getting started with the enterprise mobility suite (ems)

87
MVP Roadshow 2015 Enterprise Mobility Suite

Upload: ronni-pedersen

Post on 16-Jul-2015

831 views

Category:

Technology


6 download

TRANSCRIPT

Page 1: Getting started with the Enterprise Mobility Suite (EMS)

MVP Roadshow 2015

Enterprise Mobility Suite

Page 2: Getting started with the Enterprise Mobility Suite (EMS)

Key TakeawaysWhy is mobile management important?

What is EMS and why do you need it is your Enterprise?

How do we configure and get started with EMS?

© EG A/S 2

Page 3: Getting started with the Enterprise Mobility Suite (EMS)

Ronni PedersenMicrosoft MVP: Enterprise Client Management

Senior Infrastructure Architect

Founder: System Center User Group Denmark

Microsoft Certified Trainer

Microsoft TechNet Moderator

Twitter: https://twitter.com/ronnipedersen

Blog: http://www.ronnipedersen.com/

Mail: [email protected]

© EG A/S 3

Page 4: Getting started with the Enterprise Mobility Suite (EMS)

Kenny Buntinx

Managing Consultant

[email protected]

© EG A/S

https://twitter.com/KennyBuntinx

http://be.linkedin.com/KennyBuntinx

http://scug.be/blogs/sccm

Page 5: Getting started with the Enterprise Mobility Suite (EMS)

Demo EnvironmentPowered by Hyper-V in the Cloud

DC01

Domain Controller

DNS Server

DHCP Server

CLIENT02

Windows 10 TP

CM01

SQL 2012

ConfigMgr 2012 R2

CLIENT01

Windows 8.1

MDT01

Page 6: Getting started with the Enterprise Mobility Suite (EMS)

Enterprise Mobility Suite

Page 7: Getting started with the Enterprise Mobility Suite (EMS)

2015 Enterprise Mobility PredictionsSay goodbye to BOYD

Say Hello to Data Protection

Organizations will generally have three types of devicesEmployee Owned, Company Managed (EOCM)Company Owned, Company Managed (COCM)Company Owned, Company Dictated (COOD)

Source:http://simon-may.com/yet-another-predictions-post-mobility-2015/

© EG A/S 7

Page 8: Getting started with the Enterprise Mobility Suite (EMS)

• SCCM is undisputed winner

of PC Mgmt w/ >70% share

• You need to look into a MDM

solution today

• We believe Microsoft is the

long-term winner

Growth is all in Mobile Devices

349 315 296 294 293 292

725

1,0101,131

1,2831,434

1,579162

231

270

308

340

368

0

500

1,000

1,500

2,000

2,500

1 2 3 4 5 6

Series3 Series2

Series1

Devices Shipments (MM)

Source: IDC

Page 9: Getting started with the Enterprise Mobility Suite (EMS)

LicensingMicrosoft Intune (Standalone)

Enterprise Mobility SuiteMicrosoft IntuneAzure Active Directory PremiumAzure Rights Management

Enterprise Cloud SuiteEnterprise Mobility SuiteOffice 365 Enterprise E3Windows Software Assurance (Per

http://www.microsoft.com/licensing/about-licensing/briefs/enterprise-cloud-suite.aspx

© EG A/S 9

Page 10: Getting started with the Enterprise Mobility Suite (EMS)

Enterprise Mobility SuiteMicrosoft Intune

Mobile and Device Management

Azure Active Directory PremiumHybrid Identity Management

Azure Rights ManagementInformation Protection

© EG A/S 10

Page 11: Getting started with the Enterprise Mobility Suite (EMS)

Microsoft IntuneMobile Device Management

Windows, Windows Phone, IOS and Android

Policy and Application Management

Compliance reporting

Conditional Access to resources

Selective Wipe Devices

Hybrid / Cloud solution

© EG A/S 11

Page 12: Getting started with the Enterprise Mobility Suite (EMS)

