36
Armoring your mobile workforce warriors for the 21st century with System Center Configuration Manager 2012 R2 Tim De Keukelaere Kenny Buntinx #CMCE_CH Feb 9 th 2015

Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

Armoring your mobile workforce warriors for the 21st century

with System Center Configuration Manager 2012 R2

Tim De KeukelaereKenny Buntinx

#CMCE_CH

Feb 9th 2015

Page 2: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

About Kenny

Kenny Buntinx

Managing Consultant

[email protected]

#CMCE_CH

@KennyBuntinx

http://be.linkedin.com/KennyBuntinx

http://scug.be/blogs/sccm

Page 3: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

About Tim

Tim De Keukelaere

Managing Consultant

[email protected]

#CMCE_CH

@Tim_DK

http://be.linkedin.com/in/timdekeukelaere/

http://scug.be/tim/

Page 4: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Key Takeaways

Understanding

• These concepts:

• UDM Integration with CM12

• ConfigMgr Extensions for Windows Intune

• Company Resource Access

Knowing • How to implement them

#CMCE_CH

Page 5: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Assumptions

About our audience

• Practical experience with System Center Configuration Manager 2012 SP1/R2

• Knowledge of Windows Intune and Device Enrollment

About us

• Not aiming to explain in detail

• “How to enroll all possible devices”

• “All possible UDM capabilities”

#CMCE_CH

Page 6: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

INTRODUCTION

#CMCE_CH

Page 7: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

AppsUsers DataDevices

Page 8: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

#CMCE_CH

Empowering people-centric IT

Mobile Device Management

Access and information protection

Desktop Virtualization

Hybrid Identity

Page 9: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

UDM Management Capabilities

• Over the air enrollment

• Retire and wipe devices

• Configure compliance settings on devices

– Settings for passwords, security, roaming, encryption, and wireless communication.

• Deploy certain Resource Profiles• VPN Profiles, WIFI and Email Profiles.

• Deploy line of business apps to device

• Deploy apps from the store that the device connects to

• Collect inventory• Hardware

• Software

#CMCE_CH

Page 10: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Is your ConfigMgr Environment ready for UDM?

• Cumulative Update 3 or 4– http://support.microsoft.com/kb/2994331

– http://support.microsoft.com/kb/3026739

• Additional Hotfixes (if on CU3):– http://support.microsoft.com/kb/2990658

– http://support.microsoft.com/kb/3002291

#CMCE_CH

Page 11: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

DEVICE ENROLLMENT

#CMCE_CH

Page 12: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Enrolling Devices

Users can enroll devices that configure the device for management with Windows Intune; the user can then use the Company Portal for easy access to corporate applications

Data from Windows Intune is in sync with Configuration Manager, which provides unified management across both on-premises and in the cloud

Dirsync

w Pwd Sync

Connector

Inte

rna

l

Co

nn

ec

tor

Page 13: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Mobile Device – Personal vs Corporate

App Management

• By default, user-enrolled devices are “Personal”

• Admin can specify corporate-owned devices !

Personal

vs.

Corporate Owned

Devices

Page 14: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Mobile Device – PortalsAll portals offer the same experience

(except for Windows Phone)

Page 15: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

DEMOEnrollment

Page 16: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

As a side note …

• ADFS with Workplace join?

– Windows Phone 8.1 requires GDR 2

– v 8.10.14192.280

#CMCE_CH

Page 17: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

INTUNE EXTENSIONS

#CMCE_CH

Page 18: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Configuration Manager Extensions for Windows Intune

• Rapid delivery of features within ConfigMgr , see

http://scug.be/tim/2015/02/06/microsoft-intune-february-update-

introduces-more-new-features/

• Updates are automatically downloaded and optionally enabled

through admin console.

Admin is notified that an

extension is available

when console is launched

Admin goes to

Extensions for Intune in

console, and

enables the extension

Extension is activated in ConfigMgr

•(Extension enables on all site system, then console updates are avail)

Admin restarts

console, and

console is updated with the

extension

Admin uses feature

delivered by the

extension

Admin may wish to

disable the extension

Page 19: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

As a side note …

• Permissions !

