Showing posts with label MAM. Show all posts
Showing posts with label MAM. Show all posts

Friday, September 11, 2015

Using ConfigMgr 2012 R2 SP1 and Microsoft Intune in a Hybrid configuration

Within my daily job I'm doing Configuration Manager (ConfigMgr) and Endpoint Protection (SCEP) consultancy and training a lot. ConfigMgr is a great product for managing on-premises devices, like servers, desktops and notebooks. With Microsoft Intune, Mobile Device and Application Management on tablets and smartphones can be done. This is a standalone Software as a service (SAAS) solution which exists for multiple years now. When integrating both solutions, you have a Hybrid configuration in-place.

Benefit of using a Hybrid configuration is integration! You can manage both Windows, Mac and Mobile devices within a single management console. Just make sure to set the management authority (which can be set on Office 365, Intune or Configuration Manager) on the right one. When it's set on Configuration Manager no management has to be done in the SAAS console anymore. Just use collections, applications and policies which are in ConfigMgr by default, to manage mobile devices as well. On the different clients, a Intune Company Portal needs to be installed for management.

Last years Microsoft has done a good job to improve speed on client communication and policies. That way you can enroll a mobile device in a few minutes, publish policies and applications, and set an unenrollment (when needed) all within approx. 15/20 minutes. When forcing a Reset passcode (new passcode must be entered) or Remote lock (device is locked and passcode needs to be set again), it will be active in approx. 1/2 minutes. During unenrollment all configuration and apps are removed also. Reasons enough to stay enrolled.

With Windows 10 Mobile coming, the richest set on policies can be configured. When creating policies (configuration items), you will see the difference on Android, iOS and Windows (Phone) platforms. Hope that will be better and easier in the future. It's possible also to deploy applications (from the different app stores) and weblinks to mobile devices. You can choose to open them in a web browser or install them. During installation a shortcut is created in Apps, so no need to open the Intune Company Portal again.

Hope to have some real experience on Windows 10 (Mobile) soon. It looks like the choice is really easy now! Just use Windows 10, Azure Active Directory (AAD), Enterprise Mobility Suite (EMS/Intune) and ConfigMgr from now on. That way Microsoft can convince you on the new generation available, which is Mobile first, Cloud first. Windows as a service, ConfigMgr as a service (2016) and Software as a service! I'm very excited about this, hope you are too?!

The following can be found on the "In the cloud" blog:
While there have been many improvements to the MDM capabilities, not every management capability exists – yet. To solve for this, we have effectively built a “bridge” between the ConfigMgr agent and the MDM agent which enables the agents to co-exist and expose all the existing manageability that you know today – as well as the new functionality that is being exposed via MDM to be manageable from the ConfigMgr console. No one else (traditional PC management or EMM vendor) has done any work like this. This is another HUGE reason that ConfigMgr + EMS is your best solution for deploying and managing Windows 10.

Just great if you ask me :-)

Thursday, January 16, 2014

Support for Windows Intune Trial Management of Windows RT

Last year I wrote a blogpost about Windows Intune Trial Management of Windows Phone 8. When using Windows Intune for demo usage and want to test Windows Phone 8 a certificate is needed. This can be resolved by using "Support Tool for Windows Intune Trial Management of Window Phone 8".

This time there's a workaround for Windows RT sideloading keys also.

Developer license successfully renewed

Use the PowerShell cmdlet "Show-WindowsDeveloperLicenseRegistration" to activate sideloading on Windows. This will enable Windows Intune to install apps without a sideloading key being set up. The limitations are that it requires a manual process on the client to activate sideloading, the license is only for 30 days (but can be renewed by running the cmdlet again), and the Windows team reserve the right to act if they feel the developer license registration is being abused.

Thursday, November 21, 2013

Support Tool for Windows Intune Trial Management of Window Phone 8

When using Windows Intune for demo usage and want to test Windows Phone 8 a certificate is needed. This can be resolved by using "Support Tool for Windows Intune Trial Management of Window Phone 8". This tool facilitates Microsoft System Center 2012 Configuration Manager admins and Windows Intune admins to try out Windows Phone 8 software distribution scenarios during the Trial period.

