SlideShare a Scribd company logo
Microsoft Enterprise Mobility Suite | Getting started…
• Introduction
• What is EMS and why do you need it?
• How to get started
• Newly added features
Agenda
- Senior Consultant at Atea
- Soon to be a father
- Likes long walks on the beach….
- Email: Thomas.Godsted.Rysgaard@Atea.dk
- Twitter: @thomasrysgaard
Thomas Godsted Rysgaard
What's driving change?
User Devices Apps Data IT
Microsoft Enterprise Mobility Suite | Getting started....
Microsoft Enterprise Mobility Suite | Getting started....
Enterprise Mobility Suite
Azure Active Directory Premium
• Hybrid Identity Control panel
• Multifactor Authentication
• Password Reset
Microsoft Intune
• Mobile and Device Management
• Compliance settings
• Mobile Application Management
Azure Rights Management
• Information Protection
• Document tracking
• Bring your own key
First step - Identity
Azure Active Directory Premium
Microsoft Enterprise Mobility Suite | Getting started....
Self-service Single
sign on
•••••••••••
Username
Identity as the foundation
Azure AD
Connect
Cloud
SaaS
Azure
Office 365Public
cloud
Other
Directories
Windows Server
Active Directory
On-premises Microsoft Azure Active Directory
Azure AD Connect
Consolidated deployment
assistant for your identity
bridge components
• Express Settings
• Multi-forest support
• Password # Sync
• Streamlined fed setup with
ADFS
• Configurable Sync settings
DirSync
Azure AD Sync
FIM+Azure AD
Connector
Sync Engine
On-boarding to Azure AD & Office 365
ADFS
http://blogs.technet.com/b/ad/archive/2014/12/15/azure-ad-connect-one-simple-fast-lightweight-tool-to-connect-active-directory-and-azure-active-directory.aspx
ADFS
ADFS is optional, can addresses complex
enterprise deployments
Domain Join SSO, Enforcement of AD login policy,
Smart Card or 3rd party MFA
• Multi-factor authentication
• Group-based app access
• Advanced security reports and alerts
• Self-service Enablement
• Forefront Identity Manager (FIM)
• Enterprise SLA
A stand-alone Azure Identity and Access
management service also included in Azure Active
Directory Premium
Prevents unauthorized access to both on-premises
and cloud applications by providing an additional
level of authentication
Trusted by thousands of enterprises to authenticate
employee, customer, and partner access.
Azure Multi-factor Authentication
DEMO
Second step – Device Management
Microsoft Intune
Desktop
virtualization
Access &
information
protection
Mobile device &
application
management
Hybrid
identity
Simplified device enrollment and registration
Single console to manage all devices
Managed productivity with Office mobile apps
Conditional access to corporate resources
Desktop
Virtualization
Mobile devices and PCs Mobile devices
System Center
Configuration
Manager
Domain joined PCs
Configuration Manager integrated with Intune (hybrid)Intune standalone (cloud only)
Deployment flexibility
IT IT
Intune web console Configuration Manager console
Single management console for IT admins
Configuration Manager console (hybrid)Intune web console (cloud only)
© EG A/S 18
Microsoft Enterprise Mobility Suite | Getting started....
Consistent experience across:
Windows
Windows Phone
Android
iOS
Discover and install corporate apps
Manage devices and data
Ability to contact IT
Customizable terms and conditions
Raise of hands…
Conditional access to email
Policy
verification
•••••••••
Username
Microsoft Intune
Required settings
defined by IT admin:
Enrolled device
Encrypted device
Passcode set
Admin console
Not jailbroken/rooted
IT
ITUser
Demo
Conditional Access for Exchange Online (quickest
demo….. In the world!)
Microsoft Enterprise Mobility Suite | Getting started....
