Microsoft Intune: Mobile Device and Application Management From The Cloud
Microsoft Intune: Mobile Device and Application Management From The Cloud
Microsoft Intune: Mobile Device and Application Management From The Cloud
Speaker Name
Date
Mobility is the new normal
52% 90% >80%
Enable Protect
your users Unify your environment your data
Why Microsoft? Our mobility solution is different
Access from many devices It’s integrated on common identity
Easily manage identities across Manage and protect corporate apps Encryption, identity, and authorization
on-premises and cloud. Single sign-on and data on almost any device with policies to secure corporate files and
and self-service for corporate resources. MDM and MAM. email across phones, tablets, and PCs.
Device management challenges
Traditional PC management
BYOD
CYOD
Regulated devices
User IT
Microsoft Intune
User IT
User IT
Microsoft Intune
User IT
Microsoft Intune
Windows 10 Azure AD
Enterprise-compliant services Joined Devices
Ability to contact IT
Volume purchasing
Purchase licenses in bulk for paid
apps using the Windows Store for Volume purchasing integration
Business and Apple Volume
Purchasing Program (VPP)
Assign licenses to users
Deploy licenses to users with License and app
Intune and install apps as required installed by store
devices
Schools providing
tablets for technology-
based learning
Bulk enrollment options
Business IT
Manager
Apply policies
On-premises
Mobile devices
Devices Apps
PCs Data Apps
Users Data
Web browsers
Access
The control cannot
perimeter to corporate data today
help protect data stored in the cloud
Protect data in a mobile-first, cloud-first world
Enterprise
Mobility Suite
Devices Apps
Users Data
SharePoint Exchange
Online Online
IP Range
Device State
User
Cloud
Advanced
Windows 10
options
User Group
On-premises
Conditional access
Policy compliance verification
User
Measured boot integrity status
(Windows PPCH)
Policy
verification Advanced device compliance
(antivirus, firewall, patch state, etc.)
Windows 10
Microsoft Intune
Windows
Provable PC
Health (PPCH)
Mobile device management
Apply and enforce device configuration settings across iOS,
Android, and Windows via Intune MDM
Manage settings across Windows 10 PC, phone, and IoT devices via Intune MDM –
including Windows Defender (anti-malware), Firewall, and Cortana
Personal
User data IT
MAM
policies Corporate apps
User
6 User continues to use the app as per
usual
Intune app partners
Microsoft apps, such as Office, Dynamics CRM, Power BI, and more
IT
IT
Apply policies
Control app access to corporate data and
prevent copy and paste-related data leaks
Save
File share
Protect data at rest and wherever it may
roam*
User
Secure content collaboration through Save Personal
integration with Azure Rights Management storage
Corporate
network
* Some roaming scenarios use Azure Right Management
Protect corporate data with Windows 10
Device protection Data separation Leak protection Sharing protection
Device settings
Windows
Defender
Firewall
Firewall
apps integrated with content
and access systems
Custom Custom Custom Depends on
email app collab app file app specific DMZ
infrastructure
Firewall
Firewall
file layer
User IT
Summary
flexibility architecture
Enable
enterprise mobility with
EMS
Deployment flexibility
Intune standalone (cloud only) Configuration Manager integrated with Intune (hybrid)
IT IT
System Center
Configuration
Manager
Making it easier to deliver Keeping the selling workforce Bringing a new level of
a great brand experience productive efficiency to management
Next Steps
Sign up for a free trial: aka.ms/IntuneFreeTrial Learn more about our enterprise mobility products
and solutions:
Request an enterprise mobility proof-of-
concept from your account team or partner Enterprise Mobility Suite:
aka.ms/EnterpriseMobilitySuite
Find a partner with competency in devices,
Mobile device and application management:
deployment, identity, and access
aka.ms/MDM-MAM
Take advantage of your Microsoft Intune:
Software Assurance Planning Services benefits aka.ms/MicrosoftIntune
System Center 2012 R2 Configuration
Manager: aka.ms/ConfigMgr
alias@Microsoft.com
© 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.
