260 likes | 271 Views
Discover ways to secure corporate data access, control scenarios, productivity solutions with Microsoft Intune & Configuration Manager for unified endpoint management.
E N D
Lessons from the Field: Protecting Corporate Data on any Device with Microsoft Intune and EMS Quoc Lai Senior Program Manager Intune Customer Experience Team BRK3029 Clay Taylor Senior Program Manager Intune Customer Experience Team
Agenda Explore and understand many ways data can be accessed Levels of controls to secure the access to the corporate data Common scenarios and options to control corporate data exposure
Productivity Simplicity MicrosoftIntune &Configuration Manager Unified Endpoint Management The simplest way to manage all Microsoft 365 endpoints Security
Who is accessing the data on a particular device? What is their role and should their device be trusted?
Who is accessing the data on a particular device Identity driven access control to data What is their role and what level of access should they have? Identify roles and responsibilities for end user personas
Demo Identity based controls to data access
How do I protect app data on an unmanaged device? App Protection Policies App Based Conditional Access/ Native Mail App? Corporate Identity binding controls How do I enable app protection for my LOB apps and 3rd Party apps? Enlightened for Windows / SDK iOS and Android
Bring your own device End-user personal device Do not want IT managing their personal data Want convenience of access to corporate services Mobile Application Management (MAM) controls Windows 10 – Windows Information Protection without enrollment Apple iOS – Intune APP Restrictions Android – Intune APP Restrictions + AE Work Profile Enlightened apps through Intune SDK integration or Application Wrapping Tool Corporate Identity user context awareness driven Application level restrictions and file based encryption
Introduction to Intune App Protection Policies (APP) MAM policies Familiar Office experience • Seamless “enrollment” into app management • Use for personal and corporate accounts Comprehensive protection • App encryption at rest • App access control – PIN or credentials • Save as/copy/paste restrictions • App-level selective wipe MDM mgmt. by Intune or third-party is optional Might be a good solution for these scenarios: • BYOD when MDM is not required • Extending app access to vendors and partners • Already have an existing MDM solution Corporate apps MDM – optional (Intune or 3rd-party) Personal apps MDM policies
Demo Application level data trust controls
When should I require a device to be fully MDM managed? How should I protect data on a managed device?
When should I require a device to be fully MDM managed? Corporate vs. BYOD What do users need to access? Are there additional security requirements; certificates, S/MIME? How should I protect data on a managed device? Enrollment Restrictions Windows Security Baseline Settings Windows Hello Encryption Mobile Threat Defense
Fully managed data compliance Self-enrollment assisted through guided registration process Access authorization driven via conditional access controls Mandatory device compliance requirements enforced Microsoft Windows 8.1 & 10 – Azure Active Directory Device Registration Apple iOS – Open-In Management Android Enterprise – Work Profile and Managed Google Play Protect
Demo Device level data trust controls
Compliance data controls Configuration Policies and compliance policies Security Baselines Administrative template policy controls
Are there actions to remediate unhealthy devices and the data?
Is the device healthy? What is the baseline for a compliant device state? How is remediation Example of emergency visit vs well check Compliance Policies vs. configuration policies
Who is accessing the data on a particular device? What is their role and what level of access should they have? Can I protect app data of unknown device? When should I require a device to be fully MDM managed? How should I protect data on a managed device? What about device health and compliance? Are there actions to remediate unhealthy devices and the data?
Please evaluate this sessionYour feedback is important to us! Please evaluate this session through MyEvaluations on the mobile appor website. Download the app:https://aka.ms/ignite.mobileApp Go to the website: https://myignite.techcommunity.microsoft.com/evaluations