Corporate
Complete mobile application management
• Securely access corporate information using
Office mobile apps, while preventing company
data loss by restricting actions such as
copy/cut/paste/save in your managed app
ecosystem
• Extend these capabilities to existing line of
business apps using the Intune app wrapper
• Enable secure viewing of content using the
Managed Browser, PDF Viewer, AV Player, and
Image Viewer apps
Manage all of your corporate apps and
data with Intune’s mobile device and
application management solution
Personal
Managed
Browser &
Viewer Apps
Mobile Application Management with Microsoft Intune
Selective wipe
Personal apps
Managed apps Company Portal
Are you sure you want to wipe
corporate data and applications
from the user’s device?
OK Cancel
Perform selective wipe via self-service company portal or admin console
Remove managed apps and data
Keep personal apps and data intact
ITIT
Demo
Create and Deploy Mobile Application
Management Configuration
Conditional access policy
• Ability to restrict access to Exchange on-premises email based upon device enrollment
• Ability to restrict access to Exchange Online email based upon device enrollment and compliance policies
Mobile app management
• Management of Office mobile apps (Word, Excel, PowerPoint) for iOS devices, including ability to restrict actions such as
copy, cut, and paste outside of the managed app ecosystem
• Ability to extend application protection to existing line-of-business apps using the Intune App Wrapping Tool for iOS
• Managed Browser app for Android devices that controls actions that users can perform, including allow/deny access to
specific websites
• PDF Viewer, AV Player, and Image Viewer apps for Android devices that help users securely view corporate content
Configuration policies and
resource access
• Deployment of email, WiFi, VPN profiles as well as certificates
• Lockdown of Supervised iOS devices and devices using Samsung KNOX with Kiosk mode
• Targeting of policies and apps by device groups
• Enforcement of application install or uninstall
• Convenient access to internal corporate resources via per-app VPN configurations for iOS
• Application install allow/deny list
• Remote pin reset for Windows Phone 8.1 (currently supported for iOS and Android)
• Multi-factor authentication at enrollment for Windows 8.1 and Windows Phone 8.1 devices
• Ability to restrict administrator access to a specific set of user and device groups
• Ability to create configuration files using Apple Configurator and import these files into Intune to set custom iOS policies
• Lockdown of Windows Phone 8.1 devices with Assigned Access mode using OMA-URI settings
• Ability to set additional policies on Windows Phone 8.1 devices using OMA-URI settings
Ongoing support for device
platforms
• Service account enrollment
• Customizable terms and conditions
• Enhanced user interface for Intune administration console
• Ability to push free store apps to iOS devices
• Support for Apple Configurator
Conditional access policy
• Ability to restrict access to SharePoint Online (includes OneDrive for Business) based upon device enrollment and compliance
• Ability to restrict access to Exchange on-premises for Exchange ActiveSync clients on Android devices
Mobile app management
• Management of the Office Mobile app (access, view, and edit Word, Excel, and PowerPoint documents) for Android phones
• Management of OneNote and OneDrive apps
• Management of Work Folders app for iOS devices
Configuration policies and
resource access
• Ability to require encryption on Windows 8.1 (x86) devices
• Ability to set minimum classification of platform updates to be installed automatically on Windows 8.1 (x86) devices
• Ability to restrict the number of devices a user can enroll in Intune
• Support for Cisco AnyConnect per-app VPN configurations for iOS devices
• Deployment of WiFi profiles for Windows devices using XML import and Windows Phone devices using OMA-URI (currently supported for
iOS and Android)
• Ability to create WiFi profiles with pre-shared keys (PSK) for Android devices
• Ability to resolve certificate chains on Android devices without the need to deploy each intermediate certificate individually
• Ability to deploy .appx files and .appx bundles to Windows Phone 8.1 devices
Ongoing support for device
platforms
• Support for Apple Device Enrollment Program (DEP)
• Ability to browse and install apps on Windows Phone 8.1 devices using Intune Company Portal website
• Ability to manage Windows Defender on Windows 10 PCs running Windows 10 Technical Preview without need for separate Microsoft
Intune Endpoint Protection agent to be installed
• Combined Microsoft Intune Company Portal websites for PCs and mobile devices to provide a more consistent user experience across
platforms
• Enhanced user interface for overview pages within Intune admin console
Hybrid configuration (ConfigMgr)
• Restrict access to Exchange Online email only if device is managed and compliant
• Ability to create custom WiFi profiles with pre-shared keys (PSK) for Android devices
Conditional access policy • Ability to restrict access to Outlook app based on device enrollment and compliance
Mobile app management
• Intune App SDK for iOS
• Intune app Wrapping tool for Android
• Support for MAM in Outlooks app
• Multi-identity
Ongoing support for
device platforms
• Support of Apple Volume Purchase Program (VPP)
• Windows 10 support
• Mac OS X support
Roadmap
Microsoft Enterprise Mobility Suite | Getting started....
