Download presentation
Presentation is loading. Please wait.
1
Microsoft Ignite 2015 2/2/2019 7:15 PM
© 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
2
BRK3861 What’s New and Upcoming with Microsoft Intune and System Center Configuration Manager Mark Florida Principal PM Manager Vladimir Petrosyan Technical Product Manager
3
Session Objectives And Takeaways
Tech Ready 15 2/2/2019 Session Objectives And Takeaways Session Objective(s): Vision and future of client and device management at Microsoft Broad coverage of the new capabilities and the roadmap Key Takeaway(s): Managed Mobile Productivity == Enterprise Mobility Suite Windows 10 is coming and Configuration Manager and Microsoft Intune will be there to support you Intune has greatly expanded its management capabilities © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
4
Agenda Vision and direction Enable users and protect your data
2/2/2019 Agenda Vision and direction Enable users and protect your data Unify your environment Windows 10 management © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
5
Mobility is the new normal
52% 90% >80% 52% of information workers across 17 countries report using three or more devices for work* 90% of enterprises will have two or more mobile operating systems to support in 2017** >80% of employees admit to using non-approved software-as-a-service (SaaS) applications in their jobs*** * Forrester Research: “BT Futures Report: Info workers will erase boundary between enterprise & consumer technologies,” Feb. 21, 2013 ** Gartner Source: Press Release, Oct. 25, 2012, ***
6
What's driving change? User Devices Apps Data IT
7
Empowering enterprise mobility
Microsoft Ignite 2015 2/2/2019 7:15 PM Empowering enterprise mobility Enable your users People-centric approach Protect your data User Devices Apps Data IT Unify your environment © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
8
Enable users and protect your data
2/2/2019 7:15 PM Enable users and protect your data © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
9
Unified device management
User Mobile device management Application management Comprehensive Windows, Linux, and Mac management IT System Center Configuration Manager
10
Mobile device management
Microsoft Ignite 2015 2/2/2019 7:15 PM Mobile device management IT User Company Portal Recommended apps for user’s devices Devices enrolled Apply and enforce device configuration settings Deploy , VPN, and WiFi profiles Deploy certificates Deploy and install apps Collect hardware and software inventory data Apply policies © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
11
Email profile management
Corporate server User IT Any service supported by Exchange ActiveSync Microsoft Intune Deploy profile on enrollment Configure account settings and security restrictions Enable certificate authentication Synchronize , task, contacts, and calendar Support for iOS, Samsung KNOX, and Windows Phone
12
Company portal self-service experience
Consistent experience across: Windows Windows Phone Android iOS Discover and install corporate apps Manage devices and data Customizable terms and conditions Ability to contact IT
13
Access control to corporate data today
NETWORK DMZ INTERNET Active Directory Mobile devices PCs Policies Filter EAS Filter web access Filter or block mobile app access Block unmanaged devices Prevent downloads Force multi-factor authentication Require domain joined Force traffic via proxy/VPN Browsers Exchange Server SharePoint Server
14
Protecting data in a mobile first, cloud first world
CORPORATE NETWORK DMZ INTERNET Active Directory Mobile devices SharePoint Online Exchange Online The perimeter can not help protect data Challenge PCs Solution Access control and data containment integrated natively in the apps, devices, and the cloud. Browsers Exchange Server SharePoint Server
15
Typical EMM Stack CORPORATE NETWORK Perimeter network Containers
Microsoft Ignite 2015 2/2/2019 7:15 PM Typical EMM Stack SharePoint Server Exchange Server CORPORATE NETWORK Active Directory SDK/wrapper, helper apps Managed browser, viewers Custom SDK/wrapper enables LoB apps to be managed Perimeter network Mobile application management Custom data container provides mobile productivity apps integrated with content and access systems. Custom app Custom file app Custom collab app Containers Depend on specific DMZ infrastructure Work on premise only Firewall Firewall Native device MDM Standard MDM provides device configuration and management © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