The downloaded support tool contains a script that populates a sample Application Enrollment Token in the Microsoft System Center 2012 Configuration Manager environment, a sample Windows Phone 8 Company Portal app, and two sample applications that can be used for WP8 software distribution scenarios.

Operation is finished successfully

Download link and Install instructions: Microsoft Download Center

Monday, November 18, 2013

How to Set Mobile Device Management Authority

In Windows Intune you can choose to set the Mobile Device Management Authority for Mobile Device Management. The Mobile Device Management Authority can be set to Windows Intune OR System Center Configuration Manager (SCCM/ConfigMgr). Consider carefully whether you want to manage mobile devices by using Windows Intune only or SCCM with Windows Intune Integration. After you set the mobile device management authority to either of these options, this cannot be changed.

In Windows Intune you can set the Mobile Device Management Authority from within the Admin Console. More information about this choice can be found on Microsoft TechNet.
1.Open the Windows Intune administrator console.
2.In the workspace shortcuts pane, click the Administration icon.
3.In the navigation pane, click Mobile Device Management Setup.
4.In the Tasks list on the Policy Overview page, click Set Mobile Device Management Authority.
5.The Set Mobile Device Management Authority dialog box appears, and it prompts you to choose whether to use Windows Intune to manage the mobile devices in your account. Do one of the following: Click Yes to use Windows Intune to manage mobile devices for your account. If you set Windows Intune as the management authority, you must manage mobile devices by using the Windows Intune administrator console.

Important: If you plan to use SCCM to manage mobile devices for your account, do not set the mobile device management authority to Windows Intune. To set the mobile device management authority to SCCM, you must use your organizational account to create a Windows Intune subscription from within the SCCM console, and select the option to allow Configuration Manager to manage the subscription.

In SCCM you can set the Mobile Device Management Authority from within the Administration pane. More information about this can be found on Microsoft TechNet.
1.In the Configuration Manager console, click Administration.
2.For System Center 2012 Configuration Manager SP1: In the Administration workspace, expand Hierarchy Configuration, and click Windows Intune Subscriptions.
For System Center 2012 R2 Configuration Manager: In the Administration workspace, expand Cloud Services, and click Windows Intune Subscriptions.
3.For System Center 2012 Configuration Manager SP1: On the Home tab, in the Create group, click Create Windows Intune Subscription.
System Center 2012 R2 Configuration Manager: On the Home tab, click Add Windows Intune Subscription.
4.On the Introduction page of the Create Windows Intune Subscription Wizard, review the text and click Next.
5.On the Subscription page, click Sign in and sign in by using your Windows Intune organizational account. Select the Allow the Configuration Manager console to manage this subscription check box. When you select this setting, you will only be able to manage mobile devices by using the Configuration Manager console. To continue with your subscription, you must select this option.

Important: Once you select Configuration Manager as your management authority, you cannot change the management authority to Windows Intune in the future.

In case of bad decision it's possible to contact Microsoft Support on this to reset the Mobile Device Management Authority for your account. In that case all managed computers and/or mobile devices must be removed from Windows Intune. After the reset it's possible to set the Mobile Device Management Authority again.

Friday, May 31, 2013

Enterprise Mobility Management Smackdown whitepaper available now!

This whitepaper is the 4th in the Smackdown series and is focused on Enterprise Mobility Management solutions.


A blog with link to the whitepaper is available HERE.

Do you want to know the real difference between “Mobile Device Management” and “Mobile Application Management”? Do you want to know the role of Enterprise Mobility in BYO and Consumerization of IT? Are you looking for insights into Enterprise Mobility in Application and Desktop Delivery? Are you looking for an independent overview of the Enterprise Mobility Management (EMM) solutions and curious about the different features- and functions each EMM vendor is offering? If so, the EMM Smackdown whitepaper is a MUST read!