SlideShare a Scribd company logo
Microsoft InTune
@directorcia
http://about.me/ciaops
Mobile application
management
PC managementMobile device
management
Intune helps organizations provide their employees with access to corporate applications, data, and
resources from virtually anywhere on almost any device, while helping to keep corporate information secure.
User IT
Mobile devices and PCs Mobile devices
System Center
Configuration
Manager
Domain joined PCs
Configuration Manager integrated with Intune (hybrid)Intune standalone (cloud only)
IT IT
Intune web console Configuration Manager console
Consistent experience across:
Discover and install corporate apps
Manage devices and data
Ability to contact IT
Customizable terms and conditions
Configuration Manager console (hybrid)Intune web console (cloud only)
β€’
β€’
β€’
β€’
β€’
β€’
Microsoft Cloud Device Management comparisions
Device
Management
Microsoft IntuneBuilt-InBuilt-in Microsoft Intune
Conditional
Access
Selective
Wipe
LoB
app
Microsoft Cloud Device Management comparisions
β€’Mobile Device Management
β€’ Deploy certificates, WiFi, VPN, and email profiles automatically
once a device is enrolled
β€’Mobile Application Management
β€’ Provide the ability to deny specific applications or URL addresses
from being accessed on mobile devices
β€’PC Management
β€’ Simplify administration by deploying software and configuring
Windows Firewall settings on computers based upon policies
defined by the administrator
Office 365 MDM
Category Feature
Exchange
ActiveSync
MDM for
Office 365
Intune
Standalone
Intune +
ConfigMgr
(Hybrid)
Device
configuration
Inventory mobile devices that access corporate applications ● ● ● ●
Remote factory reset (full device wipe) ● ● ● ●
Mobile device configuration settings (PIN length, PIN required, lock time, etc.) ● ● ● ●
Self-service password reset (Office 365 cloud only users) ● ● ● ●
Office365
Provides reporting on devices that do not meet IT policy ● ● ●
Group-based policies and reporting (ability to use groups for targeted device configuration) ● ● ●
Root cert and jailbreak detection ● ● ●
Remove Office 365 app data from mobile devices while leaving personal data and apps intact (selective wipe) ● ● ●
Prevent access to corporate email and documents based upon device enrollment and compliance policies ● ● ●
Premium
mobiledevice&
appmanagement
Self-service Company Portal for users to enroll their own devices and install corporate apps ● ●
App deployment (Windows Phone, iOS, Android) ● ●
Deploy certificates, VPN profiles (including app-specific profiles), email profiles, and Wi-Fi profiles ● ◐
Prevent cut/copy/paste/save as of data from corporate apps to personal apps (mobile application management) ● ●
Secure content viewing via Managed browser, PDF viewer, Imager viewer, and AV player apps for Intune ● ●
Remote device lock via self-service Company Portal and via admin console ● ●
PC
Management
Client PC management (e.g. Windows 8.1, inventory, antimalware, patch, policies, etc.) ● ●
PC software management ● ●
Comprehensive PC management (e.g. Windows Server/Linux/Mac OS X support, virtual desktop and power
management, custom reporting, etc.)
●
OS deployment ●
Single management console for PCs, Windows Server/Linux/Mac OS X, and mobile devices ●
β€’ Ability to apply security policies
β€’ Selective wipe of Office 365 data
β€’ Familiar user experience
β€’ Included with all Office 365 commercial subscriptions,
including Business, Enterprise, EDU and Government plans
Windows Phone 8.1 iOS 7.1+ Android 4+
Exchange
Exchange ActiveSync
includes native email and
third-party apps, like
TouchDown, that use
Exchange ActiveSync.
Exchange ActiveSync
Exchange Mail
Exchange ActiveSync
Mail
Exchange ActiveSync
Email
Office and OneDrive for
Business
No supported apps
Outlook
OneDrive
Word
Excel
PowerPoint
On phones and tablets:
Outlook
OneDrive
Word
Excel
PowerPoint
On phones only:
Office Mobile
https://technet.microsoft.com/library/ms.o365.cc.devicepolicysupporteddevice.aspx
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
http://blog.ciaops.com/2015/05/mobile-device-management-has-arrived.html
β€’ Now set the device policies
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Note – Policies apply to security groups
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Personal apps
Managed apps Company Portal
Are you sure you want to wipe
corporate data and applications
from the user’s device?
OK Cancel
Perform selective wipe via self-service company portal or admin console
Remove managed apps and data
Keep personal apps and data intact
ITIT
β€’Conditional Access : You can set up security policies on
devices that connect to Office 365 to ensure that Office 365
corporate email and documents can be accessed only on phones
and tablets that are managed by your company and are compliant.
β€’Device management : You can set and manage security
policies such as device-level pin lock and jailbreak detection to help
prevent unauthorized users from accessing corporate email and
data on a device when it is lost or stolen.
β€’Selective wipe : You can easily remove Office 365 company
data from an employee’s device while leaving their personal data in
place.
