SlideShare a Scribd company logo
1 of 46
Download to read offline
Moderne device management
door middel van Cloud
Maarten Goet        Ronny de Jong
System Center MVP   System Center specialist
MVP
MCT
MCSE
Agenda
•   Welkom
•   Windows 8
•   Governance vs. Management
•   Windows Intune
•   System Center 2012
•   Demo’s 
•   Q&A
Windows 8

     Windows      All the apps                      Get more at the
     reimagined   you want       Cloud-connected    Windows Store




     Reimagined
     browsing     At home        Great experience   Built on
     with IE10    and at work    across hardware    a solid foundation
Windows 8 Enterprise



                       Support Mobile
                       Workforce
Governance vs. Management
Challenges to Enabling Consumerization


         I want to use the                How can IT support
         device I prefer                  and manage all
                               Change the Approach to
                                          those devices?
                               Client Management
                               • Put the end user in control of their
                                 experience
        I want to connect to   • Provide the IT Pro withprovide to
                                          How can IT the means
        people and be            safeguard apps and apps and
                                          access to data
        productive                        data while maintaining
        anywhere, anytime                 security?
Users + IT
•   Device Choice                         •   Manage all devices through single interface
•   Application Self-service              •   Deliver applications to the user, not the device
•   Personalized Application Experience   •   Integrated security and compliance
•   Non-intrusive management              •   Reduced infrastructure complexity


                                                                         Single admin
                                                                         console
          Access to corp resources
        across devices & platforms




            Users                                                                           IT
User-centric
Windows Intune
Microsoft’s recommended solution for Managed Deployment is
    Windows Intune
                                                      • IT manages collection of apps,
                                                        manages certificates and
                                                        enrollment and unenrollment of
                                                        phones




                                                                         • Enrollment
                                                                         • View apps via
              • Cloud services                                             Self Service
                                                                           Portal

Learn more about 3rd-party options at:
http://dev.windowsphone.com/en-us/featured/partners
Company portal
Management features for each platform
 Management Feature

 Over-the-air            Y   Y   Y
 Enrollment
 Inventory               Y   Y   Y   Y

 Settings Management     Y   Y   Y   Y

 Software Distribution   Y   Y   Y   Y

 Remote Wipe                 Y   Y   Y

 Retire                  Y   Y   Y   Y
demo
Windows Intune overview
System Center 2012                                                                                   2012




                                        Laptops,
 Client Management                                      Comprehensive    Management      Consumerization
                      Groups Model       Servers,
Infancy (NT Domain)                                      Management     from the Cloud        of IT
                                     Enterprise Scale
System Center 2012
                                                      Simplify
Empower Users          Unify Infrastructure         Administration




Empower people to be   Reduce costs by unifying   Improve IT effectiveness
more productive from      IT management               and efficiency.
 almost anywhere on        infrastructure.
  almost any device.
Architectuur
Modern Device Management
                   Devices & Platforms




   Single admin
   console
Native vs. Integrated



      Native       Integrated
demo
System Center 2012
Windows RT
A new member of the
Windows family


Commonality and    High-quality and   Long battery life /
shared code with   predictable        thin, light, and
Windows 8          experience         sleek
Windows RT for business
 Devices &
 Devices & experiences   Enterprise-Grade
                         Enabled for
 users love
 Experiences Users       Solutions use
                         business
 Want
Apps


   .ipa   .appx   traditioneel




   .ipk   .xap
App Deployment
Two Options Available to Deploy Apps
                 Use Windows Intune to manage the policies, app inventory, auto get app token,
Managed          manage apps, enroll and un-enroll employees. Employees discover and install
                 apps through the Self-service Portal
Windows Intune   OR
Or 3rd party
                 Use 3rd-party management and deployment tools


Unmanaged        Use email to communicate with employees
                 Employees view app inventory either in repositories (e.g. SharePoint) or through
Custom           an app that company can build using the Enterprise SDK API (the “Company
deployment       Hub”)
What Are the Steps?
Develop
or Acquire Apps
Windows Store apps
Installation                                             Provisioning




Install via an “Enterprise App Store” using:             Provision using the Microsoft Deployment
– System Center 2012 Configuration Manager               Toolkit 2012 or DISM
  SP1                                                    – Include in sysprepped image
– Windows Intune                                         – Customize Start screen layout