Settings management
Comprehensive security
policies are enforced on
each platform
Reporting available on
each setting whether it is
applicable, conformant or
has an error
Extensive configuration
settings are available for
each platform
Policies can be applied to
user and device groups
User
Third step – Data Protection
Azure Rights Management
Azure RMS is built on…
Encryption: documents are strongly encrypted at rest, in motion and in-use
Identity and access management: user identities are used to restrict access
Policy enforcement: granular rights control (who can print/edit/save/forward)
Access logging: a document access is logged whenever and whenever it is
used
Integration
BYO Key
Sync
Azure RMS
Connector
Azure Rights Management
Native Applications and Generic
protection using Protected File (PFILE)
Custom administrator
defined policies
I can protect and share information
securely across device types
RMS Application
DEMO
The Document Tracking site
User tracks a document he sends to his staff
Summary View
Timeline View
Map View
43
User wants to revoke the document
Microsoft Enterprise Mobility Suite | Getting started....
http://blogs.technet.com/b/rms/archive/2015
/06/03/rms-protection-tool-ga.aspx
$lic = New-RMSProtectionLicense -UserEmail thomas.godsted.rysgaard@atea.dk -Permission EDIT
Protect-RMSFile -License $lic -File "C:UsersthomasDesktopConfidential"
ITUser
Enterprise
Mobility Suite
Identify and authorize
user
Apply device policies
Apply application policies
Apply content
policies
Active Directory Premium
Rights Management
aka.ms/EnterpriseMobilitySuite
Q&A
© 2014 Atea A/S. All rights reserved.
This presentation is for informational purposes only. Atea A/S makes no warranties, express or implied, in this summary.
Specialists in IT infrastructure

More Related Content

PDF
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
PPTX
Enterprise mobility suite
PDF
Enterprise Mobility Suite
PDF
Microsoft Enterprise Mobility Suite Presented by Atidan
PPTX
Getting started with the Enterprise Mobility Suite (EMS)
PDF
Empower Enterprise Mobility with Microsoft EMS
PPTX
Microsoft EMS - Everybody Together Now - Edge Pereira - Microsoft Office 365 ...
PPTX
What is Microsoft Enterprise Mobility Suite and how to deploy it
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
Enterprise mobility suite
Enterprise Mobility Suite
Microsoft Enterprise Mobility Suite Presented by Atidan
Getting started with the Enterprise Mobility Suite (EMS)
Empower Enterprise Mobility with Microsoft EMS
Microsoft EMS - Everybody Together Now - Edge Pereira - Microsoft Office 365 ...
What is Microsoft Enterprise Mobility Suite and how to deploy it

What's hot (20)

PDF
IT/Dev Connections: Intune, ConfigMgr, or Both: Choose the Right Tool for the...
PPTX
Agile IT EMS webinar series, session 1
PPTX
Enterprise Mobility Suite- Introduction
PPTX
Enterprise Mobility Suite- Azure AD Premium
PDF
Windows Intune webinar
PPTX
Enterprise Mobility Suite-Microsoft Intune
PDF
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
PPTX
Windows 10 and EMS better together @ Windows 10 Partner Technical Bootcamp Mi...
