SlideShare une entreprise Scribd logo
1  sur  37
Télécharger pour lire hors ligne
Windows 10 in the Enterprise
Nico Sienaert (MVP)
Tweet and win an Ignite 2016 ticket #itproceed
KEY TAKEAWAYS
Windows 10 Management
Windows 10 Deployment
Prepare your environment
About Myself
Nico Sienaert
• Innovation Manager @ Getronics
• v-Technology Solutions Professional @ Microsoft
• Microsoft MVP – Enterprise Client Management
• http://scug.be/blogs/nico
• @nsienaert
ONE WINDOWS
Phone
Small
Tablet
2-in-1s
(Tablet or Laptop)
Desktops
& All-in-Ones
Phablet
Large
Tablet
Classic
Laptop
BEST OF ALL WORLDS
Windows 10
Converged
OS kernel
Converged
app model
LAST MAJOR RELEASE
GUI IMPROVEMENTS
• The Start Button
• Continuum
• Snap Assistant
• Task View
• Modern Apps in Desktop view  Charms inside the Apps
• Notification Center
• Apps: Cortana, New FotoApp, Music App, Better Calendar for WP,…
• Edge Browser
• Ctrl C + V in a Command Prompt ☺
APP & DEVICE COMPAT
INTERNET EXPLORER
A REQUIRED STEPPING STONE TO WINDOWS 10
• Migrate to Internet Explorer 11 on Windows 7 (before JAN 2016)
• Enterprise Mode, offering improved Internet Explorer 8 compatibility and document
type overrides
• Enterprise Site Discovery Toolkit, to better understand how users are browsing
DEPLOYMENT CHOICES
Traditional process
• Capture data and settings
• Deploy (custom) OS image
• Inject drivers
• Install apps
• Restore data and settings
Still an option for all
scenarios (Refresh, Replace,
Bare Metal)
Wipe-and-Load In-Place
Let Windows do the work
• Preserve all data, settings,
apps, drivers
• Install (standard) OS image
• Restore everything
Recommended for existing
devices (Windows 7/8/8.1)
IN-PLACE
NEW COMMAND LINE OPTIONS FOR SETUP.EXE /auto upgrade
• Regain control after success or failure using /postoobe and /postrollback switches
• Control driver migration operations using /migratealldrivers and /installdrivers
• Copy log files to a location of your choise using /copylogs (Default: “C:$Windows.~BTSourcesPanther”)
ENABLING UPGRADE FROM WINDOWS 7 VIA WINDOWS UPDATE
• WindowsTechnicalPreview.exe (a.k.a. KB2990214) enables installation via Windows Update on Windows 7
• Removing KB2990214 will remove the option
• KB3035583 (Optional KB – tooltip “reserve upgrade”)
USE CONFIGMGR TO HAVE MAX CONTROL
WSUS NOT SUPPORTED (YET)
NOT FOR ALL SCENARIOS
UPGRADE PROCESS
System Check
Inventory Apps
Inventory Drivers
Assess Compatibility
Prepare WinRe
Lay down previous OS
Install new OS
Prepare new OS
Specialize the machine
Migrate drivers
Migrate Apps
More migration tasks
Finalize installation
Welcome the user back
TOOLING SUPPORT
CM12 and R2 will support full Windows 10 thru a Service Pack
CM vNext will have full Windows 10 Support OoB
CM07 will support certain Windows 10 features
MDT2013 will support Windows 10 thru update (Preview today – Only LTI)
http://blogs.technet.com/b/configmgrteam/archive/2014/09/30/windows-10-enterprise-management-with-sc-
configmgr-and-intune.aspx
DEPLOYMENT CHOICES
Traditional process
• Capture data and settings
• Deploy (custom) OS image
• Inject drivers
• Install apps
• Restore data and settings
Still an option for all
scenarios (Refresh, Replace,
Bare Metal)
Wipe-and-Load In-Place Provisioning
Let Windows do the work
• Preserve all data, settings,
apps, drivers
• Install (standard) OS image
• Restore everything
Recommended for existing
devices (Windows 7/8/8.1)
Configure new devices
• Transform into an
Enterprise device
• Remove extra items, add
organizational apps and
config
New capability for new
devices
PROVISIONING
MANAGEMENT CHOICES
IDENTITY CHOICES
ORGANIZATIONOWNED(CYOD)
PERSONALLYOWNED(BYOD)
• Computer joins AD to
establish trust
• User signs on using AD
account
• Group Policy + System
Center
• Computer registers with AD or AAD via Device
Registration to establish trust for remote
resource access
• User signs in with a Microsoft account,
associates an AAD account
• Intune/MDM
• Computer joins AAD to
establish trust
• User signs on using
AAD account
• Intune/MDM
• Settings roaming
DOMAIN CLOUD JOIN
http://scug.be/nico/2015/03/19/windows-10-azure-domain-join/
CLOUD JOIN OOBE
Windows Pro is typically purchased for work machines, so we made a guess – but now’s the
time to correct us.
Looks like your company owns this PC – Did we get that right?
NextBack
Help me choose
MOBILE DEVICE MGMT
• Provisioning
• Bulk enrollment
• Simple bootstrap
• Converged protocol
• Azure AD Integration
• Greatly extended set of policies
(Parity with Windows Phone 8.1)
• Context based policies
• Client certificates – Direct install
(PFX)
• Enterprise Wi-Fi
• VPN management
• Email provisioning
• MDM Push when user not
logged in
• Device Update control
• Kiosk Mode, Start screen / Start
menu configuration and control
• Curated Windows Store
• Business Store Portal app
deployment; License reclaim/re-
use
• Enterprise App management
• Simplified LOB app management
• Win32 app management
• App inventory (MDM/store apps)
• App allow/deny lists through
Applocker
• Enterprise data protection
• Full device wipe
• Remote Lock, PIN reset,
Ring, Find
• Enhanced inventory for
compliance decisions
• Un-enrollment in two
phases & alerts
• Removal of Enterprise
configuration (apps, certs,
profiles, policies) and
Enterprise encrypted data
(with EDP)
• Additional device inventory
ENROLL INTO INTUNE
MDM Architecture
New capabilities exposed
using Configuration Service
Provider (CSP) model
WMI Bridge gives access to
new CSPs
Rootcimv2mdm
MDM_*
CSP CSP / WMI
Wrapper
Common component Desktop component
MDM Client EAS Client
CSP CSP CSP CSP
WMI Bridge
PowerShell
Scripts
ConfigMgr
Settings Mgmt
Configuration component
ONE WINDOWS STORE
WINDOWS
PHONE 8.1
WINDOWS 8.1
WINDOWS
10
• Converged developer portal for Windows
and Windows Phone
• Separate user and developer capabilities
• Fully converged experience
• Best features from each
• New capabilities
XBOX
STORE OF TOMORROW
CONSUMER WINDOWS
STORE
• Modern apps
• Sign in with MSA
• Pay with credit card, gift card, PayPal,
Alipay, INICIS, mobile operators (Phone)
BUSINESS STORE
• Modern apps