Enterprise side loading requirements
• Windows 8 Enterprise, domain joined or with a separate side load product key
• Windows 8 Pro or Windows RT, with a separate side load product key
Using ConfigMgr
Things to Remember

•   Windows Store apps install per user
     – Cannot be installed via a task sequence
     – No native support for provisioning apps, but this can be done using
       standard software distribution and custom command lines
     – Use the App Catalog web site to enable self-service installation of Windows
       Store apps
     – “Deep links” can be used, but the user must still log in with a Microsoft
       Account and click “Install”
•   Requires ConfigMgr 2012 SP1
Enrollment
demo
Windows RT management
Cross platform support
Cross platform support
Settings management
• Settings can be be applied to devices managed in Windows Intune
  and devices managed through the Exchange Server Connector
• Single security policy template is used to managed settings on all
  managed mobile devices. System figures out applicability to each
  platform
• In ConfigMgr Exchange managed device settings are configured
  separately
• Reporting available on each setting (applicable, conformant or
  error)
• If a device is receiving policy from more than 1 entity, the policy that
  applies the most secure value for a setting is applied.
Settings for each mobile platform
               Setting name                                                                                EAS (Activesync)   WinRT/ WinPh8   iOS

               Require a password to unlock mobile devices                                                        √                √          √
               Required password type                                                                             √                √          √
               Minimum password length                                                                            √                √          √
               Allow simple passwords                                                                             √                √          √
Password
               Number of repeated sign-in failures before device is wiped                                         √                √          √
               Minutes of inactivity before device screen is locked                                               √                √          √
               Password expiration (days)                                                                         √                √          √
               Remember password history                                                                          √                √          √
               Allow convenience logon (WindowsRT only)                                                           X                √          X
               Allow camera                                                                                       √                X          √
               Allow web browser                                                                                  √                X          √
Restrictions   Allow backup to iCloud (iOS only)                                                                  X                X          √
               Allow documents sync to iCloud (iOS only)                                                          X                X          √
               Allow photostream sync to icloud (iOS only)                                                        X                X          √
               Maximum size of e-mail attachments                                                                 √                X          X
               E-mail synchronization for last (days)                                                             √                X          X
Email
               Allow mobile devices that don’t fully support these settings to synchronize with Exchange          √                X          X
               Require encryption on mobile device                                                                √                X          X
Encryption
               Require encryption on storage cards                                                                √                X          X
demo
Settings Management
Federation




http://technet.microsoft.com/en-us/library/hh967629.aspx
Retirement
Retire details
                      Windows RT         Windows Phone 8        iOS                       Android (EAS
                                                                                          managed)
Device record       Yes                  Yes                    Yes                       Yes
removed from Intune
DB and UI
Device record         No (see note)      No                     No                        Yes
removed from
Exchange (no email)
Removal of Side-      Yes                Yes (Application       --                        --
loaded keys                              Enrollment Token is
                                         removed)
Installed LOB apps    Side loaded apps   Side loaded apps are   Installed apps will still Installed apps will still
                      won’t run          uninstalled            run                       run
Installing new LOB    Apps cannot be     No since SSP is        Apps cannot be            Apps can still be
apps                  installed          uninstalled            installed                 installed
Bedankt! Vragen?
System Center trainingen!
Moderne device management door middel van cloud

More Related Content

What's hot

OIB Brochure (Eng)
OIB Brochure (Eng)OIB Brochure (Eng)
OIB Brochure (Eng)dyanger
 
PCTY 2012, Tivoli Endpoint Manager v. Martin Vittrup
PCTY 2012, Tivoli Endpoint Manager v. Martin VittrupPCTY 2012, Tivoli Endpoint Manager v. Martin Vittrup
PCTY 2012, Tivoli Endpoint Manager v. Martin VittrupIBM Danmark
 
Designing Rich Mobile Apps in a Fragmented World
Designing Rich Mobile Apps in a Fragmented WorldDesigning Rich Mobile Apps in a Fragmented World
Designing Rich Mobile Apps in a Fragmented WorldWorklight
 