Intune Device and
Application Management
Category Feature
Exchange
ActiveSync
MDM for
Office 365
Intune
Standalone
Intune +
ConfigMgr
(Hybrid)
Device
configuration
Inventory mobile devices that access corporate applications ● ● ● ●
Remote factory reset (full device wipe) ● ● ● ●
Mobile device configuration settings (PIN length, PIN required, lock time, etc.) ● ● ● ●
Self-service password reset (Office 365 cloud only users) ● ● ● ●
Office365
Provides reporting on devices that do not meet IT policy ● ● ●
Group-based policies and reporting (ability to use groups for targeted device configuration) ● ● ●
Root cert and jailbreak detection ● ● ●
Remove Office 365 app data from mobile devices while leaving personal data and apps intact (selective wipe) ● ● ●
Prevent access to corporate email and documents based upon device enrollment and compliance policies ● ● ●
Premium
mobiledevice&
appmanagement
Self-service Company Portal for users to enroll their own devices and install corporate apps ● ●
App deployment (Windows Phone, iOS, Android) ● ●
Deploy certificates, VPN profiles (including app-specific profiles), email profiles, and Wi-Fi profiles ● ◐
Prevent cut/copy/paste/save as of data from corporate apps to personal apps (mobile application management) ● ●
Secure content viewing via Managed browser, PDF viewer, Imager viewer, and AV player apps for Intune ● ●
Remote device lock via self-service Company Portal and via admin console ● ●
PC
Management
Client PC management (e.g. Windows 8.1, inventory, antimalware, patch, policies, etc.) ● ●
PC software management ● ●
Comprehensive PC management (e.g. Windows Server/Linux/Mac OS X support, virtual desktop and power
management, custom reporting, etc.)
●
OS deployment ●
Single management console for PCs, Windows Server/Linux/Mac OS X, and mobile devices ●
Enroll
β€’ Provide a self-service Company
Portal for users to enroll devices
β€’ Deliver custom terms and
conditions at enrollment
β€’ Bulk enroll devices using Apple
Configurator or service account
β€’ Restrict access to Exchange
email if a device is not enrolled
Retire
β€’ Revoke access to corporate
resources
β€’ Perform selective wipe
β€’ Audit lost and stolen devices
Provision
β€’ Deploy certificates, email, VPN,
and WiFi profiles
β€’ Deploy device security policy
settings
β€’ Install mandatory apps
β€’ Deploy app restriction policies
β€’ Deploy data protection policies
Manage and Protect
β€’ Restrict access to corporate
resources if policies are violated
(e.g., jailbroken device)
β€’ Protect corporate data by
restricting actions such as
copy/cut/paste/save outside of
managed app ecosystem
β€’ Report on device and app
compliance
User IT
Manage and Protect
β€’ No existing infrastructure necessary
β€’ No existing Configuration Manager
deployment required
β€’ Simplified policy control
β€’ Simple web-based administration console
β€’ Faster cadence of updates
β€’ Always up-to-date
Devices Supported
β€’ Windows PCs (x86/64, Intel SoC)
β€’ Windows RT
β€’ Windows Phone 8.x
β€’ iOS
β€’ Android
Mobile devices and PCs
Intune standalone (cloud only)
IT
Intune web console
System Center 2012 R2 Configuration
Manager with Microsoft Intune
β€’ Build on existing Configuration Manager
deployment
β€’ Full PC management (OS deployment, endpoint
protection, application delivery control, custom
reporting)
β€’ Deep policy control requirements
β€’ Greater scalability
β€’ Extensible administration tools (RBA, PowerShell,
SQL reporting services)
Devices Supported
β€’ Windows PCs
(x86/64, Intel SoC)
β€’ Windows to Go
β€’ Windows Server
β€’ Linux
β€’ Mac OS X
β€’ Windows RT
β€’ Windows Phone 8.x
β€’ iOS
β€’ Android
Mobile devices
System Center
Configuration
Manager
Domain joined PCs
Configuration Manager integrated with Intune (hybrid)
IT
Configuration Manager console
Intune standalone (cloud only)
Lightweight, agentless OR agent-based management
PC protection from malware
PC software update management
Software distribution
Proactive monitoring and alerts
Hardware and software inventory
Policies for Windows Firewall management
Intune standalone (cloud only) Configuration Manager integrated with Intune (hybrid)
Lightweight, agentless OR agent-based management Agent-based management only
PC protection from malware PC protection from malware
PC software update management PC software update management
Software distribution Software distribution
Proactive monitoring and alerts Proactive monitoring and alerts
Hardware and software inventory Hardware and software inventory
Policies for Windows Firewall management Policies for Windows Firewall management
Operating system deployment
PC, mobile device, Windows Server, Linux/Unix, Mac, and virtual desktop management
Power management
Custom reporting
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Microsoft Cloud Device Management comparisions
Intune Policies
Category Feature
Exchange
ActiveSync
MDM for
Office 365
Intune
Standalone
Intune +
ConfigMgr
(Hybrid)
Device
configuration
Inventory mobile devices that access corporate applications ● ● ● ●
Remote factory reset (full device wipe) ● ● ● ●
Mobile device configuration settings (PIN length, PIN required, lock time, etc.) ● ● ● ●
Self-service password reset (Office 365 cloud only users) ● ● ● ●
Office365
Provides reporting on devices that do not meet IT policy ● ● ●
Group-based policies and reporting (ability to use groups for targeted device configuration) ● ● ●
Root cert and jailbreak detection ● ● ●
Remove Office 365 app data from mobile devices while leaving personal data and apps intact (selective wipe) ● ● ●
Prevent access to corporate email and documents based upon device enrollment and compliance policies ● ● ●
Premium
mobiledevice&
appmanagement
Self-service Company Portal for users to enroll their own devices and install corporate apps ● ●
App deployment (Windows Phone, iOS, Android) ● ●
Deploy certificates, VPN profiles (including app-specific profiles), email profiles, and Wi-Fi profiles ● ◐
Prevent cut/copy/paste/save as of data from corporate apps to personal apps (mobile application management) ● ●
Secure content viewing via Managed browser, PDF viewer, Imager viewer, and AV player apps for Intune ● ●
Remote device lock via self-service Company Portal and via admin console ● ●
PC
Management
Client PC management (e.g. Windows 8.1, inventory, antimalware, patch, policies, etc.) ● ●
PC software management ● ●
Comprehensive PC management (e.g. Windows Server/Linux/Mac OS X support, virtual desktop and power
management, custom reporting, etc.)