Azure Active Directory PremiumActive Directory in the cloud

Federation and identity provisioning

Centrally managed identitiesSynchronizationSingle User Identity (SSO)

Monitoring and protect access to cloud appsAuthentication and Security reportsMulti-Factor Authentication (MFA)

Empower end UsersSelf-Service password reset

© EG A/S 12

Page 13: Getting started with the Enterprise Mobility Suite (EMS)

Microsoft Rights ManagementEncrypt and control

DocumentsMails

Prevent unwanted viewing/printing or access to Corporate data

© EG A/S 13

Page 14: Getting started with the Enterprise Mobility Suite (EMS)

Getting Started with IntuneSetting up the environment

Page 15: Getting started with the Enterprise Mobility Suite (EMS)

Subscription requirements

© EG A/S 15

Page 16: Getting started with the Enterprise Mobility Suite (EMS)

Process Overview

Prepare

• Create Accounts for cloud services

• Create Subscriptions

Deploy

• Add Public DNS

• Configure AD Users with Public Domain UPNs

• Deploy and Configure Azure AD Sync

Configure

• Configure Configuration Manager for Mobile Device Management

• Configure Device Enrolment

© EG A/S 16

Page 17: Getting started with the Enterprise Mobility Suite (EMS)

Create accounts for the cloudStart by creating dedicated admin accounts:

Microsoft account: https://signup.live.com/

Apple ID: https://appleid.apple.com/account

Google account: https://accounts.google.com/Signup

© EG A/S 17

Page 18: Getting started with the Enterprise Mobility Suite (EMS)

Create the trial subscriptionsMicrosoft Office 365:http://aka.ms/ITcampO365Trial

Microsoft Intune:http://aka.ms/tryintune

Microsoft Azure Active Directory (AD) Premium:http://azure.microsoft.com/en-us/pricing/free-trial

Azure Rights Management:https://manage.windowsazure.com

© EG A/S 18

Page 19: Getting started with the Enterprise Mobility Suite (EMS)

DEMOCreate accounts and subscriptions

Page 20: Getting started with the Enterprise Mobility Suite (EMS)

Azure AD Sync and ADFSConnect your Active Directory to the Cloud

Page 21: Getting started with the Enterprise Mobility Suite (EMS)

Domain, DNS, and UPN management

21

Tony Allen

[email protected]

Add external

domaincontoso.com

[email protected]

Tony Allen

[email protected]

[email protected]

Add UPN suffix to

Active Directorycontoso.onmicrosoft.com

Change UPNs toSynchronise with

Directory synchronization

Alternative approachRecommended option

User name

and UPN

must match

Active Directory Windows Azure AD

contoso.onmicrosoft.comcontoso.com Default domain

Default UPN suffix

Domain name

@contoso.com @contoso.onmicrosoft.comAccounts created as

Page 22: Getting started with the Enterprise Mobility Suite (EMS)

Planning for Azure AD Sync (DirSync) / ADFS

Azure AD Sync with HashThe Password hash is stored in Azure

Azure AD Sync without the HashPassword are stored in AzureMultiple user ID and password

Azure AD Sync without the hash + ADFSRequires wildcard certificatePasswords are only stored in AD

© EG A/S 22

Page 23: Getting started with the Enterprise Mobility Suite (EMS)

Azure AD Sync AccountsCreate a dedicated Accounts for Azure AD Sync

Azure AD: [email protected]

On-Prem: AD: DOMAIN\SA-AzureADSync

© EG A/S 23

Page 24: Getting started with the Enterprise Mobility Suite (EMS)

Disable password expiry on Sync Account$MsolCredential = get-credential

$ExchangeSession = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri "https://outlook.office365.com/powershell-liveid/" -Credential $MsolCredential -Authentication Basic -AllowRedirection

Import-PSSession $ExchangeSessionConnect-MsolService -Credential $MsolCredential

Set-MsolUser -UserPrincipalName [email protected] -PasswordNeverExpires $true

© EG A/S 24

Page 25: Getting started with the Enterprise Mobility Suite (EMS)

DEMOSetting up Azure AD Sync

Page 26: Getting started with the Enterprise Mobility Suite (EMS)

Single management console for IT admins

© EG A/S 26

Page 27: Getting started with the Enterprise Mobility Suite (EMS)

Is your ConfigMgr Environment ready for UDM?

