Windows-Intune-Overview-Uk-MMS___________

ShikharMalhotra4 37 views 27 slides Apr 29, 2024
Slide 1
Slide 1 of 27
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27

About This Presentation

sfeqfewfew


Slide Content

Windows Intune Overview Susan Smith Intune TSP Microsoft UD-B335

For company-owned smartphones, only 55% of decision-makers say that their company has security policies and sufficient tools. The situation for employee-owned smartphones— only 30% of firms have policies and sufficient tools, and 15% lack policy entirely 1 1 ‘Mobile Workers Use Personal Apps to Solve Customer Problems — Is IT Ready, Willing, And Able To Assist? A September 2012 commissioned study conducted by Forrester Consulting on behalf of Unisys’ 61% of global enterprises provide IT support for company-owned smartphones and tablets, up from only 27% in 2011. This contrasts with 17% supporting employee-owned smartphones and tablets. 1 Worldwide total unit shipments for smart connected devices will reach 1.2B in 2012 , and grow 14% CAGR to over 2B units in 2016 IDC Press Release, IDC Expects Smart Connected Device Shipments to Grow by 14% Annually Through 2016, Led by Tablets and Smartphones September 26, 2012 No longer One User = One Desktop A World of Connected Devices

Enabling users to be productive, responsibly Finding the right balance Devices & Experiences Users Want Applications and data across devices, anywhere Empower User Productivity Unified Management Infrastructure Common Identity Access and Information Protection Controlled access to data with seamless authentication

Unified Device Management Single management interface Integrated security and compliance Improve IT efficiency Reduced infrastructure complexity Unified Management Infrastructure + Empower User Productivity Device choice Application self-service Personalized application Experience Non-intrusive management

What is Windows Intune? A service you can TRUST ISO/IEC 27001:2005 certified = Industry standard information security practices A service you can RELY on Financially backed SLA - 99.9% uptime A world class cloud-based device management service. Monthly Uptime Percentage Service Credit < 99.9% 25% < 99% 50% < 95% 100%

Windows Intune – Standalone service Devices & Platforms IT Single admin console Windows PCs (x86/64, Intel SoC ), Windows RT Windows Phone 8 iOS Android Windows Intune Standalone Service: Manage up to 5000 users

Windows Intune – Attached to System Center Configuration Manager 2012 Devices & Platforms IT Single admin console Windows PCs (x86/64, Intel SoC ), Windows to Go Windows Embedded Mac OS X Windows RT Windows Phone 8 iOS Android

Help protect PCs from malware Manage updates Proactive monitoring and alerts Provide remote assistance Inventory hardware and software Monitor & track licenses Increase insight with reporting Set security policies Distribute software Latest Release Richer Mobile Device Management Manage and Secure PCS and Devices Anywhere Simple web-based Administration Console and a richer experience for Information Workers

Demo: PC management with Windows Intune - Overview Susan Smith

PC Management - Demo scenario IT Pro walks into a cloud and sees Windows Intune…  Initial Configuration Setting up Windows Intune for PC management Managing users through Azure Active Directory Enrolling devices for management PC management - Security – Updates, Endpoint Protection, Security settings Planning - Asset Management – SW/HW inventory, Licensing Support - Remote Tasks Productivity - PC Software distribution

Preserving the Windows 8 experience Management tasks can work with the Windows 8 maintenance window No distractions from management tasks (reboots) Does not use up computer resources when the user is active Reduced background activity to preserve battery life Management tasks do not interrupt if the end user immersed in a modern application Windows Intune suppresses interruptions reboots for updates that were installed without a deadline Windows Intune provides sufficient lead time to the user before an automatic reboot Windows Intune leverages the Windows 8 toast and respects user’s settings for notifications

Functionality changes to note No monitoring for Windows 8 platform No remote assistance in Windows 8 and Windows RT

Mobile Device Management with Windows Intune EAS based management Introduced in last release Direct management (Windows RT, Windows Phone8, iOS ) (New!) Over-the-air enrollment of devices for management Mobile application management Settings Management Mobile device inventory Corporate data protection

Application management on mobile devices Platforms Windows 8/Windows RT Windows Phone 8 iOS Android Sideload to install *. appx *. xap *. ipa *. apk Deep links to store apps – install from store

Software distribution summary Platform Desktop Apps (. msi , . exe) Modern App Types Side loading Deep Links web apps . appx . xap . ipa . apk Windows 8 Pro/ Ent √ √ √ √ Windows RT ** iOS   √ √ √ Android √ WP8   √ √ √ Windows 7 and below √       √   Not a supported app type on that specific platform √ Available since last release √ Added in latest release ** Windows 8 SSP on WinRT will show MSI/EXE apps that can remotely install to other PCs linked to the user, but not installable on the local Window RT device

Policy Security policy on devices ( iOS , Windows RT and WP8) Direct management and Exchange ActiveSynch . Recommendation: Manage policy through only one management authority Android and Windows Phone 7 devices can be managed through EAS The same security policy template is used for both Direct Management and EAS to help Admins Reporting available on each setting whether it is applicable, conformant or has an error.

