SlideShare a Scribd company logo
Empower
Enterprise
Mobility
Kris Wagner, Microsoft MVP
Sr. Manager, Cloud Platforms
Tahoe Partners
Companies gain an extra __ hours of
work/year from employees due to
mobile working?
of employees use personal
devices for work purposes.*
of employees that typically
work on employer premises,
also frequently work away
from their desks.***
of all software will be available
on a SaaS delivery by 2020.**
66% 25% 33%
*CEB The Future of Corporate ITL: 203-2017. 2013.
**Forrester Application Adoption Trends: The Rise Of SaaS
***CEB IT Impact Report: Five Key Findings on Driving Employee Productivity Q1 2014.
Cost
Risk
Change drives complexity
VDI Solutions
Data Security Solutions
MDM Solutions
System Center
ID Solutions
?
?
?
?
?
New Solution
Cost
Risk
Cost
Risk
Cost
Risk
Cost
Risk
ComplexityComplexityComplexityComplexityComplexityComplexity
Cost
Risk
?
Microsoft’s unified approach
Cost
Risk
Complexity
Progress
Devices Apps Data
Company Portal
IT Administrator
Corporate devices Personal devices
Cloud services Line of business apps SaaS apps Store apps
Microsoft’s Enterprise
Mobility solution
provides user-centric
device and information
management
User
The logos above may bethe property of their respective owners.
Single ID
Single sign-on
Self-service experiences
Conditional/Contextual access
SaaS applications
Desktop
Virtualization
Access &
information
protection
Mobile device &
application
management
Hybrid
identity
What is Enterprise Mobility Suite ?
Hybrid Identity Management
w/AzureActiveDirectory Premium
Mobile Device & Application Mgmt
w/Microsoft Intune
Single-sign on to over 2,400 SaaS Applications
Multi-factor Authentication(MFA)
Self-servicepassword reset
Group-based SaaSprovisioning
Centralized application access management
FIM CALs for on premise usage
SLA
Advanced securityreporting
Cloud App Discovery
Information Protection
w/Azure Rights Management
User’s identity
•••••••••••••
Username
?
ITUser
Cloud
On-premises
User’s identity
•••••••••••••
New device
ITUser
Cloud
On-premises
Policy control
SaaS discovery
User’s identity
ITUser
Cloud
On-premises
Discover all SaaS apps in use within your organization
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Accelerate  your  organization.
What’s  next  in  Identity  and  Access  Management  (IAM)?
Empower  your  users.
Support  end  user  devices  
and  end  user  self-­‐service.
Bring  Your  Own  Device
Workplace  Join
End  User  Self-­‐Service
Password  reset
Group  management
Unify   your  environment.
One  user,  one  identity.
One  Identity
Improve  user  experience
Unify  cloud  and  on-­‐prem
Reduce   compliance   risk
Reduce   IT  overhead
Many  Organizations
Administrative  Units
B2B  (future)
Protect  your  data.
Maintain  control  while  
getting  out  of  the  way.
Control  Access
Multi-­‐Factor  Auth
Conditional  Access
RBAC
Cloud  domain  join  (W10)
Next  gen  creds  (W10)
Encrypt  Data
RMS  Data  Protection
Maintain   Visibility
Security  reports
Heuristic   based  analytics
Deliver  apps  faster.
Discover,  manage,  and  
develop  apps  faster.
Discover  applications
Cloud  app  discovery
Manage   applications
SaaS  App  Management
Azure  AD  App  Proxy
Develop  applications
Secure,   scalable  platform
Standards  based  APIs
DevStudio  integration
B2C  (preview)
15
Enriched user experience through a single, verified identity
Unified across cloud and on-premises with single sign-on
Integrated identity solution reduces risk across the business
Reduced IT burden of creating and managing multiple identities
__% respondents believe their company
effectively controls what can be done
on the mobile device?
