Exchange Exchange Connecter with Configuration Manager Configuration Manager with Intune Protect and Manage Devices and Infrastructure.

Slides:



Advertisements
Similar presentations
Windows 8.1 Device Management With Windows Intune Mark O’Shea MVP Windows Expert – IT Pro 30 June 2014.
Advertisements

Managing and Securing Devices using Exchange, System Center, and Intune LAWRENCE NOVAK MICHAEL INDENCE DMVMUG Reston, VA
Sophos Mobile Control. Tablets on the rise 2 Trends 3 75% of 157 polled companies encourage employee owned smart phones and tablets to access corporate.
Meraki Mobile Device Management
Protect your data Enable your users Unify Your Environment DevicesAppsData Help organizations enable their users to be productive on the devices they.
SharePoint Server Exchange Server CORPORATE NETWORK Mobile devices PCs Browsers INTERNET DMZ Active Directory Policies Filter EAS Filter web access.
Script Kiddies; CybercrimeCyber-espionage; Cyber-warfare CybercriminalsState sponsored actions; Unlimited resources Attacks on fortune 500All sectors.
Management lifecycle summary Mobile Device Management with Windows Intune or 3 rd Party tools Simplified and flexible device enrollment, using.
Data Devices People 6.5B Wireless connections today >42% of global population owns smartphone by end of 2015 >50% User will go to tablet or smartphone.
Protect your data Enable your users Unify Your Environment DevicesAppsData Help organizations enable their users to be productive on the devices they.
4/17/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Desktop virtualization Access & information protection Mobile device & application management Hybrid identity Simplified device enrollment and.
4/17/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
IOS 8 for MDM/EMM Greg Elliott Shiv Chandra Kumar.
Empower Enterprise Mobility Jasbir Gill Azure Mobility.
Managing Client Access
Module 4 Managing Client Access. Module Overview Configuring the Client Access Server Role Configuring Client Access Services for Outlook Clients Configuring.
Howard A. Carter III Senior Consultant Microsoft Consulting Services
Lack of control for mobile devices Different tools for phone & PC Policy conflict Inconsistent user experience… Granular mobile device mgmt Converged.
Microsoft Windows 8.1 Enterprise: A brief overview of Microsoft Windows 8 Enhancements. Welcome!
IT:Network:Microsoft Server 2 Chapter 27 WINDOWS SERVER UPDATE SERVICES.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Four Configuring Outlook and Outlook Web Access.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
Securing Microsoft® Exchange Server 2010
Module 8 Configuring Mobile Computing and Remote Access in Windows® 7.
Module 4 Planning and Deploying Client Access Services in Microsoft® Exchange Server 2010 Presentation: 120 minutes Lab: 90 minutes After completing.
Solution Benefits Of Adopting Unified Solution Goals Management support for Windows 8.x and heterogeneous devices Improve user productivity on.
Microsoft NDA Confidential Enabling users to be productive, responsibly Finding the right balance Devices & Experiences Users Want Applications and.
Microsoft ® Official Course Module 13 Implementing Windows Azure Active Directory.
Empowering people-centric IT Mobile Device Management Access and information protection Desktop Virtualization Hybrid Identity.
1. 2 Overview In Exchange security is managed by assigning permissions in Active Directory Exchange objects are secured with DACL and ACEs Permissions.
The explosion of devices is eroding the standards-based approach to corporate IT. Devices Deploying and managing applications across platforms is.
Enabling users to be productive, responsibly Finding the right balance Devices & Experiences Users Want Applications and data across devices, anywhere.
Empowering people-centric IT Patrick Rogers May 29, 2014.
Purpose Intended Audience and Presenter Contents Proposed Presentation Length Intended audience is all distributor partners and VARs This would be presented.
Gary Gruba Systems Engineer Absolute Manage MDM Managing iPhones, iPads, iPod Touches and Android Dougald MacNaughton Account Executive.
Get identities to the cloud Mix on-premises and cloud identity for improved PC, mobile, and web productivity Cloud identities help you run your business.
Devices & Platforms Single admin console.
Configuration Manager and InTune Gemeinsam oder einsam?
Managing iOS Device Using ConfigMgr and Intune Hybrid MDM John Presenter #2 Twitter Handle Blog or address.
Microsoft Virtual Academy Preparing for the Windows 8.1 MCSA Module 5: Managing Devices & Resource Access.
User and Device Management
What’s New Data Loss Prevention 14. Information is Everywhere Brings Productivity, Agility, Convenience ……and Problems Copyright © 2015 Symantec Corporation.
Windows Intune Cloud Based Management Speaker: Neil Phillips 13th August 2014.
Craig Pringle & Derek Moir
Windows 8 tablets with Intel Core 64-bit processors Windows 8 tablets with Intel Atom 32-bit processors Windows RT tablets with ARM processors.
Protect your data Enable your users Unify Your Environment DevicesAppsData Help organizations enable their users to be productive on the devices they.
Why EMS? What benefit does EMS provide O365 customers Manage Mobile Productivity Increase IT ProductivitySimplify app delivery and deployment LOB Apps.
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
69% of employees say they are accessing business apps on personal devices Organizations say 34% of their employees are accessing business apps on.
Tomaž Čebul Principal Consultant Microsoft Bring Your Own Device, kaj pa je to?
Managing modern devices with System Center 2012 R2 Configuration Manager Niall Brady.
Managing Devices in the Enterprise: From EMS zero to Hero in only 60 minutes Ken Goossens Herman Arnedo Mahr.
Selecting the Management Platform Cloud-based Management Standalone Windows Intune No existing Configuration Manager deployment Simplified policy.
MaaS360 MDM for iOS, Android & Windows Phone 7
CudaLaunch for Barracuda NG Firewall.
Preparing for the Windows 8.1 MCSA
System Center 2012 Configuration Manager
Conduct a successful pilot deployment of Microsoft Intune
Microsoft Virtual Academy
Microsoft Virtual Academy
Exam Prep : Section 2: Design for Device Access and Protection
Mobile Device Management options in Office 365 and beyond
Microsoft Intune MAM without Device Enrollment
SVTRAININGS. SVTRAININGS Features of SCCM  Application management  Provides a set of tools and resources that can help you create, manage, deploy, and.
Getting Started.
Getting Started.
Microsoft Virtual Academy
SCCM in hybrid world Predrag Jelesijević Microsoft 7/6/ :17 AM
Microsoft 365 Business Technical Fundamentals Series
Presentation transcript:

