SlideShare a Scribd company logo
2
Most read
8
Most read
10
Most read
Coming
next…
Working with MS
Endpoint Manager
George Chrysovalantis Grammatikos
MCSA : Cloud Platform, MS Dynamics 365 | Azure Solutions Architect Expert | Microsoft Azure MVP
E-mail : george@cloudopszone.com
Blog: https://cloudopszone.com
Microsoft Wiki Profile: George Chrysovaladis Grammatikos
Tech Community Profile: George Chrysovalantis Grammatikos
Working with MS Endpoint Manager
Enterprise Mobility + Security
Azure Active Directory
MS Endpoint Configuration Manager
MS Intune
Azure Information Protection
MS Cloud App Security
MS Advanced Threat Analytics
MS Defender for Identity
A T P
What is the Endpoint Manager?
Endpoint Manager is a MS cloud service which allows us to
manage centrally corporate and personal devices, and mobile
phones.
MDM Lifecycle
Configuration
Protection
Retirement
Enrollment
Enrollment Methods
Add work or school account
Enroll in MDM only(User driven)
Azure AD Join (Out Of the Box Experience - OOBE)
Azure AD Join (Autopilot – User driven deployment mode)
Azure AD Join (Autopilot – Self-deploying mode)
Enroll in MDM only (Device Enrollment Manager)
System Center Configuration Manager co-management
Azure AD Join (Bulk Enrollment)
MS Intune – MDM and MAM
Source: https://docs.microsoft.com/el-gr/mem/intune/fundamentals/high-level-architecture
(MDM) Mobile Device
Management
(MAM) Mobile
Application Management
Microsoft Endpoint Manager
MS Intune
System Center
Configuration
Manager
MS Endpoint
Manager
Configuration Profiles
• Minimum password length (12)
• Password expiration days (180 days)
• Block simple passwords
• Number of sign-in before wiping device (Full Wipe)
• Microsoft Defender Antivirus
• ……..
Device Restrictions
• Microsoft Defender SmartScreen
• Microsoft Defender Firewall
• Windows encryption (BitLocker disk encryption)
• Microsoft Defender Application Control
• Local device security options
• ……..
Endpoint Protection
Windows Apps Policies
• Install MS365 Apps (Word, Excel, OneDrive, etc.)
• Install Line-of-business app
• Install Windows app (Win32)
• Install Microsoft Edge, version 77 and later
• ….
App Configuration Policies
Options for corporate data removal
Restore device to factory defaults
• All data on the device is removed
• Device is reset to factory defaults
• Typically used for lost/stolen
devices or resetting corporate-
owned devices
Full wipe
• Remove company assets from device
• Company resources (apps, data, profiles,
certificates, settings, and email) are removed
• MAM support adds ability to remove only
corporate data from multi-account
applications
• Typically used for personal-owned devices
Selective wipe
• Retire device from MDM
• Company resources ( apps, data,
settings, email profiles)
• Leaves user’s personal data
• Typically use for contractors' devices
Retire device
Important Tips to follow
• Always store corporate files to MS365 (SharePoint, OneDrive On-Line)
• Use apps like LastPass to keep corporate passwords
• Keep fully updated Windows OS and Antivirus/Antimalware
• Frequently scan devices for malwares/viruses
• Reboot the device after Windows Update installation
Tips
Source: https://docs.microsoft.com/en-us/mem/autopilot/windows-autopilot
Windows Autopilot – Process Overview
Windows Autopilot enables you to:
•Automatically join devices to Azure Active Directory (Azure AD) or
Active Directory (via Hybrid Azure AD Join). For more information
about the differences between these two join options,
see Introduction to device management in Azure Active Directory.
•Auto-enroll devices into MDM services, such as Microsoft Intune
(Requires an Azure AD Premium subscription for configuration).
•Restrict the Administrator account creation.
•Create and auto-assign devices to configuration groups based on a
device's profile.
•Customize OOBE content specific to the organization.
Demo
Try Microsoft Intune
•Microsoft 365 E5
•Microsoft 365 E3
•Enterprise Mobility + Security E5
•Enterprise Mobility + Security E3
•Microsoft 365 Business Premium
•Microsoft 365 F1
•Microsoft 365 F3
•Microsoft 365 Government G5
•Microsoft 365 Government G3
•Intune for Education
MS Intune licensing
Enterprise Mobility +
Security E3
Enterprise Mobility +
Security E5
Identity and access management Simplified access management and security, MFA,
Conditional access, Advanced security reporting,
Privileged identity management, Windows Server
CAL*
Simplified access management and security, MFA,
Conditional access, Risk-based conditional access,
Advanced security reporting, Privileged identity
management, Windows Server CAL*
Endpoint management Mobile application management, Advanced MS
O365 data protection, Integrated PC
management, Integrated on-premises
management
Mobile application management, Advanced MS
O365 data protection, Integrated PC
management, Integrated on-premises
management
Information Protection Persistent data protection, Document tracking
and revocation, Encryption key management per
regulatory needs
Persistent data protection, Intelligent data
classification and labeling, Document tracking and
revocation, Encryption key management per
regulatory needs
Identity –driven security Microsoft Advanced Threat Analytics Microsoft Advanced Threat Analytics, Microsoft
Cloud App Security, Microsoft Defender for
Identity
1. Microsoft Advanced Threat Analytics (ATA) will end Mainstream Support on January 12, 2021. Extended Support will continue until January 2026. Find additional information here.
* Customers purchasing Windows Server CAL agreements, Microsoft Endpoint Configuration Manager, System Center Endpoint Protection, Microsoft Active Directory Rights Management Services CALs via the Microsoft Enterprise Volume Licensing agreements may purchase
the Enterprise Mobility + Security Add-on offer.
** Open estimated retail per-month pricing. Pricing is in US dollars and can vary by country. Volume discounts are also available. To receive a quote, contact your partner or Microsoft representative.
Enterprise Mobility + Security pricing options
Useful Links
• Azure AD joined
• Set up enrollment for Windows devices
• Bulk enrollment for Windows devices
• Azure AD joined with Autopilot (User driven mode)
• Device Enrollment Manager (DEM)
• Demonstrate Autopilot deployment
MS Intune Useful Links
Thank You!