Desktop
Virtualization
Access &
information
protection
Mobile device &
application
management
Hybrid
identity
Consistent user experience
Simplified device enrollment and registration
Single console to manage devices
What is Enterprise Mobility Suite ?
Hybrid Identity Management
w/AzureActiveDirectory Premium
Mobile Device & Application Mgmt
w/Microsoft Intune
Single-sign on to over 2,400 SaaS Applications
Multi-factor Authentication(MFA)
Self-servicepassword reset
Group-based SaaSprovisioning
Centralized application access management
FIM CALs for on premise usage
SLA
Advanced securityreporting
Cross-platformmobiledevicemgmt (Windows, iOS, Android)
Hardware& softwareinventory
Application distribution
Policy settings
Full & selectivewipeof corporatedate
Information Protection
w/Azure Rights Management
Empower Enterprise Mobility with Microsoft EMS
Microsoft Intuneintegrated with System Center 2012 R2
Configuration Manager
Mac OS X
Windows PCs
(x86/64, Intel SoC),
Windows to Go
Windows Embedded
Windows RT,
Windows Phone 8
iOS, Android
Manage mobile productivity andprotect data with Office Mobile
apps for iOS and Android
Manage policy for existing iOS line of business apps (so called
“app wrapping”)
Managed browser and PDF/Audio/Videoviewers
Provide access to Exchange and OneDrive for Business resources
only to managed devices
Deny access if a device falls out of compliance
Enable IT to bulk enroll corporate-owned task-worker devices
Support for Apple Configurator
Manage mobile productivity without compromising compliance
Conditional Access
Policy to Email and
Documents
Enroll and Manage
Corporate-owned
Devices
Manage Mobile
Productivity
and Protect Data
with Office
Personal
Corporate
Managed
Browser
Native
E-mail
1. Susan tries to set up her new unmanaged tablet to connect to Exchange
and is blocked.
2. She enrolls the tablet into Windows Intune and is then granted access to Exchange.
3. Susan tries to save attachment to OneDrive, and is blocked since OneDrive is not managed by IT.
4. She saves attachment to OneDrive for Business, which is allowed since it is managed by IT.
5. She then tries to copy/paste content into a PowerPoint slide, and is successful.
6. Susan tries to copy text from her attachment and paste it into another,
unmanaged app. This action is blocked since this app is not managed by IT.
7. Susan later leaves the company, and a selective wipe is performed on her tablet, removing
corporate apps and data while leaving her personal content on the device.
Native
E-mail
Managed
Browser
LoB
Layer 1 – Mobile device lockdown via MDM
Protects corporate data
by…
Gaps it
leaves open
Restricting device behaviors: PIN,
encryption, wipe, disable screen
capture and cloud backup, track
compliance, etc.
Provisioning credentials that
enable corporate resource access
control
Apps may share corporate
data with other apps outside
IT control
Apps may save corporate data to
consumer cloud services
Layer 2 – Application and data containers
(aka “managed mobile productivity”)
Protects corporate data
by…
Gaps it
leaves open
Preventing apps from sharing
data with other apps outside
of IT control
Preventing apps from saving data
to stores outside of
IT control
Encrypting app data to
supplement device encryption
Only protects corporate data that
resides on devices. Cannot
protect data beyond a device.
Applies same protection to all
data that an app touches. Does
not allow for specific protection
per document.
Layer 3 – Data wrapping
Protects corporate data
by…
Gaps it
leaves open
Protecting data
wherever it resides
Providing granular, content
specific protection – e.g. time
bomb vision docs
Requires enlightened applications
Requires all data to be protected
if not complemented by Layers 1
and 2
LoB
This roadmap contains two Windows Intune releases. Dates are subject to change.