Exchange Exchange Connecter with Configuration Manager Configuration Manager with Intune Protect and Manage Devices and Infrastructure

Exchange

Set-ActiveSyncOrganizationSettings New-ActiveSyncDeviceAccessRule Set-ActiveSyncDeviceAccessRule New-ActiveSyncMailboxPolicy Set-CasMailbox Exchange - Protecting your Infrastructure

Set-ActiveSyncOrganizationSettings Set-ActiveSyncOrganizationSettings -DefaultAccessLevel Quarantine - AdminMailRecipients Exchange - Protecting your Infrastructure

New-ActiveSyncDeviceAccessRule New-ActiveSyncDeviceAccessRule -QueryString iPhone -Characteristic DeviceModel -AccessLevel Block New-ActiveSyncDeviceAccessRule -QueryString NokiaE521/2.00()MailforExchange -Characteristic UserAgent - AccessLevel Allow Exchange - Protecting your Infrastructure

Set-ActiveSyncDeviceAccessRule Set-ActiveSyncDeviceAccessRule 'ContosoPhone(DeviceModel)' - AccessLevel:Quarantine Get-ActiveSyncDeviceAccessRule | Where {$_.AccessLevel -eq 'Allow'} | Set-ActiveSyncDeviceAccessRule -AccessLevel:Quarantine Exchange - Protecting your Infrastructure

Mobile Device Mailbox Policies When you install Exchange 2013, a default mobile device mailbox policy is created. All users are automatically assigned this default mobile device mailbox policy. Exchange - Protecting your Infrastructure

New-ActiveSyncMailboxPolicy New-ActiveSyncMailboxPolicy -Name 'All Users' - AllowNonProvisionableDevices $false -DevicePasswordEnabled $true - AlphanumericDevicePasswordRequired $false - MaxInactivityTimeDeviceLock '00:15:00' -MinDevicePasswordLength '4' -PasswordRecoveryEnabled $false -RequireDeviceEncryption $true - AttachmentsEnabled $true -AllowSimpleDevicePassword Exchange - Protecting your Infrastructure

Adding and Removing Users from a Mobile Mailbox Policy Get-CASMailbox -Identity -ActiveSyncMailboxPolicy "Sales" Get-Mailbox | where { $_.CustomAttribute1 -match "Manager"} | Set- CASMailbox -activesyncmailboxpolicy(Get-ActiveSyncMailboxPolicy "Contoso").Identity Exchange - Protecting your Infrastructure

Current list of available settings per device OS nts Exchange - Protecting your Infrastructure