16
Microsoft’s Mobility Stack
Microsoft Ignite 2015 2/2/2019 7:15 PM Microsoft’s Mobility Stack Intune App SDK Intune App Wrapping Tool Extensibility based on AAD and Intune. Enable business apps to interoperate with Office Mobile SharePoint Online Exchange Online Native cloud integration Managed Office productivity and more O365: Mobile productivity Azure AD: Access control to O365 Intune: Data container for Office mobile apps Azure RMS: Information protection at file level SharePoint Server Exchange Server CORPORATE NETWORK Perimeter network Active Directory Standard on-premises integration Native device MDM Intune: standard MDM Firewall Firewall © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
17
Mobile data protection
On-premises User IT Protect corporate data accessed from devices Protect corporate data cached on devices
18
Conditional access to email
User IT Required settings defined by IT admin: IT Enrolled device Encrypted device Passcode set Not jailbroken/rooted Policy verification Username Microsoft Intune ••••••••• Admin console
19
Conditional access to email
User IT Required settings defined by IT admin: IT Enrolled device Encrypted device Passcode set Not jailbroken/rooted Policy verification Username Microsoft Intune ••••••••• Admin console
20
Mobile application management policies
Enforce corporate data access requirements Prevent data leakage on the device Enforce encryption of app data at rest App-level selective wipe
21
Mobile application management
User Personal apps Personal apps Managed apps Managed apps IT Maximize mobile productivity and protect corporate resources with Office mobile apps Extend these capabilities to existing line-of-business apps using the Intune App Wrapping Tool Enable secure viewing of content using the Managed Browser, PDF Viewer, AV Player, and Image Viewer apps
22
Selective wipe IT Company Portal IT
Personal apps IT Managed apps Company Portal Are you sure you want to wipe corporate data and applications from the user’s device? IT OK Cancel Perform selective wipe via self-service company portal or admin console Remove managed apps and data Keep personal apps and data intact
23
Multiple layers of data protection
Active Directory Premium IT User Identify and authorize user Apply device policies Apply application policies Rights Management Apply content policies Enterprise Mobility Suite
24
Demo – mobile data protection
Microsoft Ignite 2015 2/2/2019 7:15 PM Demo – mobile data protection Vladimir Petrosyan © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
25
Unify your environment
2/2/2019 7:15 PM Unify your environment © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
26
Enterprise Mobility Suite + Office 365
2/2/2019 Enterprise Mobility Suite + Office 365 Common identity infrastructure Control access to on prem and SaaS Authentication and SSO Encryption and policy at the file level Azure AD Azure RMS Identity & Access Integrated experiences Conditional access Secure collaboration based enrollment Device and user provisioning Single sign-on Device compliance App restriction Lost or stolen device Device wipe Employee leaves the company …and more in the works Intune Device & App Management Mobile device management Mobile application management Contain corporate data on devices World class productivity and collaboration Consistent experience across all devices IT compliance and data protection Office 365 Productivity © 2015 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
27
2/2/2019 World Class Services Built from the ground up: Datacenter, Fabric, SaaS Designed to work together Always up to date Continuous feature upgrades Always available and reachable Built using world class engineering & security Compliant and certified © 2015 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
28
Deployment options Intune standalone (cloud only)
Configuration Manager integrated with Intune (hybrid) IT IT Intune web console Configuration Manager console System Center Configuration Manager Windows PC, Windows Phone, iOS, Android Windows PC, Mac, Linux, Windows Phone, iOS, Android
29
Configuration Manager integrated with Intune (hybrid)
