Showing posts with label Mobile Application Management. Show all posts
Showing posts with label Mobile Application Management. Show all posts

Thursday, September 17, 2015

My experience with ConfigMgr 2012 R2 SP1 and Intune in Hybrid scenario

Last months I did multiple ConfigMgr implementations in Hybrid scenario. That means that a Microsoft Intune (SAAS) subscription is connected, and ConfigMgr is set as Management Authority. Combining both solutions has a great benefit; managing all devices (desktops, notebooks, servers, Mac-clients and mobile devices) from a single management console. I did multiple blogposts on that as well, which are included in the end of this post. Let's have a closer look.

When the Microsoft Intune subscription is connected, configuration is needed for the different (mobile) platforms. They are not hard to configure, but needs different certificates for management. Let's have a look for the options available:
When enrolling Android devices no certificate is needed. Enrollment is done by installing the company portal. Downside is there's less to manage on this operating system. Both compliance policy and configuration items (less settings) can be configured. Not the best experience on this one for me. Depends on the device maybe?

When enrolling iOS devices an Apple Push Notification (APN) certificate is needed. This one is free and valid for 12 months. I like to enroll IPad's because of fast communication and great screen. Enrollment is done by installing the company portal. Optionally you can choose for DEP (Device Enrollment Program) and VPP (Volume Purchase Program) programs. That way you have over-the-air zero touch enrollment, and applications can be quickly installed without the need to have manually actions everytime. This because when doing required app deployment you must approve them one by one. With these programs this isn't needed anymore. Both compliance policy and configuration items (many settings) can be configured. Best experience for me so far.

When enrolling Windows Phone (WP) devices an Symantec certificate is needed (most of times). Enrollment is done by using workplace join and installing the company portal. For WP 8.1 devices the Symantec certificate is needed only for signing line-of-business apps. Enrollment is quick and easy, but I prefer the iOS way myself. When enrolling Windows 10 (Mobile) the behavior is same. Just by using workplace join, device management becomes available in ConfigMgr. Hope this experience becomes better in ConfigMgr 2016 (available soon) with Windows 10 (Mobile). That way Microsoft has the best solution available for device management. For some customers I like to use DEP and VPP for easy enrollment and app deploy. This because of over-the-air zero touch enrollment, and easy app installation.

On multiple operating systems I have almost same behavior for now. Enrollment and compliance settings are quick and easy. Configuration items however are slow and unstable. You can choose to deploy them to user/device collections (or both, depends on the setting?), but sometimes they work, sometimes not..
Example: I did an enrollment on an IPad, have the compliance policy in 1/2 minutes and the configuration baseline in 10/15 minutes. I installed some apps and they will be available on screen. After that I unenrolled the device. Apps are gone, configuration baseline is gone, compliance policy is not required anymore. Just great. Then I did another enrollment on the device. Have the compliance policy in 1/2 minutes again, did install the apps again. But the configuration baseline never come back again. That's sad and not reliable.

Hope this part will be better (and quicker) in a next release. For now I hope to do way more on Hybrid scenario :) Stay tuned for more!

Other blogposts about this topic:
How to reset your MDM authority in Microsoft Intune

Note: Most captures in Dutch, sorry for that :)

Friday, September 11, 2015

Using ConfigMgr 2012 R2 SP1 and Microsoft Intune in a Hybrid configuration

Within my daily job I'm doing Configuration Manager (ConfigMgr) and Endpoint Protection (SCEP) consultancy and training a lot. ConfigMgr is a great product for managing on-premises devices, like servers, desktops and notebooks. With Microsoft Intune, Mobile Device and Application Management on tablets and smartphones can be done. This is a standalone Software as a service (SAAS) solution which exists for multiple years now. When integrating both solutions, you have a Hybrid configuration in-place.

Benefit of using a Hybrid configuration is integration! You can manage both Windows, Mac and Mobile devices within a single management console. Just make sure to set the management authority (which can be set on Office 365, Intune or Configuration Manager) on the right one. When it's set on Configuration Manager no management has to be done in the SAAS console anymore. Just use collections, applications and policies which are in ConfigMgr by default, to manage mobile devices as well. On the different clients, a Intune Company Portal needs to be installed for management.