Cumulative Update 4http://support.microsoft.com/kb/3026739

Why CU’s Matter?http://blogs.technet.com/b/configmgrteam/archive/2015/02/26/updates-for-managing-mobile-devices-with-configuration-manager-and-microsoft-intune.aspx

http://scug.be/sccm/2014/12/29/hybrid-scenarios-with-system-center-configuration-manager-2012-r2-windows-intune-adfs-wap-ndes-workplace-join-hotfixes-you-really-need-in-your-environment/

© EG A/S

Page 28: Getting started with the Enterprise Mobility Suite (EMS)

DEMOConfiguring Microsoft Intune

Page 29: Getting started with the Enterprise Mobility Suite (EMS)

Single management console for IT admins

© EG A/S 29

Page 30: Getting started with the Enterprise Mobility Suite (EMS)

Company Portal(s)

Page 31: Getting started with the Enterprise Mobility Suite (EMS)

Company portal self-service experienceConsistent experience across:

WindowsWindows PhoneAndroidiOS

Discover and install corporate apps

Manage devices and data

Customizable terms and conditions

Ability to contact IT

Force the Policy refresh

© EG A/S 3131

Page 32: Getting started with the Enterprise Mobility Suite (EMS)

Mobile Device – Portals

All portals offer the same experience(except for Windows Phone)

Page 33: Getting started with the Enterprise Mobility Suite (EMS)

Device Enrollment

Page 34: Getting started with the Enterprise Mobility Suite (EMS)

Enrolling Devices

Users can enroll devices that configure the device for management with Windows Intune; the user can then use the Company Portal for easy access to corporate applications

Data from Windows Intune is in sync with Configuration Manager, which provides unified management across both on-premises and in the cloud

Dirsync

w Pwd Sync

Connector

Inte

rnal

Co

nn

ect

or

Page 35: Getting started with the Enterprise Mobility Suite (EMS)

Expanding device support with Workplace Join

Limited access

No IT Control

Active Directory

Not Joined to AD Workplace Joined Domain Joined

Page 36: Getting started with the Enterprise Mobility Suite (EMS)

Lost Device ProtectionDevices registered via Workplace Join are registered within Active Directory in the container :

CN=<Device ID>,CN=RegisteredDevices,DC=mydomain,DC=com.

Lost devices can be denied access by disabling or deleting the appropriate object within AD. Access through AD FS is immediately revoked for the workplace joined client.

From testing thus far, devices joined, left and re-registered via Workplace Join are not currently cleaned up within the RegisteredDevices container. Some PowerShell scripting is currently required to enforce this.

© EG A/S

Page 37: Getting started with the Enterprise Mobility Suite (EMS)

As a side note…ADFS with Workplace join?

Windows Phone 8.1 requires GDR 2

v 8.10.14192.280

© EG A/S 37

Page 38: Getting started with the Enterprise Mobility Suite (EMS)

Mobile Device – Personal vs Corporate

App Management

By default, user-enrolled devices are “Personal”

Complete inventory of all Apps on the device only when set to Corporate

Only the admin can specify corporate-owned devices !

Personal

vs.