System Center 2012 R2 Configuration Manager with Microsoft Intune Build on existing Configuration Manager deployment Full PC management (OS deployment, endpoint protection, application delivery control, custom reporting) Deep policy control requirements Larger scale Extensible administration tools (RBA, PowerShell, SQL reporting services) IT Configuration Manager console System Center Configuration Manager Devices Supported Windows PCs (x86/64, Intel SoC) Windows to Go Windows Server Linux Mac OS X Windows RT Windows Phone 8.x iOS Android Windows PC, Mac, Linux, Windows Phone, iOS, Android
30
Q4 2014 features Conditional access policy Mobile app management
Ability to restrict access to Exchange on-premises based upon device enrollment Ability to restrict access to Exchange Online based upon device enrollment and compliance policies Mobile app management Management of Office mobile apps (Word, Excel, PowerPoint) for iOS devices, including ability to restrict actions such as copy, cut, and paste outside of the managed app ecosystem Ability to extend application protection to existing line-of-business apps using the Intune App Wrapping Tool for iOS Managed Browser app for Android devices that controls actions that users can perform, including allow/deny access to specific websites PDF Viewer, AV Player, and Image Viewer apps for Android devices that help users securely view corporate content Configuration policies and resource access Deployment of , WiFi, VPN profiles as well as certificates Lockdown of Supervised iOS devices and devices using Samsung KNOX with Kiosk mode Targeting of policies and apps by device groups Enforcement of application install or uninstall Convenient access to internal corporate resources via per-app VPN configurations for iOS Application install allow/deny list Remote pin reset for Windows Phone 8.1 (currently supported for iOS and Android) Multi-factor authentication at enrollment for Windows 8.1 and Windows Phone 8.1 devices Ability to restrict administrator access to a specific set of user and device groups Ability to create configuration files using Apple Configurator and import these files into Intune to set custom iOS policies Lockdown of Windows Phone 8.1 devices with Assigned Access mode using OMA-URI settings Ability to set additional policies on Windows Phone 8.1 devices using OMA-URI settings Ongoing support for device platforms Service account enrollment Customizable terms and conditions Enhanced user interface for Intune administration console Ability to push free store apps to iOS devices Support for Apple Configurator
31
2015 features released so far…
Conditional access policy Ability to restrict access to SharePoint Online (includes OneDrive for Business) based upon device enrollment and compliance Ability to restrict access to Exchange on-premises for Exchange ActiveSync clients on Android devices Mobile app management Management of the Office Mobile app (access, view, and edit Word, Excel, and PowerPoint documents) for Android phones Management of OneNote and OneDrive apps Management of Work Folders app for iOS devices Configuration policies and resource access Ability to require encryption on Windows 8.1 (x86) devices Ability to set minimum classification of platform updates to be installed automatically on Windows 8.1 (x86) devices Ability to restrict the number of devices a user can enroll in Intune Support for Cisco AnyConnect per-app VPN configurations for iOS devices Deployment of WiFi profiles for Windows devices using XML import and Windows Phone devices using OMA-URI (currently supported for iOS and Android) Ability to create WiFi profiles with pre-shared keys (PSK) for Android devices Ability to resolve certificate chains on Android devices without the need to deploy each intermediate certificate individually Ability to deploy .appx files and .appx bundles to Windows Phone 8.1 devices Ongoing support for device platforms Support for Apple Device Enrollment Program (DEP) Ability to browse and install apps on Windows Phone 8.1 devices using Intune Company Portal website Ability to manage Windows Defender on Windows 10 PCs running Windows 10 Technical Preview without need for separate Microsoft Intune Endpoint Protection agent to be installed Combined Microsoft Intune Company Portal websites for PCs and mobile devices to provide a more consistent user experience across platforms Enhanced user interface for overview pages within Intune admin console Hybrid configuration (ConfigMgr) Restrict access to Exchange Online only if device is managed and compliant Ability to create custom WiFi profiles with pre-shared keys (PSK) for Android devices
32
Roadmap Conditional access policy Mobile app management
