Microsoft Enterprise Mobility Suite



Similar documents
Mobile device and application management. Speaker Name Date

Enterprise Mobility Suite Overview. Joe Kuster Catapult Systems

Ondřej Výšek Sales Lead, Microsoft MVP.

Overview of Microsoft Enterprise Mobility Suite (EMS) Cloud University

Alexander De Houwer Technology Advisor Devices Win 10 Vincent Dal Technology Advisor Business Productivity

Identity + Mobile Management + Security = Enterprise Mobility Suite

Azure Active Directory

Microsoft Enterprise Mobility Suite

Azure Active Directory

Enterprise Mobility Services

SINGLE & SAME SIGN-ON ASPECTS

Webinar Self-service in Microsoft Azure AD Premium

Agenda. Enterprise challenges. Hybrid identity. Mobile device management. Data protection. Offering details

Creating a Single Sign on Web Portal using Azure. Robert Crane Office 365

Andrej Zdravkovic Regional Vice President, Platform Solutions Intellinet

How Microsoft IT manages mobile device management

Advanced Configuration Steps

Microsoft Enterprise Mobility and Client Futures

STRONGER AUTHENTICATION for CA SiteMinder

Enterprise Mobility Suite (EMS) Sean Lewis Principal Partner Technology Strategist

How To Make Your Computer System More Secure And Secure

TCS Hy5 Presidio Your Mobile Environment, Your Way Configure, Secure, Deploy. Mobility Solutions

Securing Office 365 with MobileIron

Identity and Access Management for the Hybrid Enterprise

Apps. Devices. Users. Data. Deploying and managing applications across platforms is difficult.

Mod 2: User Management

Conditional Access and Mobile Application Management explained

ADDING STRONGER AUTHENTICATION for VPN Access Control

Infrastructure Deployment for Mobile Device Management with Microsoft System Center Configuration Manager and Windows Intune

Cloud Services MDM. ios User Guide

Microsoft Azure Multi-Factor authentication. (Concept Overview Part 1)

* Over de uitslag kan niet worden gecorrespondeerd, prijzen zijn voorbeelden All results are final, prices are examples

An Overview of Samsung KNOX Active Directory and Group Policy Features

Dell World Software User Forum 2013

AirWatch Solution Overview

Security Best Practices for Microsoft Azure Applications

Centrify Cloud Connector Deployment Guide

When enterprise mobility strategies are discussed, security is usually one of the first topics

Employee Active Directory Self-Service Quick Setup Guide

Enterprise Mobility Management Migration Migrating from Legacy EMM to an epo Managed EMM Environment. Paul Luetje Enterprise Solutions Architect

Windows Phone 8.1 Mobile Device Management Overview

Device Enrollment Guide

TechReady. Are you ready to implement IT solutions? Training and Consulting

Secure Your Enterprise with Usher Mobile Identity

How To Manage A Corporate Device Ownership (Byod) On A Corporate Network (For Employees) On An Iphone Or Ipad Or Ipa (For Non-Usenet) On Your Personal Device

Technology Day 2015 Xylos

Identity & Access Management in the Cloud: Fewer passwords, more productivity

Managing enterprise in a mobile world

Speeding Office 365 Implementation Using Identity-as-a-Service

Ben Hall Technical Pre-Sales Manager

Google Identity Services for work

Bill Fiddes Learning and Development Specialist Rob Latino Program Manager in Office 365 Support

Kony Mobile Application Management (MAM)

Mobility Manager 9.5. Users Guide

Mobile Iron User Guide

Course Outline. Mobile Device Management Course 55078: 2 days Instructor Led

1. What are the System Requirements for using the MaaS360 for Exchange ActiveSync solution?

Introduction to Google Apps for Business Integration

Symantec Mobile Management 7.2

Deploying Management and Security Agents to Mobile Devices

W M U G NL. WMUG Meeting #2 - Deployment MOBILE APPLICATION DEPLOYMENT

Multi-Factor Authentication for OWA in Exchange Online Dedicated

Sophos Mobile Control User guide for Apple ios. Product version: 4

LICENSTJEK OUTSOURCING

Supporting Cloud Services

Integrating Cisco ISE with GO!Enterprise MDM Quick Start

The Centrify Vision: Unified Access Management

All your apps & data in the cloud, all in one place.

LabTech Mobile Device Management Overview

EndUser Protection. Peter Skondro. Sophos

Planning your Microsoft Application Strategy in a Cloud Crazy World. Steve Soper Senior Managing Partner

McAfee Enterprise Mobility Management

Where are Organizations Today? The Cloud. The Current and Future State of IT When, Where, and How To Leverage the Cloud. The Cloud and the Players

What We Do: Simplify Enterprise Mobility

Secure Collaboration within Organizations, B2B and B2C.