Setting name EAS (Activesync) WinRT / WinPh8 iOS Require a password to unlock mobile devices √ √ √ Required password type √ √ √ Minimum password length √ √ √ Allow simple passwords √ √ √ Number of repeated sign-in failures before device is wiped √ √ √ Minutes of inactivity before device screen is locked √ √ √ Password expiration (days)   √ √ √ Remember password history √ √ √ Allow convenience logon ( WindowsRT only) X √ X Allow camera   √ X √ Allow web browser   √ X √ Allow backup to iCloud   (iOS only) X X √ Allow documents sync to iCloud   (iOS only) X X √ Allow photostream sync to icloud (iOS only) X X √ Maximum size of  e-mail attachments   √ X X E-mail synchronization for last (days)   √ X X Allow mobile devices that don’t fully support these settings to synchronize with Exchange √ X X Require encryption on mobile device   √ X X Require encryption on storage cards   √ X X Password Device restrictions Email Encryption Mobile Device Settings

Mobile device inventory Hardware properties for mobile devices are collected through the Device Management Authority as well as Exchange ActiveSync (for Android) No software inventory for mobile devices to respect the Information Worker’s privacy on their own device IT Pros can track storage on mobile devices which help them anticipate/troubleshoot issues

Mobile Device Inventory Property Win RT WP8 iOS Android (EAS) Device name Y Y Y Y Unique device ID Y Y Y Serial number Y Email address Y Y Y Y OS type Y Y Y OS version Y Y Y Y OS language Y Y Total storage space (GB) Y Y Free Storage space (GB) Y Y System enclosure Chassis Y System enclosure IMEI Y Manufacturer Y Y Model Y Y Y Y Phone number (masked except last 4 digits) Y Y Subscriber carrier Y Cellular technology(none, GSM, CDMA) Y WiFI MAC Y Y Enrolled date (local time) Y Y Y Last contact (local time) Y Y Y Y Last Exchange status Y Last Policy update status Y Access State Y Access state reason Y Management state Y ActiveSync ID Y

Demo : Mobile Device Management with Windows Intune Including Intune-Office365 Integration Susan Smith

MDM – Demo scenario IT Pro wants to enable IWs to work from BYOD devices Initial Configuration Setting up Windows Intune MDM Setting up Windows Intune for Mobile software distribution Enrolling devices for management MDM Settings management Hardware inventory User centric mobile software distribution

Recap: MDM features per platform Management Feature Windows RT Windows Phone 8 iOS Android Over-the-air Enrollment Y Y Y N Inventory Y Y Y Y Settings Management Y Y Y Y Software Distribution Y Y Y Y Remote Wipe N Y Y Y

Information Worker(IW) self-service experience Connect every user ‘s device to the service Each platform is supported with an end user experience Enable them to discover applications Access applications or web links recommended by the IT pro Install Line Of Business (LOB) applications supplied by the IT pro Let users manage their own devices and data End users can enroll, rename and un-enroll devices End users can wipe data or email Provide a premium end user experience Minimal interruptions from management tasks End user privacy is respected End user in control of their mobile devices Users in control of configuring their devices Productive on their own device Choose their applications on their devices

Demo – IW in Control - Company App Susan Smith

End User Experience Consistent self service experience for end user across mobile platforms Native Windows app package (. appx ) Available in the Windows Store Windows Phone 8 Company Portal iOS /Android Company Portal Native Windows Phone 8 app (. xap ) Needs to be sideloaded Web based portal Hosted in Windows Intune Windows RT Company Portal

Recap: End user capabilities for each platform Windows 8 Ent /Pro Windows RT Windows Phone 8 iOS Android Enroll (local device) Yes Yes Yes Yes EAS Rename devices Yes Yes No No No Retire (un-enroll local device) Yes Yes Yes No No Wipe (remotely other devices) Yes Yes No No No Install enterprise LOB applications Yes Yes Yes Yes Yes Install publicly available applications Yes Yes Yes Yes yes Browse to web links Yes Yes Yes Yes Yes Install apps (remotely on other devices) Yes (only msi /exe) Yes (only msi /exe) No No No Contact IT Yes Yes No Yes Yes

Corporate Data Protection – Retire and Wipe All devices and PCs can be retired Retiring a device removes the record of the device from Intune management Retiring a device impacts Application distribution and Policies on the retired device Wipe option depends on the platform and management type (EAS or native) Complete wipe and reset to factory defaults – iOS and WP8 EAS mailbox removal only - Android Only EAS mailbox removal if managed through EAS - Windows RT and Windows 8 Enterprise and Professional No wipe - Windows 7 and below (no change from previous release)
Tags