• Organization Store for the org’s preferred
or LOB apps
• Sign in with MSA to acquire public apps;
sign in with AAD to acquire org apps
• Pay with credit card or PO/invoice
• Deploy modern apps offline, in images,
and more
ENTERPRISE APP STORE
• Sideload line-of-business modern apps
• Deploy apps from the Windows Store
(even when the Store UI is disabled)
STORE OF TOMORROW
SECURITY
Multi Factor Authentication
• Azure MFA
Secure Token Protection
• Hard Container (leverage Hyper-v)
Next Generation Credentials (alternatives for passwords)
• PIN
• Key Pair wih a phone, USB dongle,…
• BIO gestures (like face, Iris, fingerprint) -> “Windows Hello”
https://www.youtube.com/watch?v=1AsoSnOmhvU
Information
Protection
Secure
Identities
Threat
Resistance
SECURITY
Device Protection
• BitLocker
Data Protection
• (Azure) RMS
• Conditional Access
Accidental Data Leakage
• Corporate  Personal Data
• Managed Applications
• SOFT or HARD Block Options
• Remote Wipe
Information
Protection
Secure
Identities
Threat
Resistance
SECURITY
Malware Prevention (Device Guard)
• Store Apps
• Signing Service
Pre-Booth Authentication
• Secure boot
• Trusted boot
• Measured boot
Information
Protection
Secure
Identities
Threat
Resistance
MISCELLANEOUS (1)
KMS
• New KMS and MAK keys for Windows 10
• Updates for existing KMS computers to support new products and keys
GROUP POLICIES (new ADMX files)
• Start Screen & Start Menu Settings
• Edge Browser Settings
• Universal App Management
NEW WMI CLASSES
• Win32_InstalledProgram +Usage +File +Framework
• Win32_DeviceContainer, Win32_InstalledDevice +HardwareID
MISCELLANEOUS (2)
Active Directory Changes
• Microsoft Passport
• Enterprise Data Protection
Windows 10 versions
• Home, Mobile, Pro (Upgrade for free the first year)
• Enterprise, Education, Mobile Enterprise
Windows Updates for Business (WUFB)
• Based on Telemetry
• Will not replace WSUS or ConfigMgr
• Hope to move customers to WUFB to improve the Windows Experience
THE END
Windows 10 will “probably” be the best OS Microsoft has ever released
Best of All Worlds
One Windows
You can still have impact by joining the Insider Program!
• Enterprise forums through TechNet
https://social.technet.microsoft.com/Forums/en-US/home?category=WinPreview2014
• Community discussions through Answers
http://answers.microsoft.com/en-us/windows/forum/windows_tp
• Windows Feature Suggestions
https://windows.uservoice.com
And win a Lumia 635
Feedback form will be sent to you by email
Give me feedback
Follow Technet Belgium
@technetbelux
Subscribe to the TechNet newsletter
aka.ms/benews
Be the first to know
Join the lunch sessions and
WIN NICE PRICES
Room Company Session
4 Go Hybrid with Azure Web Apps, by Tom Van Gramberen - Solutions Architect
Running dynamic websites? Always wanted to enjoy the scalability of Azure Web
Apps? But never could because you need to keep your data in a certain location? Now
with Azure Web App and Azure VNet everybody can overcome the hurdle of keeping
data "on-premise". Join us in this technical session where we will explore the basics of
Azure Web Apps and Virtual Networks. Learn about some possibilities to extend an
Azure VNet to your on-premise environment and how to integrate an Azure Web App
into the connection. In this demo packed session you will learn the specific network
requirements and network routing to make it all work together.
5 To the Cloud and Back – a Journey of Choices, by Paul van der Lingen, Consulting
Systems Engineer
The cloud is today the most compelling new technology, but as with all things new
and shiny, how do we make the most of it - leveraging all the good but deftly side-
stepping the bad. The key is choice and consistency. We believe customer data
remains at the heart of the new technology and in this session we’ll show how
transparent but consistent data movement and protection remain the most
important aspects of a complete cloud strategy.
6 Lost in translation - How Azure Networkingis different, by Joeri Van Hoof, Consulting
Sales Engineer
As one of the major cloud providers Microsoft Azure has a big adoption rate in a lot of
businesses around the world. Customers are moving parts of their infrastructure from
their own datacenter(s) to the Azure Cloud. Developers, system engineers, network
engineers and security staff are all effected by this change. On premise network
engineers have been building secure networks for years. Obviously they want to
extend and reuse this knowledge in the cloud. They are talking about network
firewalls, network segmentation, vlan’s. However in the Azure cloud this is slightly
different and some of the trusted mechanisms are unavailable. In this talk we go in-
depth on the various Azure networking options and how establish secure connectivity
between Azure and various on-premise locations
8 Effectively manage and resolve major IT incidents. A 24/7 solution in the palm of your
hand, by Matthes Derdack, CEO
Being on call is difficult enough. 24/7 IT operations require 24/7responsiveness. You
need to respond ASAP regardless of your week-end plans. Wouldn't it be great if you
could do whatever you wanted from wherever you are? Derdack now brings you an
innovative & intelligent companion that introduces a new level of on-call incident
handling. Your IT users will enjoy shorter down times and your team better KPIs. Our
Enterprise Alert mobile app comes with everything you need: reliably receive alerts
on the go, incident details and history analysis, collaborate with peers, inform users
on incident impacts, remote runbook execution & more. Join us on a journey through
your on-call day and enjoy an interactive, real-time and mobile experience.
10 Migration Center, Migrate Workloads as a service, by Anne-Elisabeth CAILLOT, Senior
Pre-Sales engineer
Double-Take Cloud Migration Center provides a self-service portal for customers and
partners who need the flexibility to move between virtualization and cloud
technologies. Five click migrations are now possible with the simplified workflow in
the Cloud Migration Center.
Thank you!
Belgiums’ biggest IT PRO Conference

