510 likes | 748 Views
Configuration Manager and InTune. Gemeinsam oder einsam?. Introduction. It’s all about me !. Who am I? Andrew Craig Where am I from ? And now ? Living three years in Switzerland Working for Syliance IT Services GmbH as System Center Senior Consultant www.syliance.com
E N D
Configuration Manager andInTune Gemeinsam oder einsam?
It’s all aboutme! • Who am I? • Andrew Craig • Where am I from? • Andnow? • Living threeyears in Switzerland • Working forSyliance IT Services GmbH as System Center Senior Consultant • www.syliance.com • andrewdcraig.wordpress.com • Twitter: @mracraig @syliance
Agenda • Was heisst einsam? • Was heisst gemeinsam? • Warum gemeinsam? • Windows AzureActive Directory (WAAD) integration • Howquicklycan I setupInTune? • Whatcan I do tomy mobile devices? • Apps, hints, tips, tricks Spoiler Alert
Cloud Management Capabilities 1 = Managed applications only 2 = Compliance reporting but no remediation automation 3 = Via Remote Assistance
Windows Intune Cloud Architecture Windows 8 Windows 7 Windows Vista Windows XP Windows RT Windows Phone 8 x86 / x64 iOS Android App Publishing Direct Management & App Publishing Windows 8 Windows 7 Windows Vista Windows XP DirSync x86 / x64 EAS Policy & Inventory Android Internet CorpNet
Unified Configuration 8.1 R2
Unified Management Capabilities 1 = Basic information only through Exchange ActiveSync 2 = Managed applications only 3 = Compliance reporting but no remediation automation 4 = Device User has to accept the update 5 = Via Remote Assistance
Windows Intune Unified Architecture Windows 8 Windows To Go Windows 7 Windows Embedded Windows Vista Windows XP Mac Windows RT R2 x86 / x64 Windows Phone 8 iOS Android App Distribution Direct Management & App Distribution DirSync ADFS ADFSProxy EASPolicy & Inventory Android Active Directory Windows 8 Windows 7 Windows Vista Windows XP Internet Corporate Net x86 / x64
A housewithmanywindows Single paneofglass
Exchange Connector/ActiveSync • EAS – Applicationlayer • InTune MDM – OS Layer • ConfigMgr – Manage Exchange Policies
Unified Management Capabilities 1 = Basic information only through Exchange ActiveSync 2 = Managed applications only 3 = Compliance reporting but no remediation automation 4 = Device User has to accept the update 5 = Via Remote Assistance
SelectionCriteria • Scale of Solution • Approx. Max of 5000 Users? • Approx. Max of 100,000 Users? • Current Infrastructure • On-premise ConfigMgr? • Something else? • Required Feature Set • Capabilities • Supported Platforms
Provisioning Users Scriptable Automated Manual
Cloud-Only / No Integration Cloud Only / No Integration Directory Synchronization Directory and Federated SSO Exchange Online Windows Azure Active Directory Authentication platform Joe@contoso.msonline.com SharePoint Online Contoso customer premises Admin Portal/ PowerShell/GRAPH IdP Lync Online IdP AD Directory Store Provisioning platform WindowsIntune Joe@contoso.com
Directory Synchronization No Integration Directory Synchronization Directory and Single sign-on (SSO) Exchange Online Windows Azure Active Directory Authentication platform SharePoint Online Contoso customer premises Admin Portal/ PowerShell/GRAPH IdP Lync Online IdP Directory Store Provisioning platform Directory Sync(DirSync) AD WindowsIntune
Directory and Federated SSO No Integration Directory Synchronization Directory and Federated SSO Exchange Online Windows Azure Active Directory Authentication platform SharePoint Online Contoso customer premises Trust Active Directory Federation Server 2.0 Admin Portal/ PowerShell/GRAPH IdP Lync Online IdP Directory Store Provisioning platform Directory Sync(DirSync) AD WindowsIntune
Integration Comparison 1. No Integration 2. Directory Only 3. Directory and SSO • Appropriate for • Smaller orgs without AD on-premise • Pros • No servers required on-premise • Same Domain name for users possible • Cons • No SSO • No 2FA • 2 sets of credentials to manage with differing password policies • IDs mastered in the cloud • Appropriate for • Medium/Large orgs with AD on-premise • Pros • Users and groups mastered on-premise • Enables co-existence scenarios • Cons • No SSO • No 2FA • 2 sets of credentials to manage with differing password policies or manual / 3rd Party password sync • Single server deployment • Appropriate for • Larger enterprise orgs with AD on-premise • Pros • SSO with corporate cred • IDs mastered on-premise • Password policy controlled on-premise • 2FA solutions possible • Enables hybrid scenarios • Location isolation • Cons • Additional Servers required for ADFS
Activating Windows Intune Users Built-in group associated with a customer’s Windows Intune account • Membership required for: • Users to appear in administrator console • Users to access company portal • Users added to user group • When created • When edited • Users removed from group • When edited
Do thepaperwork • Sign up at www.windowsintune.com • Logon at admin.manage.microsoft.com • Public domain and CNAME DNS • User Principal Names (UPNs) • Active Directory Federated Services (ADFS)
Synchronize your AD with Windows Azure AD Allowplentyof time forsync Run Office 365 Deployment Readiness Tool
Apps • Microsoft Apps • Windows Phone Store • iTunes App Store • Google Play • In-House • LOB • Visual Studio and Windows Phone SDKs • XcodeandiOS SDK • Eclipse, Android Studio and Android SDK
AvailableExamples • Dynamics CRM • Lync • Sharepoint • Office* • Others…
Requirements • Developer Licenses • Code SigningCertificates • Development Platforms
Hints, Tips, Tricks • Planning • Domain considerations • Client-side • Troubleshooting. Wherearethe Logfiles? • Somethings happen overnight • Naughtychildren
Summary • ConfigMgrhas a richfeaturesetformanagingclients • InTuneenhancesthisbyadding MDM • StandaloneInTuneisenhancedbydeployingConfigMgr • Everyonebenefits • Take time to plan yourimplementationproperly • Beawarethat mobile devicesdon’tbehave like desktopsandlaptops