More Related Content

PDF
Modern Devices Management
PPTX
Enterprise Mobility Suite-Microsoft Intune
PPTX
Microsoft Defender for Endpoint
PPTX
Cloud computing presentation
PPT
Evolution of the cloud
PDF
Cloud computing
PDF
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
PPTX
Origins of cloud computing
Modern Devices Management
Enterprise Mobility Suite-Microsoft Intune
Microsoft Defender for Endpoint
Cloud computing presentation
Evolution of the cloud
Cloud computing
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
Origins of cloud computing

What's hot (20)

PPTX
Microsoft intune
PPTX
Enterprise Mobility+Security Overview
PDF
Microsoft Intune - Global Azure Bootcamp 2018
PPTX
Overview of Microsoft Enterprise Mobility & Security(EMS)
PPTX
Managing iOS with Microsoft Intune
PDF
Microsoft 365 Enterprise Security with E5 Overview
PDF
Azure Information Protection
PDF
Introduction to Microsoft 365 Enterprise
PPTX
Azure active directory
PPTX
Windows intune
PPTX
Secure your Access to Cloud Apps using Microsoft Defender for Cloud Apps
PDF
Microsoft Office 365 Security and Compliance
PDF
Pitching Microsoft 365
PPTX
EPC Group Intune Practice and Capabilities Overview
PPTX
Microsoft Azure Information Protection
PDF
Microsoft 365 Security and Compliance
PDF
Microsoft Defender and Azure Sentinel
PDF
Introduction to Microsoft Enterprise Mobility + Security
PPTX
What is active directory
PDF
Microsoft 365 business presentation
Microsoft intune
Enterprise Mobility+Security Overview
Microsoft Intune - Global Azure Bootcamp 2018
Overview of Microsoft Enterprise Mobility & Security(EMS)
Managing iOS with Microsoft Intune
Microsoft 365 Enterprise Security with E5 Overview
Azure Information Protection
Introduction to Microsoft 365 Enterprise
Azure active directory
Windows intune
Secure your Access to Cloud Apps using Microsoft Defender for Cloud Apps
Microsoft Office 365 Security and Compliance
Pitching Microsoft 365
EPC Group Intune Practice and Capabilities Overview
Microsoft Azure Information Protection
Microsoft 365 Security and Compliance
Microsoft Defender and Azure Sentinel
Introduction to Microsoft Enterprise Mobility + Security
What is active directory
Microsoft 365 business presentation
Ad

Similar to Working with MS Endpoint Manager (20)