Contenu connexe

Tendances

Brian Desmond - Quickly and easily protect your applications and services wit...
Brian Desmond - Quickly and easily protect your applications and services wit...Brian Desmond - Quickly and easily protect your applications and services wit...
Brian Desmond - Quickly and easily protect your applications and services wit...
Nordic Infrastructure Conference
 
Application Virtualization overview - BayCUG
Application Virtualization overview - BayCUGApplication Virtualization overview - BayCUG
Application Virtualization overview - BayCUG
Denis Gundarev
 

Tendances (20)

SCUGBE_Lowlands_Unite_2017_Rest azured microsoft cloud demystified
SCUGBE_Lowlands_Unite_2017_Rest azured   microsoft cloud demystifiedSCUGBE_Lowlands_Unite_2017_Rest azured   microsoft cloud demystified
SCUGBE_Lowlands_Unite_2017_Rest azured microsoft cloud demystified
 
Sami laiho - What's new in windows 8.1
Sami laiho - What's new in windows 8.1Sami laiho - What's new in windows 8.1
Sami laiho - What's new in windows 8.1
 
ECMDay2015 - Kenny Buntinx - Tim De Keukelaere - Armoring your mobile workfor...
ECMDay2015 - Kenny Buntinx - Tim De Keukelaere - Armoring your mobile workfor...ECMDay2015 - Kenny Buntinx - Tim De Keukelaere - Armoring your mobile workfor...
ECMDay2015 - Kenny Buntinx - Tim De Keukelaere - Armoring your mobile workfor...
 
Brian Desmond - Quickly and easily protect your applications and services wit...
Brian Desmond - Quickly and easily protect your applications and services wit...Brian Desmond - Quickly and easily protect your applications and services wit...
Brian Desmond - Quickly and easily protect your applications and services wit...
 
Identity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft AzureIdentity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft Azure
 
4 Modern Desktop - Planning a Modern Desktop Deployment
4   Modern Desktop -  Planning a Modern Desktop Deployment4   Modern Desktop -  Planning a Modern Desktop Deployment
4 Modern Desktop - Planning a Modern Desktop Deployment
 
#MFSummit2016 Operate: Solving desktop challenges with application virtualisa...
#MFSummit2016 Operate: Solving desktop challenges with application virtualisa...#MFSummit2016 Operate: Solving desktop challenges with application virtualisa...
#MFSummit2016 Operate: Solving desktop challenges with application virtualisa...
 