B sep ds-21194634.en-us
B sep ds-21194634.en-usB sep ds-21194634.en-us
B sep ds-21194634.en-usPelos TCHIKAYA
 
Evaluating Microsoft Windows 8 Security on Intel Architecture Tablets
Evaluating Microsoft Windows 8 Security on Intel Architecture TabletsEvaluating Microsoft Windows 8 Security on Intel Architecture Tablets
Evaluating Microsoft Windows 8 Security on Intel Architecture TabletsIT@Intel
 
Discovering Computers: Chapter 08
Discovering Computers: Chapter 08Discovering Computers: Chapter 08
Discovering Computers: Chapter 08Anna Stirling
 
Audio And Web Conferencing
Audio And Web ConferencingAudio And Web Conferencing
Audio And Web ConferencingMicrotelSystems
 
What's new in ibm i notes 9.0
What's new in ibm i notes 9.0What's new in ibm i notes 9.0
What's new in ibm i notes 9.0Ranjit Rai
 
Pb 0160 I Pedge Rev4 Fyi
Pb 0160 I Pedge Rev4 FyiPb 0160 I Pedge Rev4 Fyi
Pb 0160 I Pedge Rev4 FyiBridget Deets
 
TCO & TVT
TCO & TVTTCO & TVT
TCO & TVTLeoCurtis
 
What is new in xd 5.6 and fp1 061212
What is new in xd 5.6 and fp1 061212What is new in xd 5.6 and fp1 061212
What is new in xd 5.6 and fp1 061212Nuno Alves
 
Comp tia a+_session_03
Comp tia a+_session_03Comp tia a+_session_03
Comp tia a+_session_03Niit Care
 
Lotus Notes Mobile Application Development Using XPages
Lotus Notes Mobile Application Development Using XPagesLotus Notes Mobile Application Development Using XPages
Lotus Notes Mobile Application Development Using XPagesCognizant
 
Comp tia n+_session_09
Comp tia n+_session_09Comp tia n+_session_09
Comp tia n+_session_09Niit Care
 
Remote Access Management
Remote Access ManagementRemote Access Management
Remote Access Managementdavidzucker
 

What's hot (20)

OIB Brochure (Eng)
OIB Brochure (Eng)OIB Brochure (Eng)
OIB Brochure (Eng)
 
PCTY 2012, Tivoli Endpoint Manager v. Martin Vittrup
PCTY 2012, Tivoli Endpoint Manager v. Martin VittrupPCTY 2012, Tivoli Endpoint Manager v. Martin Vittrup
PCTY 2012, Tivoli Endpoint Manager v. Martin Vittrup
 
Designing Rich Mobile Apps in a Fragmented World
Designing Rich Mobile Apps in a Fragmented WorldDesigning Rich Mobile Apps in a Fragmented World
Designing Rich Mobile Apps in a Fragmented World
 
B sep ds-21194634.en-us
B sep ds-21194634.en-usB sep ds-21194634.en-us
B sep ds-21194634.en-us
 
Evaluating Microsoft Windows 8 Security on Intel Architecture Tablets
Evaluating Microsoft Windows 8 Security on Intel Architecture TabletsEvaluating Microsoft Windows 8 Security on Intel Architecture Tablets
Evaluating Microsoft Windows 8 Security on Intel Architecture Tablets
 
Output
OutputOutput
Output
 
Discovering Computers: Chapter 08
Discovering Computers: Chapter 08Discovering Computers: Chapter 08
Discovering Computers: Chapter 08
 
Audio And Web Conferencing
Audio And Web ConferencingAudio And Web Conferencing
Audio And Web Conferencing
 
What's new in ibm i notes 9.0
What's new in ibm i notes 9.0What's new in ibm i notes 9.0
What's new in ibm i notes 9.0
 
Pb 0160 I Pedge Rev4 Fyi
Pb 0160 I Pedge Rev4 FyiPb 0160 I Pedge Rev4 Fyi
Pb 0160 I Pedge Rev4 Fyi
 
TCO & TVT
TCO & TVTTCO & TVT
TCO & TVT
 
Mdm solutions comparison
Mdm solutions comparisonMdm solutions comparison
Mdm solutions comparison
 