●
OS deployment ●
Single management console for PCs, Windows Server/Linux/Mac OS X, and mobile devices ●
β€’
β€’
β€’
β€’ List of complete settings
β€’
β€’ OMA-URI Settings
β€’ Configurator Profile
β€’ OMA-URI Settings
β€’ OMA-URI Settings
β€’
If compliant,
email access is
granted
7
Enrollment /
compliance
remediation
5
If not compliant,
push device into
quarantine
Quarantine
4
2
Quarantine email with
remediation steps
Link to enroll device
and compliance
remediation steps
Who does what?
Intune: Evaluate policy
compliance for device
Azure AD: Authenticate
user and provide device
compliance status
Exchange Online:
Enforces access to email
based on device state
Attempt
email
connection
1
3
Azure
Active Directory
Set device
management/
compliance
status
6
Office 365
Mobile device
Microsoft Intune
Personal apps
Managed apps
Maximize productivity while preventing leakage of company
data by restricting actions such as copy/cut/paste/save in
your managed app ecosystem
User
Enforce corporate data
access requirements
Prevent data leakage
on the device
Enforce encryption
of app data at rest
App-level
selective wipe
PC Management
Category Feature
Exchange
ActiveSync
MDM for
Office 365
Intune
Standalone
Intune +
ConfigMgr
(Hybrid)
Device
configuration
Inventory mobile devices that access corporate applications ● ● ● ●
Remote factory reset (full device wipe) ● ● ● ●
Mobile device configuration settings (PIN length, PIN required, lock time, etc.) ● ● ● ●
Self-service password reset (Office 365 cloud only users) ● ● ● ●
Office365
Provides reporting on devices that do not meet IT policy ● ● ●
Group-based policies and reporting (ability to use groups for targeted device configuration) ● ● ●
Root cert and jailbreak detection ● ● ●
Remove Office 365 app data from mobile devices while leaving personal data and apps intact (selective wipe) ● ● ●
Prevent access to corporate email and documents based upon device enrollment and compliance policies ● ● ●
Premium
mobiledevice&
appmanagement
Self-service Company Portal for users to enroll their own devices and install corporate apps ● ●
App deployment (Windows Phone, iOS, Android) ● ●
Deploy certificates, VPN profiles (including app-specific profiles), email profiles, and Wi-Fi profiles ● ◐
Prevent cut/copy/paste/save as of data from corporate apps to personal apps (mobile application management) ● ●
Secure content viewing via Managed browser, PDF viewer, Imager viewer, and AV player apps for Intune ● ●
Remote device lock via self-service Company Portal and via admin console ● ●
PC
Management
Client PC management (e.g. Windows 8.1, inventory, antimalware, patch, policies, etc.) ● ●
PC software management ● ●
Comprehensive PC management (e.g. Windows Server/Linux/Mac OS X support, virtual desktop and power
management, custom reporting, etc.)