APPENDIX B1 - FUNCTIONALITY AND INTEGRATION REQUIREMENTS RESPONSE FORM FOR A COUNTY HOSTED SOLUTION

Total Enterprise Mobility

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

Mobile Device Management for CFAES

Symantec Mobile Management Suite

WHITEPAPER. 13 Questions You Must Ask When Integrating Office 365 With Active Directory

Mobile Device Manager. Windows User Guide (Windows Phone 8/RT)

Secure, Centralized, Simple

Direct Control for Mobile & Supporting Mac OS X in Windows Environments

Microsoft SharePoint Architectural Models

ForeScout MDM Enterprise

Course Outline. Managing Enterprise Devices and Apps using System Center Configuration ManagerCourse 20696B: 5 days Instructor Led

IT Resource Management & Mobile Data Protection vs. User Empowerment

Company Facts. 1,800 employees. 150 countries. 12,000 customers and growing. 17 languages. 11 global offices

Total Cost of Ownership Overview ADFS vs OneLogin WHITEPAPER

AVG Business SSO Partner Getting Started Guide

Identity and Access Management

I believe. Satya Nadella CEO, Microsoft. History of making big bets

Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management

Administration Guide BES12. Version 12.3

How To Manage A Mobile Device Management (Mdm) Solution

Sophos Mobile Control SaaS startup guide. Product version: 6

Mobile Security and Management Opportunities for Telcos and Service Providers

Kaspersky Lab Mobile Device Management Deployment Guide

Systems Manager Cloud Based Mobile Device Management

Transcription:

Microsoft Enterprise Mobility Suite Standalone - overview Peter Daalmans http://configmgrblog.com, peter@daalmans.com IT-Concern John Marcum Enterprise Client Management Architect / johnmarcum@outlook.com BABC

John Marcum Peter Daalmans @SCCM_Marcum @pdaalmans Enterprise Mobility Microsoft MVP Enterprise Mobility Microsoft MVP 13 years end user device mgmt Sn. Consultant, Author, Blogger I enjoy a cold beer new and then So am I.

Agenda Main EMS Components covered Azure AD Premium Microsoft Intune Azure RMS How to get started?

Enterprise Mobility Suite

What is MS EMS? Enterprise Mobility Suite Azure Active Directory Azure Rights Management Services Azure Remote App Advanced Threat Analytics Intune Identity Manager

Identity Azure AD Premium

Making hybrid identity simple DirSync Azure AD Sync Azure AD Connect Azure AD Connect Consolidated deployment assistant for your identity bridge components FIM+Azure AD Connector (The difference is the Password) ADFS use cases Tighter AD integration Security Policy Conditional Access Smart Card Authentication

Identity: Cloud, Sync or Federated? Cloud identity provides a solution where all identity resides in the cloud Identity sync enables customers to bridge their existing identity into the cloud Federated identity allows customers to retain all authentication on-premises B2B federated identity allows customers to securely share and collaborate with each other

Azure Active Directory Premium Active Directory in the cloud Federation and identity provisioning Centrally managed identities Synchronization Single User Identity (SSO) Monitoring and protect access to cloud apps Authentication and Security reports Multi-Factor Authentication (MFA) Empower end Users Self-Service password reset

AAD editions comparison 500,000 Object Limit No Object Limit No Object Limit No Object limit for Office 365 user accounts No Limit 10 apps per user Self-Service Password Change for cloud users Yes Yes Yes Yes Premium + Basic Features Identity Synchronization Tool (Windows Server Active Directory integration, Multi Forest) Yes Yes Yes Yes Security Reports 3 Basic Reports 3 Basic Reports Advanced Security Reports 3 Basic Reports Cloud App Discovery* Yes(Basic) Yes(Basic) Yes(Advanced)** Yes(Basic) Group-based access management/provisioning Yes Yes Self-Service Password Reset for cloud users Yes Yes Company Branding (Logon Pages/Access Panel customization) Yes Yes SLA Yes Yes Yes Limited Cloud only features for accessing Office 365

Other premium features

Self service experience for users Users can edit their profile details to update and add missing information Users can reset their passwords significantly reducing help desk burden and costs. Self-service group management, including dynamic membership calculation in these groups and distribution lists, based on the user s attributes.

Monitor and protect access on go-anywhere devices Built-in security features, like you cant be in two places at once. XXXXX Security reporting that tracks inconsistent access patterns, analytics and alerts. XXXXX Ensure secure access by enabling MFA XXXXX

Multi-factor authentication Any two or more of the following factors: Something you know: a password or PIN. Something you have: a phone, credit card or hardware token. Something you are: a fingerprint, retinal scan or other biometric. Stronger when using two different channels (out-of-band).

