Getting your corporate Windows devices enrolled as a standard user with a security baseline that you trust and customized for a better end user experience. Deploying Windows LOB application from different sources for both simple and complex scenarios.
https://tdswe.se/events/manage-your-windows-device-in-a-modern-way/
7. Device lifecycle management
• No more maintenance of images and drivers
• No need for IT to touch the devices
• Simple process for users and IT
• Reset device back to a business ready state
Business ready
Break fix
RetirementManagementProcurement Deployment
8. Assigning an Autopilot profile
• Options for grouping:
• Dynamic group with all Autopilot devices
• Dynamic group based on device tag (orderID)
• Manual
9. Windows Autopilot Enrollment status page
• Confirm minimum baseline requirements
• Protect data during device set up
• Deliver a compliant secure device
• Personalize the out of box experience
20. Get the best user experience
• OneDrive for Business – Known Folder Move
• Enterprise State Roaming
• Disable Consumer Expirence
• Custom Start menu
• Two-Step verification
21. Let’s have a closer look
Get the best user experience
23. Intune Win32 Software Deployment
• Limited to single file MSI for Win32 apps
• Challenge for customers to deploy complex Windows apps
PowerShell Scripts
In the Past
Mobile MSI
24. Intune Win32 Software Deployment
• Limited to single file MSI for Win32 apps
• Use new Intune capability to directly deploy Win32 apps (MSI, EXE and MSP/MST)
What’s New
PowerShell Scripts
Mobile MSI
MSI, EXE, MSP
27. How to start a POC
• Cloud Identity
• Windows 10 Only
• Intune Standalone
• Describe your minimum security and management requirements
• Find test users that will benefit from modern management
Microsoft Cloud & Client Management
How safe do you think your information is?
About the presenter:
Please do not hesitate to ask questions during the presentation, we will have a Q&A at the end of the presentation but I prefer a open dialog and see where it will take us
About me:
Microsoft MVP - Enterprise Mobility, Solution Architect, Technical Lead Microsoft Enterprise Mobility Suite (EMS) and Microsoft Partner Technology Solutions Professional (P-TSP)
Co-Owner of Everything Windows User Group Denmark
Find me:
E-mail: per.larsen@atea.dk
Phone: +45 3078 1828
Follow me:
Twitter: https://twitter.com/perlarsen1975/
LinkedIn: https://www.linkedin.com/in/perlarsen1975/
Blog: https://osddeployment.dk
Join me:
Everything User Group Denmark: http://ewug.dk
Windows 10 med Modern Device Management
Your users are the center of the universe –
- IT department does not need to image or reimage devices - the user can just reset the device and re-enroll with there corporate identity
Secure your corporate data and identities
- We can help secure corporate data on any device, and secure identities from threats
Secure the device
- We can secure devices with encryption, use Device Guard to ensure that the devices is only running trusted applications
- Helps enterprise customers to detect, investigate, and respond to advanced and targeted attacks.
- Windows Update for Business
Deploy only profiles to devices when it makes sense
- Deploy profiles to configure Windows and applications
Use self-service
- Use company portal as a end-user self-service portal for application, and app portal for SSO with 2800+ applicatiions
- AutoPilot to get the device inside the coporate domain
NCSC – National Cyber Security Center
EUD Guidance: Windows 10 (1803) with Mobile Device Management - https://www.ncsc.gov.uk/guidance/eud-guidance-windows-10-1803-mobile-device-management
IntunePowerShellAutomation/DeviceConfiguration_NCSC - Windows10 (1803) SecurityBaseline.ps1 https://github.com/PerLarsen1975/IntunePowerShellAutomation/blob/master/DeviceConfiguration_NCSC%20-%20Windows10%20(1803)%20SecurityBaseline.ps1
Sneak peek: Public preview of Win32 application deployment using Microsoft Intune : https://techcommunity.microsoft.com/t5/Enterprise-Mobility-Security/Sneak-peek-Public-preview-of-Win32-application-deployment-using/ba-p/264460
How to deploy Adobe Acrobat Reader with MSIntune Win32 app deployment https://osddeployment.dk/2018/10/15/how-to-deploy-adobe-acrobat-reader-with-msintune-win32-app-deployment/
Download the tool at Github : https://github.com/Microsoft/Intune-Win32-App-Packaging-Tool
Generate the app manifest
Encrypt installation files
Convert installation files into .intunewin