PDF
MMS 2015: What is ems and how to configure it
PDF
Microsoft Cloud Device Management comparisions
PPTX
Protecting corporate data with Enterprise Mobility Suite
PPTX
EPC Group Intune Practice and Capabilities Overview
PPTX
Windows intune
PDF
Microsoft Windows Intune getting started guide dec 2012 release
PPTX
EMS-HPT Template-v.1.0
PDF
Mobile Device Management for Office 365 - Atidan
PDF
Microsoft Intune - Global Azure Bootcamp 2018
PDF
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
PPTX
MDM - airwatch
PDF
Airwatch od VMware
IT/Dev Connections: Intune, ConfigMgr, or Both: Choose the Right Tool for the...
Agile IT EMS webinar series, session 1
Enterprise Mobility Suite- Introduction
Enterprise Mobility Suite- Azure AD Premium
Windows Intune webinar
Enterprise Mobility Suite-Microsoft Intune
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
Windows 10 and EMS better together @ Windows 10 Partner Technical Bootcamp Mi...
MMS 2015: What is ems and how to configure it
Microsoft Cloud Device Management comparisions
Protecting corporate data with Enterprise Mobility Suite
EPC Group Intune Practice and Capabilities Overview
Windows intune
Microsoft Windows Intune getting started guide dec 2012 release
EMS-HPT Template-v.1.0
Mobile Device Management for Office 365 - Atidan
Microsoft Intune - Global Azure Bootcamp 2018
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
MDM - airwatch
Airwatch od VMware
Ad

Viewers also liked (11)

PPTX
Mct summit 2013 rt in the enterprise
PPTX
Mct summit 2013 Windows RT in the enterprise
PPTX
Community day the power of certification
PPTX
Mct summit na exchange 2010 sp2 - what to expect
PPTX
NICConf 2015 - azure disaster recovery in 60min
PDF
Managing Mobile Devices with Windows Intune and SCCM 2012 (Adrian Stoian)
PDF
BYOD for your business with WSO2 Enterprise Mobility Manager
PPTX
Enterprise Mobility+Security Overview
PPTX
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
PDF
Microsoft Azure Rights Management
PPTX
Introducing Microsoft Office 365 E5
Mct summit 2013 rt in the enterprise
Mct summit 2013 Windows RT in the enterprise
Community day the power of certification
Mct summit na exchange 2010 sp2 - what to expect
NICConf 2015 - azure disaster recovery in 60min
Managing Mobile Devices with Windows Intune and SCCM 2012 (Adrian Stoian)
BYOD for your business with WSO2 Enterprise Mobility Manager
Enterprise Mobility+Security Overview
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
Microsoft Azure Rights Management
Introducing Microsoft Office 365 E5
Ad

Similar to Microsoft Enterprise Mobility Suite | Getting started.... (20)

PPTX
Intune_DSEP. traininf for mam and mbam a
PPTX
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...
PPTX
Slim omgaan met uw mobiele devices - EM+S
PDF
July 2018 Azure Need to Know Webinar
PPTX
Primend Pilvekonverents - Mobiilne ettevõte mobiilsete andmetega
PPTX
Gerenciamento de dispositivos móveis com Intune e SCCM
PDF
#EVRYWhatsNext EMS Slide Deck
PDF
Microsoft intune with managed apps and security device policies - Sascha Fred...
PPTX
Security Beyond the Firewall
PPTX
Microsoft Intune Deployment Guide to align
PPTX
Microsoft Intune y Gestión de Identidad Corporativa
PDF
Enterprise Mobility (Admin)
PPTX
Modern Workplace: Modernize and automate with M365 – Nenad Veličković.pptx
PDF
Windows phone 8 device management with windows intune
PDF
Management of all the devices using Microsoft 365 Business
PPTX
05-Empowering-Enterprise-Mobility-FR.pptx
PPTX
Mdm with config mgr nico
PPTX
Mdm with config mgr nico
PPTX
CoLabora - Protecting Company data using EMS - June 2015
PPTX
Fortified security and simplification come together with Microsoft Intune
Intune_DSEP. traininf for mam and mbam a
Managing Mobility - Microsoft Enterprise Mobility - Accelerate, Protec and M...