Wave
H.0
November December
Wave
H.1
Deployment of email profiles
Deployment of certificates
Deployment of VPN profiles
Deployment of WiFi profiles
Configure EAS email only if device is managed (Exchange on-prem)
Deployment of free store apps for iOS
Convenient access tointernal corporate resources via per-app VPN configurations for iOS
Requiredapp install/uninstall
Remote pin reset for WP 8.1 (currently supported for iOS and Android)
MFA at enrollment
Group filteringwithin admin console (RBAC lite)
Service account enrollment
Device lockdown via Supervisor mode (iOS) and Kiosk mode (KNOX)
Policies andapps targetedto devices
Application install allow/deny list
Customizable terms of use
Configure EAS email only if device is managed (O365)
Configure MOWA email only if device is managed
Configure documents only if device is managed **
Restrict access ifdevice falls out of compliance policy
ManagedOffice mobile apps – Word, Excel,PowerPoint
App wrapper for existingiOS line-of-business apps *
Managedbrowser
PDF viewer,AV player, Image viewer
Selective wipe of managed apps and data
Support for Apple Configurator
Device lockdown via AssignedAccess mode (WP 8.1)
URL allow/deny (via Managedbrowser)
* SSO not supported in December release
** OD4B team dependency – possible delay
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
Today’s MAM Containers Protected Mobile Productivity
Desktop
Virtualization
Access &
information
protection
Mobile device &
application
management
Hybrid
identity
Dynamic Access Control
Rights management
Secure access to work files
FPO
What is Enterprise Mobility Suite ?
Hybrid Identity Management
w/AzureActiveDirectory Premium
Mobile Device & Application Mgmt
w/Microsoft Intune
Single-sign on to over 2,400 SaaS Applications
Multi-factor Authentication(MFA)
Self-servicepassword reset
Group-based SaaSprovisioning
Centralized application access management
FIM CALs for on premise usage
SLA
Advanced securityreporting
Cross-platformmobiledevicemgmt (Windows, iOS, Android)
Hardware& softwareinventory
Application distribution
Policy settings
Full & selectivewipeof corporatedate
Information Protection
w/Azure Rights Management
Share RMSprotected documents with anyoneon any device
On-premiseusefor hybrid scenarios with no infrastructure
v
ITUser
v
ITUser
Empower Enterprise Mobility with Microsoft EMS
Productivity
SecurityMobility
Businesses must keep up by
fostering productivity, enabling
mobility and ensuring security.
Microsoft can help.
EMS
Employee productivity−anywhere, any device
"With employees using the self-service password reset feature in Azure
AD Premium, we’ve been able to reduce annual help-desk costs by $20,000.”
Empowerusers to do more
with single sign-on, self-service
password reset, and managed
access to apps
è Provide single sign-on to apps and
data from personal or corporate
devices based on user identity
è Enable self-service password reset
with multi-factor authentication
è Let users register personal devices and
install IT-approved apps through a
web-based, company-specific app store
(Company Portal)
Sign-on
Single Sign-on Self-service
password reset
Company
Portal
***
Download
apps
Enable your mobile workforce
“With Windows Azure MFA, we have a stronger level of protection
for Office 365…so we have all of our external services well protected.”
Authenticated access to apps and data
Make sure users are
who they say they are
è Verify identity with multi-factor
authentication (call, text, mobile app)
è Choose who can read, copy, print, save,
forward, and edit−and set when these
rights expire
è Let users download only the apps
they’re authorized to use through the
Company Portal
Multi-factor authentication
Data Apps Docs
Double-check identity
through text, call or app
Log on to any device
Help protect corporate
data, apps and docs
“Now we can deploy, secure, and manage mobile apps that staff
use to move faster than the competition and drive business.”
Remote device management across platforms
Deliveran up-to-dateand
security-enhanced experience
on nearly any device
è Remotely manage & help protect
Windows, iOS, and Android devices
è Handle device theft and loss with
remote wipe: selectively remove
corporate apps, data, and policies
è Better protect corporate data as users
and devices travel
è Deploy policies and updates, and
inventory HW and SW via the cloud
AndroidiOSWindows
IT
Simplified, device management via the cloud
Company Portal
IT Administrator
Corporate devices Personal devices
Cloud services Line of business apps SaaS apps Store apps
Microsoft’s Mobile
Management solution
provides user-centric
device and information
management
User
The logos above may bethe property of their respective owners.