Azure conditional access
Azure conditional accessAzure conditional access
Azure conditional access
 
ITPROCEED_WorkplaceMobility_Delivering traditional File Server Workloads in a...
ITPROCEED_WorkplaceMobility_Delivering traditional File Server Workloads in a...ITPROCEED_WorkplaceMobility_Delivering traditional File Server Workloads in a...
ITPROCEED_WorkplaceMobility_Delivering traditional File Server Workloads in a...
 
#MFSummit2016 Operate: The race for space
#MFSummit2016 Operate: The race for space#MFSummit2016 Operate: The race for space
#MFSummit2016 Operate: The race for space
 
The Basics of Getting Started With Microsoft Azure
The Basics of Getting Started With Microsoft AzureThe Basics of Getting Started With Microsoft Azure
The Basics of Getting Started With Microsoft Azure
 
3 modern desktop - office 365 pro plus deployment + servicing
3   modern desktop - office 365 pro plus deployment + servicing3   modern desktop - office 365 pro plus deployment + servicing
3 modern desktop - office 365 pro plus deployment + servicing
 
SSAS Azure RemoteApp
SSAS Azure RemoteAppSSAS Azure RemoteApp
SSAS Azure RemoteApp
 
Troubleshooting The Modern Managed Client - Workplace Nijna Summit 2020
Troubleshooting The Modern Managed Client - Workplace Nijna Summit 2020  Troubleshooting The Modern Managed Client - Workplace Nijna Summit 2020
Troubleshooting The Modern Managed Client - Workplace Nijna Summit 2020
 
Azure Networking - The First Technical Challenge
Azure Networking  - The First Technical ChallengeAzure Networking  - The First Technical Challenge
Azure Networking - The First Technical Challenge
 
AMER Webcast: Build Development and Testing Environments on VMware vCloud Air
AMER Webcast: Build Development and Testing Environments on VMware vCloud AirAMER Webcast: Build Development and Testing Environments on VMware vCloud Air
AMER Webcast: Build Development and Testing Environments on VMware vCloud Air
 
Application Virtualization overview - BayCUG
Application Virtualization overview - BayCUGApplication Virtualization overview - BayCUG
Application Virtualization overview - BayCUG
 
2 modern desktop - windows deployment & servicing
2   modern desktop - windows deployment & servicing2   modern desktop - windows deployment & servicing
2 modern desktop - windows deployment & servicing
 
System center 2016 10 nyheder på 60 min
System center 2016   10 nyheder på 60 minSystem center 2016   10 nyheder på 60 min
System center 2016 10 nyheder på 60 min
 
Azure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD DeploymentAzure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD Deployment
 

Similaire à ITPROCEED_WorkplaceMobility_Windows 10 in the enterprise

In tune inaction
In tune inactionIn tune inaction
In tune inaction
Olav Tvedt
 
Hosted Virtual Desktops and Streamed Applications
Hosted Virtual Desktops and Streamed ApplicationsHosted Virtual Desktops and Streamed Applications
Hosted Virtual Desktops and Streamed Applications
Pete Valentine
 
A Citrix Masterclass
A Citrix MasterclassA Citrix Masterclass
A Citrix Masterclass
bluechipper
 
Desktop virtualisation
Desktop virtualisationDesktop virtualisation
Desktop virtualisation
BlueChipICT
 

Similaire à ITPROCEED_WorkplaceMobility_Windows 10 in the enterprise (20)

Windows 10: all you need to know!
Windows 10: all you need to know!Windows 10: all you need to know!
Windows 10: all you need to know!
 
SCUG.dk Windows 10 Management - September 2015
SCUG.dk   Windows 10 Management - September 2015SCUG.dk   Windows 10 Management - September 2015
SCUG.dk Windows 10 Management - September 2015
 
Bsm mw10
Bsm mw10Bsm mw10
Bsm mw10
 
World Wide Technology Tec37 Webinar - Deploy and Manage Windows 10 at Scale v1
World Wide Technology Tec37 Webinar -  Deploy and Manage Windows 10 at Scale v1World Wide Technology Tec37 Webinar -  Deploy and Manage Windows 10 at Scale v1
World Wide Technology Tec37 Webinar - Deploy and Manage Windows 10 at Scale v1
 
Next Level Learning IT Track - Windows 10
Next Level Learning IT Track - Windows 10Next Level Learning IT Track - Windows 10
Next Level Learning IT Track - Windows 10
 
Kasutajaõiguste ja seadmete haldus, monitooring ja kontroll
Kasutajaõiguste ja seadmete haldus, monitooring ja kontrollKasutajaõiguste ja seadmete haldus, monitooring ja kontroll
Kasutajaõiguste ja seadmete haldus, monitooring ja kontroll
 
Get On The Bus Keynote
Get On The Bus KeynoteGet On The Bus Keynote
Get On The Bus Keynote
 
Presentatie 21 mei Tergos Modern Management
Presentatie 21 mei   Tergos Modern ManagementPresentatie 21 mei   Tergos Modern Management
Presentatie 21 mei Tergos Modern Management
 
AWS re:Invent 2016: Zero to Google Chrome in 60 Minutes: Lightweight and Inex...
AWS re:Invent 2016: Zero to Google Chrome in 60 Minutes: Lightweight and Inex...AWS re:Invent 2016: Zero to Google Chrome in 60 Minutes: Lightweight and Inex...
AWS re:Invent 2016: Zero to Google Chrome in 60 Minutes: Lightweight and Inex...
 
