Protect your data Enable your users Unify Your Environment DevicesAppsData Help organizations enable their users to be productive on the devices they.

Slides:



Advertisements
Similar presentations
Powerful and convenient management for Windows Mobile ® 6.1 devices in an enterprise environment. These features include: Centralized, over-the-air device.
Advertisements

People Centric IT Unified Device Management with SCCM + Windows Intune
Mobile Device Management Intune-Configmanager CHANDAN BHARTI PREMIER FIELD ENGINEER-MICROSOFT.
© 2009 VMware Inc. All rights reserved VMware Horizon Mobile Intro - NetHope Deepak Puri Director Mobile Business Development +1 (415)
2 Agenda Introductions – Kathleen Wetherell Introduction of the Enterprise Mobility Suite– Kathleen Wetherell Overview of Microsoft’s Intune with Product.
Windows 8.1 Device Management With Windows Intune Mark O’Shea MVP Windows Expert – IT Pro 30 June 2014.
Managing and Securing Devices using Exchange, System Center, and Intune LAWRENCE NOVAK MICHAEL INDENCE DMVMUG Reston, VA
Desktop Central Managing Desktops, Servers & Devices Romanus Prabhu R Technical Account Manager LinkedIn : romanus.prabhu.
Sophos Mobile Control. Tablets on the rise 2 Trends 3 75% of 157 polled companies encourage employee owned smart phones and tablets to access corporate.
Enterprise Mobility Platform Microsoft Differentiation Managed Mobile Productivity Layered Protection Hybrid Solutions Office 365DynamicsWorkday.
Protect your data Enable your users Unify Your Environment DevicesAppsData Help organizations enable their users to be productive on the devices they.
Plan Build Custom Image (Drivers, Apps, Updates) New Hardware In-Place (Refresh) WipeReimage New Windows Version or Major Image Revision.
SharePoint Server Exchange Server CORPORATE NETWORK Mobile devices PCs Browsers INTERNET DMZ Active Directory Policies Filter EAS Filter web access.
Script Kiddies; CybercrimeCyber-espionage; Cyber-warfare CybercriminalsState sponsored actions; Unlimited resources Attacks on fortune 500All sectors.
Microsoft Ignite /16/2017 3:59 PM
Management lifecycle summary Mobile Device Management with Windows Intune or 3 rd Party tools Simplified and flexible device enrollment, using.
ITUser Enterprise Mobility Suite Identify and authorize user Apply device policies Apply application policies Apply content policies Active Directory.
Data Devices People 6.5B Wireless connections today >42% of global population owns smartphone by end of 2015 >50% User will go to tablet or smartphone.
4/17/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Desktop virtualization Access & information protection Mobile device & application management Hybrid identity Simplified device enrollment and.
4/17/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Empower Enterprise Mobility Jasbir Gill Azure Mobility.
Empowering people-centric IT Mobile Device Management Access and information protection Desktop Virtualization Hybrid Identity.
Exchange Exchange Connecter with Configuration Manager Configuration Manager with Intune Protect and Manage Devices and Infrastructure.
Howard A. Carter III Senior Consultant Microsoft Consulting Services
Lack of control for mobile devices Different tools for phone & PC Policy conflict Inconsistent user experience… Granular mobile device mgmt Converged.
© 2013 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property. Mobile Application Ecosystem.
Tim Vander Kooi Systems
Harris Schneiderman Account Manager Kloud Solutions.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Empowering people-centric IT Mobile Device Management Access and information protection Desktop Virtualization Hybrid Identity.
The explosion of devices is eroding the standards-based approach to corporate IT. Devices Deploying and managing applications across platforms is.
Access and Information Protection Product Overview Andrew McMurray Technical Evangelist – Windows
FND2851. Mobile First | Cloud First Sixty-one percent of workers mix personal and work tasks on their devices* >Seventy-five percent of network intrusions.
Devices & Platforms Single admin console.
Configuration Manager and InTune Gemeinsam oder einsam?
Managing iOS Device Using ConfigMgr and Intune Hybrid MDM John Presenter #2 Twitter Handle Blog or address.
Michael Niehaus Using the Windows Store for Business: New Capabilities for Managing Apps in the Enterprise WIN335.
User and Device Management
Pat Fetty – Principal PM Manager Securing your mobile assets with Microsoft Intune WIN33 1.
Windows Intune Cloud Based Management Speaker: Neil Phillips 13th August 2014.
Craig Pringle & Derek Moir
Windows 8 tablets with Intel Core 64-bit processors Windows 8 tablets with Intel Atom 32-bit processors Windows RT tablets with ARM processors.
The information contained in this document represents the current view of Microsoft Corp on the issues discussed as of the date of publication. Because.
Protect your data Enable your users Unify Your Environment DevicesAppsData Help organizations enable their users to be productive on the devices they.
Why EMS? What benefit does EMS provide O365 customers Manage Mobile Productivity Increase IT ProductivitySimplify app delivery and deployment LOB Apps.
One Drive for Business: More Than a File Share Erica Toelle
Tomaž Čebul Principal Consultant Microsoft Bring Your Own Device, kaj pa je to?
The information contained in this document represents the current view of Microsoft Corp on the issues discussed as of the date of publication. Because.
Go mobile. Stay in control. Craig Morris EMPOWER ENTERPRISE MOBILITY.
Managing modern devices with System Center 2012 R2 Configuration Manager Niall Brady.
Managing Devices in the Enterprise: From EMS zero to Hero in only 60 minutes Ken Goossens Herman Arnedo Mahr.
Selecting the Management Platform Cloud-based Management Standalone Windows Intune No existing Configuration Manager deployment Simplified policy.
MaaS360 MDM for iOS, Android & Windows Phone 7
Barracuda Mobile Device Manager
Conduct a successful pilot deployment of Microsoft Intune
Cloud-First, Modern Windows Management and Security
Exam Prep : Section 2: Design for Device Access and Protection
Mobile Device Management options in Office 365 and beyond
Microsoft Ignite /18/2018 8:30 PM BRK2065
Microsoft Intune MAM without Device Enrollment
Application Delivery & MAM Policy
Protect your OneDrive and SharePoint files on mobile devices
Microsoft Ignite /20/2018 2:21 PM
Microsoft Ignite NZ October 2016 SKYCITY, Auckland
Microsoft Ignite /2/2019 7:15 PM
Modern LoB App Deployment
Microsoft Virtual Academy
SCCM in hybrid world Predrag Jelesijević Microsoft 7/6/ :17 AM
Microsoft 365 Business Technical Fundamentals Series
Presentation transcript:

Protect your data Enable your users Unify Your Environment DevicesAppsData Help organizations enable their users to be productive on the devices they love while helping ensure corporate assets are secure

Manage mobile productivity and protect data with Office Mobile apps for iOS and Android Manage policy for existing iOS line of business apps (so called “app wrapping”) Managed browser and PDF/Audio/Video viewers Provide access to Exchange and OneDrive for Business resources only to managed devices Deny access if a device falls out of compliance Enable IT to bulk enroll corporate-owned task-worker devices Support for Apple Configurator Manage mobile productivity without compromising compliance Conditional Access Policy to and Documents Enroll and Manage Corporate-owned Devices Manage Mobile Productivity and Protect Data with Office Personal Corporate

Layer 2 – Application and data containers (aka “managed mobile productivity”) Protects corporate data by… Gaps it leaves open Preventing apps from sharing data with other apps outside of IT control Preventing apps from saving data to stores outside of IT control Encrypting app data to supplement device encryption Only protects corporate data that resides on devices. Cannot protect data beyond a device. Applies same protection to all data that an app touches. Does not allow for specific protection per document. Layer 3 – Data wrapping Protects corporate data by… Gaps it leaves open Protecting data wherever it resides Providing granular, content specific protection – e.g. time bomb vision docs Requires enlightened applications Requires all data to be protected if not complemented by Layers 1 and 2 Native Managed Browser LoB Layer 1 – Mobile device lockdown via MDM Protects corporate data by… Gaps it leaves open Restricting device behaviors: PIN, encryption, wipe, disable screen capture and cloud backup, track compliance, etc. Provisioning credentials that enable corporate resource access control Apps may share corporate data with other apps outside IT control Apps may save corporate data to consumer cloud services LoB

Enterprise Mobility Lifecycle Manage and Protect Measure device and app compliance Block access if policy violated (eg: jailbreak) Contain data to prevent leaks Self service portal for users Retire Revoke company resource access Selective wipe Audit lost/stolen devices etc Employees Enroll Enroll devices in AD and MDM Block /SharePoint etc until enrolled Customizable Terms & Conditions Simple end user experience Provision Provision access to corporate resources Install VPN, Wifi, Certificates Deploy device security policy settings Install mandatory apps Deploy app restriction policies Deploy data protection policies