Corporate Owned

Devices

Page 39: Getting started with the Enterprise Mobility Suite (EMS)

Collecting IMEI from devicesRetrieve International Mobile Equipment Identity (IMEI)

Through custom MOF

Windows Phone 8.1

Full Details:http://blogs.technet.com/b/configmgrteam/archive/2014/07/30/collecting-imei-from-devices-enrolled-in-windows-intune-with-sc-2012-r2-configmgr.aspx

© EG A/S

Page 40: Getting started with the Enterprise Mobility Suite (EMS)

DEMOEnrollment Walkthrough / Workplace Join / Lost Devices

Page 41: Getting started with the Enterprise Mobility Suite (EMS)

Workplace Join Hitman tool

Beta available via TechNet Galleries:

http://gallery.technet.microsoft.com/WorkPlace-Join-Hitman-8c691238#content

Page 42: Getting started with the Enterprise Mobility Suite (EMS)

Settings Management

Page 43: Getting started with the Enterprise Mobility Suite (EMS)

Key Concepts

Page 44: Getting started with the Enterprise Mobility Suite (EMS)

Mobile device setting categories

© EG A/S 44

Category Win 8.1 PC &

RT

Windows

Phone 8.1

iOS Android/KNOX Exchange

ActiveSync

Password ● ● ● ●

Encryption ● ● ●

Malware ●

System Settings ● ● ● ●

Cloud ● ●

Window Server Work Folders ●

Accounts and Sync ● ●

Email ● ● ●

Browser ● ● ● ●

Store Applications & Gaming ● ● ●

Device Hardware ● ● ●

Device Cellular/Roaming ● ● ●

Device Features ● ● ●

Page 45: Getting started with the Enterprise Mobility Suite (EMS)

DEMOSettings Management

Page 46: Getting started with the Enterprise Mobility Suite (EMS)

Intune Extensions

Page 47: Getting started with the Enterprise Mobility Suite (EMS)

Configuration Manager Extensions for IntuneRapid delivery of Configuration Manager features to support new Mobile Device Management features through Microsoft Intune

Updates are automatically downloaded and optionally enabled through admin console.

© EG A/S 47

Admin is

notified that

an extension

is available

when console

is launched

Admin goes

to Extensions

for Intune in

console, and

enables the

extension

Extension is

activated in

ConfigMgr

• (Extension

enables on all

site system,

then console

updates are

avail)

Admin

restarts

console, and

console is

updated with

the extension

Admin uses

feature

delivered by

the extension

Admin may

wish to

disable the

extension

Page 48: Getting started with the Enterprise Mobility Suite (EMS)

As a side note …

Permissions !

Local Admin Required

Security Scope: All Instances

See:

http://scug.be/sccm/2014/02/11/cm12-extensions-for-windows-intune-resources-and-gotchas/

© EG A/S

Page 49: Getting started with the Enterprise Mobility Suite (EMS)

Extending Settings management Through OMA-DM

Page 50: Getting started with the Enterprise Mobility Suite (EMS)

OMA-DMSpecification designed for management of mobile devices

• Mobile Phones

• PDA’s

• Tablets

Supporting following use case scenarios• Provisioning – Configuration of the device (including first time use), enabling and disabling features

• Device Configuration – Allow changes to settings and parameters of the device

• Software Upgrades – Provide for new software and/or bug fixes to be loaded on the device, including applications and system software

• Fault Management – Report errors from the device, query about status of device

OMA-DM for WP8.1:• http://technet.microsoft.com/en-us/library/dn499787.aspx

© EG A/S

Page 51: Getting started with the Enterprise Mobility Suite (EMS)

DEMOExtending Settings Management

Page 52: Getting started with the Enterprise Mobility Suite (EMS)

Business Scenario

At a customer during a Windows Intune UDM Proof of concept :

Customer was ordering 1000 corporate owned (COPE) Nokia Lumia 630 Windows Phones

He wanted us to provide the option when a ‘device owner’ in CM12 R2 is set to “corporate” , a user can’t unenroll a “corporate” device.

Unless you are the ConfigMgr 2012 MDM admin , you can’t.

Read the full story here :

http://scug.be/sccm/2014/04/24/configmgr-2012-r2-windows-intune-udm-how-to-prevent-an-end-user-can-un-enroll-his-corporate-windows-phone-8-1/

© EG A/S

Page 53: Getting started with the Enterprise Mobility Suite (EMS)

Solution Outline• Create configuration item “Deny WP8.1 MDM UnEnrollment’

• Select the checkbox : ‘Configure additional settings that are not in the default settings groups’ • Hit the “Create Setting” tab.