●
OS deployment ●
Single management console for PCs, Windows Server/Linux/Mac OS X, and mobile devices ●
Resources
β€’ MDM in Office 365 overview - https://technet.microsoft.com/en-
US/library/ms.o365.cc.DevicePolicy.aspx
β€’ Different ways to manage devices with InTune -
https://technet.microsoft.com/library/dn957912.aspx
β€’ Capabilities of Office 365 MDM –
https://technet.microsoft.com/library/ms.o365.cc.devicepolicysupporteddevice.aspx
β€’ Manage mobile devices in Office 365 – https://support.office.com/en-
us/article/Manage-mobile-devices-in-Office-365-dd892318-bc44-4eb1-af00-9db5430be3cd
β€’ EMS now available without Enterprise Agreement -
http://blogs.technet.com/b/ad/archive/2015/03/12/azure-ad-and-enterprise-mobility-suite-
now-broadly-available-outside-of-an-enterprise-agreement.aspx
β€’ Microsoft Intune features - http://www.microsoft.com/en-au/server-
cloud/products/microsoft-intune/features.aspx
CIAOPS Resources
β€’ Blog – http://blog.ciaops.com
β€’ Free SharePoint Training via email – http://bit.ly/gs-spo
β€’ Free Office 365, Azure Administration newsletter – http://bit.ly/o365-tech
β€’ Free Office 365, Azure video tutorials – http://www.youtube.com/directorciaops
β€’ Free documents, presentations, eBooks – http://docs.com/ciaops
β€’ Office 365, Azure, Cloud podcast – http://ciaops.podbean.com
β€’ Office 365, Azure online training courses – http://www.ciaopsacademy.com
β€’ Office 365, Azure eBooks – http://www.ciaops.com/publications
Twitter
@directorcia
Facebook
https://www.facebook.com/ciaops
Email
director@ciaops.com
Skype for Business
admin@ciaops365.com

More Related Content

PDF
Microsoft Intune - Global Azure Bootcamp 2018
PDF
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
PPTX
Managing iOS with Microsoft Intune
PPTX
Enterprise Mobility Suite-Microsoft Intune
PDF
Microsoft Enterprise Mobility Suite Presented by Atidan
PPTX
Microsoft Enterprise Mobility Suite | Getting started....
PPTX
EPC Group Intune Practice and Capabilities Overview
PDF
Microsoft Windows Intune getting started guide dec 2012 release
Microsoft Intune - Global Azure Bootcamp 2018
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
Managing iOS with Microsoft Intune
Enterprise Mobility Suite-Microsoft Intune
Microsoft Enterprise Mobility Suite Presented by Atidan
Microsoft Enterprise Mobility Suite | Getting started....
EPC Group Intune Practice and Capabilities Overview
Microsoft Windows Intune getting started guide dec 2012 release

What's hot (20)

PPTX
Enterprise Mobility Suite- Introduction
PDF
Windows Intune webinar
Β 
PDF
Microsoft intune with managed apps and security device policies - Sascha Fred...
PDF
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
PDF
Mobile Device Management for Office 365 - Atidan
PPTX
Getting started with the Enterprise Mobility Suite (EMS)
PDF
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
PPTX
Enterprise Mobility Suite- Azure RMS
PPTX
Enterprise Mobility Suite- Azure AD Premium
PDF
Windows 10 Enterprise E3 - Best in Class Security and Control - Presented by ...
PPTX
Office 365 Mobile Device Management: What Is It, and Why Should You Care - Pa...
PPTX
MDM - airwatch
PDF
[Brochure ] mobi manager mdm_software
PPTX
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
PDF
Get Ahead of Cyber Attacks with Microsoft Enterprise Mobility + Security
PDF
Enterprise Mobility (Admin)
PPTX
Preparing for Mobile Device Management & Bring your Own Device
PDF
Airwatch od VMware
PDF
Mobile Device Management for Dummies
PPTX
Gerenciamento de dispositivos mΓ³veis com Intune e SCCM
Enterprise Mobility Suite- Introduction
Windows Intune webinar
Β 
Microsoft intune with managed apps and security device policies - Sascha Fred...
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
Mobile Device Management for Office 365 - Atidan
Getting started with the Enterprise Mobility Suite (EMS)
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
Enterprise Mobility Suite- Azure RMS
Enterprise Mobility Suite- Azure AD Premium
Windows 10 Enterprise E3 - Best in Class Security and Control - Presented by ...
Office 365 Mobile Device Management: What Is It, and Why Should You Care - Pa...
MDM - airwatch
[Brochure ] mobi manager mdm_software
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Get Ahead of Cyber Attacks with Microsoft Enterprise Mobility + Security
Enterprise Mobility (Admin)
Preparing for Mobile Device Management & Bring your Own Device
Airwatch od VMware
Mobile Device Management for Dummies
Gerenciamento de dispositivos mΓ³veis com Intune e SCCM
Ad

Similar to Microsoft Cloud Device Management comparisions (20)

PPTX
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...
PDF
July 2018 Azure Need to Know Webinar
PPTX
Intune_DSEP. traininf for mam and mbam a
PPTX
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
PPTX
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
PDF
#EVRYWhatsNext EMS Slide Deck
PPTX
Microsoft Intune Deployment Guide to align
PPTX
Mobile device management and BYOD – simple changes, big benefits
PPTX
Device Management via Intune : Balancing Security and Flexibility
PDF
Management of all the devices using Microsoft 365 Business
PPTX
Understand_device_management_using_Microsoft_Intune_(1)[1].pptx
PPTX
Primend Pilvekonverents - Mobiilne ettevΓ΅te mobiilsete andmetega
PDF
What's your BYOD Strategy? Objectives and tips from Microsoft & Aptera
PDF
Microsoft Intune Pricing and Licensing Options
PPTX
Security Beyond the Firewall
PPTX
Managed Intune Service Safeguarding Company's Devices Efficiently
PDF
MMS 2015: What is ems and how to configure it
PDF
Microsoft Intune Device Management | Techom Systems
PPTX
Managed Intune Service Protecting Your Business Data.pptx
PDF
Atea erfa microsoft mobile security
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...