Input
InputInput
Input
 
What is new in xd 5.6 and fp1 061212
What is new in xd 5.6 and fp1 061212What is new in xd 5.6 and fp1 061212
What is new in xd 5.6 and fp1 061212
 
Comp tia a+_session_03
Comp tia a+_session_03Comp tia a+_session_03
Comp tia a+_session_03
 
Lotus Notes Mobile Application Development Using XPages
Lotus Notes Mobile Application Development Using XPagesLotus Notes Mobile Application Development Using XPages
Lotus Notes Mobile Application Development Using XPages
 
Comp tia n+_session_09
Comp tia n+_session_09Comp tia n+_session_09
Comp tia n+_session_09
 
Remote Access Management
Remote Access ManagementRemote Access Management
Remote Access Management
 
DA8_presentation
DA8_presentationDA8_presentation
DA8_presentation
 
X230 brochure
X230 brochureX230 brochure
X230 brochure
 

Similar to Moderne device management door middel van cloud

Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Nordic Infrastructure Conference
 
Enterprise Mobility (Admin)
Enterprise Mobility (Admin)Enterprise Mobility (Admin)
Enterprise Mobility (Admin)Microsoft
 
New Features for Mobile Device Management (MDM) With Entgra
New Features for Mobile Device Management (MDM) With EntgraNew Features for Mobile Device Management (MDM) With Entgra
New Features for Mobile Device Management (MDM) With EntgraVichitra Godamunne
 
Entgra IoT Server 4.1 Webinar.pdf
Entgra IoT Server 4.1 Webinar.pdfEntgra IoT Server 4.1 Webinar.pdf
Entgra IoT Server 4.1 Webinar.pdfVichitraGodamunne1
 
What's your BYOD Strategy? Objectives and tips from Microsoft & Aptera
What's your BYOD Strategy? Objectives and tips from Microsoft & ApteraWhat's your BYOD Strategy? Objectives and tips from Microsoft & Aptera
What's your BYOD Strategy? Objectives and tips from Microsoft & ApteraAptera Inc
 
Migrate from BigFix to Ivanti
Migrate from BigFix to IvantiMigrate from BigFix to Ivanti
Migrate from BigFix to IvantiIvanti
 
Aptera Cloud Event 2013 - Windows Intune - Eric Rupp
Aptera Cloud Event 2013 - Windows Intune - Eric RuppAptera Cloud Event 2013 - Windows Intune - Eric Rupp
Aptera Cloud Event 2013 - Windows Intune - Eric RuppAptera Inc
 
In tune inaction
In tune inactionIn tune inaction
In tune inactionOlav Tvedt
 
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Nordic Infrastructure Conference
 
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...
Managing Mobility - Microsoft Enterprise Mobility -  Accelerate, Protec and M...Managing Mobility - Microsoft Enterprise Mobility -  Accelerate, Protec and M...
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...Herman Arnedo
 
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
Microsoft Enterprise Mobility Suite Launch Presentation - AtidanMicrosoft Enterprise Mobility Suite Launch Presentation - Atidan
Microsoft Enterprise Mobility Suite Launch Presentation - AtidanDavid J Rosenthal
 
End User Computing & Server Licensing Slides - Nhs Microsoft Licensing Wo...
End User Computing & Server Licensing Slides - Nhs Microsoft Licensing Wo...End User Computing & Server Licensing Slides - Nhs Microsoft Licensing Wo...
End User Computing & Server Licensing Slides - Nhs Microsoft Licensing Wo...Charlie78horse
 
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneSystem Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneAmit Gatenyo
 
Microsoft Enterprise Mobility Suite | Getting started....
Microsoft Enterprise Mobility Suite | Getting started....Microsoft Enterprise Mobility Suite | Getting started....
Microsoft Enterprise Mobility Suite | Getting started....Thomas Godsted Rysgaard
 
Microsoft System center Configuration manager 2012 sp1
Microsoft System center Configuration manager 2012 sp1Microsoft System center Configuration manager 2012 sp1
Microsoft System center Configuration manager 2012 sp1solarisyougood
 

Similar to Moderne device management door middel van cloud (20)