PDF
Information protection and compliance
PDF
MTUG - På tide med litt oversikt og kontroll?
PPTX
Gestión de identidad
PDF
Protect your data in / with the Cloud
PPTX
In t trustm365ems_v3
PDF
MMS 2015: What is ems and how to configure it
PDF
Microsoft Enterprise Mobility and Security Launch - August 5-2015 - Atidan
PPTX
SharePoint Conference 2018 - Securing Office 365 and SharePoint Online with A...
PPTX
Microsoft Intune y Gestión de Identidad Corporativa
PDF
Microsoft Enterprise Mobility Suite Presented by Atidan
PDF
#EVRYWhatsNext EMS Slide Deck
PPTX
Securely Harden Microsoft 365 with Secure Score
PPTX
Microsoft Security Advice ISSA Slides.pptx
PDF
Softwerx Microsoft 365 Security Webinar Presentation
PDF
December 2019 Microsoft 365 Need to Know Webinar
PDF
Office 365 Security, Privacy and Compliance - SMB Nation 2015
PDF
Empower Enterprise Mobility with Microsoft EMS
PPTX
Securing your Organization with Microsoft 365
PDF
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
PDF
January 2023 CIAOPS Need to Know Webinar
Information protection and compliance
MTUG - På tide med litt oversikt og kontroll?
Gestión de identidad
Protect your data in / with the Cloud
In t trustm365ems_v3
MMS 2015: What is ems and how to configure it
Microsoft Enterprise Mobility and Security Launch - August 5-2015 - Atidan
SharePoint Conference 2018 - Securing Office 365 and SharePoint Online with A...
Microsoft Intune y Gestión de Identidad Corporativa
Microsoft Enterprise Mobility Suite Presented by Atidan
#EVRYWhatsNext EMS Slide Deck
Securely Harden Microsoft 365 with Secure Score
Microsoft Security Advice ISSA Slides.pptx
Softwerx Microsoft 365 Security Webinar Presentation
December 2019 Microsoft 365 Need to Know Webinar
Office 365 Security, Privacy and Compliance - SMB Nation 2015
Empower Enterprise Mobility with Microsoft EMS
Securing your Organization with Microsoft 365
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
January 2023 CIAOPS Need to Know Webinar
Ad

More from George Grammatikos (7)

PDF
Deploy resources on Azure using IaC (Azure Terraform)
PDF
Land your data safely and accurately with Power Platform and Azure.pdf
PDF
IT PRO | Connections 2020 : Introduction to Logic Apps and automation solutio...
PPTX
Intro to Azure Service Bus
PPTX
Introduction to Azure logic apps
PPTX
Azure Batch Service Meetup Presentation
PDF
SQL or NoSQL, is this the question? - George Grammatikos
Deploy resources on Azure using IaC (Azure Terraform)
Land your data safely and accurately with Power Platform and Azure.pdf
IT PRO | Connections 2020 : Introduction to Logic Apps and automation solutio...
Intro to Azure Service Bus
Introduction to Azure logic apps
Azure Batch Service Meetup Presentation
SQL or NoSQL, is this the question? - George Grammatikos

Recently uploaded (20)

PDF
Advanced IT Governance
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
KodekX | Application Modernization Development
PPTX
Big Data Technologies - Introduction.pptx
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
Advanced IT Governance
Diabetes mellitus diagnosis method based random forest with bat algorithm
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
The AUB Centre for AI in Media Proposal.docx
KodekX | Application Modernization Development
Big Data Technologies - Introduction.pptx
GamePlan Trading System Review: Professional Trader's Honest Take
Chapter 3 Spatial Domain Image Processing.pdf
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Mobile App Security Testing_ A Comprehensive Guide.pdf
NewMind AI Weekly Chronicles - August'25 Week I
MYSQL Presentation for SQL database connectivity
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Network Security Unit 5.pdf for BCA BBA.