66%of enterprise seats
covered with System
Center Configuration
Manager
240mUser accounts in Microsoft
AzureActiveDirectory
…lets you build on your investments
14B+Microsoft AzureActive
Directory authentications
per week
Sunil Tahilramani
Find a partner
link
PLA would like to help your organization gain clarity on how to manage your mobile workforce Bring Your Own Device
(BYOD) challenges. Microsoft’s Enterprise Mobility Suite can help make this dream a reality and allow you to proactively
control your evolving mobile users and their devices.
Topics include:
q End-User Mobility
q Implementing Hybrid Identity Management
q Mobile Device & Application Management
q Access & Information Protection
q Self-service Password reset
For more information contact PLA at
EMS@projectleadership.net or call (877) 752-0451
Enterprise Mobility Suite
½ Day Strategy Assessment
Each person that completes a ½ day EMS Strategy
Assessment by 12/31 will be entered into a
drawing to win a Surface Pro 3
Online Survey Link - http://1drv.ms/1s2YnMl
Thank you!

More Related Content

PPTX
Microsoft EMS - Everybody Together Now - Edge Pereira - Microsoft Office 365 ...
PPTX
Agile IT EMS webinar series, session 1
PPTX
What is Microsoft Enterprise Mobility Suite and how to deploy it
PDF
Microsoft Enterprise Mobility Suite Presented by Atidan
PDF
MMS 2015: What is ems and how to configure it
PPTX
Microsoft Enterprise Mobility Suite | Getting started....
PDF
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
PPTX
Getting started with the Enterprise Mobility Suite (EMS)
Microsoft EMS - Everybody Together Now - Edge Pereira - Microsoft Office 365 ...
Agile IT EMS webinar series, session 1
What is Microsoft Enterprise Mobility Suite and how to deploy it
Microsoft Enterprise Mobility Suite Presented by Atidan
MMS 2015: What is ems and how to configure it
Microsoft Enterprise Mobility Suite | Getting started....
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
Getting started with the Enterprise Mobility Suite (EMS)

What's hot (20)

PPTX
Windows 10 and EMS better together @ Windows 10 Partner Technical Bootcamp Mi...
PDF
Enterprise Mobility Suite
PPTX
Enterprise mobility suite
PDF
Microsoft Enterprise Mobility Suite Poster
PDF
Windows Intune webinar
PPTX
Overview of Microsoft Enterprise Mobility & Security(EMS)
PDF
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
PDF
Get Ahead of Cyber Attacks with Microsoft Enterprise Mobility + Security
PPTX
Enterprise Mobility+Security Overview
PDF
Windows 10 A Guide to Secure Mobility in the Enterprise
PPTX
EMS-HPT Template-v.1.0
PDF
Next Level Learning IT Track - Windows 10
PPTX
EPC Group Intune Practice and Capabilities Overview
PDF
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
PPTX
Protecting corporate data with Enterprise Mobility Suite
PPTX
Enterprise Mobility Suite- Azure AD Premium
PDF
Next Level Learning IT Track - Managing Devices in a BYOD world
PDF
Next Level Learning IT Track 6 - Cloud Trust
PPTX
Microsoft Intune y Gestión de Identidad Corporativa
PDF
Microsoft Windows Intune getting started guide dec 2012 release
Windows 10 and EMS better together @ Windows 10 Partner Technical Bootcamp Mi...