Discover Great Reasons to move to ConfigMgr 2012 SP1
Discover Great Reasons to move to ConfigMgr 2012 SP1Discover Great Reasons to move to ConfigMgr 2012 SP1
Discover Great Reasons to move to ConfigMgr 2012 SP1
 
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
 
Enterprise Mobility (Admin)
Enterprise Mobility (Admin)Enterprise Mobility (Admin)
Enterprise Mobility (Admin)
 
New Features for Mobile Device Management (MDM) With Entgra
New Features for Mobile Device Management (MDM) With EntgraNew Features for Mobile Device Management (MDM) With Entgra
New Features for Mobile Device Management (MDM) With Entgra
 
Entgra IoT Server 4.1 Webinar.pdf
Entgra IoT Server 4.1 Webinar.pdfEntgra IoT Server 4.1 Webinar.pdf
Entgra IoT Server 4.1 Webinar.pdf
 
Windows intune
Windows intuneWindows intune
Windows intune
 
VMware Workspace One
VMware Workspace OneVMware Workspace One
VMware Workspace One
 
W8 client management
W8 client managementW8 client management
W8 client management
 
What's your BYOD Strategy? Objectives and tips from Microsoft & Aptera
What's your BYOD Strategy? Objectives and tips from Microsoft & ApteraWhat's your BYOD Strategy? Objectives and tips from Microsoft & Aptera
What's your BYOD Strategy? Objectives and tips from Microsoft & Aptera
 
Migrate from BigFix to Ivanti
Migrate from BigFix to IvantiMigrate from BigFix to Ivanti
Migrate from BigFix to Ivanti
 
Aptera Cloud Event 2013 - Windows Intune - Eric Rupp
Aptera Cloud Event 2013 - Windows Intune - Eric RuppAptera Cloud Event 2013 - Windows Intune - Eric Rupp
Aptera Cloud Event 2013 - Windows Intune - Eric Rupp
 
In tune inaction
In tune inactionIn tune inaction
In tune inaction
 
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
 
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...
Managing Mobility - Microsoft Enterprise Mobility -  Accelerate, Protec and M...Managing Mobility - Microsoft Enterprise Mobility -  Accelerate, Protec and M...
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...
 
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
Microsoft Enterprise Mobility Suite Launch Presentation - AtidanMicrosoft Enterprise Mobility Suite Launch Presentation - Atidan
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
 
Airwatch od VMware
Airwatch od VMwareAirwatch od VMware
Airwatch od VMware
 
End User Computing & Server Licensing Slides - Nhs Microsoft Licensing Wo...
End User Computing & Server Licensing Slides - Nhs Microsoft Licensing Wo...End User Computing & Server Licensing Slides - Nhs Microsoft Licensing Wo...
End User Computing & Server Licensing Slides - Nhs Microsoft Licensing Wo...
 
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneSystem Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
 
Microsoft Enterprise Mobility Suite | Getting started....
Microsoft Enterprise Mobility Suite | Getting started....Microsoft Enterprise Mobility Suite | Getting started....
Microsoft Enterprise Mobility Suite | Getting started....
 
Microsoft System center Configuration manager 2012 sp1
Microsoft System center Configuration manager 2012 sp1Microsoft System center Configuration manager 2012 sp1
Microsoft System center Configuration manager 2012 sp1
 

More from CompuTrain. De IT opleider.

Techdays 2013 managing your hybrid cloud datacenter with scom 2012 and what...
Techdays 2013   managing your hybrid cloud datacenter with scom 2012 and what...Techdays 2013   managing your hybrid cloud datacenter with scom 2012 and what...
Techdays 2013 managing your hybrid cloud datacenter with scom 2012 and what...CompuTrain. De IT opleider.
 
Planet azure starship system center exploring new worlds
Planet azure starship system center exploring new worldsPlanet azure starship system center exploring new worlds
Planet azure starship system center exploring new worldsCompuTrain. De IT opleider.
 
Techdays 2013 the road to end user self service with service manager 2012
Techdays 2013   the road to end user self service with service manager 2012Techdays 2013   the road to end user self service with service manager 2012
Techdays 2013 the road to end user self service with service manager 2012CompuTrain. De IT opleider.
 
