CM Client Settings

Table of Contents

Categories ITSOs may want to focus on include:

Client Cache Settings - This determines how much cache is available for deploying applications. If you have unusually large application packages you may want increased values in this category.  The default cache size is 10 GB.
Power Management - These controls Wake on LAN and similar settings.
Software Center - This controls branding information, selecting which tabs are visible in Software Center as well as the view defaults.
Computer Agent - This controls various general management settings.
Computer Restart - This controls restart settings related to software updates.

  • Custom client settings can be deployed as the default for all of your computers, or variations of the same setting can be applied to different collections of computers.
  • Client settings are applied using a priority system.  The "highest" priority is 1 and will always be the final settings applied, this is reserved for settings EPM needs to enforce for all.  The "Default Client Settings" priority is set to 10000, these settings will apply to all endpoints unless a custom Client Settings with a higher priority has been created and deployed.
  • Full Microsoft documentation on client settings can be found at Client settings - Configuration Manager | Microsoft Docs


The values below are the "Default client settings". Custom settings can be requested except where indicated.


Values shaded in GRAY not applicable even though they have a displayed value, this is due to a parent feature being disabled or not applicable.
Values shaded in RED are set by EPM, these will override custom client settings set by an ITSO. 

Note

Modifications to the client settings must be submitted to the EPM team to ensure changes made to client settings will not negatively impact the platform.
Send requests to epm-requests@its.utexas.edu


Client Setting Category

SettingValue

Background Intelligent Transfer


Limit the maximum network bandwidth for BITS background transfersNo

Throttling window start time9 AM

Throttling window end time5 PM

Maximum transfer rate during throttling window (Kbps)1000

Allow BITS downloads outside the throttling windowNo

Maximum transfer rate outside the throttling window (Kbps)9999


Cloud Services


Allow access to cloud distribution pointYes

Automatically register new Windows 10 or later domain joined devices with Azure Active DirectoryYes

Enable clients to use a cloud management gatewayYes


Client Cache Settings


Configure BranchCacheNo

Enable BranchCacheNo

Maximum BranchCache cache size (percentage of disk)10

Configure client cache sizeNo

Maximum cache size (MB)5120

Maximum cache size (percentage of disk)20

Enable as peer cache sourceNo

Port for initial network broadcast8004

Port for content download from peer8003


Client Policy


Client policy polling interval (minutes)60

Enable user policy on clientsYes

Enable user policy requests from Internet clientsNo

Enable user policy for multiple user sessionsYes


Compliance Settings


Enable compliance evaluation on clientsYes

Schedule compliance evaluationOccurs every 4 days effective 05/18/2019 7:00 AM

Enable User Data and profilesNo


Computer Agent


Deployment, deadline greater than 24 hours, remind user every (hours)48

Deployment, deadline less than 24 hours, remind user every (hours)4

Deployment, deadline less than 1 hour, remind user every (minutes)15

Default Application Catalog website point(none)

Add default Application Catalog website to Internet Explorer trusted sites zoneYes

Allow Silverlight applications to run in elevated trust modeYes

Organization name displayed in Software CenterUT Austin Software

Use new Software CenterYes

Enable communication with Health Attestation ServiceYes

Use on-premises Health Attestation ServiceNo

On-premises Health Attestation Service URL

Install permissionsAll users

Suspend BitLocker PIN entry on restartNever

Additional software manages the deployment of applications and software updatesNo

PowerShell execution policyBypass

Show notifications for new deploymentsYes

Grace period for enforcement after deployment deadline (hours)0

Enable Endpoint Analytics data collectionYes


Computer Restart


Configuration Manager can force a device to restartYes

Specify the amount of time after the deadline before a device gets restarted (minutes)90

Specify the amount of time that a user is presented a final countdown notification before a device gets restarted (minutes)15

After the deadline, specify the frequency of restart reminder notifications to the user (minutes)240

When a deployment requires a restart, show a dialog window to the user instead of a toast notificationNo

When a deployment requires a restart, allow low-rights users to restart a device running Windows ServerNo


Delivery Optimization


Use Configuration Manager Boundary Groups, for Delivery Optimization Group IDNo

Enable devices managed  by Configuration Manager to use Microsoft Connected Cache servers for content downloadNo


Endpoint Protection


Manage Endpoint Protection client on client computersYes

Install Endpoint Protection client on client computersYes

Allow Endpoint Protection client installation and restart outside maintenance windows. Maintenance windows must be at least 30 minutes long for client installation.No