Enterprise Mobility Suite
Enterprise mobility suite
Microsoft Enterprise Mobility Suite Poster
Windows Intune webinar
Overview of Microsoft Enterprise Mobility & Security(EMS)
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
Get Ahead of Cyber Attacks with Microsoft Enterprise Mobility + Security
Enterprise Mobility+Security Overview
Windows 10 A Guide to Secure Mobility in the Enterprise
EMS-HPT Template-v.1.0
Next Level Learning IT Track - Windows 10
EPC Group Intune Practice and Capabilities Overview
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
Protecting corporate data with Enterprise Mobility Suite
Enterprise Mobility Suite- Azure AD Premium
Next Level Learning IT Track - Managing Devices in a BYOD world
Next Level Learning IT Track 6 - Cloud Trust
Microsoft Intune y Gestión de Identidad Corporativa
Microsoft Windows Intune getting started guide dec 2012 release
Ad

Similar to Empower Enterprise Mobility with Microsoft EMS (20)

PPTX
05-Empowering-Enterprise-Mobility-FR.pptx
PPTX
Gestión de identidad
PDF
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...
PPTX
Slim omgaan met uw mobiele devices - EM+S
PPTX
Primend Pilvekonverents - Mobiilne ettevõte mobiilsete andmetega
PDF
#EVRYWhatsNext EMS Slide Deck
PPTX
Enterprise Mobility: Microsoft Cloud OS Roadshow
PPTX
Stratégies de croissance via la mobilité (ems)
PPTX
M365 reinventing digital environment for modern workplace
PDF
MMS 2015: Secure your data and apps with the enterprise
PPTX
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...
PPTX
Security Beyond the Firewall
PDF
Enterprise Mobility Poster from Microsoft and Atidan
PPTX
Intune_DSEP. traininf for mam and mbam a
PPTX
Primendi Pilveseminar - Enterprise Mobility suite
PDF
MTUG - På tide med litt oversikt og kontroll?
PPTX
CoLabora - Protecting Company data using EMS - June 2015
PDF
VMware Workspace One
PDF
VMworld 2013: Unleashing Productivity in the New Mobile Era
PDF
Microsoft Cloud Update: New Programs, Platforms, and Opportunity
05-Empowering-Enterprise-Mobility-FR.pptx
Gestión de identidad
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...
Slim omgaan met uw mobiele devices - EM+S
Primend Pilvekonverents - Mobiilne ettevõte mobiilsete andmetega
#EVRYWhatsNext EMS Slide Deck
Enterprise Mobility: Microsoft Cloud OS Roadshow
Stratégies de croissance via la mobilité (ems)
M365 reinventing digital environment for modern workplace
MMS 2015: Secure your data and apps with the enterprise
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...
Security Beyond the Firewall
Enterprise Mobility Poster from Microsoft and Atidan
Intune_DSEP. traininf for mam and mbam a
Primendi Pilveseminar - Enterprise Mobility suite
MTUG - På tide med litt oversikt og kontroll?
CoLabora - Protecting Company data using EMS - June 2015
VMware Workspace One
VMworld 2013: Unleashing Productivity in the New Mobile Era
Microsoft Cloud Update: New Programs, Platforms, and Opportunity
Ad

More from Kris Wagner (8)

PPTX
CRM Online + Social Listening
PDF
Hooking SharePoint APIs with Android
PDF
Azure AD OAuth in Office 365
PDF
Hooking into Apps for SharePoint
PPTX
Cloud Powered Mobile Apps with Azure
PPTX
GAB Intro to Azure & Hands on Lab
PPTX
Microsoft Azure Identity and O365
PDF
The Social Side Of SharePoint
CRM Online + Social Listening
Hooking SharePoint APIs with Android
Azure AD OAuth in Office 365
Hooking into Apps for SharePoint
Cloud Powered Mobile Apps with Azure
GAB Intro to Azure & Hands on Lab
Microsoft Azure Identity and O365
The Social Side Of SharePoint

Empower Enterprise Mobility with Microsoft EMS

  • 1. Empower Enterprise Mobility Kris Wagner, Microsoft MVP Sr. Manager, Cloud Platforms Tahoe Partners
  • 2. Companies gain an extra __ hours of work/year from employees due to mobile working?
