SlideShare a Scribd company logo
1 of 41
Microsoft NDA Confidential
Devices & Platforms
Single admin
console
Microsoft NDA Confidential
1. Create Windows Intune Subscription
2. Verify Users have Public Domain UPNs and perform AD User Discovery
3. Deploy and Configure AD Directory Synchronization
4. Verify Public Domain
5. Deploy and Configure AD Federated Services (ADFS 2.0)
6. Activate User in Intune (Reset User Password, if not using ADFS)
7. Configure Configuration Manager for Mobile Device Management
8. Verification of Configuration Manager successfully connecting to Windows
Intune Service
user1@BestOfMMS.onmicrosoft.com
Intune
user1@BestOfMMS.com
Intune
Microsoft NDA Confidential
Not required but strongly recommended!
Microsoft NDA Confidential
Microsoft NDA Confidential
Microsoft NDA Confidential
Microsoft NDA Confidential
Platform Certificates or keys
Windows Phone 8 Code signing certificate: All sideloaded apps must be code-signed.
Windows RT
Sideloading Keys: Windows RT devices have to be provisioned with
sideloading keys to enable installation of sideloaded apps.
All sideloaded apps must be code-signed.
iOS Apple Push Notification service certificate
Android None
Microsoft NDA Confidential
1. Create Windows Intune Subscription
2. Verify Users have Public Domain UPNs and perform AD User Discovery
3. Deploy and Configure AD Directory Synchronization
4. Verify Public Domain
5. Deploy and Configure AD Federated Services (ADFS 2.0)
6. Activate User in Intune (Reset User Password, if not using ADFS)
7. Configure Configuration Manager for Mobile Device Management
8. Verification of Configuration Manager successfully connecting to Windows
Intune Service
Windows8/Windows
RT
Windows Phone 8 iOS Android Mac OS X
Install *.APPX *.XAP *.IPA *.APK *.DMG
*.MPKG
*.PKG
*. APP
Deep links to
the store
• Settings can be be applied to devices managed in Windows Intune and
devices managed through the Exchange Server Connector
• If a device is receiving policy from more than 1 authority, the most
secure value for a setting is applied.
• Reporting available on each setting
• Applicable settings strongly depend on platform
• There are some lists coming up at TechNet
• Fastest way is to use the Wizard in ConfigMgr “Platform Applicability”
• Hardware properties for mobile devices are collected through Device
Management as well as Exchange ActiveSync
• Software inventory for apps installed via MDM. For privacy reasons, we do
not collect app inventory for apps installed through other means on the
device
• Inventory is not extensible for mobile devices
Retire
• User or Admin initiated
• Disables further MDM app installation and settings management on the
device
Wipe effects depend on the platform and management type (EAS or native)
• iOS and WP8: Complete wipe and reset to factory defaults
• Android: EAS mailbox removal only
• Windows RT: Only EAS mailbox removal if managed
through EAS
Windows Phone Dev Center Account to get a Publisher ID
Request with that Publisher ID an Enterprise Code Signing Certificate
Download Windows Phone 8 Company Portal App and sign
Upload the signed Company Portal App & Symantec Certificate in
IntuneConfigMgr and deploy to all users.
Browse on the Device to CompanyApps
Install Company Portal
Run Powershell as Administrator
Set-ExecutionPolicy -ExecutionPolicy Unrestricted
cd ‘C:Program Files (x86)Microsoft SDKsWindows
Phonev8.0ToolsMDILXAPCompile’
.BuildMDILXap.ps1 -xapfilename c:pathfilename.xap' -pfxfilename
'c:pathtocertificatecertificatefilename.pfx' -password mypassword
1.Install Certificate from Symantec
2.Export with Private Key (Password)
3.Sign App with Powershell
Download an APNs certificate Request
Get a APNs Certificate (via Apple ID)
Upload the APNs certificate into IntuneConfigMgr
Browse on the Apple device to the Windows Intune Portal
Get a certificate (for instance internal PKI) to sign your Apps
Sign your Apps with the certificate
Upload the certificate into ConfigMgrIntune
Upload Sideloading key into ConfigMgrIntune
Go on the Windows RT device to “Company Applications”
Install Company Portal
• Admin has not configured mobile device management
• Admin has not enabled enrollment for specific device types
• User is trying to enroll several devices at the same time or has more
than 20 mobile devices in the system
• User is not provisioned by their IT admin
• Interesting Log files
DMPUPLOADER
DMPDOWNLOADER
CLOUDUSERSYNC
User not licensed to enroll device
User previously licensed but not a
member of device management
collection anymore
Non-zero guid indicates user is licensed
to enroll device
• Nice integration with ConfigMgr (Single Pane of Glass of MDM)
Room for improvement regarding UDM
• There are competitors with more features
• Intune is cloud servcie, so features will be added fast
Mdm with config mgr nico
Mdm with config mgr nico
Mdm with config mgr nico

