management scenario jungle Nicola Suter Workplace Engineer itnetX - - PowerPoint PPT Presentation

management scenario jungle
SMART_READER_LITE
LIVE PREVIEW

management scenario jungle Nicola Suter Workplace Engineer itnetX - - PowerPoint PPT Presentation

A safari through the Intune device management scenario jungle Nicola Suter Workplace Engineer itnetX (Switzerland) AG Blog tech.nicolonsky.ch Twitter @nicolonsky Content Intune basics MAM Android Enterprise iOS / macOS


slide-1
SLIDE 1

A safari through the Intune device management scenario jungle

Nicola Suter Workplace Engineer itnetX (Switzerland) AG Blog tech.nicolonsky.ch Twitter @nicolonsky

slide-2
SLIDE 2

Content

▪ Intune basics ▪ MAM ▪ Android Enterprise ▪ iOS / macOS ▪ Windows 10 ▪ Recent announcements

slide-3
SLIDE 3

Current MEM capabilities

slide-4
SLIDE 4

How to get started with Intune

▪ Identif tify use cases ▪ Which devices do you want to manage? ▪ Ownership? ▪ Management mode?

slide-5
SLIDE 5

Prerequisites

▪ Licenses (EM+S E3) ▪ Azure AD (identities) ▪ Compatible devices

▪ OS version ▪ Hardware capabilities ▪ Encryption support

slide-6
SLIDE 6

Now what?

slide-7
SLIDE 7

Default enrollment restrictions

slide-8
SLIDE 8

Distinguish personal / company owned?

▪ Register Serial / IMEI ▪ Use enrollment service

▪ Autopilot ▪ Apple automated device enrollment (DEP) ▪ Google Zero T

  • uch / Samsung Knox

more infos

slide-9
SLIDE 9

Management scenarios

MDM MAM MDM + MAM

slide-10
SLIDE 10

MAM 101

▪ Fully fletched DLP solution

▪ Data protection ▪ Access requirements

▪ App configurations ▪ Broker apps ▪ Apps need to implement Intune SDK

▪ List of supported apps ▪ App wrapping possible -> 

slide-11
SLIDE 11

Experiences from the field

▪ Usability vs. security ▪ Contact sync to native address book ▪ about:intunehelp

slide-12
SLIDE 12

How to enforce usage of MAM?

▪ Conditional Access «require approved client app» supported apps ▪ Conditional Access «require app protection policy» supported apps ▪ 3rd party / LOB apps -> 

slide-13
SLIDE 13

Android management 101

slide-14
SLIDE 14

AE Work Profile

personal owned

slide-15
SLIDE 15

AE Fully Managed

Former «COPE»

company owned

slide-16
SLIDE 16

AE Dedicated

more info about scenarios

company owned

slide-17
SLIDE 17

Enrollment methods

more info

Management type Token needed Options Work profile

  • Company Portal

Dedicated x (expires) NFC, QR, Token entry, Knox, Zero Touch Fully managed x Fully managed with work profile x (expires)

slide-18
SLIDE 18

Microsoft Launcher

▪ Customize Android appearance ▪ M365 Newsfeed ▪ Icons, groups, background ▪ For fully managed / dedicated devices ▪ No default browser setting  ▪ JSON configuration

Configure Microsoft Launcher

slide-19
SLIDE 19

Android OEMConfig

▪ Configure manufacturer specific device settings ▪ Requires manufacturer specific app

slide-20
SLIDE 20

Apple managment 101

▪ MDM: APNS certificate ▪ VPP: App deployment ▪ Monitor token expiration ▪ (Onboard apple business/school manager)

slide-21
SLIDE 21

«Work profile»

▪ Apple User Enrollment in preview

▪ BYOD scenarios ▪ More privacy for end users ▪ Limited management capabilities ▪ Dedicated container ▪ User based app deployment

slide-22
SLIDE 22

Managing macOS?

▪ Basic management capabilities ☺

▪ Encryption, Firewall, Gatekeeper ▪ Certificates, VPN, Wi-Fi ▪ App deployment, scripts

▪ Advanced use cases -> Jamf

▪ Conditional Access integration

slide-23
SLIDE 23

Automated device enrollment (ADE)

▪ Requires «special» ordered devices ▪ Federate Apple Business manager with Intune for managed apple id’s ▪ Additional settings available ▪ Single app mode to force MDM enrollment

slide-24
SLIDE 24

Windows 10 device states

▪ Azure AD Joined ▪ Hybrid Azure AD Joined ▪ On premises resource access ▪ Windows Hello for Business

slide-25
SLIDE 25

Windows 10 management 101

▪ Try out Azure AD Joined devices & Autopilot ▪ Keep it simple & secure ▪ Use best of both worlds with cloud attach ▪ Lots of new ADMX policies

slide-26
SLIDE 26

General recommendations

▪ Use shared mailbox for EMM accounts ▪ Don’t mix Intune with Office 365 policies ▪ Asset management ▪ Housekeeping

slide-27
SLIDE 27

Conditional Access

▪ Configure device compliance policies for all your supported platforms ▪ Block enrollment of platforms you’re not supporting

slide-28
SLIDE 28

Recent announcements (Ignite)

▪ Microsoft Tunnel (preview) ▪ Endpoint Analytics GA ▪ Group policy migration (preview) ▪ Defender Antivirus reports (preview) ▪ Advanced Autopilot troubleshooting (Q4) ▪ WVD management (Q4)

slide-29
SLIDE 29

Microsoft Tunnel

«Microsoft Tunnel is a VPN gateway solution for Microsoft Intune.»

slide-30
SLIDE 30

Microsoft Tunnel – WHAT?

slide-31
SLIDE 31

Endpoint analytics

slide-32
SLIDE 32

Group Policy analytics

slide-33
SLIDE 33

Thank you!

https://tech.nicolonsky.ch/events

slide-34
SLIDE 34