Ability to restrict access to Outlook app based on device enrollment and compliance Mobile app management Intune App SDK for iOS Intune app Wrapping tool for Android Support for MAM in Outlooks app Multi-identity Ongoing support for device platforms Support of Apple Volume Purchase Program (VPP) Windows 10 support Mac OS X support
33
Windows 10 Management 2/2/2019 7:15 PM
© 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
34
Overview: Windows 10 management with ConfigMgr and Intune
Product Version Release Vehicle Release Timing Windows 10 Features Supported Windows Servicing Model Supported ConfigMgr Technical Preview 5/4 New and existing features Current Branch & Long-Term Servicing Branch Generally Available Q4 CY2015 ConfigMgr 2012 SP2 and ConfigMgr 2012 R2 SP1 Service Packs 5/14 Existing features Long-Term Servicing Branch ConfigMgr 2007 Hotfix Existing features (management only, no OSD) Microsoft Intune Monthly Service Updates 5/4 app compatibility and management of new Windows 10 features via custom policies with incremental updates to deliver full support Current Branch & Long-Term Servicing Branch
35
What’s new in ConfigMgr 2012 SP2 and 2012 R2 SP1
Key features Faster virtual app (App-V) publishing at first logon for non-persistent VDI environments Increased hierarchy and primary standalone site scale Improved scale and performance for pull distribution points (DP) Hybrid parity features for ConfigMgr integrated with Microsoft Intune SQL SQL Improved data transfer reliability for slow and latent networks Full compatibility with existing features for Windows 10 Native support for SQL Server 2014
36
Improvements in ConfigMgr 2012 SP2 and 2012 R2 SP1
OS distribution Support for Windows 10 OS deployments Setup prerequisite is still Windows 8.1 ADK but it supports Windows 10 ADK Improvements to driver management UI Ability to notify IT admin before implementing a potentially risky task sequence OS deployment Added task sequence resiliency during software update restarts Improved consistency of Smsts logging so that events are fully tracked throughout the deployment Role-based access for standalone media Enhanced audit messages (Clearing a PXE flag on a collection, audit status message with ID 30,000 is not generated if a Task Sequence is created and the console user is "Operating System Deployment Manager”) “OS Installer Package” renamed to “OS Upgrade Packages” Increased task sequence media supports >32GB USB Resource access Support for multiple NDES servers per certificate profile Application management Support for Windows 10 app deployments Fixed issues with app model supersedence Faster virtual app (App-V) publishing at first logon for non-persistent VDI environments
37
Improvements in ConfigMgr 2012 SP2 and 2012 R2 SP1
Content management Improved data-transfer reliability for slow and latent networks New checkpoint restart functionality between site servers and remote distribution points (DPs) New checkpoint restart with failover functionality between source DPs and Pull DPs Improved Pull DP scale and performance Ability to define HTTPS configured source DPs for Pull DPs via the management console Added start/end date for “distribution point usage summary" report and bug fixes Hierarchy Added client auto-upgrade option to exclude servers Improved management point (MP) rotation logic so when a client gets a new MP list, the client doesn’t arbitrarily choose a new MP Improved preferred MP list logic so clients get MP list ordered with MPs in a boundary group at the top of the list Native support for SQL Server 2014 Increased hierarchy scale to 600K Increased standalone primary site scale to 150K with WSUS optimizations Scale limit remains at 100K when attached to Central Administration Site (CAS) Increased secondary site scale to support up to 10K clients
38
Hybrid features for ConfigMgr 2012 R2 SP1 integrated with Intune
