Showing posts with label Mobile Device Management. Show all posts
Showing posts with label Mobile Device Management. Show all posts

Thursday, September 17, 2015

My experience with ConfigMgr 2012 R2 SP1 and Intune in Hybrid scenario

Last months I did multiple ConfigMgr implementations in Hybrid scenario. That means that a Microsoft Intune (SAAS) subscription is connected, and ConfigMgr is set as Management Authority. Combining both solutions has a great benefit; managing all devices (desktops, notebooks, servers, Mac-clients and mobile devices) from a single management console. I did multiple blogposts on that as well, which are included in the end of this post. Let's have a closer look.

When the Microsoft Intune subscription is connected, configuration is needed for the different (mobile) platforms. They are not hard to configure, but needs different certificates for management. Let's have a look for the options available:
When enrolling Android devices no certificate is needed. Enrollment is done by installing the company portal. Downside is there's less to manage on this operating system. Both compliance policy and configuration items (less settings) can be configured. Not the best experience on this one for me. Depends on the device maybe?

When enrolling iOS devices an Apple Push Notification (APN) certificate is needed. This one is free and valid for 12 months. I like to enroll IPad's because of fast communication and great screen. Enrollment is done by installing the company portal. Optionally you can choose for DEP (Device Enrollment Program) and VPP (Volume Purchase Program) programs. That way you have over-the-air zero touch enrollment, and applications can be quickly installed without the need to have manually actions everytime. This because when doing required app deployment you must approve them one by one. With these programs this isn't needed anymore. Both compliance policy and configuration items (many settings) can be configured. Best experience for me so far.

When enrolling Windows Phone (WP) devices an Symantec certificate is needed (most of times). Enrollment is done by using workplace join and installing the company portal. For WP 8.1 devices the Symantec certificate is needed only for signing line-of-business apps. Enrollment is quick and easy, but I prefer the iOS way myself. When enrolling Windows 10 (Mobile) the behavior is same. Just by using workplace join, device management becomes available in ConfigMgr. Hope this experience becomes better in ConfigMgr 2016 (available soon) with Windows 10 (Mobile). That way Microsoft has the best solution available for device management. For some customers I like to use DEP and VPP for easy enrollment and app deploy. This because of over-the-air zero touch enrollment, and easy app installation.

On multiple operating systems I have almost same behavior for now. Enrollment and compliance settings are quick and easy. Configuration items however are slow and unstable. You can choose to deploy them to user/device collections (or both, depends on the setting?), but sometimes they work, sometimes not..
Example: I did an enrollment on an IPad, have the compliance policy in 1/2 minutes and the configuration baseline in 10/15 minutes. I installed some apps and they will be available on screen. After that I unenrolled the device. Apps are gone, configuration baseline is gone, compliance policy is not required anymore. Just great. Then I did another enrollment on the device. Have the compliance policy in 1/2 minutes again, did install the apps again. But the configuration baseline never come back again. That's sad and not reliable.

Hope this part will be better (and quicker) in a next release. For now I hope to do way more on Hybrid scenario :) Stay tuned for more!

Other blogposts about this topic:
How to reset your MDM authority in Microsoft Intune

Note: Most captures in Dutch, sorry for that :)

Friday, September 11, 2015

Using ConfigMgr 2012 R2 SP1 and Microsoft Intune in a Hybrid configuration

Within my daily job I'm doing Configuration Manager (ConfigMgr) and Endpoint Protection (SCEP) consultancy and training a lot. ConfigMgr is a great product for managing on-premises devices, like servers, desktops and notebooks. With Microsoft Intune, Mobile Device and Application Management on tablets and smartphones can be done. This is a standalone Software as a service (SAAS) solution which exists for multiple years now. When integrating both solutions, you have a Hybrid configuration in-place.

Benefit of using a Hybrid configuration is integration! You can manage both Windows, Mac and Mobile devices within a single management console. Just make sure to set the management authority (which can be set on Office 365, Intune or Configuration Manager) on the right one. When it's set on Configuration Manager no management has to be done in the SAAS console anymore. Just use collections, applications and policies which are in ConfigMgr by default, to manage mobile devices as well. On the different clients, a Intune Company Portal needs to be installed for management.

