New modern management features for IT pros 9/11/2018 11:17 AM BRK3073 New modern management features for IT pros Tanvir Ahmed Program Manager @mdm_tanvir Mamta Kumar Senior Program Manager @ZuprMamtaKumar Jeremy Moskowitz Microsoft MVP @jeremymoskowitz © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
The Classic Workplace The Digital Transformation The Modern Workplace 9/11/2018 11:17 AM The Digital Transformation The Modern Workplace © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Characteristics of Traditional PC Management 9/11/2018 11:17 AM Characteristics of Traditional PC Management Classic Workplace On-Premises Infrastructure High Control with ConfigMgr and GPOs Business-owned Devices © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Characteristics of Mobile Device Management 9/11/2018 11:17 AM Characteristics of Mobile Device Management Modern Workplace Cloud Services Simpler IT Process Business-owned & BYOD © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
The Promises of Modern Management 9/11/2018 11:17 AM The Promises of Modern Management MODERN WORKPLACE CLOUD IT LOWER TCO © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
What do you get from MMAT? 9/11/2018 11:17 AM What do you get from MMAT? Win10 MMAT GP Report IT admin Win7 © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Download MMAT from http://aka.ms/mmat
Paths to Modern Management 9/11/2018 11:17 AM Paths to Modern Management A new organization starting with modern workplace Cloud-first Many workloads need to be modernized at the same time Big Switch Transition Doesn't address the needs of the full organization Group by Group Transition Iteratively move workloads to modern Iterative (Co-management) © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Co-management Configuration Manager and Intune 9/11/2018 11:17 AM Co-management Configuration Manager and Intune Intune & Azure Active Directory ConfigMgr Software Distribution Patching Device Compliance On-premises Cloud Modern Management Modern Management © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Meet some folks from Contoso 9/11/2018 11:17 AM Meet some folks from Contoso IT admin at Contoso Information worker at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
As an IT admin, I need to… SECURE CORPORATE ASSETS 9/11/2018 11:17 AM As an IT admin, I need to… MAKE USERS PRODUCTIVE Office Pro Plus Deployment Delivery Optimization SECURE CORPORATE ASSETS Security Policies & Configuration BitLocker Management Security Baselines IT Admin at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
9/11/2018 11:17 AM With every release, MDM helps me meet my organization’s security needs! IT Admin at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Inbox management updates 9/11/2018 11:17 AM Inbox management updates Creators Update (1703) Fall Creators Update (1710) BitLocker management Firewall configuration Office Pro Plus deployment and configuration Interactive logon policies Selected Group Policy settings User account control Win32 app settings configuration Windows remote management With every release, MDM helps me meet my organization’s security needs! © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
BitLocker Management Demo 9/11/2018 11:17 AM BitLocker Management Demo © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
A closer look at BitLocker Management 9/11/2018 11:17 AM A closer look at BitLocker Management In MDM Console, IT Admin can view Encryption Compliance for entire org IT Admin can see status report that device is encrypted Go to MDM Console Enforce Disk Encryption for MDM enrolled devices What happens if you need your BitLocker Recovery key? Device Encryption status is sent to MDM BitLocker Recovery key is sent to AAD Call Help Desk, get Recovery key Device starts encryption. User can continue working on device OR Encrypt Access device, and start working again On 2nd device, go to AAD portal, get Recovery key Employee receives notification to start encryption Device completes encryption. With every release, MDM helps me meet my organization’s security needs! © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
When I move to MDM, I want to continue using Security Baselines. 9/11/2018 11:17 AM When I move to MDM, I want to continue using Security Baselines. IT Admin at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Windows Security Baselines 9/11/2018 11:17 AM Windows Security Baselines MDM Admin Portal http://mymdmserver.com/SecurityBaselines Security Baselines in Windows RS3 Security Baselines RS4 Security Baselines Basic UX Support with no customization Enabled MDM Security Baselines MDM Admin Portal http://mymdmserver.com/SecurityBaselines Security Baselines in Windows Internet Explorer Browser Advanced UX Support with Customization 66 settings available. Enable a category to configure settings SmartScreen Search Enabled MDM Admin Portal http://mymdmserver.com/SecurityBaselines Security Baselines in Windows – Internet Explorer Internet Explorer – Computer (32 settings) Internet Zone Allow Scriptlets Allow Enterprise Mode Site List Turn On Enhanced Protected Mode Enabled Allow font downloads MDM gets Baselines Customer gets Baselines When I move to MDM I want to continue using Security Baselines © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
I can easily deploy Office 365 Pro Plus to my organization using MDM. 9/11/2018 11:17 AM I can easily deploy Office 365 Pro Plus to my organization using MDM. IT Admin at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Office 365 ProPlus Office 365 ProPlus all apps