Conditional access policy Restrict access to Exchange on-premises only if the device is managed Restrict access to Exchange Online only if the device is managed and compliant (Extension released to add support for Exchange Online in March 2015) Restrict access to SharePoint Online and OneDrive for Business only if the device is managed and compliant Mobile application management Managed Office mobile apps – Word, Excel, PowerPoint, OneDrive, OneNote App Wrapping Tool for existing iOS line-of-business apps Managed Browser for iOS and Android devices PDF Viewer, AV Player, and Image Viewer for iOS (in web viewer) and Android devices Configuration policies and resource access Deployment of certificates in .pfx format (Network Device Enrollment Service (NDES) not required) Device lockdown via supervised iOS devices and Assigned Access for Windows Phone 8.1 Application install allow/deny list Support for custom policies for iOS devices Deployment of profiles for Android devices using Samsung KNOX Deployment of VPN profiles for Android devices Passcode reset and remote device lock for iOS, Android, and Windows Phone devices Ongoing support for device platforms Support for Apple Device Enrollment Program (DEP) Support for Samsung KNOX Standard Push free store apps to iOS devices Convenient access to internal corporate resources via per-app VPN configurations for iOS
39
What’s new in the ConfigMgr Technical Preview
Full compatibility with existing features for Windows 10 Support for Windows in-place upgrade First iteration of new hybrid option to manage Windows 10 devices via MDM with on-premises infrastructure Client deployment upgrade status monitoring added in admin console Support for running ConfigMgr in Azure Virtual Machines
40
In-place upgrade with ConfigMgr Technical Preview
Preserve applications, drivers, user data, and settings Compared to refresh, in-place upgrade is… Faster: 30 to 60 minutes on average to upgrade Smaller: File size is default OS Media, no applications More robust rollback capabilities on failure to functional down-level OS Zero dependencies on Windows ADK, supplemental to existing deployment scenarios Another tool in the OS deployment toolbox Refresh, replace, and bare metal Reduce upfront testing and deployment preparation
41
Manage Windows 10 devices via MDM with on-premises infrastructure
On-premises network Functionality available in ConfigMgr Technical Preview Ability to manage Windows 10 mobile devices Per-user device enrollment Settings and policies Device wipe and retire New features SQL Policies Data Windows 10 PCs and mobile devices (with MDM-style management of PCs) ConfigMgr Coming in Q4 2015 Ability to manage Windows 10 PCs with MDM-style management Software and app deployment Resource access profiles Bulk enrollment ConfigMgr console Example scenarios: IoT/embedded devices, highly regulated customers
42
Azure Virtual Machines architecture
VMs in Azure What’s new: Ability to run ConfigMgr roles in Azure Virtual Machines Offers flexibility with ConfigMgr architecture: on-premises, fully in Azure, or a hybrid configuration Primary site Management point/ distribution point On-premises network Internet-based device Management point/ distribution point On-premises client
43
Demo – ConfigMgr Technical Preview
Microsoft Ignite 2015 2/2/2019 7:15 PM Demo – ConfigMgr Technical Preview Mark Florida © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
44
Session Review Key Takeaway(s):
Tech Ready 15 2/2/2019 Session Review Key Takeaway(s): Managed Mobile Productivity == Enterprise Mobility Suite Windows 10 is coming and Configuration Manager and Microsoft Intune will be there to support you Intune has greatly expanded its management capabilities © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
45
Microsoft Mobility Quest
Liked what you saw? Experience it and win Visit our booth Check out our solutions Complete our missions ….You are entered to win!
46
Intune and ConfigMgr sessions
Tuesday: BRK3856 5:00pm Securing Access to Office 365 and other apps with Enterprise Mobility Suite Wednesday: BRK :45am Evolving Mobile Application Management for BYOD Devices with Microsoft Intune BRK3310 1:30pm Managing Windows 10 with Microsoft Intune and System Center Configuration Manager BRK3113 3:15pm Device and Data Protection with Mobile Device Management in Office 365 BRK3328 5:00pm What’s New with OSD in System Center Configuration Manager and the Microsoft Deployment Toolkit Thursday: BRK :45am Deep Dive on Android and iOS Device Management with Microsoft Intune BRK3495 5:00pm Managing Your Datacenter with Microsoft System Center Configuration Manager Friday: BRK3858 9am Configuring Corporate-Owned Mobile Devices with Microsoft Intune
47
Please evaluate this session
2/2/2019 7:15 PM Please evaluate this session Your feedback is important to us! Visit Myignite at or download and use the Ignite Mobile App with the QR code above. © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
48
2/2/2019 7:15 PM © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.