In tune inaction
In tune inactionIn tune inaction
In tune inaction
 
Windows 7 Optimized Desktop
Windows 7 Optimized DesktopWindows 7 Optimized Desktop
Windows 7 Optimized Desktop
 
James Jara Portfolio 2014 - Cloud Operating System Voip -Part 2
James Jara Portfolio 2014  - Cloud Operating System Voip -Part 2James Jara Portfolio 2014  - Cloud Operating System Voip -Part 2
James Jara Portfolio 2014 - Cloud Operating System Voip -Part 2
 
Modernise your Windows 10 deployment with Windows Autopilot
Modernise your Windows 10 deployment with Windows AutopilotModernise your Windows 10 deployment with Windows Autopilot
Modernise your Windows 10 deployment with Windows Autopilot
 
Hosted Virtual Desktops and Streamed Applications
Hosted Virtual Desktops and Streamed ApplicationsHosted Virtual Desktops and Streamed Applications
Hosted Virtual Desktops and Streamed Applications
 
Tdswe 1810 learn how to create a secure and modern windows device
Tdswe 1810   learn how to create a secure and modern windows deviceTdswe 1810   learn how to create a secure and modern windows device
Tdswe 1810 learn how to create a secure and modern windows device
 
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
 
A Citrix Masterclass
A Citrix MasterclassA Citrix Masterclass
A Citrix Masterclass
 
Desktop virtualisation
Desktop virtualisationDesktop virtualisation
Desktop virtualisation
 
Ensuring Rock-Solid Unified Endpoint Management
Ensuring Rock-Solid Unified Endpoint ManagementEnsuring Rock-Solid Unified Endpoint Management
Ensuring Rock-Solid Unified Endpoint Management
 
In t trustm365ems_v3
In t trustm365ems_v3In t trustm365ems_v3
In t trustm365ems_v3
 

Plus de ITProceed

Plus de ITProceed (20)

The Internet of your things by Jan Tielens
The Internet of your things by Jan  TielensThe Internet of your things by Jan  Tielens
The Internet of your things by Jan Tielens
 
Optimal Azure Database Development by Karel Coenye
 Optimal Azure Database Development by Karel Coenye Optimal Azure Database Development by Karel Coenye
Optimal Azure Database Development by Karel Coenye
 
Azure stream analytics by Nico Jacobs
Azure stream analytics by Nico JacobsAzure stream analytics by Nico Jacobs
Azure stream analytics by Nico Jacobs
 
ITPROCEED_WorkplaceMobility_Delivering applications with Azure RemoteApp
ITPROCEED_WorkplaceMobility_Delivering applications with Azure RemoteAppITPROCEED_WorkplaceMobility_Delivering applications with Azure RemoteApp
ITPROCEED_WorkplaceMobility_Delivering applications with Azure RemoteApp
 
ITPROCEED_TransformTheDatacenter_Automate yourself service management like a ...
ITPROCEED_TransformTheDatacenter_Automate yourself service management like a ...ITPROCEED_TransformTheDatacenter_Automate yourself service management like a ...
ITPROCEED_TransformTheDatacenter_Automate yourself service management like a ...
 
ITPROCEED_WorkplaceMobility_Creating a seamless experience with ue v and wind...
ITPROCEED_WorkplaceMobility_Creating a seamless experience with ue v and wind...ITPROCEED_WorkplaceMobility_Creating a seamless experience with ue v and wind...
ITPROCEED_WorkplaceMobility_Creating a seamless experience with ue v and wind...
 
ITPROCEED2015_WorkplaceMobility_Configuration Manager 2012’s latest Service P...
ITPROCEED2015_WorkplaceMobility_Configuration Manager 2012’s latest Service P...ITPROCEED2015_WorkplaceMobility_Configuration Manager 2012’s latest Service P...
ITPROCEED2015_WorkplaceMobility_Configuration Manager 2012’s latest Service P...
 
Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...
 
Office Track: Exchange 2013 in the real world - Michael Van Horenbeeck
Office Track: Exchange 2013 in the real world - Michael Van HorenbeeckOffice Track: Exchange 2013 in the real world - Michael Van Horenbeeck
Office Track: Exchange 2013 in the real world - Michael Van Horenbeeck
 
Office Track: SharePoint Online Migration - Asses, Prepare, Migrate & Support...
Office Track: SharePoint Online Migration - Asses, Prepare, Migrate & Support...Office Track: SharePoint Online Migration - Asses, Prepare, Migrate & Support...
Office Track: SharePoint Online Migration - Asses, Prepare, Migrate & Support...
 
