Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
ITCamp 2011 - Tudor Galos - Windows Intune
1. Windows Intune
Tudor Galoș, Windows Business Group Lead
Microsoft Romania
www.tudorgalos.ro , @tudorg
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
2. IT Camp 2011
• Thanks for coming!
• ITCamp is made possible by our sponsors:
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
3. Session agenda
• Windows Intune Overview
• Deploying and Installing the Windows
Intune Client
• Computer Administration by Using
Windows Intune
• Windows Intune Systems Management
• Using the Windows Intune Client
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
4. Challenges in Managing Business PCs
– Multiple configurations, versions, and
licenses
– Lack of insight and control
– Workers in many locations
– Reactive response to support issues
– High infrastructure investments required
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
5. Introducing Windows Intune
– Manage and secure Windows PCs anywhere
• Online PC management and security mean that you can work from
anywhere over the Internet
• The management console is browser-based, so administrators can be
anywhere
– The best Windows experience
• Includes upgrade rights to Windows 7 Enterprise
• Keep up to date with Software Assurance
– Grows with the business
• Offers per-seat licensing
• No server infrastructure is required
• It is easy to deploy, use, and maintain
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
6. Managing and Securing PCs in Any Location by
Using Windows Intune
– Agents report to the Windows Intune service
– Support engineers access the data via the Web-based
console
– Windows Live ID is required for administrative access
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
7. Session agenda
• Windows Intune Overview
• Deploying and Installing the Windows
Intune Client
• Computer Administration by Using
Windows Intune
• Windows Intune Systems Management
• Using the Windows Intune Client
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
8. Windows Intune Deployment Routes
• Direct download
• Network share
• Flash drive
• Electronic Software Distribution (ESD)
• Web distribution
Windows Intune
Service
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
9. The Windows Intune Client Installation Process
• The Windows Intune agent starts
• It authenticates against the cloud service and enrolls the client computer
• The computer can be viewed in the Unassigned Computers group in the
Enrollment
administrator console
• The installation downloads agents from the Windows Update service
• Each agent starts up as it is downloaded
Agent • Each agent reports information to the Windows Intune service
installation • Agents with failed installations raise alerts on the administrator console
• A restart is required for the Microsoft Online Policy Agent
• Installation completes and all agents report to Windows Intune within 30
minutes
Computer • Check Control Panel on the managed computer for the installed services
restart
• Check the Unassigned Computers group for newly enrolled computers
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
10. Session agenda
• Windows Intune Overview
• Deploying and Installing the Windows
Intune Client
• Computer Administration by Using
Windows Intune
• Windows Intune Systems Management
• Using the Windows Intune Client
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
11. Understanding Groups
– The default groups are All Computers
and Unassigned Computers
– On client installation, computers are added
to both default groups
– Create custom groups to organize
computers in your customers’ organizations
– Computers can belong to multiple groups
– Deploy updates and policies to groups
– Child groups inherit updates and policies
from parent groups
• Windows Intune groups are independent of Active Directory groups
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
12. The Windows Intune Update Process
Microsoft Update Service
Windows Intune
Administrator Console
5-Approved
• Managed 4-Approved for
Computer deployment?
Cloud Service
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
13. Managing Endpoint Protection
• Schedule scans
– Default quick scans are scheduled daily at 02:00
• Policy can control scan options:
– Run full scans
– Define the types of files and folders to scan
– Check for definitions
– Enable Endpoint Protection on the managed
computer
– Enable real-time protection
– Track resolved malicious software (in days)
– Join SpyNet and set Membership level
Note: If third-party malicious software
protection is installed when Windows Intune
is installed, the Windows Intune Endpoint
Protection agents will not be installed by
default
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
14. Windows Intune Policy Concepts
• Policies enable you to centrally control settings on managed computers
• After you create policies, you deploy them to one or more computer
groups
• Policy changes are distributed as updates to managed computers
• Policy conflicts?
Group Policy settings
take precedence
Policy 1
Policy 2 Policy 3
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
15. Session agenda
• Windows Intune Overview
• Deploying and Installing the Windows
Intune Client
• Computer Administration by Using
Windows Intune
• Windows Intune Systems Management
• Using the Windows Intune Client
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
16. Software Management
• The Software workspace is built upon Microsoft Asset Inventory Service (AIS)
• It provides data on installed software on all managed computers
• Each software title has an entry in the list:
– Software publisher
– Name
– Installation count
– Category
• Software reports are available in the Reports workspace
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
17. Working with Software Inventories
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
18. Working with Hardware Inventories
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
20. Session agenda
• Windows Intune Overview
• Deploying and Installing the Windows
Intune Client
• Computer Administration by Using
Windows Intune
• Windows Intune Systems Management
• Using the Windows Intune Client
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
21. Accessing Windows Update Services
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
22. Accessing Windows Intune Endpoint Protection
• If third-party protection against malicious
software has been installed instead of Windows
Intune Endpoint Protection, this application will
not be available until the Windows Intune
Endpoint Protection service is started
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
23. What Is Windows Intune Remote Assistance?
– It is based on the Microsoft Easy Assist Live Meeting service:
• Firewall “friendly”: ports 80 and 443
• Initiated by the end user
– It enables:
• Desktop sharing
• Application sharing
• Secure chat
• File transfer
• Multiway sessions
Note: The Live Meeting video
recording feature is not supported
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
24. End-to-End Remote Assistance
Administrator
Computer
End-User
Computer
Windows Intune
Service
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
25. Installing Microsoft Easy Assist
• It is only required on:
– Administrator
computers that
Windows Intune does
not manage
• It enables:
– Desktop sharing
– Application sharing
– Secure chat
– File transfer
– Multiway sessions
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
26. DEMO
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
27. Q&A
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro
28. Don’t forget!
Get your free Azure pass! We want your feedback!
• 30+15 days, no CC req’d • Win a WP7 smartphone
– http://bit.ly/ITCAMP11 – Fill in your feedback forms
– Promo code: ITCAMP11 – Raffle: end of the day
Premium conference on Microsoft’s Dev and ITPro technologies @itcampro / #itcampro