July 2018 Azure Need to Know Webinar
Intune_DSEP. traininf for mam and mbam a
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
#EVRYWhatsNext EMS Slide Deck
Microsoft Intune Deployment Guide to align
Mobile device management and BYOD – simple changes, big benefits
Device Management via Intune : Balancing Security and Flexibility
Management of all the devices using Microsoft 365 Business
Understand_device_management_using_Microsoft_Intune_(1)[1].pptx
Primend Pilvekonverents - Mobiilne ettevΓ΅te mobiilsete andmetega
What's your BYOD Strategy? Objectives and tips from Microsoft & Aptera
Microsoft Intune Pricing and Licensing Options
Security Beyond the Firewall
Managed Intune Service Safeguarding Company's Devices Efficiently
MMS 2015: What is ems and how to configure it
Microsoft Intune Device Management | Techom Systems
Managed Intune Service Protecting Your Business Data.pptx
Atea erfa microsoft mobile security
Ad

More from Robert Crane (20)

PDF
202310
PDF
September 2023 CIAOPS Need to Know Webinar
PDF
August 2023 CIAOPS Need to Know Webinar
PDF
July 2023 CIAOPS Need to Know Webinar
PDF
June 2023 CIAOPS Need to Know Webinar
PDF
May 2023 CIAOPS Need to Know Webinar
PDF
April 2023 CIAOPS Need to Know Webinar
PDF
March 2023 CIAOPS Need to Know Webinar
PDF
January 2023 CIAOPS Need to Know Webinar
PDF
December 2022 CIAOPS Need to Know Webinar
PDF
November 2022 CIAOPS Need to Know Webinar
PDF
October 2022 CIAOPS Need to Know Webinar
PDF
September 2022 CIAOPS Need to Know Webinar
PDF
August 2022 CIAOPS Need to Know Webinar
PDF
July 2022 CIAOPS Need to Know Webinar
PDF
June 2022 CIAOPS Need to Know Webinar
PDF
May 2022 CIAOPS Need to Know Webinar
PDF
April 2022 CIAOPS Need to Know Webinar
PDF
An introduction to Defender for Business
PDF
March 2022 CIAOPS Need to Know Webinar
202310
September 2023 CIAOPS Need to Know Webinar
August 2023 CIAOPS Need to Know Webinar
July 2023 CIAOPS Need to Know Webinar
June 2023 CIAOPS Need to Know Webinar
May 2023 CIAOPS Need to Know Webinar
April 2023 CIAOPS Need to Know Webinar
March 2023 CIAOPS Need to Know Webinar
January 2023 CIAOPS Need to Know Webinar
December 2022 CIAOPS Need to Know Webinar
November 2022 CIAOPS Need to Know Webinar
October 2022 CIAOPS Need to Know Webinar
September 2022 CIAOPS Need to Know Webinar
August 2022 CIAOPS Need to Know Webinar
July 2022 CIAOPS Need to Know Webinar
June 2022 CIAOPS Need to Know Webinar
May 2022 CIAOPS Need to Know Webinar
April 2022 CIAOPS Need to Know Webinar
An introduction to Defender for Business
March 2022 CIAOPS Need to Know Webinar

Recently uploaded (20)

PPTX
PptxGenJS_Demo_Chart_20250317130215833.pptx
DOCX
Unit-3 cyber security network security of internet system
PDF
Tenda Login Guide: Access Your Router in 5 Easy Steps
PPTX
presentation_pfe-universite-molay-seltan.pptx
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PDF
WebRTC in SignalWire - troubleshooting media negotiation
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PPTX
INTERNET------BASICS-------UPDATED PPT PRESENTATION
PPTX
introduction about ICD -10 & ICD-11 ppt.pptx
PDF
Unit-1 introduction to cyber security discuss about how to secure a system
PDF
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
PDF
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
PPTX
SAP Ariba Sourcing PPT for learning material
PDF
Triggering QUIC, presented by Geoff Huston at IETF 123
Β 
PDF
Testing WebRTC applications at scale.pdf
PDF
Slides PDF The World Game (s) Eco Economic Epochs.pdf
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
Β 
PPTX
artificial intelligence overview of it and more
PDF
An introduction to the IFRS (ISSB) Stndards.pdf
PPTX
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
PptxGenJS_Demo_Chart_20250317130215833.pptx
Unit-3 cyber security network security of internet system
Tenda Login Guide: Access Your Router in 5 Easy Steps
presentation_pfe-universite-molay-seltan.pptx
Job_Card_System_Styled_lorem_ipsum_.pptx
WebRTC in SignalWire - troubleshooting media negotiation
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
INTERNET------BASICS-------UPDATED PPT PRESENTATION
introduction about ICD -10 & ICD-11 ppt.pptx
Unit-1 introduction to cyber security discuss about how to secure a system
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
SAP Ariba Sourcing PPT for learning material
Triggering QUIC, presented by Geoff Huston at IETF 123
Β 
Testing WebRTC applications at scale.pdf
Slides PDF The World Game (s) Eco Economic Epochs.pdf
RPKI Status Update, presented by Makito Lay at IDNOG 10
Β 
artificial intelligence overview of it and more
An introduction to the IFRS (ISSB) Stndards.pdf
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION

Microsoft Cloud Device Management comparisions