9/11/2018 11:17 AM MDM helps me deploy apps and keep my devices up to date with less bandwidth. IT Admin at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Windows Update + DO Services 9/11/2018 11:17 AM Total Bandwidth Usage Reduced Content Servers / WSUS Cache Windows Update + DO Services MDM helps me deploy apps and keep my devices up to date with less bandwidth. © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
As an information worker, I want to… 9/11/2018 11:17 AM As an information worker, I want to… EASILY SET UP MY DEVICE Deep linking support Enrollment status pages TRUST THROUGH TRANSPARENCY MDM Info Page Enhanced Diagnostics Report WORK FROM ANYWHERE Dynamic Management Mobile Application Management Information worker at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Information worker at Contoso 9/11/2018 11:17 AM Setting up my device was easy. I just clicked a link from my email and entered my password! Information worker at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
New deep links allow enrolling with fewer clicks 9/11/2018 11:17 AM New deep links allow enrolling with fewer clicks © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
09/25/2017
Setting up your device for work Applying security policies (1 of 3) Encrypting hard drive to keep your data safe Applying security policies (2 of 3) Installing security certificates Applying security policies (3 of 3) Configuring Windows Defender Security setup complete Adding network connections (2 of 3) Configuring VPN for remote access Adding network connections (3 of 3) Adding Contoso network connections Adding network connections (1 of 3) Adding Contoso WiFi network Adding network connections Waiting for previous step to complete Network setup complete Installing applications Waiting for previous step to complete Installing applications (1 of 3) Installing Expenses Installing applications (3 of 3) Installing Dynamics 365 Installing applications (2 of 3) Installing Office 2016 Application installation complete Leave everything to us. (Don’t turn off this device.)
Excel 2016 PowerPoint 2016
I can use my device for work no matter where I go! 9/11/2018 11:17 AM I can use my device for work no matter where I go! Information worker at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
MDM policies adapt to your environment 9/11/2018 11:17 AM MDM policies adapt to your environment Dynamic Management allows IT admins to apply policies dynamically based on: Time Location Network NO PARKING TOP SECRET WiFi Camera Email Java WiFi Camera Email WiFi Camera Email © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
MDM policies adapt to your environment 9/11/2018 11:17 AM MDM policies adapt to your environment Dynamic Management allows IT admins to apply policies dynamically based on: Time Location Network WiFi Camera Email Java WiFi Camera Email WiFi Camera Email TOP SECRET NO PARKING © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Full productivity doesn’t mean full management 9/11/2018 11:17 AM Full productivity doesn’t mean full management Mobile Application Management (MAM) is the management solution for personal (BYOD) devices. Supported on Desktop and Mobile Integrated with Azure AD WiFi Camera Email Employees can use their work and personal accounts with the same app Corporate identity and data can be removed without affecting users’ apps or personal data. Uses WIP to secure corporate data on personal devices Consistent admin and user experience with Intune MAM for iOS/Android Secure, integrates with Azure ID and delivers great user experience © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Information worker at Contoso 9/11/2018 11:17 AM My organization is fully transparent with what they are managing on my device. Information worker at Contoso © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Find out what is being managed in Settings
Diagnosing issues is a breeze with the new diagnostics report C:\Users\Public\Do file:///C:/Users/Public/Documents/MDMDiagnostics.html
MDM ISV Engagement & Support Microsoft Ignite 2015 9/11/2018 11:17 AM MDM ISV Engagement & Support © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Microsoft 365 Microsoft 365 powered device Unlocks creativity Microsoft Inspire 9/11/2018 11:17 AM Microsoft 365 Unlocks creativity Built for teamwork Integrated for simplicity Intelligent security Microsoft 365 powered device The best way to experience Microsoft 365 © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Microsoft 365 powered device Microsoft Inspire 9/11/2018 11:17 AM Microsoft 365 powered device Easy to deploy and manage Always up to date Proactive insights Intelligent security, built-in © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
9/11/2018 11:17 AM Session resources Windows 10 CSP reference docs: https://aka.ms/CSPDocs What’s new in Windows 10 for MDM: http://aka.ms/newinmdm Microsoft Security Compliance Toolkit: https://aka.ms/sectoolkit 1703 Security Baselines (DRAFT): https://aka.ms/mdm1703baselines Transitioning to modern management: https://technet.microsoft.com/itpro/windows/manage/manage-windows-10-in-your-organization-modern-management Why GP Is Not Dead Manifesto: https://www.gpanswers.com/the-why-group-policy-is-not-dead-manifesto/ Transition all GP / GPPrefs to MDM: https://www.policypak.com/integration/policypak-and-mdm-utilities.html © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Please evaluate this session Tech Ready 15 9/11/2018 Please evaluate this session From your Please expand notes window at bottom of slide and read. Then Delete this text box. PC or tablet: visit MyIgnite https://myignite.microsoft.com/evaluations Phone: download and use the Microsoft Ignite mobile app https://aka.ms/ignite.mobileapp Your input is important! © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.