Last years Microsoft has done a good job to improve speed on client communication and policies. That way you can enroll a mobile device in a few minutes, publish policies and applications, and set an unenrollment (when needed) all within approx. 15/20 minutes. When forcing a Reset passcode (new passcode must be entered) or Remote lock (device is locked and passcode needs to be set again), it will be active in approx. 1/2 minutes. During unenrollment all configuration and apps are removed also. Reasons enough to stay enrolled.

With Windows 10 Mobile coming, the richest set on policies can be configured. When creating policies (configuration items), you will see the difference on Android, iOS and Windows (Phone) platforms. Hope that will be better and easier in the future. It's possible also to deploy applications (from the different app stores) and weblinks to mobile devices. You can choose to open them in a web browser or install them. During installation a shortcut is created in Apps, so no need to open the Intune Company Portal again.

Hope to have some real experience on Windows 10 (Mobile) soon. It looks like the choice is really easy now! Just use Windows 10, Azure Active Directory (AAD), Enterprise Mobility Suite (EMS/Intune) and ConfigMgr from now on. That way Microsoft can convince you on the new generation available, which is Mobile first, Cloud first. Windows as a service, ConfigMgr as a service (2016) and Software as a service! I'm very excited about this, hope you are too?!

The following can be found on the "In the cloud" blog:
While there have been many improvements to the MDM capabilities, not every management capability exists – yet. To solve for this, we have effectively built a “bridge” between the ConfigMgr agent and the MDM agent which enables the agents to co-exist and expose all the existing manageability that you know today – as well as the new functionality that is being exposed via MDM to be manageable from the ConfigMgr console. No one else (traditional PC management or EMM vendor) has done any work like this. This is another HUGE reason that ConfigMgr + EMS is your best solution for deploying and managing Windows 10.

Just great if you ask me :-)

Tuesday, March 31, 2015

Feature Comparison with Mobile Device Management for Office 365

Since this week built-in mobile device management (MDM) is available for Office 365 commercial plans. With MDM for Office 365, you can manage access to Office 365 data across a diverse range of phones and tablets, including iOS, Android and Windows Phone devices, without the need for Microsoft Intune. The built-in MDM features are included at no additional cost in all Office 365 commercial plans, including Business, Enterprise, EDU and Government plans.

 
Office 365’s MDM capabilities work to keep your data safe in three ways:
-Conditional Access: Setup security policies to ensure that Office 365 corporate email and documents can be accessed only on phones and tablets that are managed by your company and are compliant.
-Device management: Manage security policies such as PIN lock and jailbreak detection to help prevent unauthorized users from accessing corporate email and data on a device when it is lost or stolen.
-Selective wipe: Remove Office 365 company data from an device while leaving personal data in place.


When looking at the Feature Comparison, there are big differences seen between Exchange ActiveSync, MDM for Office 365, Intune Standalone and Intune + ConfigMgr (Hybrid). This Feature Comparison can help to decide which solution offers the functionality needed.

When looking for protection beyond what’s included in Office 365, you can subscribe to Microsoft Intune, part of the Microsoft Enterprise Mobility Suite, and receive additional device and application management capabilities for phones, tablets and PCs. With Microsoft Intune actions such as cut, copy, paste and save as to applications can be restricted as well, keep corporate information even more secure.

Nice to see that Office 365 has MDM capabilities from now on!

Source: Office Blogs

Sunday, May 11, 2014

Direct management of Android devices in Windows Intune

Within Windows Intune it's possible to manage (mobile) devices. Because an agent is installed, we can use Direct management instead of Exchange ActiveSync (EAS), which is limited. When Windows Intune v5.0 was released, it was needed to have ConfigMgr 2012 R2 integration configured. Otherwise new functionality (selective wipe, Android support, advanced policies) were not available. With the latest update however these are within Intune standalone now also. Let's have a look how to enroll an Android device (for example).

