Last week I did a proof of concept on Windows Intune v5 (5.0.2000.0) at customer location. During implementation I did the following experiences on functionality. Pity that Intune still is missing enterprise-ready functionality, but that will be better end of year. Have a look at the Intune roadmap for that. Let's have a look at the implementation experiences. It's not all bad :)
- Enrollment and retirement on Windows, Windows Phone, iOS and Android all goes fine (almost realtime), but sometimes retirement takes a lot of time. Microsoft is working on that to make it quicker. It can take up to 24 hours or 30 days total at the moment.
- When you want to have remote wipe functionality on notebooks (or tablets with Windows on it), just make usage of Windows 8.1. That way don't install the Intune agent, but enroll it as a mobile device. Very nice you can have remote wipe on notebooks either!
- When using Active Directory Federation Services (ADFS) there's single sign-on in place. Without ADFS you must fill-in account details every x minutes all over again. Really annoying if you ask me. Maybe DirSync will be a solution for this also. Does anyone know?
- Policies cannot be enforced from the Intune console. Sometimes it can take a while before the policy will be applied, even when you want a remote wipe on the device. Hope there will be a force button in a later release. When synchronize from the mobile device, policy is refreshed immediately. Strange, because you want to force a full wipe quick if your device is missing or stolen.
- Application blacklisting/whitelisting isn't available yet. You can set a deny on the app store (iOS 6+, Windows Phone 8.1) but there's no option to decide which apps may (not) be installed. This is on the roadmap for Q4 this year. Should be great if you can publish apps and app-links, without the need/permission to use the app store.
- Applications can be deployed optional only for users, no way to enforce the deployment. When IT support want to pre-config devices, you want bulk-enrollment for apps and policies, without to fill-in credentials on the app store (Microsoft, Apple, Google). This is on the roadmap for Q4 this year either. Fingers crossed :)
- The user stays in control of the device, and has the possibility to remove the Intune agent also. That way you're not in control of all devices anymore. Should be better if you can deny this I think? It depends if devices are personally or company owned. It would be great if you get an alert on this, that way you know if devices are missing.
I still think Windows Intune is (too) light in functionality, when Intune must be the successor of ConfigMgr, there's missing a lot. But..
Later this year there will be bulk enrollment, application blacklisting/ whitelisting, remote lock, secure mail, secure browser, Exchange and OneDrive for business, managed Office apps, app wrapper for iOS and Android, and multiple secure viewers.
Given the fact that the ConfigMgr team is same as the Intune team (and most resources are on Intune, because Microsoft still has a lot of catching up to do, and ConfigMgr is in a finished, almost perfect state), there will fast development on Intune for the next months.
Let's say it again: The future looks bright for Windows Intune!
A few months ago the Windows Intune roadmap was published during a Partner Session in February. There were some very interesting features announced, which will make Windows Intune way more advanced then in earlier versions. Because I'm doing a lot of implementation next coming months, it would be great when features are coming in soon. Let's have a look which features are announced during MS TechEd NA 2014.
As a cloud service, Windows Intune is updated on a regular basis, roughly every quarter. We’re currently rolling out an update to the Windows Intune service which provides support for Windows Phone 8.1 and Samsung KNOX Standard (formerly Samsung SAFE) support. In Q3, we will add support for Windows 8.1 Update settings specific to “family safety” which are useful for education environments.
In Q4, we’ll be releasing major new functionality specifically focused on managed mobile productivity (managed applications and data protection) and IT enhancements, including bulk enrollment and support for Apple Configurator.
Intune will support the ability to bulk enroll iOS and Android (no Windows Phone?) devices, and use a single Intune service account to enroll the devices instead of having separate IDs for each device, since they are not associated with a user each. For iOS, Intune will support Apple’s Device Enrollment Program to do this bulk enrollment.
Intune will also support the ability to configure iOS devices using the Apple Configurator tool, allowing more granular and enforced “lock down” policies through the iOS Supervisor mode. This is especially useful in education scenarios where the student should not be able to un-enroll the device or when more stringent management is required (sounds good!). Additional settings include the ability to allow or block a specific set of applications and URL addresses.
Microsoft’s approach is more natural – build manageability and data protection into the apps which people choose to use, and extend that capability for enterprises to use with their own apps. To do this, we will deliver a unique container solution that is different from the traditional containers offered by other mobile device management solutions on the market.
The future looks bright for Windows Intune!
Source: Windows Intune Team
This year the MS System Center 2012 Suite will be presented. There's nothing official to find about release dates, so my guess stays on Q1 2012 or probably Microsoft Management Summit (MMS) which is in April 16-20. The last months there were some interesting news around System Center, so here a quick overview.
Here we go:
- All products within the MS System Center 2012 Suite will have a new release (on the same time)
- There will be more integration within the various System Center products (because of Service Manager and Orchestrator)
- Service Manager will be the most important product in the 2012 suite (integration with Operations Manager [tickets], Configuration Manager [assets], and so on)
- Service Manager 2012 is the only version which integrates with Configuration Manager 2012, not the current one
- Forefront Endpoint Protection (FEP) will be called System Center Endpoint Protection (SCEP) from now on
- There will be integration between ConfigMgr and Orchestrator (checks and so on)
And some ConfigMgr 2012 news also:
- There will be Migration tools build-in to migrate applications, collections and OS images (and so on) by default
- With Package Conversion Manager (PCM) it's possible to convert old 2007 packages to the new 2012 application model
- Mobile Device Management (MDM) will have the same functionality as in Exchange 2010 (nothing more unfortunately)
- It's possible to simulate application deployments before they actually will be installed (isn't that cool?)
- Endpoint Protection will be integrated in ConfigMgr 2012 by default (no extension anymore)
- There will be (probably) e-mail notification in Software Catalog approvals (not in the console only)
It will be an exciting year with new products/functionality, and finally a brand new MS System Center 2012 Suite!
During TechEd North America 2011 Atlanta, the System Center Roadmap for 2012 is presented. As you can see all products from this suite become RTM at second half of 2011. About end 2011 or begin 2012 the complete suite will be presented as System Center 2012 suite.
New products shown in this Roadmap are:
Where Codename "Concero" manage both on-premise and in the cloud, System Center Advisor (and Windows InTune) manage solutions that literally works from the cloud (Software as a Service).
It will be an exciting year with new Beta's, RC & RTM releases, and finally a brand new System Center 2012 suite!
During Microsoft Management Summit 2011 the System Center Roadmap 2011-2012 is presented. As you can see all products from this suite become RTM at second half of 2011. About end 2011 or begin 2012 the complete suite will be presented as System Center 2012 suite.
New products shown in this Roadmap are:
- Orchestrator (formerly known as Opalis; provides automation of processes and workflows between the various System Center products)
- Advisor (analyzing configurations of systems according to best practices and experiences from the Premier Support field. This application is offered by Microsoft from the cloud)
- Codename "Concero" (allows customers to deploy applications and services; manage private clouds with SCVMM 2012, and public clouds with Windows Azure)
- Windows Intune (PC Management and protection from the cloud)
Where "Concero" manage both on-premise and in the cloud, Advisor and Windows InTune manage solutions that literally works from the cloud (Software as a Service).
It will be an exciting year with new Beta's, RC & RTM releases, and finally a brand new System Center 2012 suite!