Slim omgaan met uw mobiele devices - EM+S
July 2018 Azure Need to Know Webinar
Primend Pilvekonverents - Mobiilne ettevõte mobiilsete andmetega
Gerenciamento de dispositivos móveis com Intune e SCCM
#EVRYWhatsNext EMS Slide Deck
Microsoft intune with managed apps and security device policies - Sascha Fred...
Security Beyond the Firewall
Microsoft Intune Deployment Guide to align
Microsoft Intune y Gestión de Identidad Corporativa
Enterprise Mobility (Admin)
Modern Workplace: Modernize and automate with M365 – Nenad Veličković.pptx
Windows phone 8 device management with windows intune
Management of all the devices using Microsoft 365 Business
05-Empowering-Enterprise-Mobility-FR.pptx
Mdm with config mgr nico
Mdm with config mgr nico
CoLabora - Protecting Company data using EMS - June 2015
Fortified security and simplification come together with Microsoft Intune

Recently uploaded (20)

PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
A Presentation on Artificial Intelligence
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
cuic standard and advanced reporting.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Approach and Philosophy of On baking technology
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Understanding_Digital_Forensics_Presentation.pptx
DOCX
The AUB Centre for AI in Media Proposal.docx
PPT
Teaching material agriculture food technology
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Diabetes mellitus diagnosis method based random forest with bat algorithm
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
A Presentation on Artificial Intelligence
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
cuic standard and advanced reporting.pdf
Encapsulation_ Review paper, used for researhc scholars
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Approach and Philosophy of On baking technology
Digital-Transformation-Roadmap-for-Companies.pptx
Unlocking AI with Model Context Protocol (MCP)
Building Integrated photovoltaic BIPV_UPV.pdf
NewMind AI Weekly Chronicles - August'25 Week I
20250228 LYD VKU AI Blended-Learning.pptx
Understanding_Digital_Forensics_Presentation.pptx
The AUB Centre for AI in Media Proposal.docx
Teaching material agriculture food technology
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy

Microsoft Enterprise Mobility Suite | Getting started....

  • 1. Microsoft Enterprise Mobility Suite | Getting started…
  • 2. • Introduction • What is EMS and why do you need it? • How to get started • Newly added features Agenda
  • 3. - Senior Consultant at Atea - Soon to be a father - Likes long walks on the beach…. - Email: Thomas.Godsted.Rysgaard@Atea.dk - Twitter: @thomasrysgaard Thomas Godsted Rysgaard
  • 4. What's driving change? User Devices Apps Data IT
  • 7. Enterprise Mobility Suite Azure Active Directory Premium • Hybrid Identity Control panel • Multifactor Authentication • Password Reset Microsoft Intune • Mobile and Device Management • Compliance settings • Mobile Application Management Azure Rights Management • Information Protection • Document tracking • Bring your own key
  • 8. First step - Identity Azure Active Directory Premium
  • 10. Self-service Single sign on ••••••••••• Username Identity as the foundation Azure AD Connect Cloud SaaS Azure Office 365Public cloud Other Directories Windows Server Active Directory On-premises Microsoft Azure Active Directory
  • 11. Azure AD Connect Consolidated deployment assistant for your identity bridge components • Express Settings • Multi-forest support • Password # Sync • Streamlined fed setup with ADFS • Configurable Sync settings DirSync Azure AD Sync FIM+Azure AD Connector Sync Engine On-boarding to Azure AD & Office 365 ADFS http://blogs.technet.com/b/ad/archive/2014/12/15/azure-ad-connect-one-simple-fast-lightweight-tool-to-connect-active-directory-and-azure-active-directory.aspx ADFS ADFS is optional, can addresses complex enterprise deployments Domain Join SSO, Enforcement of AD login policy, Smart Card or 3rd party MFA
  • 12. • Multi-factor authentication • Group-based app access • Advanced security reports and alerts • Self-service Enablement • Forefront Identity Manager (FIM) • Enterprise SLA