In this situation I'm using a HP SlateBook 10 x2 PC with Android 4.2 installed on it. Just browse in Google Play and search for "Windows Intune". When installed credentials must be given. Just logon with your Intune credentials (which are [user]@[domain].onmicrosoft.com) and enrollment is done already. When applications and/or policies are deployed, they will be activated within 5 minutes. Same for properties on the device in Admin console. Just give it a minute :-)

Policy is not applied as expected

Pros:
- It's really easy setup, especially on Android devices. No certificates needed at all.
- Enrollment of devices is almost real-time. Retirement is done within approximately 15 minutes.
- APK files can be downloaded for free, without the need to register them or install a certificate.

- Remote Lock and/or Passcode Reset, which are added in the last update.

Cons:
- Retirement is done within 24 hours max. That will be way faster in a later update.
- Every [?] minutes you must fill-in credentials again on Intune console and Company portal.
- Focus is on Microsoft and iOS, not that much on Android. Almost no settings available.
- When retire the device, apps and data remain installed which were installed by Intune before.

No Required install because greyed out

When deploying apps you can choose for a Available install only. No Required install or Uninstall can be choosen. Maybe the're for Windows Operating Systems only!? Pity that this isn't possible.

Next time I will use my iPad for enrollment. Hope that will give me more control on the device.. On Android I can enable passwords, encryption and disable the camera. That's all? Yes for now..

The Windows Intune roadmap 2014 can be found HERE.

Thursday, March 20, 2014

Windows Intune Roadmap - Partner Session Feb 2014

Last month I get an invite for the Windows Intune Roadmap. This remote session was for partners only, to show the User and Device Management Roadmap. No big update once or twice a year, but small monthly updates to bring Intune on-speed sooner. Let's have a look at new features which are coming in next months.

Above features are implemented already. With Richer cloud-only MDM capabilities, Microsoft wants same functionality in Windows Intune standalone as hybrid configuration (for example: Android support, email profile configuration and selective wipe). No need to integrate with ConfigMgr 2012 R2 that way for these features.

Even more features will be available in the next coming months. Windows Intune will be more advanced and mature that way. At the moment it feels sometimes if functionality is missing. That will be improved when above roadmap is functional. Hope that Intune will be competitive with other MDM solutions soon.

No System Center and Intune fusion [yet] for it seems! :)

Thursday, January 16, 2014

Support for Windows Intune Trial Management of Windows RT

Last year I wrote a blogpost about Windows Intune Trial Management of Windows Phone 8. When using Windows Intune for demo usage and want to test Windows Phone 8 a certificate is needed. This can be resolved by using "Support Tool for Windows Intune Trial Management of Window Phone 8".

This time there's a workaround for Windows RT sideloading keys also.

Developer license successfully renewed

Use the PowerShell cmdlet "Show-WindowsDeveloperLicenseRegistration" to activate sideloading on Windows. This will enable Windows Intune to install apps without a sideloading key being set up. The limitations are that it requires a manual process on the client to activate sideloading, the license is only for 30 days (but can be renewed by running the cmdlet again), and the Windows team reserve the right to act if they feel the developer license registration is being abused.

Thursday, November 21, 2013

Support Tool for Windows Intune Trial Management of Window Phone 8

When using Windows Intune for demo usage and want to test Windows Phone 8 a certificate is needed. This can be resolved by using "Support Tool for Windows Intune Trial Management of Window Phone 8". This tool facilitates Microsoft System Center 2012 Configuration Manager admins and Windows Intune admins to try out Windows Phone 8 software distribution scenarios during the Trial period.

The downloaded support tool contains a script that populates a sample Application Enrollment Token in the Microsoft System Center 2012 Configuration Manager environment, a sample Windows Phone 8 Company Portal app, and two sample applications that can be used for WP8 software distribution scenarios.

Operation is finished successfully

Download link and Install instructions: Microsoft Download Center

Friday, May 31, 2013

Enterprise Mobility Management Smackdown whitepaper available now!

This whitepaper is the 4th in the Smackdown series and is focused on Enterprise Mobility Management solutions.