The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the
part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Appendix
46
Mitchells and Butlers, a pub and
restaurant company, boosts service and
satisfaction with mobile device and
application management.
“By using Microsoft Intune, we can
improve staff members’ work experience
and guest satisfaction, while reducing IT
labor and operational costs. Everyone
wins.”
Tim Banham
Solution Architect
Mitchells and Butlers
Empire Today, a national flooring
company, uses mobile device
management to expedite sales and
boost efficiency.
“Our competitive strategy depends on
deploying Microsoft Intune to manage
1,200 tablets used by our independent
sales contractors to improve our in-
home sales process and win more
business.”
Steven Creaney
Senior .NET Developer
Empire Today
Foxtons, a real estate agency, boosts
business, customer service, with
remotely managed solution.
Gurdip Kundi
Senior Systems Engineer
Foxtons
The Walsh Group, a Chicago-based
construction firm, uses cloud-based
tools to advance mobility and
productivity
“We use the Enterprise Mobility Suite to
empower employees to use their own
devices to securely access and share
their data. The upshot? We’re improving
project management and reducing
costs.”
Patrick Wirtz
Innovation Manager
The Walsh Group
A rendering of the new Tom Bradley International Terminal’s great hall. (credit: Los Angeles World Airports)
Empowering enterprise mobility
User IT
Enable Protect
your users your data
Identity
Device (optional)
Application
Data
Microsoft Passport management for Window 10
Microsoft Intune
Authenticate and
trust my unique key
Access corporate Azure Active Directory
resources and
Authentication
token Active Directory
Why CYOD?
IT admins End users
Need easy way to prepare corporate- Need fast and easy way to enroll CYOD
owned devices for enrollment devices
Need to distinguish corporate-owned Should not be able to un-enroll devices
devices from personal-owned devices in that are corporate-owned
the management console Need access to corporate apps and
Need fast and easy way to bulk enroll other MDM capabilities on devices to
shared devices be productive
Need devices to be secure at all times
and within IT control
IT User
Evolution of mobile device management in Windows
Significant investments in added functionality for both mobile and desktop devices
Comprehensive
device management
Device lockdown
Email
attachment
User
Copy Paste Save
Paste to Save to
personal app personal storage
Personal apps
Maximize productivity while preventing leakage of company
data by restricting actions such as copy, cut, paste, and save
as between Intune-managed apps and unmanaged apps
Manage devices from virtually anywhere
New intuitive dashboard
Respond to alerts
View reports
Role-based management
Devices Supported
• Windows PCs (x86/64, Intel SoC)
• Windows RT
• Windows Phone 8.x
• iOS
• Android
• OS X
Mobile devices and PCs
Deployment flexibility
System Center 2012 R2 Configuration Configuration Manager integrated with Intune (hybrid)
Manager with Microsoft Intune
• Build on existing Configuration Manager
deployment
IT
• Full PC management (OS deployment, endpoint
protection, application delivery control, custom Configuration Manager console
reporting)
•Deep policy control requirements
•Greater scalability
• Extensible administration tools (RBA, PowerShell,
SQL reporting services) System Center
Configuration
Manager
Devices Supported
• Windows PCs • Windows RT
(x86/64, Intel SoC) • Windows Phone 8.x
• Windows to Go • iOS
• Windows Server • Android
• Linux
• OS X
Domain joined PCs Mobile devices
PC management
Intune standalone (cloud only) Configuration Manager integrated with Intune (hybrid)
Lightweight, agentless OR agent-based management Lightweight, agentless OR comprehensive agent-based management
PC protection from malware PC protection from malware
PC
PC software
software update
update management
management PC software update management
Software
Software distribution
distribution Software distribution
Proactive monitoring and alerts
Proactive monitoring and alerts Proactive monitoring and alerts