– Local Admin Required

• See:– http://scug.be/sccm/2014/02/11/cm12-extensions-for-

windows-intune-resources-and-gotchas/

#CMCE_CH

Page 20: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

SETTINGS MANAGEMENT

#CMCE_CH

Page 21: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Key Concepts

Page 22: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Mobile Device Settings in ConfigMgr 2012 R2Category Win 8.1 PC & RT WP8.1 iOS Android

VPN

Wi-Fi

Certificates

Email

Password

Device restrictions

Store access

Browsers

Content Rating

Cloud Synch

Encryption

Security

Roaming

Windows Server Work Folders

Page 23: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

COMPANY RESOURCE ACCESS

#CMCE_CH

Page 24: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Resource Access Configuration

#CMCE_CH

Platforms• Windows 8.1• Windows 8.1 RT• iOS• Android• Windows Phone 8.1

Benefits• End users get

access to

company resources with no manual steps for them

Features*• Configure VPN profiles

• Support for Windows 8.1 Automatic VPN• Wi-Fi protocol and authentication settings• Email account profiles• Management and distribution of certificates

Page 25: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

VPN Profile Management

DNS name-based initiation support for Windows 8.1 and

iOS

Application ID based initiation support for Windows 8.1

Automatic VPN

connection

Support for VPN

standards

SSL VPNs from Cisco, Juniper, Check Point, Microsoft, Dell

SonicWALL, F5

Subset of vendors have Windows VPN plug-in

PPTP ,L2TP, IKEv2

Support for Major

SSL VPN Vendors

Page 26: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Wi-Fi and Certificate Profiles

Manage and distribute certificates

Deploy trusted root certificatesSupport for Simple Certificate Enrollment Protocol

(SCEP)

Manage Wi-Fi protocol and authentication settings Provision Wi-Fi networks that device can auto connect

Specify certificate to be used for Wi-Fi connection

Wi-Fi Settings

Page 27: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

EMAIL PROFILE MANAGEMENT

#CMCE_CH

Page 28: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Overview

• Delivered as Configuration Manager Extension

for Windows Intune

• Configure account settings and security

restrictions

• Enable certificate authentication

• Support for iOS and Windows Phone 8.1

##CMCE_CH

Page 29: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

DEMOSettings Management

Email Profiles Management

Page 30: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Notes from the field

• Email profile not provisioned?

– Check Mail Attribute in AD ->

cannot be empty !

– See: http://scug.be/sccm/2014/03/21/sysctr-

configmgr-2012-and-intune-provisioning-email-

profiles-and-the-why-the-profile-may-not-turn-

up-on-devices-such-as-an-ipad/

Page 31: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

ADVANCED INVENTORY

SCENARIOS

#CMCE_CH

Page 32: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Collecting IMEI from devices

• Retrieve International Mobile Equipment Identity

(IMEI)

– Through custom MOF

– Windows Phone 8.1

• Full Details:– http://blogs.technet.com/b/configmgrteam/archive/2014/07/30/collectin

g-imei-from-devices-enrolled-in-windows-intune-with-sc-2012-r2-

configmgr.aspx

#CMCE_CH

Page 33: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

DEMOAdvanced Inventory

Page 34: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Q & A

#CMCE_CH

Page 35: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Weitere Infos

Digicomp Kurse neuhttps://www.microsoft.com/learning/en-us/course.aspx?ID=20695A&Locale=en-us

https://www.microsoft.com/learning/en-us/course.aspx?ID=20696A&Locale=en-us

#CMCE_CH

Page 36: Armoring your mobile workforce warriors for the 21st century · ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY UDM Management Capabilities • Over the air enrollment

ARMORING YOUR MOBILE WORKFORCE WARRIORS FOR THE 21ST CENTURY

Herzlichen DankMirko Colemberg @mirkocolemberg @configmgr_ch #cmcu_ch

blog.colemberg.ch

Bewertung der Session: Configmgr.ch

• Xing: https://www.xing.com/net/cmce

• Facebook: https://www.facebook.com/groups/411231535670608/

• Linkedin: http://www.linkedin.com

• Twitter: https://twitter.com/configmgr_ch

Nächster Event: Freitag 19. Juni Digicomp Bern

(begrenzte Anzahl Teilnehmer)

#CMCE_CH