More Related Content

What's hot

LANDesk Service pack 3 features
LANDesk Service pack 3 featuresLANDesk Service pack 3 features
LANDesk Service pack 3 features
InfraVision
 
Mcafee Epolicy Orchestrator
Mcafee Epolicy OrchestratorMcafee Epolicy Orchestrator
Mcafee Epolicy Orchestrator
MindRiver Group
 
Analysis and research of system security based on android
Analysis and research of system security based on androidAnalysis and research of system security based on android
Analysis and research of system security based on android
Ravishankar Kumar
 
MR201408 SE for Android Overview
MR201408 SE for Android OverviewMR201408 SE for Android Overview
MR201408 SE for Android Overview
FFRI, Inc.
 
License
LicenseLicense
License
vwells
 

What's hot (17)

Android Security
Android SecurityAndroid Security
Android Security
 
SP3 features
SP3 featuresSP3 features
SP3 features
 
LANDesk Service pack 3 features
LANDesk Service pack 3 featuresLANDesk Service pack 3 features
LANDesk Service pack 3 features
 
Android security in depth
Android security in depthAndroid security in depth
Android security in depth
 
Android security
Android securityAndroid security
Android security
 
Mcafee Epolicy Orchestrator
Mcafee Epolicy OrchestratorMcafee Epolicy Orchestrator
Mcafee Epolicy Orchestrator
 
License
LicenseLicense
License
 
Android Security
Android SecurityAndroid Security
Android Security
 
A Closer Look on C&C Panels
A Closer Look on C&C PanelsA Closer Look on C&C Panels
A Closer Look on C&C Panels
 
Android security in depth - extended
Android security in depth - extendedAndroid security in depth - extended
Android security in depth - extended
 
Android security
Android securityAndroid security
Android security
 
CNIT 128 7. Attacking Android Applications (Part 2)
CNIT 128 7. Attacking Android Applications (Part 2)CNIT 128 7. Attacking Android Applications (Part 2)
CNIT 128 7. Attacking Android Applications (Part 2)
 
Analysis and research of system security based on android
Analysis and research of system security based on androidAnalysis and research of system security based on android
Analysis and research of system security based on android
 
CNIT 128 6. Analyzing Android Applications (Part 2 of 3)
CNIT 128 6. Analyzing Android Applications (Part 2 of 3)CNIT 128 6. Analyzing Android Applications (Part 2 of 3)
CNIT 128 6. Analyzing Android Applications (Part 2 of 3)
 
MR201408 SE for Android Overview
MR201408 SE for Android OverviewMR201408 SE for Android Overview
MR201408 SE for Android Overview
 
License
LicenseLicense
License
 
Introduction to Android Development and Security
Introduction to Android Development and SecurityIntroduction to Android Development and Security
Introduction to Android Development and Security
 

Viewers also liked

Viewers also liked (8)

Best ofmms2013didiervanhoye
Best ofmms2013didiervanhoyeBest ofmms2013didiervanhoye
Best ofmms2013didiervanhoye
 
Best ofmms marnix_final
Best ofmms marnix_finalBest ofmms marnix_final
Best ofmms marnix_final
 
Best ofmms2013 tdk-configmgr-2012_hadr v1.0f - publish
Best ofmms2013 tdk-configmgr-2012_hadr v1.0f - publishBest ofmms2013 tdk-configmgr-2012_hadr v1.0f - publish
Best ofmms2013 tdk-configmgr-2012_hadr v1.0f - publish
 
