Showing posts with label Enrollment. Show all posts
Showing posts with label Enrollment. Show all posts

Thursday, April 14, 2016

Enroll in to device management in Windows 10 not possible

In Windows 10 operating system (on both Mobile and full OS) the following can be done: Enroll in to device management. This on both domain-joined and non-domain-joined devices, where no ConfigMgr agent is present. When trying to enroll a new Windows 10 device however, the following message is displayed: System policies prevent you from connecting to a work or school account. Contact your support person for more information.

This because the account logged on has not enough permissions. Trick is you need local or domain admin permissions for it.

When logged in with local or domain admin permissions, enrollment is available as expected. When enrollment is done the following message is displayed: Well done! You're connected to work or school.

When logged in with user permissions again, enrollment is still not available. This because the following message is displayed: Another user on the system is already connected to a work or school. Please remove that work or school connection and try again.

If you ask me, I find all those messages bit of misleading. Why not mentioning you need special permissions for enrollment, instead of showing that system policies prevent you from connecting to a work or school account? That will help for sure!

Hope this will be more clear in a future release.

Source which points me to the solution: Kevin Kaminski's Virtual World

Sunday, May 11, 2014

Direct management of Android devices in Windows Intune

Within Windows Intune it's possible to manage (mobile) devices. Because an agent is installed, we can use Direct management instead of Exchange ActiveSync (EAS), which is limited. When Windows Intune v5.0 was released, it was needed to have ConfigMgr 2012 R2 integration configured. Otherwise new functionality (selective wipe, Android support, advanced policies) were not available. With the latest update however these are within Intune standalone now also. Let's have a look how to enroll an Android device (for example).

In this situation I'm using a HP SlateBook 10 x2 PC with Android 4.2 installed on it. Just browse in Google Play and search for "Windows Intune". When installed credentials must be given. Just logon with your Intune credentials (which are [user]@[domain].onmicrosoft.com) and enrollment is done already. When applications and/or policies are deployed, they will be activated within 5 minutes. Same for properties on the device in Admin console. Just give it a minute :-)

Policy is not applied as expected

Pros:
- It's really easy setup, especially on Android devices. No certificates needed at all.
- Enrollment of devices is almost real-time. Retirement is done within approximately 15 minutes.
- APK files can be downloaded for free, without the need to register them or install a certificate.

- Remote Lock and/or Passcode Reset, which are added in the last update.

Cons:
- Retirement is done within 24 hours max. That will be way faster in a later update.
- Every [?] minutes you must fill-in credentials again on Intune console and Company portal.
- Focus is on Microsoft and iOS, not that much on Android. Almost no settings available.
- When retire the device, apps and data remain installed which were installed by Intune before.

No Required install because greyed out

When deploying apps you can choose for a Available install only. No Required install or Uninstall can be choosen. Maybe the're for Windows Operating Systems only!? Pity that this isn't possible.

Next time I will use my iPad for enrollment. Hope that will give me more control on the device.. On Android I can enable passwords, encryption and disable the camera. That's all? Yes for now..

The Windows Intune roadmap 2014 can be found HERE.

Friday, January 24, 2014

Windows RT, Windows RT 8.1, and Windows 8.1 Enrollment

For Windows RT, users start enrollment from the Windows RT device. The users must complete the following tasks:

1. On the Windows RT device, users select Start, and type “System Configuration”, and click the dialog box to open the Company Apps.
2. The users enter their company credentials and are authenticated. This establishes a relationship between the user, the Windows RT device, and the Windows Intune service.
3. Windows Intune collects inventory and applies management settings. Users now have access to line-of-business apps and direct links to the app store through the company portal.


Company Portal on Windows RT 8.1

For Windows 8.1 and Windows RT 8.1, the user enrolls through the device.

1. On the Windows 8.1 device, the user selects Settings, clicks PC Settings, then clicks Network, and finally, clicks Workplace.
2. The user enters their user ID in the (ID) field.
3. The user clicks Turn on and provides their password.
4. The user agrees to the Allow apps and services from IT admin dialog box, and clicks Turn on.


Surface 2 RT 8.1 in ConfigMgr 2012 R2
 
After that the Company Portal can be started and device will be visible within a few minutes in the ConfigMgr console! It will take a few hours however before the client activity will be turned to active.

Source: How to Manage Mobile Devices by Using Configuration Manager and Windows Intune