UEMB360: Ivanti MDM: Similarities and Differences Managing iOS, macOS, Android and Windows 10

GoIvanti 448 views 35 slides Jun 28, 2017
Slide 1
Slide 1 of 35
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30
Slide 31
31
Slide 32
32
Slide 33
33
Slide 34
34
Slide 35
35

About This Presentation

Ivanti MDM: Similarities and Differences Managing iOS, macOS, Android and Windows 10 via MDM
Plinio Pimentel
Jason Forsgren


Slide Content

UEMB360 -Ivanti MDM: Similarities and
Differences Managing iOS, macOS,
Android and Windows 10 via MDM
Plinio Pimentel and Jason Forsgren

Agenda
Enrollment1
Profiles2
Applications3
Dual Managed 4
Demo5

§Enrollment

Enrollment
Workflow1
DNS Configuration2
General Configuration3

Workflow
Mobile Devices
CSA
Firewall
Windows Devices
(enrollment)
Console
Core
APNS /FCM (GCM) / WINS
DNS

DNS configuration
§DNS entry to redirect to CSA
§Allows enrollment without having to type the CSA domain name
§Only available for iOS, MAC and Android enrollment
§Windows DNS mappings
§Allows enrollment in environments where there are redirections
§E.g. Office365, Federated Authentication
§Trick the Windows Enroller to go where we want

DNS text string
§Apple (iOS / Mac)
§iOS-enroll=https://[CSA URL]/rtc/[CORE NAME]/MDM/api/v1/IosEnroll
§Android
§Android-enroll=https://[CSA URL]/rtc/[CORE NAME]/MDM/api/v1/AndroidEnroll
§Windows
§Add a (CNAME) to use e-mail to resolve to a different Domain

Configuration
§DNS Text
§APNS, FCM(GCM), WINS
§Certificate from apnsportal.landesk.com (License credentials)
§FCM requires Google credentials
§WINS requires a Microsoft developer account (small fee)
§CSA selection

Domain mappings
§Used with Windows enrollment only
§Required since we use the native Windows Enroller

*Note: If DNS is not available, the server address is presented and you only need to type:
https://[CSA URL]/Core Name]

§Profiles

Profiles
Entities1
Inventory2

Profile entities
§Agent behaviors
§Compliance
§Connectivity
§Exchange/Office365
§Security
ScheduledTask
AgentBehaviors
Profilesand
Certificates

Entities cont.
ScheduledTask
AgentBehaviors
Profilesand
Certificates
Last scheduled task wins
You can have default behaviors
Agent behaviors can have more
than one profile, and profiles can
be enable or disabled.

Inventory
§Currently, reporting agent behaviors and scheduled tasks
§With the current implementation there are differences on how profiles
are applied.
§E.g. Apple most restrictive wins, and Wi-Fi will not be yanked if connected
§Compliance behaviors have no “Default” because they have restrictions
inside of them, like only apply if the device matches some criteria

§Applications

Applications
macOS / iOS1
Android2

iOS and macOS
§Apple Volume Purchase Program
§Purchase bulk apps from app store
§Add bulk token to Core Server
§Free apps, Links and Documents
§Manifest or Custom Apps

Android
§Distribution of free apps
§Distribution of links an documents
§Distribution of Manifests or Custom Apps
§Behavior dependent on the Agent
§Android for Enterprise Agent
§Profile owner mode (BYOD)
§Device owner mode (Corporate owns the device)
§Android Agent
§Regular management (Mingle data)

§Dual Managed

Dual Managed
Why/Scenarios1
What to watch for2

Why and when should I use it?
§macOS want to distribute VPP apps
§Windows wants to configure Wi-Fi / Email settings but still needs
full management
§The device was migrated from MDM to Full Management

What to watch for?
§macOS
§They will always share Device ID (Hardware based)
§SYNC Scan will temporarily override the agent scan

What to watch for?
§Windows
§If the Device was had an agent and then enrolled in MDM
§It will use current duplicate detection logic but it may take a couple
scans
§MDM Sync scan will override temporarily the full scan
§Both can co-exists

§Sneak Preview

Some of what is coming to MDM
§Group enrollment
§iOS Profile Configurations
§macOSProfile Configurations
§Applied Profiles(agent behaviors) shown in Inventory
§“Moving more into a “State Management”
§Master Configuration and Applications
§Windows 10 Enhancements
§MDM Software Distribution
§Software inventory

§Demo

Thank you