Manage and Protect Retire Enroll Provision

Intune web console Mobile devices and PCs ConfigMgr console Microsoft Intune Mobile devices System Center ConfigMgr Domain joined PCs ConfigMgr integrated with Intune (hybrid) Intune standalone (cloud only) Microsoft Intune System Center 2012 R2 Configuration Manager with Microsoft Intune Build on existing Configuration Manager deployment Full PC management (OS Deployment, Endpoint Protection, application delivery control, rich reporting) Deep policy control requirements Scale to 100,000 devices Extensible administration tools (RBA, PowerShell, SQL Reporting Services) Cloud-based Management Microsoft Intune No existing Configuration Manager deployment Simplified policy control PC+MDM: 4K users, 6K PCs, and 7K devices MDM Only: 25k users and 50k mobile devices Simple web-based administration console

The End User Experience Family

Bulk Enrollment Support for Apple Device Enrollment Program and Apple Configurator Service account enrollment Configuration Policies Device lockdown through supervisor mode Policies and apps targeted to devices Application install allow/deny list URL allow/deny

Device Type Allow/Block enforcement Windows Phone Enforced by device OS (always compliant) iOSAudit reporting AndroidAudit reporting

No trip to the store. - Installation begins directly. Monitor installation – Get install status in the console Push apps – Apps can be required installations Inventory apps - App on the device is marked as a Managed app in inventory Works only for Free apps. App Restriction policies can be applied Managed store apps IW is taken to the store for installation Intune is NOT aware of the installation. No Installation status. IT Pro can only make it Available install App on the device is marked as a Personal app in inventory Works for both free and paid app App Restriction policies can NOT be applied External/Deep link

Detect Option 1: Configure app in deny list Option 2: Deploy managed iOS app Audit Option 1: Audit devices that have “denied” app installed Option 2: Report on installation failure Advise Advise end user to uninstall iOS app Deploy Deploy managed iOS app successfully to device

App Origination ScenariosWindows 8.1 Windows Phone 8.1 iOSAndroid Line of Business (Sideloading) Available Install deployed to users Required Install & Uninstall deployed to users and devices User Consent required Public Store apps Deep linked app: Available user targeted Managed store app: Available user targeted Managed store app: Required Install & Uninstall deployed to users & devices User Consent required Coming soon

App Origination ScenariosWindows 8.1Windows Phone 8.1 iOSAndroidInstallation Status Application Update Line of Business (Sideloading) Available Install deployed to users Required Install & Uninstall deployed to users and devices User Consent required User Consent required * Public Store apps Deep linked app: Available user targeted  Managed store app: Available user targeted  Managed store app: Required Install & Uninstall deployed to users & devices  User Consent required  * Coming soon

Manage and Protect Retire Enroll Provision

Microsoft Office apps are natively manageable with Intune Intune offers key apps to support content viewing Build or buy your app with the Intune SDK Make any app manageable, without modifying code OWA OneDrive for Business Word Excel PowerPoint Managed Browsers PDF Viewer AV Viewer Image Viewer Developers can easily integrate applications for manageability. Provide more control over user experience than wrapping Apply all MAM policies to apps

Acquire Option 1: Wrap LOB apps or recompile with the Intune App SDK Option 2: Purchase store applications that include the Intune App SDK Import Import LOB App Packages or App deeplinks into Intune Configure Create MAM Policies Deploy Associate MAM Policy with User group(s) during Application deployment

Tool Download the Intune App Wrapping Tool from Download Center and Install Certs Acquire appropriate packaging certs (e.g. Apple signing certification and provisioning profile) Package Run the App Wrapping Tool and generate the new app package

Manage and Protect Retire Enroll Provision

Restore device to factory defaultsRemove company assets from device All assets on device are removed Typically used for lost/stolen devices or resetting corporate owned devices Company assets (Apps, Data, Profiles, Certs, Settings and ) are removed MAM support adds ability to remove only company data from multi-account applications Typically used for personally owned device

Initiate Option 1: IT Pro opens in the Microsoft Intune console, finds the device and chooses Retire Option 2: IW opens the Microsoft Company Portal, finds device and chooses Retire Wipe Option 1: IT Pro/IW chooses Full Wipe Option 2: IT Pro/IW choose Selective Wipe Device For Selective Wipe: IWs will notifications for specific platforms (e.g. Android) IWs will be informed of Company Data removal in MAM enabled applications