A blog with link to the whitepaper is available HERE.

Do you want to know the real difference between “Mobile Device Management” and “Mobile Application Management”? Do you want to know the role of Enterprise Mobility in BYO and Consumerization of IT? Are you looking for insights into Enterprise Mobility in Application and Desktop Delivery? Are you looking for an independent overview of the Enterprise Mobility Management (EMM) solutions and curious about the different features- and functions each EMM vendor is offering? If so, the EMM Smackdown whitepaper is a MUST read!

Monday, September 10, 2012

Next Release of Windows Intune announced!

Today the Next Release of Windows Intune is announced. The Next Release of Windows Intune is adding new client management capabilities as it relates to System Center 2012 Configuration Manager (ConfigMgr) Service Pack 1 (SP1) Beta.


Microsoft offers two separate endpoint management solutions – System Center 2012 Configuration Manager (ConfigMgr) for on-premises management, and Windows Intune for management through the cloud.  With ConfigMgr 2012 SP1 and the next version of Windows Intune, Microsoft is taking the first step in delivering interoperability between these products through Configuration Manager’s administration console. 

This will enable customers to add mobile devices managed through the cloud with Windows Intune into their ConfigMgr 2012 SP1 console and manage all the devices through one tool. While you can continue to use Windows Intune as a "fully in the cloud" management solution for PC and mobile device management, the interoperability of Microsoft's on-premises and cloud services is a big step forward for organizations that want to manage all of their devices from one place.

To evaluate the current release of Windows Intune, you can sign up for a free 30-day trial of Windows Intune at the Microsoft website.   

Brad Anderson mentioned during MMS 2012 in Las Vegas already: Regarding Windows Intune and ConfigMgr: "as we go forward we are going to bring these two closer together".

Great to see that ConfigMgr 2012 and Windows Intune now works together to manage both on-premises and through the cloud! Look for availability of ConfigMgr 2012 SP1 and the next release of Windows Intune in early 2013.

More information about Windows Intune can be found HERE.

Thursday, December 29, 2011

Mobile Device Management in ConfigMgr 2012

Next year (probably around MMS 2012) ConfigMgr 2012 will be released. One of the new features in this release will be Mobile Device Management integration. In the current System Center suite there was a single product for that, named: System Center Mobile Device Manager (SCMDM). Also there was a small integration in ConfigMgr 2007 possible. Both solutions were based on Windows Mobile 6.x devices. Because most customers have various mobile phone solutions this was not really an option. With ConfigMgr 2012 actually it is!

With Mobile Device Management in ConfigMgr 2012 there is more integration possible with mobile phone solutions. There will be support for iPads, iPhones, Symbian devices, Android devices and Windows Phone 7 devices. There will be a difference in Light Management and Depth Management devices. This can be seen on the following picture:

For Light Management devices an Exchange connector will be used. Then Mobile Device Management (MDM) will have the same functionality as in Exchange 2010 (nothing more unfortunately). With Depth Management there is more management possible, but only on WinCE 6.0, WM 6.0/6.1, WP 6.5 and Nokia Symbian based devices.

Let's hope there will be more functionality on Light Management devices above Inventory, Settings Management & Remote Wipe, like: Over the air enrollment & Software Distribution. Remote management on multiple platforms will be key here!

It's also possible to use Odessey's Athena to extend MDM functionality. More information about that can be found here: Symantec Athena Then the following functionality becomes available:
  • Live, remote control of devices in the field
  • Device software, application & patch provisioning & installation
  • Comprehensive software and hardware asset information
  • Location based data via GPS (current and bread crumb)
  • Detailed phone and messaging information and stats
  • Security to protect sensitive data (device lock & wipe)

In the Beta2 and RC releases available for download there isn't much to do on MDM functionality. Let's wait till ConfigMgr 2012 will be released (RTM or Final version) to see more of this.

More information about: System Center Mobile Device Manager
More information about: Mobile Device Management in Configuration Manager (2007)
More information about: Determine How to Manage Mobile Devices in Configuration Manager (2012)