Office Track: Lync & Skype Federation v2 Deep Dive - Johan Delimon
Office Track: Lync & Skype Federation v2 Deep Dive - Johan DelimonOffice Track: Lync & Skype Federation v2 Deep Dive - Johan Delimon
Office Track: Lync & Skype Federation v2 Deep Dive - Johan Delimon
 
Office Track: Lync in a VDI Infrastructure - Ruben Nauwelaers & Wim Borgers
Office Track: Lync in a VDI Infrastructure - Ruben Nauwelaers & Wim BorgersOffice Track: Lync in a VDI Infrastructure - Ruben Nauwelaers & Wim Borgers
Office Track: Lync in a VDI Infrastructure - Ruben Nauwelaers & Wim Borgers
 
SQL Track: Restoring databases with powershell
SQL Track: Restoring databases with powershellSQL Track: Restoring databases with powershell
SQL Track: Restoring databases with powershell
 
SQL Track: Get more out of your data visualizations
SQL Track: Get more out of your data visualizationsSQL Track: Get more out of your data visualizations
SQL Track: Get more out of your data visualizations
 
SQL Track: SQL Server unleashed meet SQL Server's extreme sides
SQL Track: SQL Server unleashed meet SQL Server's extreme sidesSQL Track: SQL Server unleashed meet SQL Server's extreme sides
SQL Track: SQL Server unleashed meet SQL Server's extreme sides
 
SQL Track: In Memory OLTP in SQL Server
SQL Track: In Memory OLTP in SQL ServerSQL Track: In Memory OLTP in SQL Server
SQL Track: In Memory OLTP in SQL Server
 
SQL Track: Hybrid cloud with sql server 2014
SQL Track: Hybrid cloud with sql server 2014SQL Track: Hybrid cloud with sql server 2014
SQL Track: Hybrid cloud with sql server 2014
 
SQL: Enough business intelligence time for administration intelligence
SQL: Enough business intelligence  time for administration intelligenceSQL: Enough business intelligence  time for administration intelligence
SQL: Enough business intelligence time for administration intelligence
 
Sysctr Track: Managing your hybrid Mobile cloud Workforce Demystified with Sy...
Sysctr Track: Managing your hybrid Mobile cloud Workforce Demystified with Sy...Sysctr Track: Managing your hybrid Mobile cloud Workforce Demystified with Sy...
Sysctr Track: Managing your hybrid Mobile cloud Workforce Demystified with Sy...
 
Sysctr Track: Can SCOM monitor other stuff than Windows thingies Euhm yes it ...
Sysctr Track: Can SCOM monitor other stuff than Windows thingies Euhm yes it ...Sysctr Track: Can SCOM monitor other stuff than Windows thingies Euhm yes it ...
Sysctr Track: Can SCOM monitor other stuff than Windows thingies Euhm yes it ...
 

Dernier

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 

Dernier (20)

Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 

ITPROCEED_WorkplaceMobility_Windows 10 in the enterprise

  • 1. Windows 10 in the Enterprise Nico Sienaert (MVP) Tweet and win an Ignite 2016 ticket #itproceed
  • 2. KEY TAKEAWAYS Windows 10 Management Windows 10 Deployment Prepare your environment
  • 3. About Myself Nico Sienaert • Innovation Manager @ Getronics • v-Technology Solutions Professional @ Microsoft • Microsoft MVP – Enterprise Client Management • http://scug.be/blogs/nico • @nsienaert
  • 4. ONE WINDOWS Phone Small Tablet 2-in-1s (Tablet or Laptop) Desktops & All-in-Ones Phablet Large Tablet Classic Laptop
  • 5. BEST OF ALL WORLDS Windows 10 Converged OS kernel Converged app model
  • 7. GUI IMPROVEMENTS • The Start Button • Continuum • Snap Assistant • Task View • Modern Apps in Desktop view Charms inside the Apps • Notification Center • Apps: Cortana, New FotoApp, Music App, Better Calendar for WP,… • Edge Browser • Ctrl C + V in a Command Prompt ☺
  • 8. APP & DEVICE COMPAT
  • 9. INTERNET EXPLORER A REQUIRED STEPPING STONE TO WINDOWS 10 • Migrate to Internet Explorer 11 on Windows 7 (before JAN 2016) • Enterprise Mode, offering improved Internet Explorer 8 compatibility and document type overrides • Enterprise Site Discovery Toolkit, to better understand how users are browsing
  • 10. DEPLOYMENT CHOICES Traditional process • Capture data and settings • Deploy (custom) OS image • Inject drivers • Install apps • Restore data and settings Still an option for all scenarios (Refresh, Replace, Bare Metal) Wipe-and-Load In-Place Let Windows do the work • Preserve all data, settings, apps, drivers • Install (standard) OS image • Restore everything Recommended for existing devices (Windows 7/8/8.1)
  • 11. IN-PLACE NEW COMMAND LINE OPTIONS FOR SETUP.EXE /auto upgrade • Regain control after success or failure using /postoobe and /postrollback switches • Control driver migration operations using /migratealldrivers and /installdrivers • Copy log files to a location of your choise using /copylogs (Default: “C:$Windows.~BTSourcesPanther”) ENABLING UPGRADE FROM WINDOWS 7 VIA WINDOWS UPDATE • WindowsTechnicalPreview.exe (a.k.a. KB2990214) enables installation via Windows Update on Windows 7 • Removing KB2990214 will remove the option • KB3035583 (Optional KB – tooltip “reserve upgrade”) USE CONFIGMGR TO HAVE MAX CONTROL WSUS NOT SUPPORTED (YET) NOT FOR ALL SCENARIOS
  • 12. UPGRADE PROCESS System Check Inventory Apps Inventory Drivers Assess Compatibility Prepare WinRe Lay down previous OS Install new OS Prepare new OS Specialize the machine Migrate drivers Migrate Apps More migration tasks Finalize installation Welcome the user back
  • 13.
  • 14. TOOLING SUPPORT CM12 and R2 will support full Windows 10 thru a Service Pack CM vNext will have full Windows 10 Support OoB CM07 will support certain Windows 10 features MDT2013 will support Windows 10 thru update (Preview today – Only LTI) http://blogs.technet.com/b/configmgrteam/archive/2014/09/30/windows-10-enterprise-management-with-sc- configmgr-and-intune.aspx
  • 15. DEPLOYMENT CHOICES Traditional process • Capture data and settings • Deploy (custom) OS image • Inject drivers • Install apps • Restore data and settings Still an option for all scenarios (Refresh, Replace, Bare Metal) Wipe-and-Load In-Place Provisioning Let Windows do the work • Preserve all data, settings, apps, drivers • Install (standard) OS image • Restore everything Recommended for existing devices (Windows 7/8/8.1) Configure new devices • Transform into an Enterprise device • Remove extra items, add organizational apps and config New capability for new devices
  • 18. IDENTITY CHOICES ORGANIZATIONOWNED(CYOD) PERSONALLYOWNED(BYOD) • Computer joins AD to establish trust • User signs on using AD account • Group Policy + System Center • Computer registers with AD or AAD via Device Registration to establish trust for remote resource access • User signs in with a Microsoft account, associates an AAD account • Intune/MDM • Computer joins AAD to establish trust • User signs on using AAD account • Intune/MDM • Settings roaming
  • 20. CLOUD JOIN OOBE Windows Pro is typically purchased for work machines, so we made a guess – but now’s the time to correct us. Looks like your company owns this PC – Did we get that right? NextBack Help me choose
  • 21. MOBILE DEVICE MGMT • Provisioning • Bulk enrollment • Simple bootstrap • Converged protocol • Azure AD Integration • Greatly extended set of policies (Parity with Windows Phone 8.1) • Context based policies • Client certificates – Direct install (PFX) • Enterprise Wi-Fi • VPN management • Email provisioning • MDM Push when user not logged in • Device Update control • Kiosk Mode, Start screen / Start menu configuration and control • Curated Windows Store • Business Store Portal app deployment; License reclaim/re- use • Enterprise App management • Simplified LOB app management • Win32 app management • App inventory (MDM/store apps) • App allow/deny lists through Applocker • Enterprise data protection • Full device wipe • Remote Lock, PIN reset, Ring, Find • Enhanced inventory for compliance decisions • Un-enrollment in two phases & alerts • Removal of Enterprise configuration (apps, certs, profiles, policies) and Enterprise encrypted data (with EDP) • Additional device inventory
  • 23. MDM Architecture New capabilities exposed using Configuration Service Provider (CSP) model WMI Bridge gives access to new CSPs Rootcimv2mdm MDM_* CSP CSP / WMI Wrapper Common component Desktop component MDM Client EAS Client CSP CSP CSP CSP WMI Bridge PowerShell Scripts ConfigMgr Settings Mgmt Configuration component
  • 24. ONE WINDOWS STORE WINDOWS PHONE 8.1 WINDOWS 8.1 WINDOWS 10 • Converged developer portal for Windows and Windows Phone • Separate user and developer capabilities • Fully converged experience • Best features from each • New capabilities XBOX