  • 13. A stand-alone Azure Identity and Access management service also included in Azure Active Directory Premium Prevents unauthorized access to both on-premises and cloud applications by providing an additional level of authentication Trusted by thousands of enterprises to authenticate employee, customer, and partner access. Azure Multi-factor Authentication DEMO
  • 14. Second step – Device Management Microsoft Intune
  • 15. Desktop virtualization Access & information protection Mobile device & application management Hybrid identity Simplified device enrollment and registration Single console to manage all devices Managed productivity with Office mobile apps Conditional access to corporate resources Desktop Virtualization
  • 16. Mobile devices and PCs Mobile devices System Center Configuration Manager Domain joined PCs Configuration Manager integrated with Intune (hybrid)Intune standalone (cloud only) Deployment flexibility IT IT Intune web console Configuration Manager console
  • 17. Single management console for IT admins Configuration Manager console (hybrid)Intune web console (cloud only)
  • 18. © EG A/S 18
  • 20. Consistent experience across: Windows Windows Phone Android iOS Discover and install corporate apps Manage devices and data Ability to contact IT Customizable terms and conditions
  • 22. Conditional access to email Policy verification ••••••••• Username Microsoft Intune Required settings defined by IT admin: Enrolled device Encrypted device Passcode set Admin console Not jailbroken/rooted IT ITUser
  • 23. Demo Conditional Access for Exchange Online (quickest demo….. In the world!)
  • 25. Corporate Complete mobile application management • Securely access corporate information using Office mobile apps, while preventing company data loss by restricting actions such as copy/cut/paste/save in your managed app ecosystem • Extend these capabilities to existing line of business apps using the Intune app wrapper • Enable secure viewing of content using the Managed Browser, PDF Viewer, AV Player, and Image Viewer apps Manage all of your corporate apps and data with Intune’s mobile device and application management solution Personal Managed Browser & Viewer Apps Mobile Application Management with Microsoft Intune
  • 26. Selective wipe Personal apps Managed apps Company Portal Are you sure you want to wipe corporate data and applications from the user’s device? OK Cancel Perform selective wipe via self-service company portal or admin console Remove managed apps and data Keep personal apps and data intact ITIT
  • 27. Demo Create and Deploy Mobile Application Management Configuration
  • 28. Conditional access policy • Ability to restrict access to Exchange on-premises email based upon device enrollment • Ability to restrict access to Exchange Online email based upon device enrollment and compliance policies Mobile app management • Management of Office mobile apps (Word, Excel, PowerPoint) for iOS devices, including ability to restrict actions such as copy, cut, and paste outside of the managed app ecosystem • Ability to extend application protection to existing line-of-business apps using the Intune App Wrapping Tool for iOS • Managed Browser app for Android devices that controls actions that users can perform, including allow/deny access to specific websites • PDF Viewer, AV Player, and Image Viewer apps for Android devices that help users securely view corporate content Configuration policies and resource access • Deployment of email, WiFi, VPN profiles as well as certificates • Lockdown of Supervised iOS devices and devices using Samsung KNOX with Kiosk mode • Targeting of policies and apps by device groups • Enforcement of application install or uninstall • Convenient access to internal corporate resources via per-app VPN configurations for iOS • Application install allow/deny list • Remote pin reset for Windows Phone 8.1 (currently supported for iOS and Android) • Multi-factor authentication at enrollment for Windows 8.1 and Windows Phone 8.1 devices • Ability to restrict administrator access to a specific set of user and device groups • Ability to create configuration files using Apple Configurator and import these files into Intune to set custom iOS policies • Lockdown of Windows Phone 8.1 devices with Assigned Access mode using OMA-URI settings • Ability to set additional policies on Windows Phone 8.1 devices using OMA-URI settings Ongoing support for device platforms • Service account enrollment • Customizable terms and conditions • Enhanced user interface for Intune administration console • Ability to push free store apps to iOS devices • Support for Apple Configurator
