrict cut, copy and paste to non-corporate accounts", "tooltip": "Restrict cut, copy and paste to non-corporate accounts" } }, "WindowsEnrollment": { "AutoEnrollment": { "menuDescription": "Configure Windows devices to enroll when they join or register with Microsoft Entra ID.", "menuTitle": "Automatic Enrollment" }, "Cname": { "badRequest": "Unable to test CNAME, check the format of the CNAME value.", "details": "After configuring the CNAME resource records in your DNS, enter the corresponding domain here to confirm that it has been configured correctly. Changes to DNS records might take up to 72 hours to propagate.", "domain": "Domain", "domainValidationError": "Domain should be entered as CompanyDomain.TopLevelDomain", "error": "Unable to test CNAME.", "fail": "CNAME for {0} not configured or configured incorrectly.", "info": "Configuring a CNAME in your DNS saves your users from having to enter the address of the MDM server when enrolling their Windows devices.", "link": "http://go.microsoft.com/fwlink/?LinkId=839850", "menuDescription": "Test company domain CNAME registration for Windows enrollment.", "menuTitle": "CNAME Validation", "placeholder": "Enter a domain", "success": "CNAME for {0} is configured correctly.", "test": "Test", "testing": "Testing CNAME for {0}." }, "coManagementAuthorityDesc": "Configure co-management settings for Configuration Manager integration", "coManagementAuthorityTitle": "Co-management Settings ", "deploymentProfiles": "Windows Autopilot deployment profiles", "description": "Learn about the seven different ways a Windows 10/11 PC can be enrolled into Intune by users or admins.", "descriptionLabel": "Windows enrollment methods", "DevicePreparation": { "description": "Configure devices for initial provisioning.", "title": "Device preparation" }, "Devices": { "deleteEnrolledDevicesMessage": "Selected devices will be deleted from Windows Autopilot only. If any of these devices are currently enrolled, they will continue to be managed by Intune.", "deleteMultiselectLimitMessage": "Unselect at least {0} device(s) before retrying.", "deleteMultiselectLimitTitle": "Note that only 100 devices can be deleted per batch. {0} devices selected", "deleteSuccess": "Devices successfully deleted.", "deleteSuccessSerialNumber": "Successfully deleted device with serial number {0}", "deleteTimeout": "Device deletion took longer than normal.", "deleteTimeoutDescription": "Try refreshing the devices list.", "deleteTitle": "Are you sure you want to delete the selected devices? ({0} selected)", "failedToDeleteDevice": "Failed to delete device with serial number {0}", "failedToDeleteDevices": "Failed to delete devices.", "howManyDevicesDeleted": "{0} of {1} devices were deleted.", "menuDescription": "Manage Windows Autopilot devices.", "menuTitle": "Devices", "submittingDevicesForDeletion": "Submitting devices for deletion.", "submittingNumberDevicesForDeletion": "Submitting {0} devices for deletion.", "submittingOneDeviceForDeletion": "Submitting device with serial number {0} for deletion." }, "DjConnector": { "bladeDescription": "Intune connector for Active Directory (Preview)", "name": "Connector name", "status": "Status", "time": "Latest sync time" }, "DjConnectorAdd": { "bladeSubtitle": "Intune connector for Active Directory (Preview)", "bladeTitle": "Add connector", "section1Details": "Configure your account and server to connect to the on-premises Intune connector for Active Directory", "section2Details": "Download and install the on-premises Intune Connector for Active Directory", "section2Link": "Download the on-premises Intune Connector for Active Directory", "sectionHeader": "Configuring the Intune connector for Active Directory" }, "DjConnectors": { "bladeSubtitle": "Windows enrollment", "bladeTitle": "Intune Connector for Active Directory", "Cmd": { "add": "Add", "filter": "Filter", "refresh": "Refresh" }, "Column": { "name": "Connector name", "status": "Status", "syncTime": "Latest sync time", "version": "Version" }, "menuDescription": "Configure Microsoft Entra hybrid joined devices", "menuTitle": "Intune Connector for Active Directory", "StatusActive": { "plural": "{0} active connectors", "singular": "{0} active connector" } }, "EnrollmentSettings": { "description": "Configure enrollment settings such as blocking enrollment and assign