  • 3. of employees use personal devices for work purposes.* of employees that typically work on employer premises, also frequently work away from their desks.*** of all software will be available on a SaaS delivery by 2020.** 66% 25% 33% *CEB The Future of Corporate ITL: 203-2017. 2013. **Forrester Application Adoption Trends: The Rise Of SaaS ***CEB IT Impact Report: Five Key Findings on Driving Employee Productivity Q1 2014.
  • 4. Cost Risk Change drives complexity VDI Solutions Data Security Solutions MDM Solutions System Center ID Solutions ? ? ? ? ? New Solution Cost Risk Cost Risk Cost Risk Cost Risk ComplexityComplexityComplexityComplexityComplexityComplexity Cost Risk ? Microsoft’s unified approach Cost Risk Complexity Progress
  • 6. Company Portal IT Administrator Corporate devices Personal devices Cloud services Line of business apps SaaS apps Store apps Microsoft’s Enterprise Mobility solution provides user-centric device and information management User The logos above may bethe property of their respective owners.
  • 7. Single ID Single sign-on Self-service experiences Conditional/Contextual access SaaS applications Desktop Virtualization Access & information protection Mobile device & application management Hybrid identity
  • 8. What is Enterprise Mobility Suite ? Hybrid Identity Management w/AzureActiveDirectory Premium Mobile Device & Application Mgmt w/Microsoft Intune Single-sign on to over 2,400 SaaS Applications Multi-factor Authentication(MFA) Self-servicepassword reset Group-based SaaSprovisioning Centralized application access management FIM CALs for on premise usage SLA Advanced securityreporting Cloud App Discovery Information Protection w/Azure Rights Management
  • 12. Discover all SaaS apps in use within your organization
  • 15. Accelerate  your  organization. What’s  next  in  Identity  and  Access  Management  (IAM)? Empower  your  users. Support  end  user  devices   and  end  user  self-­‐service. Bring  Your  Own  Device Workplace  Join End  User  Self-­‐Service Password  reset Group  management Unify   your  environment. One  user,  one  identity. One  Identity Improve  user  experience Unify  cloud  and  on-­‐prem Reduce   compliance   risk Reduce   IT  overhead Many  Organizations Administrative  Units B2B  (future) Protect  your  data. Maintain  control  while   getting  out  of  the  way. Control  Access Multi-­‐Factor  Auth Conditional  Access RBAC Cloud  domain  join  (W10) Next  gen  creds  (W10) Encrypt  Data RMS  Data  Protection Maintain   Visibility Security  reports Heuristic   based  analytics Deliver  apps  faster. Discover,  manage,  and   develop  apps  faster. Discover  applications Cloud  app  discovery Manage   applications SaaS  App  Management Azure  AD  App  Proxy Develop  applications Secure,   scalable  platform Standards  based  APIs DevStudio  integration B2C  (preview) 15
  • 16. Enriched user experience through a single, verified identity Unified across cloud and on-premises with single sign-on Integrated identity solution reduces risk across the business Reduced IT burden of creating and managing multiple identities
  • 17. __% respondents believe their company effectively controls what can be done on the mobile device?