Best ofmms2013 dieter wijckmans
Best ofmms2013 dieter wijckmansBest ofmms2013 dieter wijckmans
Best ofmms2013 dieter wijckmans
 
Best ofmms mikeresseler
Best ofmms mikeresselerBest ofmms mikeresseler
Best ofmms mikeresseler
 
Best ofmms scsm - iaas
Best ofmms scsm - iaasBest ofmms scsm - iaas
Best ofmms scsm - iaas
 
Best ofmms kb_final
Best ofmms kb_finalBest ofmms kb_final
Best ofmms kb_final
 
Best ofmms2013 what's new in sc2012 sp1 vmm
Best ofmms2013   what's new in sc2012 sp1 vmmBest ofmms2013   what's new in sc2012 sp1 vmm
Best ofmms2013 what's new in sc2012 sp1 vmm
 

Similar to Mdm with config mgr nico

Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Nordic Infrastructure Conference
 
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Nordic Infrastructure Conference
 
ClickOnce Deployment Seminar
ClickOnce Deployment SeminarClickOnce Deployment Seminar
ClickOnce Deployment Seminar
tamilarnesan
 

Similar to Mdm with config mgr nico (20)

Enterprise Mobility (Admin)
Enterprise Mobility (Admin)Enterprise Mobility (Admin)
Enterprise Mobility (Admin)
 
18 windows phone 8.1 for the enterprise developer
18   windows phone 8.1 for the enterprise developer18   windows phone 8.1 for the enterprise developer
18 windows phone 8.1 for the enterprise developer
 
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
 
Windows 8.1 a closer look
Windows 8.1 a closer lookWindows 8.1 a closer look
Windows 8.1 a closer look
 
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
 
Windows Phone 8 Security Deep Dive
Windows Phone 8 Security Deep DiveWindows Phone 8 Security Deep Dive
Windows Phone 8 Security Deep Dive
 
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneSystem Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
 
TechEd NZ 2014: Enterprise Management with Microsoft System Center Configurat...
TechEd NZ 2014: Enterprise Management with Microsoft System Center Configurat...TechEd NZ 2014: Enterprise Management with Microsoft System Center Configurat...
TechEd NZ 2014: Enterprise Management with Microsoft System Center Configurat...
 
Airwatch od VMware
Airwatch od VMwareAirwatch od VMware
Airwatch od VMware
 
Windows Autopilot (1).pdf
Windows Autopilot (1).pdfWindows Autopilot (1).pdf
Windows Autopilot (1).pdf
 
Microsoft System center Configuration manager 2012 sp1
Microsoft System center Configuration manager 2012 sp1Microsoft System center Configuration manager 2012 sp1
Microsoft System center Configuration manager 2012 sp1
 
Mobile Enterprise Application Platform
Mobile Enterprise Application PlatformMobile Enterprise Application Platform
Mobile Enterprise Application Platform
 
Unified device management_the_royal_albert_hall_v4_public
Unified device management_the_royal_albert_hall_v4_publicUnified device management_the_royal_albert_hall_v4_public
Unified device management_the_royal_albert_hall_v4_public
 
VMware Workspace One
VMware Workspace OneVMware Workspace One
VMware Workspace One
 
MMS 2015: What is ems and how to configure it
MMS 2015: What is ems and how to configure itMMS 2015: What is ems and how to configure it
MMS 2015: What is ems and how to configure it
 
ClickOnce Deployment Seminar
ClickOnce Deployment SeminarClickOnce Deployment Seminar
ClickOnce Deployment Seminar
 
Windows Autopilot - Workplace Nijna Summmit 2020
Windows Autopilot - Workplace Nijna Summmit 2020Windows Autopilot - Workplace Nijna Summmit 2020
Windows Autopilot - Workplace Nijna Summmit 2020
 
push_notification
push_notificationpush_notification
push_notification
 
Sysctr Track: Managing your hybrid Mobile cloud Workforce Demystified with Sy...
Sysctr Track: Managing your hybrid Mobile cloud Workforce Demystified with Sy...Sysctr Track: Managing your hybrid Mobile cloud Workforce Demystified with Sy...
Sysctr Track: Managing your hybrid Mobile cloud Workforce Demystified with Sy...
 