Exchange Connector

Use the Exchange Server connector in System Center 2012 Configuration Manager when you want to manage mobile devices that connect to Exchange Server (on-premises or online) by using the Microsoft Exchange ActiveSync protocol, and you cannot enroll them by using Configuration Manager. Exchange Connector – Managing and Securing Devices

Settings you can control General Password Management Security Application Exchange Connector – Managing and Securing Devices

Option to control settings via Active Sync Exchange Access rules control Allow, Block, or Quarantine Remotely Wipe via ConfigMgr Self Wipe via Application catalog On-premise automatically added to catalog on sync Hosted requires manual user device affinity before visible in catalog. Exchange Connector – Managing and Securing Devices

When you manage mobile devices by using the Exchange Server connector, this does not install the Configuration Manager client on the mobile devices. Some management functions are therefore limited. For example, you cannot install software on these devices or use configuration items to configure these devices. Exchange Connector – Managing and Securing Devices

When you use the Exchange Server connector, the mobile devices are managed by the settings that you configure in Configuration Manager instead of being managed by the default Exchange ActiveSync mailbox policies. Exchange Connector – Managing and Securing Devices

An account is required to configure the Exchange Connector in Configuration Manager. The account can be the computer account of the site server or a Windows user account, and must have rights in Exchange to certain cmdlets. Exchange Connector – Managing and Securing Devices

An account is required to configure the Exchange Connector in Configuration Manager. The account can be the computer account of the site server or a Windows user account, and must have rights in Exchange to certain cmdlets. Exchange Server management roles that contain the required cmdlets are the Recipient Management, View-Only Organization Management, Server Management, and above. Exchange Connector – Managing and Securing Devices

Intune

System Center Intune has various access points and knowing each one is important to not confuse users and get the most of the subscription. Portal.Manage.Microsoft.com (Users) Account.Manage.Microsoft.com (Subscription Administration) Manage.Microsoft.com (Intune Administration) System Center Intune - Managing and Securing Devices

There are various pre-requisites that must be configured and working before Intune can manage mobile devices or be connected to System Center Configuration Manager. Intune Account Verified Public Domain Domain UPN Dirsync/SSO DNS Alias (CNAME) Certificate Keys System Center Intune - Managing and Securing Devices

Certificates are used with System Center Intune to secure software deployments to devices that are either company developed or push or to allow Notifications. Below is a list by OS type of cert required. Windows Phone 8 – Code Sign Cert (Symantec) Support Tool for Windows Intune Trial (temp cert for testing) Windows devices (Side loading Keys) IOS – Apple Push Notification (APN) Android (None) System Center Intune - Managing and Securing Devices

System Center Intune support many Mobile devices in Direct Managed mode or connected with System Center Configuration Manager 2012 R2. Windows Phone 8 Devices Windows 8 RT Windows 8.1 RT Windows 8.1 iOS 5.0, 6.0, and 7.0 Android Devices 2.3 and Later System Center Intune - Managing and Securing Devices

When integrating System Center Intune with System Center Configuration Manager there is a few configuration changes and system roles to be setup. Subscription Connector Setup Windows Intune Connector Role Logs ConnectorSetup CloudMgr CloudUsersSync dmpDownloader dmpuploader System Center Intune - Managing and Securing Devices

Source intune.aspx `

Company Applications Deeplinking (Store Apps) User Enrollment Managing Devices – Managing and Securing Devices

Method to deploy Vendor store apps via System Center Configuration Manager. iTunes Google Play Windows Phone Store Windows (Use reference computer) Deeplinking – Managing and Securing Devices

Windows Phone (Settings – Company Apps) Windows RT (System Configuration – Company Apps) Windows 8.1 and RT 8.1 (Workplace) iOS (ITunes – Windows Intune Company Portal) If Service Pack 1 (m.manage.Microsoft.com) Android (Google Play – Windows Intune Company Portal) User Enrollment – Managing and Securing Devices

The enterprise feature pack will include: S/MIME to sign and encrypt Access to corporate resources behind the firewall with app aware, auto-triggered VPN Enterprise Wi-Fi support with EAP-TLS Enhanced MDM policies to lock down functionality on the phone for more enterprise control, in addition to richer application management such as allowing or denying installation of certain apps Certificate management to enroll, update, and revoke certificates for user authentication Windows Phone Enterprise Feature Pack – Managing and Securing Devices

Samsung Knox and Intune– Managing and Securing Devices

Exchange Exchange Connecter with Configuration Manager Configuration Manager with Intune Protect and Manage Devices and Infrastructure