For Windows Embedded devices with write filters, commit Endpoint Protection client installation (requires restart)Yes

Suppress any required computer restarts after the Endpoint Protection client is installedYes

Allowed period of time users can postpone a required restart to complete the Endpoint Protection installation (hours)24

Disable alternate sources (such as Microsoft Windows Update, Microsoft Windows Server Update Services, or UNC shares) for the initial security intelligence update on client computersYes


Hardware Inventory


Enable hardware inventory on clientsYes

Hardware inventory scheduleOccurs every 7 days effective 2/1/1970 12:00 AM

Maximum random delay (minutes)240

Hardware inventory classesDefault inventory classes


Metered Internet Connections


Client communication on metered Internet connectionsBlock


Enrollment


Polling interval for modern devices (minutes)1440

Allow users to enroll mobile devices and Mac computersNo

Enrollment Profile(none)

Allow users to enroll modern devicesNo

Modern device enrollment profile(none)


Power Management


Allow power management of devicesYes

Allow users to exclude their device from power managementNo

Allow network wake-upNot configured

Enable wake-up proxyNo

Wake-up proxy port number (UDP)25536

Wake on LAN port number (UDP)9

Windows Defender Firewall exception for wake-up proxyDisabled

IPV6 prefixes if required for DirectAccess or other intervening network devices. Use a comma to specify multiple entries.


Remote Tools


Firewall exception profilesN/A

Users can change policy or notification settings in Software CenterNo

Allow remote control of an unattended computerYes

Prompt user for Remote Control permissionYes

Prompt user for permission to transfer content from share clipboardNo

Grant Remote Control permission to local Administrators groupYes

Access level allowedFull Control

Permitted viewers of Remote Control and Remote Assistance(none)

Show session notification icon on taskbarYes

Show session connection barYes

Play sound on clientBeginning and end of session

Manage unsolicited Remote Assistance settingsNo

Manage solicited Remote Assistance settingsNo

Level of access for Remote AssistanceNone

Manage Remote Desktop settingsNo

Allow permitted viewers to connect by using Remote Desktop connectionNo

Require network level authenticationYes


Software Center


Select the user portalSoftware Center

Select these new settings to specify company informationYes

Software Center settings


Software Deployment


Schedule re-evaluation for deploymentsOccurs every 7 days effective 02/01/1970 12:00 AM


Software Inventory


Enable software inventory on clientsYes

Schedule software inventory and file collectionOccurs every 7 days effective 05/19/2019 12:00 AM

Inventory reporting detailFull details

Inventory these files types(none)

Collect files(none)


Software Metering


Enable software metering on clientsYes

Schedule data collectionOccurs every 7 days effective 02/01/1970 12:00 AM


Software Updates


Enable software updates on clientsYes

Software update scan scheduleOccurs every 1 days effective 04/07/2022 3:30 PM

Schedule deployment re-evaluationOccurs every 1 days effective 04/07/2022 4:00 PM

Allow user proxy for software update scansNo

Enforce TLS certificate pinning for Windows Update client for detecting updatesYes

When any software update deployment deadline is reached, install all other software update deployments with deadline coming within a specified period of timeNo

Period of time for which all pending deployments with deadline in this time will also be installed1 Hours

Allow clients to download delta content when availableNo

Port that clients use to receive requests for delta content8005

If delta content is unavailable from distribution points in the current boundary group, immediately fall back to a neighbor or the site defaultNo

Enable management of the Office 365 Client AgentYes

Enable update notifications from Microsoft 365 AppsNo

Enable installation of software updates in "All deployments" maintenance window when "Software update" maintenance window is availableNo

Specify thread priority for feature updatesNot Configured

Enable third party software updatesYes

Enable Dynamic Update for feature updatesNot Configured


State Messaging


State message reporting cycle (minutes)15


User and Device Affinity


User device affinity usage threshold (minutes)2880

User device affinity usage threshold (days)30

Automatically configure user device affinity from usage dataNo

Allow user to define their primary devicesNo


Windows Diagnostic Data


Manage Windows telemetry settings with Configuration ManagerNo

Commercial ID key:

Windows 10 telemetryRequired

Windows 8.1 and earlier telemetry:Disable

Enable Windows 8.1 and earlier Internet Explorer data collection for:Disable



Related Information