  • 2. Mobile application management PC managementMobile device management Intune helps organizations provide their employees with access to corporate applications, data, and resources from virtually anywhere on almost any device, while helping to keep corporate information secure. User IT
  • 3. Mobile devices and PCs Mobile devices System Center Configuration Manager Domain joined PCs Configuration Manager integrated with Intune (hybrid)Intune standalone (cloud only) IT IT Intune web console Configuration Manager console
  • 4. Consistent experience across: Discover and install corporate apps Manage devices and data Ability to contact IT Customizable terms and conditions
  • 5. Configuration Manager console (hybrid)Intune web console (cloud only)
  • 8. Device Management Microsoft IntuneBuilt-InBuilt-in Microsoft Intune Conditional Access Selective Wipe LoB app
  • 10. β€’Mobile Device Management β€’ Deploy certificates, WiFi, VPN, and email profiles automatically once a device is enrolled β€’Mobile Application Management β€’ Provide the ability to deny specific applications or URL addresses from being accessed on mobile devices β€’PC Management β€’ Simplify administration by deploying software and configuring Windows Firewall settings on computers based upon policies defined by the administrator
  • 12. Category Feature Exchange ActiveSync MDM for Office 365 Intune Standalone Intune + ConfigMgr (Hybrid) Device configuration Inventory mobile devices that access corporate applications ● ● ● ● Remote factory reset (full device wipe) ● ● ● ● Mobile device configuration settings (PIN length, PIN required, lock time, etc.) ● ● ● ● Self-service password reset (Office 365 cloud only users) ● ● ● ● Office365 Provides reporting on devices that do not meet IT policy ● ● ● Group-based policies and reporting (ability to use groups for targeted device configuration) ● ● ● Root cert and jailbreak detection ● ● ● Remove Office 365 app data from mobile devices while leaving personal data and apps intact (selective wipe) ● ● ● Prevent access to corporate email and documents based upon device enrollment and compliance policies ● ● ● Premium mobiledevice& appmanagement Self-service Company Portal for users to enroll their own devices and install corporate apps ● ● App deployment (Windows Phone, iOS, Android) ● ● Deploy certificates, VPN profiles (including app-specific profiles), email profiles, and Wi-Fi profiles ● ◐ Prevent cut/copy/paste/save as of data from corporate apps to personal apps (mobile application management) ● ● Secure content viewing via Managed browser, PDF viewer, Imager viewer, and AV player apps for Intune ● ● Remote device lock via self-service Company Portal and via admin console ● ● PC Management Client PC management (e.g. Windows 8.1, inventory, antimalware, patch, policies, etc.) ● ● PC software management ● ● Comprehensive PC management (e.g. Windows Server/Linux/Mac OS X support, virtual desktop and power management, custom reporting, etc.) ● OS deployment ● Single management console for PCs, Windows Server/Linux/Mac OS X, and mobile devices ●
  • 13. β€’ Ability to apply security policies β€’ Selective wipe of Office 365 data β€’ Familiar user experience β€’ Included with all Office 365 commercial subscriptions, including Business, Enterprise, EDU and Government plans
  • 14. Windows Phone 8.1 iOS 7.1+ Android 4+ Exchange Exchange ActiveSync includes native email and third-party apps, like TouchDown, that use Exchange ActiveSync. Exchange ActiveSync Exchange Mail Exchange ActiveSync Mail Exchange ActiveSync Email Office and OneDrive for Business No supported apps Outlook OneDrive Word Excel PowerPoint On phones and tablets: Outlook OneDrive Word Excel PowerPoint On phones only: Office Mobile https://technet.microsoft.com/library/ms.o365.cc.devicepolicysupporteddevice.aspx
  • 18. β€’ Now set the device policies
  • 21. Note – Policies apply to security groups
  • 24. Personal apps Managed apps Company Portal Are you sure you want to wipe corporate data and applications from the user’s device? OK Cancel Perform selective wipe via self-service company portal or admin console Remove managed apps and data Keep personal apps and data intact ITIT
  • 25. β€’Conditional Access : You can set up security policies on devices that connect to Office 365 to ensure that Office 365 corporate email and documents can be accessed only on phones and tablets that are managed by your company and are compliant. β€’Device management : You can set and manage security policies such as device-level pin lock and jailbreak detection to help prevent unauthorized users from accessing corporate email and data on a device when it is lost or stolen. β€’Selective wipe : You can easily remove Office 365 company data from an employee’s device while leaving their personal data in place.