Last years Microsoft has done a good job to improve speed on client communication and policies. That way you can enroll a mobile device in a few minutes, publish policies and applications, and set an unenrollment (when needed) all within approx. 15/20 minutes. When forcing a Reset passcode (new passcode must be entered) or Remote lock (device is locked and passcode needs to be set again), it will be active in approx. 1/2 minutes. During unenrollment all configuration and apps are removed also. Reasons enough to stay enrolled.

With Windows 10 Mobile coming, the richest set on policies can be configured. When creating policies (configuration items), you will see the difference on Android, iOS and Windows (Phone) platforms. Hope that will be better and easier in the future. It's possible also to deploy applications (from the different app stores) and weblinks to mobile devices. You can choose to open them in a web browser or install them. During installation a shortcut is created in Apps, so no need to open the Intune Company Portal again.

Hope to have some real experience on Windows 10 (Mobile) soon. It looks like the choice is really easy now! Just use Windows 10, Azure Active Directory (AAD), Enterprise Mobility Suite (EMS/Intune) and ConfigMgr from now on. That way Microsoft can convince you on the new generation available, which is Mobile first, Cloud first. Windows as a service, ConfigMgr as a service (2016) and Software as a service! I'm very excited about this, hope you are too?!

The following can be found on the "In the cloud" blog:
While there have been many improvements to the MDM capabilities, not every management capability exists – yet. To solve for this, we have effectively built a “bridge” between the ConfigMgr agent and the MDM agent which enables the agents to co-exist and expose all the existing manageability that you know today – as well as the new functionality that is being exposed via MDM to be manageable from the ConfigMgr console. No one else (traditional PC management or EMM vendor) has done any work like this. This is another HUGE reason that ConfigMgr + EMS is your best solution for deploying and managing Windows 10.

Just great if you ask me :-)

Sunday, May 11, 2014

Direct management of Android devices in Windows Intune

Within Windows Intune it's possible to manage (mobile) devices. Because an agent is installed, we can use Direct management instead of Exchange ActiveSync (EAS), which is limited. When Windows Intune v5.0 was released, it was needed to have ConfigMgr 2012 R2 integration configured. Otherwise new functionality (selective wipe, Android support, advanced policies) were not available. With the latest update however these are within Intune standalone now also. Let's have a look how to enroll an Android device (for example).

In this situation I'm using a HP SlateBook 10 x2 PC with Android 4.2 installed on it. Just browse in Google Play and search for "Windows Intune". When installed credentials must be given. Just logon with your Intune credentials (which are [user]@[domain].onmicrosoft.com) and enrollment is done already. When applications and/or policies are deployed, they will be activated within 5 minutes. Same for properties on the device in Admin console. Just give it a minute :-)

Policy is not applied as expected

Pros:
- It's really easy setup, especially on Android devices. No certificates needed at all.
- Enrollment of devices is almost real-time. Retirement is done within approximately 15 minutes.
- APK files can be downloaded for free, without the need to register them or install a certificate.

- Remote Lock and/or Passcode Reset, which are added in the last update.

Cons:
- Retirement is done within 24 hours max. That will be way faster in a later update.
- Every [?] minutes you must fill-in credentials again on Intune console and Company portal.
- Focus is on Microsoft and iOS, not that much on Android. Almost no settings available.
- When retire the device, apps and data remain installed which were installed by Intune before.

No Required install because greyed out

When deploying apps you can choose for a Available install only. No Required install or Uninstall can be choosen. Maybe the're for Windows Operating Systems only!? Pity that this isn't possible.

Next time I will use my iPad for enrollment. Hope that will give me more control on the device.. On Android I can enable passwords, encryption and disable the camera. That's all? Yes for now..

The Windows Intune roadmap 2014 can be found HERE.

Friday, May 31, 2013

Enterprise Mobility Management Smackdown whitepaper available now!

This whitepaper is the 4th in the Smackdown series and is focused on Enterprise Mobility Management solutions.


A blog with link to the whitepaper is available HERE.

Do you want to know the real difference between “Mobile Device Management” and “Mobile Application Management”? Do you want to know the role of Enterprise Mobility in BYO and Consumerization of IT? Are you looking for insights into Enterprise Mobility in Application and Desktop Delivery? Are you looking for an independent overview of the Enterprise Mobility Management (EMM) solutions and curious about the different features- and functions each EMM vendor is offering? If so, the EMM Smackdown whitepaper is a MUST read!