Windows Server 2012 Seminar 4 - De mogelijkheden van Direct Access
Windows Server 2012 Seminar 4 - De mogelijkheden van Direct AccessWindows Server 2012 Seminar 4 - De mogelijkheden van Direct Access
Windows Server 2012 Seminar 4 - De mogelijkheden van Direct AccessCompuTrain. De IT opleider.
 
Windows Server 2012 - Dynamische opslag met Storage Pools
Windows Server 2012 - Dynamische opslag met Storage PoolsWindows Server 2012 - Dynamische opslag met Storage Pools
Windows Server 2012 - Dynamische opslag met Storage PoolsCompuTrain. De IT opleider.
 

More from CompuTrain. De IT opleider. (7)

Techdays 2013 managing your hybrid cloud datacenter with scom 2012 and what...
Techdays 2013   managing your hybrid cloud datacenter with scom 2012 and what...Techdays 2013   managing your hybrid cloud datacenter with scom 2012 and what...
Techdays 2013 managing your hybrid cloud datacenter with scom 2012 and what...
 
Planet azure starship system center exploring new worlds
Planet azure starship system center exploring new worldsPlanet azure starship system center exploring new worlds
Planet azure starship system center exploring new worlds
 
Cloud. het draait allemaal om de app!
Cloud. het draait allemaal om de app!Cloud. het draait allemaal om de app!
Cloud. het draait allemaal om de app!
 
Techdays 2013 the road to end user self service with service manager 2012
Techdays 2013   the road to end user self service with service manager 2012Techdays 2013   the road to end user self service with service manager 2012
Techdays 2013 the road to end user self service with service manager 2012
 
Windows Server 2012 Seminar 4 - De mogelijkheden van Direct Access
Windows Server 2012 Seminar 4 - De mogelijkheden van Direct AccessWindows Server 2012 Seminar 4 - De mogelijkheden van Direct Access
Windows Server 2012 Seminar 4 - De mogelijkheden van Direct Access
 
Windows server 2012 Seminar 3: Hyper-V replica
Windows server 2012 Seminar 3: Hyper-V replicaWindows server 2012 Seminar 3: Hyper-V replica
Windows server 2012 Seminar 3: Hyper-V replica
 
Windows Server 2012 - Dynamische opslag met Storage Pools
Windows Server 2012 - Dynamische opslag met Storage PoolsWindows Server 2012 - Dynamische opslag met Storage Pools
Windows Server 2012 - Dynamische opslag met Storage Pools
 