  • 27. Category Feature Exchange ActiveSync MDM for Office 365 Intune Standalone Intune + ConfigMgr (Hybrid) Device configuration Inventory mobile devices that access corporate applications ● ● ● ● Remote factory reset (full device wipe) ● ● ● ● Mobile device configuration settings (PIN length, PIN required, lock time, etc.) ● ● ● ● Self-service password reset (Office 365 cloud only users) ● ● ● ● Office365 Provides reporting on devices that do not meet IT policy ● ● ● Group-based policies and reporting (ability to use groups for targeted device configuration) ● ● ● Root cert and jailbreak detection ● ● ● Remove Office 365 app data from mobile devices while leaving personal data and apps intact (selective wipe) ● ● ● Prevent access to corporate email and documents based upon device enrollment and compliance policies ● ● ● Premium mobiledevice& appmanagement Self-service Company Portal for users to enroll their own devices and install corporate apps ● ● App deployment (Windows Phone, iOS, Android) ● ● Deploy certificates, VPN profiles (including app-specific profiles), email profiles, and Wi-Fi profiles ● ◐ Prevent cut/copy/paste/save as of data from corporate apps to personal apps (mobile application management) ● ● Secure content viewing via Managed browser, PDF viewer, Imager viewer, and AV player apps for Intune ● ● Remote device lock via self-service Company Portal and via admin console ● ● PC Management Client PC management (e.g. Windows 8.1, inventory, antimalware, patch, policies, etc.) ● ● PC software management ● ● Comprehensive PC management (e.g. Windows Server/Linux/Mac OS X support, virtual desktop and power management, custom reporting, etc.) ● OS deployment ● Single management console for PCs, Windows Server/Linux/Mac OS X, and mobile devices ●
  • 28. Enroll β€’ Provide a self-service Company Portal for users to enroll devices β€’ Deliver custom terms and conditions at enrollment β€’ Bulk enroll devices using Apple Configurator or service account β€’ Restrict access to Exchange email if a device is not enrolled Retire β€’ Revoke access to corporate resources β€’ Perform selective wipe β€’ Audit lost and stolen devices Provision β€’ Deploy certificates, email, VPN, and WiFi profiles β€’ Deploy device security policy settings β€’ Install mandatory apps β€’ Deploy app restriction policies β€’ Deploy data protection policies Manage and Protect β€’ Restrict access to corporate resources if policies are violated (e.g., jailbroken device) β€’ Protect corporate data by restricting actions such as copy/cut/paste/save outside of managed app ecosystem β€’ Report on device and app compliance User IT
  • 29. Manage and Protect β€’ No existing infrastructure necessary β€’ No existing Configuration Manager deployment required β€’ Simplified policy control β€’ Simple web-based administration console β€’ Faster cadence of updates β€’ Always up-to-date Devices Supported β€’ Windows PCs (x86/64, Intel SoC) β€’ Windows RT β€’ Windows Phone 8.x β€’ iOS β€’ Android Mobile devices and PCs Intune standalone (cloud only) IT Intune web console
  • 30. System Center 2012 R2 Configuration Manager with Microsoft Intune β€’ Build on existing Configuration Manager deployment β€’ Full PC management (OS deployment, endpoint protection, application delivery control, custom reporting) β€’ Deep policy control requirements β€’ Greater scalability β€’ Extensible administration tools (RBA, PowerShell, SQL reporting services) Devices Supported β€’ Windows PCs (x86/64, Intel SoC) β€’ Windows to Go β€’ Windows Server β€’ Linux β€’ Mac OS X β€’ Windows RT β€’ Windows Phone 8.x β€’ iOS β€’ Android Mobile devices System Center Configuration Manager Domain joined PCs Configuration Manager integrated with Intune (hybrid) IT Configuration Manager console
  • 31. Intune standalone (cloud only) Lightweight, agentless OR agent-based management PC protection from malware PC software update management Software distribution Proactive monitoring and alerts Hardware and software inventory Policies for Windows Firewall management Intune standalone (cloud only) Configuration Manager integrated with Intune (hybrid) Lightweight, agentless OR agent-based management Agent-based management only PC protection from malware PC protection from malware PC software update management PC software update management Software distribution Software distribution Proactive monitoring and alerts Proactive monitoring and alerts Hardware and software inventory Hardware and software inventory Policies for Windows Firewall management Policies for Windows Firewall management Operating system deployment PC, mobile device, Windows Server, Linux/Unix, Mac, and virtual desktop management Power management Custom reporting