  • 29. Conditional access policy • Ability to restrict access to SharePoint Online (includes OneDrive for Business) based upon device enrollment and compliance • Ability to restrict access to Exchange on-premises for Exchange ActiveSync clients on Android devices Mobile app management • Management of the Office Mobile app (access, view, and edit Word, Excel, and PowerPoint documents) for Android phones • Management of OneNote and OneDrive apps • Management of Work Folders app for iOS devices Configuration policies and resource access • Ability to require encryption on Windows 8.1 (x86) devices • Ability to set minimum classification of platform updates to be installed automatically on Windows 8.1 (x86) devices • Ability to restrict the number of devices a user can enroll in Intune • Support for Cisco AnyConnect per-app VPN configurations for iOS devices • Deployment of WiFi profiles for Windows devices using XML import and Windows Phone devices using OMA-URI (currently supported for iOS and Android) • Ability to create WiFi profiles with pre-shared keys (PSK) for Android devices • Ability to resolve certificate chains on Android devices without the need to deploy each intermediate certificate individually • Ability to deploy .appx files and .appx bundles to Windows Phone 8.1 devices Ongoing support for device platforms • Support for Apple Device Enrollment Program (DEP) • Ability to browse and install apps on Windows Phone 8.1 devices using Intune Company Portal website • Ability to manage Windows Defender on Windows 10 PCs running Windows 10 Technical Preview without need for separate Microsoft Intune Endpoint Protection agent to be installed • Combined Microsoft Intune Company Portal websites for PCs and mobile devices to provide a more consistent user experience across platforms • Enhanced user interface for overview pages within Intune admin console Hybrid configuration (ConfigMgr) • Restrict access to Exchange Online email only if device is managed and compliant • Ability to create custom WiFi profiles with pre-shared keys (PSK) for Android devices
  • 30. Conditional access policy • Ability to restrict access to Outlook app based on device enrollment and compliance Mobile app management • Intune App SDK for iOS • Intune app Wrapping tool for Android • Support for MAM in Outlooks app • Multi-identity Ongoing support for device platforms • Support of Apple Volume Purchase Program (VPP) • Windows 10 support • Mac OS X support Roadmap
  • 32. Settings management Comprehensive security policies are enforced on each platform Reporting available on each setting whether it is applicable, conformant or has an error Extensive configuration settings are available for each platform Policies can be applied to user and device groups User
  • 33. Third step – Data Protection Azure Rights Management
  • 34. Azure RMS is built on… Encryption: documents are strongly encrypted at rest, in motion and in-use Identity and access management: user identities are used to restrict access Policy enforcement: granular rights control (who can print/edit/save/forward) Access logging: a document access is logged whenever and whenever it is used
  • 36. Native Applications and Generic protection using Protected File (PFILE) Custom administrator defined policies I can protect and share information securely across device types RMS Application DEMO
  • 38. User tracks a document he sends to his staff
  • 42. 43 User wants to revoke the document
  • 44. http://blogs.technet.com/b/rms/archive/2015 /06/03/rms-protection-tool-ga.aspx $lic = New-RMSProtectionLicense -UserEmail thomas.godsted.rysgaard@atea.dk -Permission EDIT Protect-RMSFile -License $lic -File "C:UsersthomasDesktopConfidential"
  • 45. ITUser Enterprise Mobility Suite Identify and authorize user Apply device policies Apply application policies Apply content policies Active Directory Premium Rights Management
  • 47. Q&A
  • 48. © 2014 Atea A/S. All rights reserved. This presentation is for informational purposes only. Atea A/S makes no warranties, express or implied, in this summary. Specialists in IT infrastructure