  • 25. STORE OF TOMORROW CONSUMER WINDOWS STORE • Modern apps • Sign in with MSA • Pay with credit card, gift card, PayPal, Alipay, INICIS, mobile operators (Phone) BUSINESS STORE • Modern apps • Organization Store for the org’s preferred or LOB apps • Sign in with MSA to acquire public apps; sign in with AAD to acquire org apps • Pay with credit card or PO/invoice • Deploy modern apps offline, in images, and more ENTERPRISE APP STORE • Sideload line-of-business modern apps • Deploy apps from the Windows Store (even when the Store UI is disabled)
  • 27. SECURITY Multi Factor Authentication • Azure MFA Secure Token Protection • Hard Container (leverage Hyper-v) Next Generation Credentials (alternatives for passwords) • PIN • Key Pair wih a phone, USB dongle,… • BIO gestures (like face, Iris, fingerprint) -> “Windows Hello” https://www.youtube.com/watch?v=1AsoSnOmhvU Information Protection Secure Identities Threat Resistance
  • 28. SECURITY Device Protection • BitLocker Data Protection • (Azure) RMS • Conditional Access Accidental Data Leakage • Corporate Personal Data • Managed Applications • SOFT or HARD Block Options • Remote Wipe Information Protection Secure Identities Threat Resistance
  • 29. SECURITY Malware Prevention (Device Guard) • Store Apps • Signing Service Pre-Booth Authentication • Secure boot • Trusted boot • Measured boot Information Protection Secure Identities Threat Resistance
  • 30. MISCELLANEOUS (1) KMS • New KMS and MAK keys for Windows 10 • Updates for existing KMS computers to support new products and keys GROUP POLICIES (new ADMX files) • Start Screen & Start Menu Settings • Edge Browser Settings • Universal App Management NEW WMI CLASSES • Win32_InstalledProgram +Usage +File +Framework • Win32_DeviceContainer, Win32_InstalledDevice +HardwareID
  • 31. MISCELLANEOUS (2) Active Directory Changes • Microsoft Passport • Enterprise Data Protection Windows 10 versions • Home, Mobile, Pro (Upgrade for free the first year) • Enterprise, Education, Mobile Enterprise Windows Updates for Business (WUFB) • Based on Telemetry • Will not replace WSUS or ConfigMgr • Hope to move customers to WUFB to improve the Windows Experience
  • 32. THE END Windows 10 will “probably” be the best OS Microsoft has ever released Best of All Worlds One Windows You can still have impact by joining the Insider Program! • Enterprise forums through TechNet https://social.technet.microsoft.com/Forums/en-US/home?category=WinPreview2014 • Community discussions through Answers http://answers.microsoft.com/en-us/windows/forum/windows_tp • Windows Feature Suggestions https://windows.uservoice.com
  • 33. And win a Lumia 635 Feedback form will be sent to you by email Give me feedback
  • 34. Follow Technet Belgium @technetbelux Subscribe to the TechNet newsletter aka.ms/benews Be the first to know
  • 35. Join the lunch sessions and WIN NICE PRICES Room Company Session 4 Go Hybrid with Azure Web Apps, by Tom Van Gramberen - Solutions Architect Running dynamic websites? Always wanted to enjoy the scalability of Azure Web Apps? But never could because you need to keep your data in a certain location? Now with Azure Web App and Azure VNet everybody can overcome the hurdle of keeping data "on-premise". Join us in this technical session where we will explore the basics of Azure Web Apps and Virtual Networks. Learn about some possibilities to extend an Azure VNet to your on-premise environment and how to integrate an Azure Web App into the connection. In this demo packed session you will learn the specific network requirements and network routing to make it all work together. 5 To the Cloud and Back – a Journey of Choices, by Paul van der Lingen, Consulting Systems Engineer The cloud is today the most compelling new technology, but as with all things new and shiny, how do we make the most of it - leveraging all the good but deftly side- stepping the bad. The key is choice and consistency. We believe customer data remains at the heart of the new technology and in this session we’ll show how transparent but consistent data movement and protection remain the most important aspects of a complete cloud strategy. 6 Lost in translation - How Azure Networkingis different, by Joeri Van Hoof, Consulting Sales Engineer As one of the major cloud providers Microsoft Azure has a big adoption rate in a lot of businesses around the world. Customers are moving parts of their infrastructure from their own datacenter(s) to the Azure Cloud. Developers, system engineers, network engineers and security staff are all effected by this change. On premise network engineers have been building secure networks for years. Obviously they want to extend and reuse this knowledge in the cloud. They are talking about network firewalls, network segmentation, vlan’s. However in the Azure cloud this is slightly different and some of the trusted mechanisms are unavailable. In this talk we go in- depth on the various Azure networking options and how establish secure connectivity between Azure and various on-premise locations 8 Effectively manage and resolve major IT incidents. A 24/7 solution in the palm of your hand, by Matthes Derdack, CEO Being on call is difficult enough. 24/7 IT operations require 24/7responsiveness. You need to respond ASAP regardless of your week-end plans. Wouldn't it be great if you could do whatever you wanted from wherever you are? Derdack now brings you an innovative & intelligent companion that introduces a new level of on-call incident handling. Your IT users will enjoy shorter down times and your team better KPIs. Our Enterprise Alert mobile app comes with everything you need: reliably receive alerts on the go, incident details and history analysis, collaborate with peers, inform users on incident impacts, remote runbook execution & more. Join us on a journey through your on-call day and enjoy an interactive, real-time and mobile experience. 10 Migration Center, Migrate Workloads as a service, by Anne-Elisabeth CAILLOT, Senior Pre-Sales engineer Double-Take Cloud Migration Center provides a self-service portal for customers and partners who need the flexibility to move between virtualization and cloud technologies. Five click migrations are now possible with the simplified workflow in the Cloud Migration Center.
  • 37. Belgiums’ biggest IT PRO Conference