  • 64. Category Feature Exchange ActiveSync MDM for Office 365 Intune Standalone Intune + ConfigMgr (Hybrid) Device configuration Inventory mobile devices that access corporate applications ● ● ● ● Remote factory reset (full device wipe) ● ● ● ● Mobile device configuration settings (PIN length, PIN required, lock time, etc.) ● ● ● ● Self-service password reset (Office 365 cloud only users) ● ● ● ● Office365 Provides reporting on devices that do not meet IT policy ● ● ● Group-based policies and reporting (ability to use groups for targeted device configuration) ● ● ● Root cert and jailbreak detection ● ● ● Remove Office 365 app data from mobile devices while leaving personal data and apps intact (selective wipe) ● ● ● Prevent access to corporate email and documents based upon device enrollment and compliance policies ● ● ● Premium mobiledevice& appmanagement Self-service Company Portal for users to enroll their own devices and install corporate apps ● ● App deployment (Windows Phone, iOS, Android) ● ● Deploy certificates, VPN profiles (including app-specific profiles), email profiles, and Wi-Fi profiles ● ◐ Prevent cut/copy/paste/save as of data from corporate apps to personal apps (mobile application management) ● ● Secure content viewing via Managed browser, PDF viewer, Imager viewer, and AV player apps for Intune ● ● Remote device lock via self-service Company Portal and via admin console ● ● PC Management Client PC management (e.g. Windows 8.1, inventory, antimalware, patch, policies, etc.) ● ● PC software management ● ● Comprehensive PC management (e.g. Windows Server/Linux/Mac OS X support, virtual desktop and power management, custom reporting, etc.) ● OS deployment ● Single management console for PCs, Windows Server/Linux/Mac OS X, and mobile devices ●
  • 65. β€’ β€’ β€’ β€’ List of complete settings β€’ β€’ OMA-URI Settings β€’ Configurator Profile β€’ OMA-URI Settings β€’ OMA-URI Settings β€’
  • 66. If compliant, email access is granted 7 Enrollment / compliance remediation 5 If not compliant, push device into quarantine Quarantine 4 2 Quarantine email with remediation steps Link to enroll device and compliance remediation steps Who does what? Intune: Evaluate policy compliance for device Azure AD: Authenticate user and provide device compliance status Exchange Online: Enforces access to email based on device state Attempt email connection 1 3 Azure Active Directory Set device management/ compliance status 6 Office 365 Mobile device Microsoft Intune
  • 67. Personal apps Managed apps Maximize productivity while preventing leakage of company data by restricting actions such as copy/cut/paste/save in your managed app ecosystem User
  • 68. Enforce corporate data access requirements Prevent data leakage on the device Enforce encryption of app data at rest App-level selective wipe
  • 70. Category Feature Exchange ActiveSync MDM for Office 365 Intune Standalone Intune + ConfigMgr (Hybrid) Device configuration Inventory mobile devices that access corporate applications ● ● ● ● Remote factory reset (full device wipe) ● ● ● ● Mobile device configuration settings (PIN length, PIN required, lock time, etc.) ● ● ● ● Self-service password reset (Office 365 cloud only users) ● ● ● ● Office365 Provides reporting on devices that do not meet IT policy ● ● ● Group-based policies and reporting (ability to use groups for targeted device configuration) ● ● ● Root cert and jailbreak detection ● ● ● Remove Office 365 app data from mobile devices while leaving personal data and apps intact (selective wipe) ● ● ● Prevent access to corporate email and documents based upon device enrollment and compliance policies ● ● ● Premium mobiledevice& appmanagement Self-service Company Portal for users to enroll their own devices and install corporate apps ● ● App deployment (Windows Phone, iOS, Android) ● ● Deploy certificates, VPN profiles (including app-specific profiles), email profiles, and Wi-Fi profiles ● ◐ Prevent cut/copy/paste/save as of data from corporate apps to personal apps (mobile application management) ● ● Secure content viewing via Managed browser, PDF viewer, Imager viewer, and AV player apps for Intune ● ● Remote device lock via self-service Company Portal and via admin console ● ● PC Management Client PC management (e.g. Windows 8.1, inventory, antimalware, patch, policies, etc.) ● ● PC software management ● ● Comprehensive PC management (e.g. Windows Server/Linux/Mac OS X support, virtual desktop and power management, custom reporting, etc.) ● OS deployment ● Single management console for PCs, Windows Server/Linux/Mac OS X, and mobile devices ●
  • 71. Resources β€’ MDM in Office 365 overview - https://technet.microsoft.com/en- US/library/ms.o365.cc.DevicePolicy.aspx β€’ Different ways to manage devices with InTune - https://technet.microsoft.com/library/dn957912.aspx β€’ Capabilities of Office 365 MDM – https://technet.microsoft.com/library/ms.o365.cc.devicepolicysupporteddevice.aspx β€’ Manage mobile devices in Office 365 – https://support.office.com/en- us/article/Manage-mobile-devices-in-Office-365-dd892318-bc44-4eb1-af00-9db5430be3cd β€’ EMS now available without Enterprise Agreement - http://blogs.technet.com/b/ad/archive/2015/03/12/azure-ad-and-enterprise-mobility-suite- now-broadly-available-outside-of-an-enterprise-agreement.aspx β€’ Microsoft Intune features - http://www.microsoft.com/en-au/server- cloud/products/microsoft-intune/features.aspx
  • 72. CIAOPS Resources β€’ Blog – http://blog.ciaops.com β€’ Free SharePoint Training via email – http://bit.ly/gs-spo β€’ Free Office 365, Azure Administration newsletter – http://bit.ly/o365-tech β€’ Free Office 365, Azure video tutorials – http://www.youtube.com/directorciaops β€’ Free documents, presentations, eBooks – http://docs.com/ciaops β€’ Office 365, Azure, Cloud podcast – http://ciaops.podbean.com β€’ Office 365, Azure online training courses – http://www.ciaopsacademy.com β€’ Office 365, Azure eBooks – http://www.ciaops.com/publications Twitter @directorcia Facebook https://www.facebook.com/ciaops Email director@ciaops.com Skype for Business admin@ciaops365.com