Hardware and software inventory
Hardware and software inventory Hardware and software inventory
Policies for Windows Firewall management
Policies for Windows Firewall management Policies for Windows Firewall management
User
User IT
Mobile device
Conditional access for Exchange on-premises
Allow managed
device
5
On-premises 1
Microsoft Intune
Who does what? Exchange
server
Block unmanaged
device
Mobile device
Paths to managed applications
Intune App Wrapping
Office mobile apps Intune Viewer apps Intune App SDK
Tool
Microsoft Office mobile Intune provides apps for Make any app manageable Build your apps from the
apps are natively secure content viewing without modifying code ground-up with Intune
manageable with Intune App SDK
• Word • Managed Browser • ‘Wrap’ internal line-of-
• Developers can easily
• Excel • PDF Viewer business (LOB) apps to
manage with Intune integrate applications for
• PowerPoint • AV Player manageability
MAM policies
• OneNote • Image Viewer • Provide more control
over user experience
• Outlook
with App SDK (vs. App
• OneDrive for Business Wrapping Tool)
Making applications manageable
Intune App Wrapping Tool Intune App SDK
Allows you to apply Intune MAM policies to Enables additional options to manage internal
existing line-of business (LOB) apps: apps with Intune MAM policies:
• Post-compilation command line tool for IT Pros • Intune App SDK and App Wrapping Tool use the same
processing and enforcement engine
• Supports repackaging unencrypted applications
• SDK can be used for both LOB apps and store apps
• Applications are signed with company-specific certificates
• Enables additional MAM functionality over the app than the
App Wrapping Tool (for example: disable save as
Intune App Wrapping Tool: functionality of the app)
• Platform-specific tools for iOS (Mac OS X 10.8.5+) and
Android (Windows)
• Published by Microsoft (available on Download Center)
• Product documentation and in-tool command line help
Steps for protecting LOB apps
Intune
app wrapping tool
or SDK
User IT
LOB application
• End user is taken to the store for installation • No trip to the store; installation begins directly
• Installation status is not reported in the admin • Installation status is reported in the admin console
console
• Push apps; apps can be installed directly.
• IT Pro can only make it available in Company Portal
• App on the device is marked as a managed app in
• App on the device is marked as a personal app in the inventory
inventory
• Works only for free store apps
• Works for both free and paid apps
• MAM policies can be applied
• MAM policies cannot be applied
Options for corporate data removal
Full wipe Selective wipe
• All data on the device is removed • Company resources (apps, data, profiles,
certificates, settings, and email) are removed
• Device is reset to factory defaults
• MAM support adds ability to remove only
• Typically used for lost/stolen devices or resetting
corporate data from multi-account applications
corporate-owned devices
• Typically used for personal-owned devices
Managed corporate-owned devices
Bulk enrollment Configuration policies
• Support for Apple Device Enrollment Program • Policies and apps targeted to devices
Business IT
Manager
Apply policies
Enrolls devices
on behalf
of users Distributes
to users Restaurant School Retail Store
Bulk enrollment with Apple Configurator
iOS devices will
automatically enroll on
first power on
User IT
Export device enrollment
profile from Intune
Configure iOS
devices with the Import to Apple
Apple Configurator Configurator
Apple Device Enrollment Program (DEP)
User IT
Custom iOS policy
User IT
Windows 8.1/10 ● ● ● ●
Windows RT ● ● ●
iOS ● ● ● ●
Android ● ● ● ●
Windows Phone ● ● ●
Mobile device configuration settings (PIN length, PIN required, lock time, etc.) ● ● ● ●
Self-service password reset (Office 365 cloud only users) ● ● ● ●
Provides reporting on devices that do not meet IT policy ● ● ●
Group-based policies and reporting (ability to use groups for targeted device configuration) ● ● ●
Office 365
Self-service Company Portal for users to enroll their own devices and install corporate apps