  • 18. Desktop Virtualization Access & information protection Mobile device & application management Hybrid identity Consistent user experience Simplified device enrollment and registration Single console to manage devices
  • 19. What is Enterprise Mobility Suite ? Hybrid Identity Management w/AzureActiveDirectory Premium Mobile Device & Application Mgmt w/Microsoft Intune Single-sign on to over 2,400 SaaS Applications Multi-factor Authentication(MFA) Self-servicepassword reset Group-based SaaSprovisioning Centralized application access management FIM CALs for on premise usage SLA Advanced securityreporting Cross-platformmobiledevicemgmt (Windows, iOS, Android) Hardware& softwareinventory Application distribution Policy settings Full & selectivewipeof corporatedate Information Protection w/Azure Rights Management
  • 21. Microsoft Intuneintegrated with System Center 2012 R2 Configuration Manager Mac OS X Windows PCs (x86/64, Intel SoC), Windows to Go Windows Embedded Windows RT, Windows Phone 8 iOS, Android
  • 22. Manage mobile productivity andprotect data with Office Mobile apps for iOS and Android Manage policy for existing iOS line of business apps (so called “app wrapping”) Managed browser and PDF/Audio/Videoviewers Provide access to Exchange and OneDrive for Business resources only to managed devices Deny access if a device falls out of compliance Enable IT to bulk enroll corporate-owned task-worker devices Support for Apple Configurator Manage mobile productivity without compromising compliance Conditional Access Policy to Email and Documents Enroll and Manage Corporate-owned Devices Manage Mobile Productivity and Protect Data with Office Personal Corporate
  • 23. Managed Browser Native E-mail 1. Susan tries to set up her new unmanaged tablet to connect to Exchange and is blocked. 2. She enrolls the tablet into Windows Intune and is then granted access to Exchange. 3. Susan tries to save attachment to OneDrive, and is blocked since OneDrive is not managed by IT. 4. She saves attachment to OneDrive for Business, which is allowed since it is managed by IT. 5. She then tries to copy/paste content into a PowerPoint slide, and is successful. 6. Susan tries to copy text from her attachment and paste it into another, unmanaged app. This action is blocked since this app is not managed by IT. 7. Susan later leaves the company, and a selective wipe is performed on her tablet, removing corporate apps and data while leaving her personal content on the device.
  • 24. Native E-mail Managed Browser LoB Layer 1 – Mobile device lockdown via MDM Protects corporate data by… Gaps it leaves open Restricting device behaviors: PIN, encryption, wipe, disable screen capture and cloud backup, track compliance, etc. Provisioning credentials that enable corporate resource access control Apps may share corporate data with other apps outside IT control Apps may save corporate data to consumer cloud services Layer 2 – Application and data containers (aka “managed mobile productivity”) Protects corporate data by… Gaps it leaves open Preventing apps from sharing data with other apps outside of IT control Preventing apps from saving data to stores outside of IT control Encrypting app data to supplement device encryption Only protects corporate data that resides on devices. Cannot protect data beyond a device. Applies same protection to all data that an app touches. Does not allow for specific protection per document. Layer 3 – Data wrapping Protects corporate data by… Gaps it leaves open Protecting data wherever it resides Providing granular, content specific protection – e.g. time bomb vision docs Requires enlightened applications Requires all data to be protected if not complemented by Layers 1 and 2 LoB
  • 25. This roadmap contains two Windows Intune releases. Dates are subject to change. Wave H.0 November December Wave H.1
  • 26. Deployment of email profiles Deployment of certificates Deployment of VPN profiles Deployment of WiFi profiles Configure EAS email only if device is managed (Exchange on-prem) Deployment of free store apps for iOS Convenient access tointernal corporate resources via per-app VPN configurations for iOS Requiredapp install/uninstall Remote pin reset for WP 8.1 (currently supported for iOS and Android) MFA at enrollment Group filteringwithin admin console (RBAC lite) Service account enrollment Device lockdown via Supervisor mode (iOS) and Kiosk mode (KNOX) Policies andapps targetedto devices Application install allow/deny list Customizable terms of use