Working with MS Endpoint Manager

  • 2. George Chrysovalantis Grammatikos MCSA : Cloud Platform, MS Dynamics 365 | Azure Solutions Architect Expert | Microsoft Azure MVP E-mail : george@cloudopszone.com Blog: https://cloudopszone.com Microsoft Wiki Profile: George Chrysovaladis Grammatikos Tech Community Profile: George Chrysovalantis Grammatikos Working with MS Endpoint Manager
  • 3. Enterprise Mobility + Security Azure Active Directory MS Endpoint Configuration Manager MS Intune Azure Information Protection MS Cloud App Security MS Advanced Threat Analytics MS Defender for Identity A T P
  • 4. What is the Endpoint Manager? Endpoint Manager is a MS cloud service which allows us to manage centrally corporate and personal devices, and mobile phones.
  • 6. Enrollment Methods Add work or school account Enroll in MDM only(User driven) Azure AD Join (Out Of the Box Experience - OOBE) Azure AD Join (Autopilot – User driven deployment mode) Azure AD Join (Autopilot – Self-deploying mode) Enroll in MDM only (Device Enrollment Manager) System Center Configuration Manager co-management Azure AD Join (Bulk Enrollment)
  • 7. MS Intune – MDM and MAM Source: https://docs.microsoft.com/el-gr/mem/intune/fundamentals/high-level-architecture (MDM) Mobile Device Management (MAM) Mobile Application Management
  • 8. Microsoft Endpoint Manager MS Intune System Center Configuration Manager MS Endpoint Manager
  • 9. Configuration Profiles • Minimum password length (12) • Password expiration days (180 days) • Block simple passwords • Number of sign-in before wiping device (Full Wipe) • Microsoft Defender Antivirus • …….. Device Restrictions • Microsoft Defender SmartScreen • Microsoft Defender Firewall • Windows encryption (BitLocker disk encryption) • Microsoft Defender Application Control • Local device security options • …….. Endpoint Protection
  • 10. Windows Apps Policies • Install MS365 Apps (Word, Excel, OneDrive, etc.) • Install Line-of-business app • Install Windows app (Win32) • Install Microsoft Edge, version 77 and later • …. App Configuration Policies
  • 11. Options for corporate data removal Restore device to factory defaults • All data on the device is removed • Device is reset to factory defaults • Typically used for lost/stolen devices or resetting corporate- owned devices Full wipe • Remove company assets from device • Company resources (apps, data, profiles, certificates, settings, and email) are removed • MAM support adds ability to remove only corporate data from multi-account applications • Typically used for personal-owned devices Selective wipe • Retire device from MDM • Company resources ( apps, data, settings, email profiles) • Leaves user’s personal data • Typically use for contractors' devices Retire device
  • 12. Important Tips to follow • Always store corporate files to MS365 (SharePoint, OneDrive On-Line) • Use apps like LastPass to keep corporate passwords • Keep fully updated Windows OS and Antivirus/Antimalware • Frequently scan devices for malwares/viruses • Reboot the device after Windows Update installation Tips
  • 13. Source: https://docs.microsoft.com/en-us/mem/autopilot/windows-autopilot Windows Autopilot – Process Overview Windows Autopilot enables you to: •Automatically join devices to Azure Active Directory (Azure AD) or Active Directory (via Hybrid Azure AD Join). For more information about the differences between these two join options, see Introduction to device management in Azure Active Directory. •Auto-enroll devices into MDM services, such as Microsoft Intune (Requires an Azure AD Premium subscription for configuration). •Restrict the Administrator account creation. •Create and auto-assign devices to configuration groups based on a device's profile. •Customize OOBE content specific to the organization.
  • 15. •Microsoft 365 E5 •Microsoft 365 E3 •Enterprise Mobility + Security E5 •Enterprise Mobility + Security E3 •Microsoft 365 Business Premium •Microsoft 365 F1 •Microsoft 365 F3 •Microsoft 365 Government G5 •Microsoft 365 Government G3 •Intune for Education MS Intune licensing
  • 16. Enterprise Mobility + Security E3 Enterprise Mobility + Security E5 Identity and access management Simplified access management and security, MFA, Conditional access, Advanced security reporting, Privileged identity management, Windows Server CAL* Simplified access management and security, MFA, Conditional access, Risk-based conditional access, Advanced security reporting, Privileged identity management, Windows Server CAL* Endpoint management Mobile application management, Advanced MS O365 data protection, Integrated PC management, Integrated on-premises management Mobile application management, Advanced MS O365 data protection, Integrated PC management, Integrated on-premises management Information Protection Persistent data protection, Document tracking and revocation, Encryption key management per regulatory needs Persistent data protection, Intelligent data classification and labeling, Document tracking and revocation, Encryption key management per regulatory needs Identity –driven security Microsoft Advanced Threat Analytics Microsoft Advanced Threat Analytics, Microsoft Cloud App Security, Microsoft Defender for Identity 1. Microsoft Advanced Threat Analytics (ATA) will end Mainstream Support on January 12, 2021. Extended Support will continue until January 2026. Find additional information here. * Customers purchasing Windows Server CAL agreements, Microsoft Endpoint Configuration Manager, System Center Endpoint Protection, Microsoft Active Directory Rights Management Services CALs via the Microsoft Enterprise Volume Licensing agreements may purchase the Enterprise Mobility + Security Add-on offer. ** Open estimated retail per-month pricing. Pricing is in US dollars and can vary by country. Volume discounts are also available. To receive a quote, contact your partner or Microsoft representative. Enterprise Mobility + Security pricing options
  • 17. Useful Links • Azure AD joined • Set up enrollment for Windows devices • Bulk enrollment for Windows devices • Azure AD joined with Autopilot (User driven mode) • Device Enrollment Manager (DEM) • Demonstrate Autopilot deployment MS Intune Useful Links