to users.", "title": "Enrollment settings" }, "enrollmentStatusPage": "Enrollment Status Page", "MenuTitle": { "autopilot": "Windows Autopilot Deployment Program", "general": "General" }, "OSConfiguration": { "menuDescription": "Configure settings that users can use to recover Windows from a bootable flash drive.", "menuTitle": "Windows operating system recovery configuration" } }, "WindowsFeatureUpdate": { "EndOFSupportStatus": { "notSupported": "Not supported", "supported": "Supported", "supportEnding": "Support ending" } }, "WindowsFeatureUpdateProfile": { "Details": { "bladeTitle": "Feature update deployments", "deploymentSettingsTitle": "Deployment settings", "Description": { "label": "Description" }, "FeatureDeploymentSettings": { "header": "Feature deployment settings" }, "FeatureUpdateVersion": { "infoballoon": "This feature cannot downgrade a device.", "label": "Feature update to deploy" }, "GradualRolloutEndDate": { "label": "Final group availability" }, "GradualRolloutInterval": { "label": "Days between groups" }, "GradualRolloutStartDate": { "label": "First group availability" }, "loadError": "Loading failed!", "Name": { "label": "Name" }, "OptionalUpdate": { "label": "Required or optional update" }, "RolloutOptions": { "label": "Rollout options" }, "RolloutSettings": { "header": "When would you like to make the update available in Windows Update?" }, "ScopeSettings": { "header": "Configure scope tags for this policy." }, "StartDateOnlyStartDate": { "label": "First available date" }, "windows11EULA": "By selecting this Feature update to deploy you are agreeing that when applying this operating system to a device either (1) the applicable Windows license was purchased though volume licensing, or (2) that you are authorized to bind your organization and are accepting on its behalf the relevant Microsoft Software License Terms to be found here {0}.", "Windows11SideBySideInstall": { "disabled": "Disabled", "enabled": "Enabled", "infoBalloonContent": "Control whether to install the latest Windows 10 feature update to devices not eligible for Windows 11", "label": "When a device isn't eligible to run Windows 11, install the latest Windows 10 feature update", "notApplicable": "Not Applicable", "summaryLabel": "Install Windows 10 on devices not eligible to run Windows 11" } }, "gradualRolloutLicenseWarning": "This capability requires specific licensing.", "gradualRolloutLicenseWarningEdit": "This capability may continue to be used and configured until the policy is saved without this capability selected.", "licenseLearnMoreText": "Learn more about pre-requisites and feature update policies.", "Notifications": { "deploymentSaved": "\"{0}\" has been saved.", "newFeatureUpdateDeploymentCreated": "New feature update deployment created." }, "optionalUpdateWarning": "Optional is available for Windows 11 updates only", "profileNameWarning": "Name should be less than 255 characters", "specificLicensingRequired": "Some selected capabilities require specific licensing.", "TabName": { "deploymentSettings": "Deployment settings", "groupAssignmentSettings": "Assignments", "scopeSettings": "Scope tags" } }, "WindowsManagement": { "Assignment": { "noAssignmentCustomAttributeDisplayText": "Assign custom attribute to at least one group. Go to Properties to edit assignments.", "noAssignmentDisplayText": "Assign Powershell script to at least one group. Go to Properties to edit assignments.", "noAssignmentShellScriptDisplayText": "Assign shell script to at least one group. Go to Properties to edit assignments." }, "createButtonText": "Add", "createPowershellScriptFlowSectionName": "Add PowerShell script", "customAttributeObjectName": "Custom attribute", "CustomAttributes": { "customAttributeScriptDescription": "Max file size 1 MB.", "customAttributeScriptLabel": "Script", "customAttributeTypeDescription": "Select the data type of the result.", "customAttributeTypeLabel": "Data type of attribute", "dateTypeOption": "Date", "integerTypeOption": "Integer", "noAttributes": "The custom attributes you add will appear here. Add a custom attribute to get started.", "settingsTabHeader": "Attribute settings", "stringTypeOption": "String" }, "editPowershellScriptFlowSectionName": "Edit PowerShell script", "enforceSignatureCheckInfoBalloonContent": "The script must be signed by a