1. Give it a Name

2. Settings Type : OMA-URI

3. Data Type : Integer

4. OMA-URI : ./Vendor/MSFT/PolicyManager/My/Experience/AllowManualMDMUnenrollment

• Highlight your recently created ‘Deny MDM Unenrollment’ and hit the ‘Select’ button

1. Rule Type : Value

2. Data Type : 0 (0 = un-enroll not allowed / 1 = enroll allowed)

3. Set ‘Remediate noncompliant rules when supported’

4. Set Noncompliance severity for reports to ‘Warning’

• Create the baseline • Create the collection• Deploy the baseline • Wait 5 minutes

© EG A/S

Page 54: Getting started with the Enterprise Mobility Suite (EMS)

Resource Access Configuration

Page 55: Getting started with the Enterprise Mobility Suite (EMS)

Resource Access Configuration

© EG A/S

Benefits• End users get access to company resources

with no manual steps for them

Features*• Configure VPN profiles

• Support for Windows 8.1 Automatic VPN

• Wi-Fi protocol and authentication settings

• Email account profiles

• Management and distribution of certificates

• Conditional Access

Page 56: Getting started with the Enterprise Mobility Suite (EMS)

VPN Profile Management

DNS name-based initiation support

for Windows 8.1 and iOS

Application ID based initiation

support for Windows 8.1

Automatic VPN

connection

Support for VPN standards

SSL VPNs from Cisco, Juniper,

Check Point, Microsoft, Dell

SonicWALL, F5

Subset of vendors have Windows

VPN plug-in

PPTP ,L2TP, IKEv2

Support for Major SSL

VPN Vendors

Page 57: Getting started with the Enterprise Mobility Suite (EMS)

Wi-Fi and Certificate Profiles

Manage and distribute certificates

Deploy trusted root certificates

Support for Simple Certificate Enrollment Protocol (SCEP)

Manage Wi-Fi protocol and authentication settings

Provision Wi-Fi networks that device can auto connect

Specify certificate to be used for Wi-Fi connection

Wi-Fi Settings

Page 58: Getting started with the Enterprise Mobility Suite (EMS)

DEMOResource Access Configurations

Page 59: Getting started with the Enterprise Mobility Suite (EMS)

N-What ? NDES ? SCEP ??? WTH …

Page 60: Getting started with the Enterprise Mobility Suite (EMS)

Certificate Profiles

Manage and distribute certificates

Deploy trusted root certificates

Support for Simple Certificate Enrollment Protocol (SCEP)

Page 61: Getting started with the Enterprise Mobility Suite (EMS)

This is not a next, next, finish configuration

Page 62: Getting started with the Enterprise Mobility Suite (EMS)

Certificate enrollment via NDES1. Certificate profile

deployed to device

2. Device sends SCEP request

3. Challenge is validated

4. Certificate is issued

© EG A/S

Page 63: Getting started with the Enterprise Mobility Suite (EMS)

Why CU’s Matter (again)

CU4 improvements for NDES

Target to user instead of devices

> Ensures fastest delivery

Pre CU3 templates need to be recreated

> Re-targetting from device to user is not sufficient

© EG A/S

Page 64: Getting started with the Enterprise Mobility Suite (EMS)

As a side note …

Certificate deployment to iOS 8Required modification to template: Remove Signature in proof of origin

See:http://blog.coretech.dk/kea/troubleshooting-certificate-deployment-on-ios-devices-with-configmgr-intune/

© EG A/S

Page 65: Getting started with the Enterprise Mobility Suite (EMS)

As a side note … (2)

User based Certificate deployment to iOS 8

Required modification to “subject name format” for user deployments: Only “Common name” supported

© EG A/S

Page 66: Getting started with the Enterprise Mobility Suite (EMS)

DEMOCertificate deployment

Page 67: Getting started with the Enterprise Mobility Suite (EMS)