  • 27. Configure EAS email only if device is managed (O365) Configure MOWA email only if device is managed Configure documents only if device is managed ** Restrict access ifdevice falls out of compliance policy ManagedOffice mobile apps – Word, Excel,PowerPoint App wrapper for existingiOS line-of-business apps * Managedbrowser PDF viewer,AV player, Image viewer Selective wipe of managed apps and data Support for Apple Configurator Device lockdown via AssignedAccess mode (WP 8.1) URL allow/deny (via Managedbrowser) * SSO not supported in December release ** OD4B team dependency – possible delay
  • 41. Today’s MAM Containers Protected Mobile Productivity
  • 42. Desktop Virtualization Access & information protection Mobile device & application management Hybrid identity Dynamic Access Control Rights management Secure access to work files FPO
  • 43. What is Enterprise Mobility Suite ? Hybrid Identity Management w/AzureActiveDirectory Premium Mobile Device & Application Mgmt w/Microsoft Intune Single-sign on to over 2,400 SaaS Applications Multi-factor Authentication(MFA) Self-servicepassword reset Group-based SaaSprovisioning Centralized application access management FIM CALs for on premise usage SLA Advanced securityreporting Cross-platformmobiledevicemgmt (Windows, iOS, Android) Hardware& softwareinventory Application distribution Policy settings Full & selectivewipeof corporatedate Information Protection w/Azure Rights Management Share RMSprotected documents with anyoneon any device On-premiseusefor hybrid scenarios with no infrastructure
  • 47. Productivity SecurityMobility Businesses must keep up by fostering productivity, enabling mobility and ensuring security. Microsoft can help. EMS
  • 48. Employee productivity−anywhere, any device "With employees using the self-service password reset feature in Azure AD Premium, we’ve been able to reduce annual help-desk costs by $20,000.” Empowerusers to do more with single sign-on, self-service password reset, and managed access to apps è Provide single sign-on to apps and data from personal or corporate devices based on user identity è Enable self-service password reset with multi-factor authentication è Let users register personal devices and install IT-approved apps through a web-based, company-specific app store (Company Portal) Sign-on Single Sign-on Self-service password reset Company Portal *** Download apps Enable your mobile workforce
  • 49. “With Windows Azure MFA, we have a stronger level of protection for Office 365…so we have all of our external services well protected.” Authenticated access to apps and data Make sure users are who they say they are è Verify identity with multi-factor authentication (call, text, mobile app) è Choose who can read, copy, print, save, forward, and edit−and set when these rights expire è Let users download only the apps they’re authorized to use through the Company Portal Multi-factor authentication Data Apps Docs Double-check identity through text, call or app Log on to any device Help protect corporate data, apps and docs
  • 50. “Now we can deploy, secure, and manage mobile apps that staff use to move faster than the competition and drive business.” Remote device management across platforms Deliveran up-to-dateand security-enhanced experience on nearly any device è Remotely manage & help protect Windows, iOS, and Android devices è Handle device theft and loss with remote wipe: selectively remove corporate apps, data, and policies è Better protect corporate data as users and devices travel è Deploy policies and updates, and inventory HW and SW via the cloud AndroidiOSWindows IT Simplified, device management via the cloud
  • 51. Company Portal IT Administrator Corporate devices Personal devices Cloud services Line of business apps SaaS apps Store apps Microsoft’s Mobile Management solution provides user-centric device and information management User The logos above may bethe property of their respective owners.
  • 52. 66%of enterprise seats covered with System Center Configuration Manager 240mUser accounts in Microsoft AzureActiveDirectory …lets you build on your investments 14B+Microsoft AzureActive Directory authentications per week
  • 53. Sunil Tahilramani Find a partner link
  • 54. PLA would like to help your organization gain clarity on how to manage your mobile workforce Bring Your Own Device (BYOD) challenges. Microsoft’s Enterprise Mobility Suite can help make this dream a reality and allow you to proactively control your evolving mobile users and their devices. Topics include: q End-User Mobility q Implementing Hybrid Identity Management q Mobile Device & Application Management q Access & Information Protection q Self-service Password reset For more information contact PLA at EMS@projectleadership.net or call (877) 752-0451 Enterprise Mobility Suite ½ Day Strategy Assessment Each person that completes a ½ day EMS Strategy Assessment by 12/31 will be entered into a drawing to win a Surface Pro 3
  • 55. Online Survey Link - http://1drv.ms/1s2YnMl Thank you!