trusted publisher. This is the default.", "enforceSignatureCheckLabel": "Enforce script signature check", "executionFrequencyLabel": "Execution Frequency", "ExecutionStatus": { "Columns": { "deviceName": "Device", "lastStateUpdateDateTime": "Last Updated", "osVersion": "OS Version", "result": "Result", "runState": "Status", "userPrincipalName": "User name" }, "fail": "Failed", "notApplicable": "Not Applicable", "success": "Succeeded", "unknown": "Unknown" }, "failedToSavePolicy": "Failed to save {0}", "Mac": { "blockNotifications": "Hide script notifications on devices", "blockNotificationToolTip": { "toolTip": "Device users won’t receive script-related messages in Notification Center while the script is running. When not configured, these messages are shown in Notification Center." }, "executionFrequency": "Script frequency", "executionFrequencyToolTip": { "toolTip": "How often the script runs." }, "runMode": "Run script as signed-in user", "runModeToolTip": { "toolTip": "By default, the script is run as the root user. The root user can make system changes that a standard user account can't." }, "scriptRetry": "Max number of times to retry if script fails", "uploadFile": "Upload script", "uploadFileToolTip": { "toolTip": "Max file size 1 MB." } }, "newWMPolicyBladeSubtitle": "Windows 10 and later", "newWMPolicyBladeSubtitleMac": "macOS", "noScriptsTitle": "The scripts you add will appear here. Add a script to get started.", "PolicyFrequency": { "days1": "Every 1 day", "hours1": "Every 1 hour", "hours12": "Every 12 hours", "hours2": "Every 2 hours", "hours3": "Every 3 hours", "hours6": "Every 6 hours", "minutes15": "Every 15 minutes", "minutes30": "Every 30 minutes", "title": "Frequency of execution", "weeks1": "Every 1 week" }, "PolicyListToolBarOption": { "linux": "Linux", "macOs": "macOS", "windows": "Windows 10 and later" }, "PolicyRetry": { "times1": "1 time", "times2": "2 times", "times3": "3 times", "title": "Number of times to retry" }, "powerShellScriptObjectName": "PowerShell script", "reviewButtonText": "Review + add ", "runAs64BitInfoBalloonContent": "The script will run in a 64-bit PowerShell Host for a 64-bit client architecture. By default, the script will run in a 32-bit PowerShell Host.", "runAs64BitLabel": "Run script in 64 bit PowerShell Host", "scriptContextInfoBalloonContent": "The script runs with the users’ credentials on the client computer. By default, the script runs in user context.", "scriptContextLabel": "Run this script using the logged on credentials", "scriptsettingsTabHeader": "Script settings", "settingsHeader": "Select a script to configure", "shellScriptObjectName": "Shell script", "successfullySavedPolicy": "Saved {0}", "Titles": { "editCustomAttribute": "Edit custom attribute", "editShellScript": "Edit shell script" }, "UploadFile": { "contentRequiredWarning": "Script content required", "invalidFile": "Invalid file type.", "uploadInfoBalloonContent": "Specify the PowerShell script file. File must be less than 200KB.", "uploadLabel": "Script location" } }, "WindowsQualityUpdateDaysUntilForcedReboot": { "oneDay": "1 day", "twoDays": "2 days", "zeroDays": "0 days" }, "WindowsQualityUpdateProfile": { "Details": { "bladeTitle": "Quality updates Windows 10 and later (preview)", "DaysUntilForcedReboot": { "label": "If a reboot is required, select the number of days before it's enforced" }, "Description": { "label": "Description" }, "loadError": "Loading failed!", "Name": { "label": "Name" }, "QualityUpdateRelease": { "label": "Select the quality update you would like to Expedite" } }, "infoBoxText": "The only dedicated quality update control currently available other than the existing update rings policy for Windows 10 and later is the ability to expedite quality updates for devices that fall behind a specified patch level. Additional controls will be available in the future.", "licenseLearnMoreText": "Learn more about pre-requisites and quality update policies.", "licenseWarningBoxText": "Creating quality update policies requires specific licensing.", "TabName": { "qualityUpdateSettings": "Settings" }, "warningBoxText": "While expediting software updates can help decrease the time to get to compliance when necessary, it has a larger impact on end-user productivity. The chances that they will experience a restart during business