End result :

© EG A/S

Page 68: Getting started with the Enterprise Mobility Suite (EMS)

Custom iOS policy

© EG A/S 68

Page 69: Getting started with the Enterprise Mobility Suite (EMS)

Application Management

Page 70: Getting started with the Enterprise Mobility Suite (EMS)

Mobile Application Management

© EG A/S 70

Personal apps

Page 71: Getting started with the Enterprise Mobility Suite (EMS)

Mobile Application Management

© EG A/S 71

Page 72: Getting started with the Enterprise Mobility Suite (EMS)

Conditional access for Office 365

© EG A/S 72

7

5

4

2

1

3

6

Page 73: Getting started with the Enterprise Mobility Suite (EMS)

DEMOMobile Application Management

Page 74: Getting started with the Enterprise Mobility Suite (EMS)

Allow or block appsPrevent unauthorized apps from being used on devices

© EG A/S 74

Page 75: Getting started with the Enterprise Mobility Suite (EMS)

Business Scenario

© EG A/S

http://scug.be/nico/2014/05/22/deny-windows-phone-apps-with-configuration-manager-intune/

Page 76: Getting started with the Enterprise Mobility Suite (EMS)

Solution Outline• Create configuration item “Deny Windows Phone Apps”• Select the checkbox : ‘Configure additional settings that are not in the default settings groups’ • Hit the “Create Setting” tab.

- Give it a Name

- Settings Type : OMA-URI

- Data Type : String

- OMA-URI : ./Vendor/MSFT/PolicyManager/My/ApplicationManagement/ApplicationRestrictions

- <AppPolicy Version=”1″ xmlns=”http://schemas.microsoft.com/phone/2013/policy”><Deny><App ProductId=”{2e59d843-22e4-4df1-869e-22adadb8005b}”/></Deny></AppPolicy>

• Highlight your recently created ‘Deny Windows Phone Apps’ and hit the ‘Select’ button

- Rule Type : Value

- Data Type : 0 (0 = application not allowed / 1 = application allowed)

- Set ‘Remediate noncompliant rules when supported’

- Set Noncompliance severity for reports to ‘Warning’

• Create the baseline • Create the collection• Deploy the baseline • Wait 5 minutes

© EG A/S

Page 77: Getting started with the Enterprise Mobility Suite (EMS)

WorkFolders

Page 78: Getting started with the Enterprise Mobility Suite (EMS)

Work Folders

Simple access to corporate data• Enable offline access to files and folders stored on a Windows Server 2012 R2 file server

• Simple Group Policy configuration for domain-joined computers, with easy discoverability for BYOD systems, as well

• Leverages web protocols (HTTP) for easy synchronization through firewalls

• A complement to OneDrive and OneDrive for Business

Page 79: Getting started with the Enterprise Mobility Suite (EMS)

Make corporate data available to users with Work Folders

Page 80: Getting started with the Enterprise Mobility Suite (EMS)

Https://support.microsoft.com/kb/2891638

Windows 7 support

1. Must be joined to the domain2. Install the Work Folders client

Ipad supportHttps://itunes.apple.com/us/app/work-

folders/id950878067?mt=8

Page 81: Getting started with the Enterprise Mobility Suite (EMS)

DEMOWork Folders

Page 82: Getting started with the Enterprise Mobility Suite (EMS)

Corporate Data RemovalFull Wipe vs. Selective Wipe

Page 83: Getting started with the Enterprise Mobility Suite (EMS)

Options for corporate data removal

© EG A/S 83

Page 84: Getting started with the Enterprise Mobility Suite (EMS)

Selective wipe for business data

Page 85: Getting started with the Enterprise Mobility Suite (EMS)

DEMOSelective/Full Wipe

Page 86: Getting started with the Enterprise Mobility Suite (EMS)

Questions

© EG A/S 86

Page 87: Getting started with the Enterprise Mobility Suite (EMS)

© EG A/S 87