Moderne device management door middel van cloud

  • 1.
  • 2. Moderne device management door middel van Cloud Maarten Goet Ronny de Jong System Center MVP System Center specialist
  • 3. MVP
  • 5. Agenda • Welkom • Windows 8 • Governance vs. Management • Windows Intune • System Center 2012 • Demo’s  • Q&A
  • 6.
  • 7. Windows 8 Windows All the apps Get more at the reimagined you want Cloud-connected Windows Store Reimagined browsing At home Great experience Built on with IE10 and at work across hardware a solid foundation
  • 8. Windows 8 Enterprise Support Mobile Workforce
  • 10. Challenges to Enabling Consumerization I want to use the How can IT support device I prefer and manage all Change the Approach to those devices? Client Management • Put the end user in control of their experience I want to connect to • Provide the IT Pro withprovide to How can IT the means people and be safeguard apps and apps and access to data productive data while maintaining anywhere, anytime security?
  • 11. Users + IT • Device Choice • Manage all devices through single interface • Application Self-service • Deliver applications to the user, not the device • Personalized Application Experience • Integrated security and compliance • Non-intrusive management • Reduced infrastructure complexity Single admin console Access to corp resources across devices & platforms Users IT
  • 14. Microsoft’s recommended solution for Managed Deployment is Windows Intune • IT manages collection of apps, manages certificates and enrollment and unenrollment of phones • Enrollment • View apps via • Cloud services Self Service Portal Learn more about 3rd-party options at: http://dev.windowsphone.com/en-us/featured/partners
  • 16. Management features for each platform Management Feature Over-the-air Y Y Y Enrollment Inventory Y Y Y Y Settings Management Y Y Y Y Software Distribution Y Y Y Y Remote Wipe Y Y Y Retire Y Y Y Y
  • 18. System Center 2012 2012 Laptops, Client Management Comprehensive Management Consumerization Groups Model Servers, Infancy (NT Domain) Management from the Cloud of IT Enterprise Scale
  • 19. System Center 2012 Simplify Empower Users Unify Infrastructure Administration Empower people to be Reduce costs by unifying Improve IT effectiveness more productive from IT management and efficiency. almost anywhere on infrastructure. almost any device.
  • 21. Modern Device Management Devices & Platforms Single admin console
  • 22. Native vs. Integrated Native Integrated
  • 24. Windows RT A new member of the Windows family Commonality and High-quality and Long battery life / shared code with predictable thin, light, and Windows 8 experience sleek
  • 25.
  • 26. Windows RT for business Devices & Devices & experiences Enterprise-Grade Enabled for users love Experiences Users Solutions use business Want
  • 27. Apps .ipa .appx traditioneel .ipk .xap
  • 29. Two Options Available to Deploy Apps Use Windows Intune to manage the policies, app inventory, auto get app token, Managed manage apps, enroll and un-enroll employees. Employees discover and install apps through the Self-service Portal Windows Intune OR Or 3rd party Use 3rd-party management and deployment tools Unmanaged Use email to communicate with employees Employees view app inventory either in repositories (e.g. SharePoint) or through Custom an app that company can build using the Enterprise SDK API (the “Company deployment Hub”)
  • 30. What Are the Steps?
  • 32. Windows Store apps Installation Provisioning Install via an “Enterprise App Store” using: Provision using the Microsoft Deployment – System Center 2012 Configuration Manager Toolkit 2012 or DISM SP1 – Include in sysprepped image – Windows Intune – Customize Start screen layout Enterprise side loading requirements • Windows 8 Enterprise, domain joined or with a separate side load product key • Windows 8 Pro or Windows RT, with a separate side load product key
  • 33. Using ConfigMgr Things to Remember • Windows Store apps install per user – Cannot be installed via a task sequence – No native support for provisioning apps, but this can be done using standard software distribution and custom command lines – Use the App Catalog web site to enable self-service installation of Windows Store apps – “Deep links” can be used, but the user must still log in with a Microsoft Account and click “Install” • Requires ConfigMgr 2012 SP1
  • 38. Settings management • Settings can be be applied to devices managed in Windows Intune and devices managed through the Exchange Server Connector • Single security policy template is used to managed settings on all managed mobile devices. System figures out applicability to each platform • In ConfigMgr Exchange managed device settings are configured separately • Reporting available on each setting (applicable, conformant or error) • If a device is receiving policy from more than 1 entity, the policy that applies the most secure value for a setting is applied.
  • 39. Settings for each mobile platform Setting name EAS (Activesync) WinRT/ WinPh8 iOS Require a password to unlock mobile devices √ √ √ Required password type √ √ √ Minimum password length √ √ √ Allow simple passwords √ √ √ Password Number of repeated sign-in failures before device is wiped √ √ √ Minutes of inactivity before device screen is locked √ √ √ Password expiration (days) √ √ √ Remember password history √ √ √ Allow convenience logon (WindowsRT only) X √ X Allow camera √ X √ Allow web browser √ X √ Restrictions Allow backup to iCloud (iOS only) X X √ Allow documents sync to iCloud (iOS only) X X √ Allow photostream sync to icloud (iOS only) X X √ Maximum size of e-mail attachments √ X X E-mail synchronization for last (days) √ X X Email Allow mobile devices that don’t fully support these settings to synchronize with Exchange √ X X Require encryption on mobile device √ X X Encryption Require encryption on storage cards √ X X
  • 43. Retire details Windows RT Windows Phone 8 iOS Android (EAS managed) Device record Yes Yes Yes Yes removed from Intune DB and UI Device record No (see note) No No Yes removed from Exchange (no email) Removal of Side- Yes Yes (Application -- -- loaded keys Enrollment Token is removed) Installed LOB apps Side loaded apps Side loaded apps are Installed apps will still Installed apps will still won’t run uninstalled run run Installing new LOB Apps cannot be No since SSP is Apps cannot be Apps can still be apps installed uninstalled installed installed