hours is significantly increased." }, "WindowsUpdateRolloutOptions": { "gradualRollout": "Make update available gradually", "immediateStart": "Make update available as soon as possible", "startDateOnly": "Make update available on a specific date" }, "WIPPinRequirements": { "WipLowercaseCharacterPinRequirements": { "allow": "Allow the use of lowercase letters in PIN", "notAllow": "Do not allow the use of lowercase letters in PIN", "requireAtLeastOne": "Require the use of at least one lowercase letter in PIN" }, "WipSpecialCharacterPinRequirements": { "allow": "Allow the use of special characters in PIN", "notAllow": "Do not allow the use of special characters in PIN", "requireAtLeastOne": "Require the use of at least one special character in PIN" }, "WipUppercaseCharacterPinRequirements": { "allow": "Allow the use of uppercase letters in PIN", "notAllow": "Do not allow the use of uppercase letters in PIN", "requireAtLeastOne": "Require the use of at least one uppercase letter in PIN" } }, "WipPolicySettings": { "addNetworkBoundary": "Add network boundary", "addNetworkBoundaryButton": "Add network boundary...", "allowWindowsSearch": "Allow Windows Search to search encrypted corporate data and Store apps", "authoritativeIpRanges": "Enterprise IP Ranges list is authoritative (do not auto-detect)", "authoritativeProxyServers": "Enterprise Proxy Servers list is authoritative (do not auto-detect)", "boundaryType": "Boundary type", "cloudResources": "Cloud resources", "corporateIdentity": "Corporate identity", "dataRecoveryCert": "Upload a Data Recovery Agent (DRA) certificate to allow recovery of encrypted data", "editNetworkBoundary": "Edit network boundary", "enrollmentState": "Enrollment state", "internalProxyServers": "Internal proxy servers", "iPv4Ranges": "IPv4 ranges", "iPv6Ranges": "IPv6 ranges", "maxInactivityTime": "Maximum amount of time (in minutes) allowed after the device is idle that will cause the device to become PIN or password locked", "maxPasswordAttempts": "Number of authentication failures allowed before the device will be wiped", "mdmDiscoveryUrl": "MDM discovery URL", "mdmRequiredSettingsInfo": "This policy only applies to Windows 10 Anniversary Edition and higher. This policy uses Windows Information Protection (WIP) to apply protection.", "minimumPinLength": "Set the minimum number of characters required for the PIN", "name": "Name", "networkBoundariesGridEmptyText": "Any network boundaries you add will show up here", "networkBoundary": "Network boundary", "networkDomainNames": "Network domains", "neutralResources": "Neutral resources", "passportForWork": "Use Windows Hello for Business as a method for signing into Windows", "pinExpiration": "Specify the period of time (in days) that a PIN can be used before the system requires the user to change it", "pinHistory": "Specify the number of past PINs that can be associated to a user account that can’t be reused", "pinLowercaseLetters": "Configure the use of lowercase letters in the Windows Hello for Business PIN", "pinSpecialCharacters": "Configure the use of special characters in the Windows Hello for Business PIN", "pinUppercaseLetters": "Configure the use of uppercase letters in the Windows Hello for Business PIN", "protectedDomainNames": "Protected domains", "protectUnderLock": "Prevent corporate data from being accessed by apps when the device is locked. Applies only to Windows 10 Mobile", "proxyServers": "Proxy servers", "requireAppPin": "Disable app PIN when device PIN is managed", "requiredSettings": "Required settings", "requiredSettingsInfo": "Changing the scope or removing this policy will decrypt corporate data.", "revokeOnMdmHandoff": "Revoke access to protected data when the device enrolls to MDM", "revokeOnUnenroll": "Revoke encryption keys on unenroll", "rmsTemplateForEdp": "Specify the template ID to use for Azure RMS", "showWipIcon": "Show the enterprise data protection icon", "type": "Type", "useRmsForWip": "Use Azure RMS for WIP", "value": "Value", "weRequiredSettingsInfo": "This policy only applies to Windows 10 Creators Update and higher. This policy uses Windows Information Protection (WIP) and Windows MAM to apply protection.", "wipProtectionMode": "Windows Information Protection mode", "withEnrollment": "With enrollment", "withoutEnrollment": "Without enrollment" } }