Premium Reports Premium reports: Advanced application usage reporting Password reset activity Selfservice activity Identify unexpected logon behavior

Premium Reports

Integrate on-prem apps with Azure AD End-user portal Access Panel Azure Active Directory Azure AD authentication capabilities: Username and password synced from on-prem AD Federated login to on-prem or other federation servers Multi-factor authentication Customized login screen Authorization based on user or groups SSO to Office365, thousands of SaaS apps and all applications integrated with AAD Authorization Authentication + MFA Reporting & Auditing Application Proxy Security Monitoring Access Panel Portal Reports, auditing and security monitoring based on big data and machine learning. DMZ Connector Connector Resource Resource Resource Corporate Network

Demo Azure Active Directory Premium

Microsoft Intune MDM, MAM and more

Microsoft Intune Mobile Device Management Windows, Windows Phone/Mobile, IOS, Android and Mac OS X Policy and Application Management Compliance reporting Conditional Access to resources Selective Wipe Devices Reset passcode / unlock devices Hybrid / Cloud solution

Single management console for IT admins Intune web console (cloud only) Configuration Manager console (hybrid)

Comprehensive lifecycle management Enroll Provide a self-service Company Portal for users to enroll devices Deliver custom terms and conditions at enrollment Bulk enroll devices using Apple Configurator or service account Restrict access to Exchange email if a device is not enrolled Provision Deploy certificates, email, VPN, and WiFi profiles Deploy device security policy settings Install mandatory apps Deploy app restriction policies Deploy data protection policies User IT Retire Revoke access to corporate resources Perform selective wipe Audit lost and stolen devices Manage and Protect Restrict access to corporate resources if policies are violated (e.g., jailbroken device) Protect corporate data by restricting actions such as copy/cut/paste/save outside of managed app ecosystem Report on device and app compliance

Microsoft Intune Company Portal(s)

Company portal self-service experience Consistent experience across: Windows Windows Phone / Mobile Android ios Discover and install corporate apps Manage devices and data Customizable terms and conditions Ability to contact IT Force the Policy refresh Retire/wipe

Microsoft Intune Device Enrolment The new way Conditional access

Internal Connector Enrolling Devices Connector Data from Windows Intuneis in sync with Configuration Manager, which provides unified management across both on-premises and in the cloud Dirsync w Pwd Sync Users can enroll devices that configure the device for management with Windows Intune; the user can then use the Company Portal for easy access to corporate applications

Conditional access for Office 365 2 Attempt email connection 1 4 3 Set device management/ compliance status If not compliant, push device into quarantine 6 7 5 Enrollment/compliance remediation

Demo Device Enrollment The new way Conditional access

Microsoft Intune Application Management

Mobile Application Management What can we do? Force compliance before access to the app and data Secure the data within the app Prohibit copy/paste Prohibit screenshots Prohibit save as Force encryption Disable Outlook Sync (MDM-less MAM Only) Secure app by PIN or corporate credentials Secure LOB apps via App Wrapper See for an up to date list of apps: http://ref.ms/mamlist

Mobile Application Management Maximize mobile productivity and protect corporate resources with Office mobile apps Extend these capabilities to existing line-of-business apps using the Intune app wrapper Personal apps Enable secure viewing of content using the Managed Browser, PDF Viewer, AV Player, and Image Viewer apps

Mobile Application Management Copy Paste Save Paste to personal app Save to personal storage Maximize productivity while preventing leakage of company data by restricting actions such as copy/cut/paste/save in your managed app ecosystem

MDM-less MAM Use cases MDM-less MAM: Apps running on devices that are not enrolled in any MDM solution. Apps running on devices that are enrolled in a third party MDM solution

Mobile App Config Policy Preconfigure ios Apps with settings App need to support ios App Config Policy See for more info: http://ref.ms/mamlist

Enterprise Data Protection What is EDP? Protects data at rest, and wherever it rests or may roam to Seamless integration into the platform, no mode switching and use any app Corporate versus personal data identifiable wherever it rests on the device Prevents unauthorized apps from accessing business data IT has fully control of keys and data and can remote wipe data on demand Common experience across all Windows devices with cross platform support Available as from Windows 10 Redstone

Enterprise data protection PROVISIONING: KEYS AND POLICIES User enrolls with enterprise Intune or domain join 1 Intune or SCCM provisions policy and encryption keys User 2 Policies: Enterprise allowed apps Network policies App restriction policy

Demo Mobile Application Management

Azure Rights Management Protecting the data

Azure Rights Management It uses encryption, identity and authorization policies to help secure your files and email, and it works across multiple devices.

Azure Rights Management Cool Features Protection stays with the file Works both inside and outside the company Easy Audit and monitoring On-prem (RMS Connector) and O365 support

Demo Rights Management

How to get started? With Microsoft EMS

How to get started? Go to ref.ms/ems > Try now Sign up Setup AAD Connect (synchronize accounts) Set MDM authority Configure platforms Enroll! And that is what we are going to do after the break!

Share your ideas Share your voice / ideas! http://microsoftintune.uservoice.com/ http://configurationmanager.uservoice.com/

Questions

And Then