In this session we will discuss the features provided by Windows Intune and System Center 2012 Configuration Manager to manage mobile devices using Windows Phone, Windows RT, Android and iOS.
We will discuss the configuration steps and the integration between the two platforms using Windows Intune Connector.
Managing Mobile Devices with Windows Intune and SCCM 2012 (Adrian Stoian)
1. Premium community conference on Microsoft technologies itcampro@ itcamp14#
Managing mobile devices with
Windows Intune and System Center
2012 Configuration Manager
Adrian Stoian
IT Consultant & Trainer
MVP Enterprise Client Management
TechReady
www.adrianstoian.com
2. Premium community conference on Microsoft technologies itcampro@ itcamp14#
Huge thanks to our sponsors & partners!
3. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Windows Intune Overview
• Identity Management
• Cloud Only Windows Intune Configuration
• Unified Management with Configuration
Manager
Agenda
5. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Windows Intune is a Microsoft cloud-based
management solution
What is Windows Intune?
Computer management Mobile Device Management
Application Management
Software Updates
Inventory and Reporting
Endpoint Protection
Windows Firewall
Remote Assistance
Application Deployment
Software Updates
Inventory and Reporting
Policy Settings
Remote Wipe
Remote Lock
Passcode Reset
6. Premium community conference on Microsoft technologies itcampro@ itcamp14#
Platform Support
Scenario System Center
2012 R2
Configuration
Manager
Windows Intune Configuration
Manager and
Windows Intune
Microsoft
Windows
Yes Yes Yes
Microsoft
Windows Server
Yes No Yes
Windows Phone No Yes Yes
Windows RT No Yes Yes
iOS No Yes Yes
Android No Yes Yes
Mac OS X Yes No Yes
Unix/Linux Servers Yes No Yes
BETTER TOGETHER
7. Premium community conference on Microsoft technologies itcampro@ itcamp14#
Windows Intune Consoles
Account Portal
https://account.manage.microsoft.com/
Administrator Console
https://admin.manage.microsoft.com/
9. Premium community conference on Microsoft technologies itcampro@ itcamp14#
What is Windows Azure Active Directory?
Azure
AD
AD
DS
SharePoint
Online
Exchange
Online
Lync
Online
CRM
Online
Windows
Intune
Windows Azure Active Directory
is designed for authentication
in the cloud
• Manage users and access to
cloud applications
• Extend your on-premises
directories to the cloud
• Provide single sign-on across
your cloud applications
• Enable multi-factor
authentication
On-Premise
10. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Separate Windows Intune accounts
• Dirsync
• Active Directory Federation Services (ADFS)
Identity Management Options
11. Premium community conference on Microsoft technologies itcampro@ itcamp14#
CLOUD ONLY WINDOWS INTUNE
CONFIGURATION
12. Premium community conference on Microsoft technologies itcampro@ itcamp14#
Windows Intune Architecture – Cloud Only
Windows
Intune
Corp Net Internet
AD DS
Exchange
Windows RT
Windows Phone 8
iOS
Android
Windows 8
Windows 7
Windows Vista
Windows XP
ActiveSync
EAS Policy
Administrator
DirSync
14. Premium community conference on Microsoft technologies itcampro@ itcamp14#
UNIFIED MANAGEMENT WITH
CONFIGURATION MANAGER
15. Premium community conference on Microsoft technologies itcampro@ itcamp14#
Windows Intune Architecture – Unified Mgmt
Windows
Intune
Corp Net Internet
AD FS
Exchange
Windows RT
Windows Phone 8
iOS
AndroidWindows 8
Windows 7
Windows Vista
Windows XP
ActiveSync
EAS Policy
Administrator
Intune Connector
ConfigMgr
AD DS
Single
Sign-On
Exchange
Connector
43. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Install AD CS and configure
certificate templates
• Install NDES on a separate
Windows Server 2012 R2
and configure service
account, CA name,
Registration Authority
• Enroll for server certificate
• Install Certificate
Registration Point (CRP)
site system role
• Install Configuration
Manager Policy Module
Configuration Steps
44. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Create a certificate profile
for the Trusted Root CA
certificate
• Create a certificate profile
for devices
• Create a certificate profile
for users
• Deploy Trusted Root
certificate profile to device
collections
• Deploy other certificate
profiles for users and
devices to relevant
collections
• Monitor compliance
Enrolling for certificates
45. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Windows 8.1 (incl. RT)
• iOS (5.0, 6.0, 7.0) for
iPhone and iPad
• Android
Applicable platforms
47. Premium community conference on Microsoft technologies itcampro@ itcamp14#
VPN PROFILES
IN CONFIGURATION MANAGER
48. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Run Create VPN Profile
Wizard
• Specify connection type
• Configure authentication
method
• Specify proxy settings
• Configure Automatic VPN
• Configure supported
platforms
• Deploy VPN profile to an
users collection
Configuration Steps
49. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Devices that run Windows 8.1 32-bit and 64-bit
• Devices that run Windows RT or Windows RT 8.1
• IPhone devices that run iOS 5, iOS 6 and iOS 7
• IPad devices that run iOS 5, iOS 6 and iOS 7
Applicable platforms
51. Premium community conference on Microsoft technologies itcampro@ itcamp14#
WI-FI PROFILES
IN CONFIGURATION MANAGER
52. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Run the Create Wi-Fi Profile
Wizard
• Specify network name and
SSID
• Configure authentication
method
• Configure advanced and
proxy settings
• Configure supported
platforms
• Deploy Wi-Fi profile to an
users collection
• Monitor compliance
Configuration Steps
53. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Devices that run Windows 8.1 32-bit and 64-bit
• Devices that run Windows RT 8.1
• IPhone devices that run iOS 5, iOS 6 and iOS 7
• IPad devices that run iOS 5, iOS 6 and iOS 7
• Android devices that run version 4
Applicable platforms
54. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Enterprise Feature Pack
–S/MIME for signing and encrypting e-mail
–VPN support
–Enterprise Wi-Fi with EAP-TLS
–Rich MDM policies (lock down)
–Certificate management
• Releasing in H1 2014
What about Windows Phone 8?
56. Premium community conference on Microsoft technologies itcampro@ itcamp14#
• Mobile Device Management with Windows Intune and System
Center Configuration Manager
– Attend this 2-day seminar to find out how you can manage mobile devices
using Windows Intune, either in the Cloud Only configuration, or using the
Unified Mangement configuration with System Center 2012 Configuration
Manager R2.
• Agenda:
1. Windows Intune Overview
2. Identity Management with Windows Intune
3. Cloud Only Windows Intune Configuration
4. Mobile Device Management with Windows Intune
5. Deploying Software to Mobile Devices
6. Unified Management with Windows Intune and System Center 2012
Configuration Manager R2
7. Managing Mobile Device Settings and Compliance
8. Unified Software Deployment
9. End User Experience for Mobile Devices
Seminar
57. Premium community conference on Microsoft technologies itcampro@ itcamp14#
Q & A
Contact details:
Blog: www.adrianstoian.com
Twitter: @astoian