Mobile Device Management for Office 365 - Atidan
Mobile Device Management for Office 365 - AtidanMobile Device Management for Office 365 - Atidan
Mobile Device Management for Office 365 - Atidan
 

Mdm with config mgr nico

  • 1.
  • 4. Microsoft NDA Confidential 1. Create Windows Intune Subscription 2. Verify Users have Public Domain UPNs and perform AD User Discovery 3. Deploy and Configure AD Directory Synchronization 4. Verify Public Domain 5. Deploy and Configure AD Federated Services (ADFS 2.0) 6. Activate User in Intune (Reset User Password, if not using ADFS) 7. Configure Configuration Manager for Mobile Device Management 8. Verification of Configuration Manager successfully connecting to Windows Intune Service
  • 5.
  • 6.
  • 7.
  • 10. Microsoft NDA Confidential Not required but strongly recommended!
  • 14.
  • 15.
  • 17. Platform Certificates or keys Windows Phone 8 Code signing certificate: All sideloaded apps must be code-signed. Windows RT Sideloading Keys: Windows RT devices have to be provisioned with sideloading keys to enable installation of sideloaded apps. All sideloaded apps must be code-signed. iOS Apple Push Notification service certificate Android None
  • 18.
  • 19. Microsoft NDA Confidential 1. Create Windows Intune Subscription 2. Verify Users have Public Domain UPNs and perform AD User Discovery 3. Deploy and Configure AD Directory Synchronization 4. Verify Public Domain 5. Deploy and Configure AD Federated Services (ADFS 2.0) 6. Activate User in Intune (Reset User Password, if not using ADFS) 7. Configure Configuration Manager for Mobile Device Management 8. Verification of Configuration Manager successfully connecting to Windows Intune Service
  • 20.
  • 21. Windows8/Windows RT Windows Phone 8 iOS Android Mac OS X Install *.APPX *.XAP *.IPA *.APK *.DMG *.MPKG *.PKG *. APP Deep links to the store
  • 22. • Settings can be be applied to devices managed in Windows Intune and devices managed through the Exchange Server Connector • If a device is receiving policy from more than 1 authority, the most secure value for a setting is applied. • Reporting available on each setting • Applicable settings strongly depend on platform • There are some lists coming up at TechNet • Fastest way is to use the Wizard in ConfigMgr “Platform Applicability”
  • 23. • Hardware properties for mobile devices are collected through Device Management as well as Exchange ActiveSync • Software inventory for apps installed via MDM. For privacy reasons, we do not collect app inventory for apps installed through other means on the device • Inventory is not extensible for mobile devices
  • 24. Retire • User or Admin initiated • Disables further MDM app installation and settings management on the device Wipe effects depend on the platform and management type (EAS or native) • iOS and WP8: Complete wipe and reset to factory defaults • Android: EAS mailbox removal only • Windows RT: Only EAS mailbox removal if managed through EAS
  • 25.
  • 26.
  • 27. Windows Phone Dev Center Account to get a Publisher ID Request with that Publisher ID an Enterprise Code Signing Certificate Download Windows Phone 8 Company Portal App and sign Upload the signed Company Portal App & Symantec Certificate in IntuneConfigMgr and deploy to all users. Browse on the Device to CompanyApps Install Company Portal
  • 28. Run Powershell as Administrator Set-ExecutionPolicy -ExecutionPolicy Unrestricted cd ‘C:Program Files (x86)Microsoft SDKsWindows Phonev8.0ToolsMDILXAPCompile’ .BuildMDILXap.ps1 -xapfilename c:pathfilename.xap' -pfxfilename 'c:pathtocertificatecertificatefilename.pfx' -password mypassword 1.Install Certificate from Symantec 2.Export with Private Key (Password) 3.Sign App with Powershell
  • 29.
  • 30. Download an APNs certificate Request Get a APNs Certificate (via Apple ID) Upload the APNs certificate into IntuneConfigMgr Browse on the Apple device to the Windows Intune Portal
  • 31.
  • 32. Get a certificate (for instance internal PKI) to sign your Apps Sign your Apps with the certificate Upload the certificate into ConfigMgrIntune Upload Sideloading key into ConfigMgrIntune Go on the Windows RT device to “Company Applications” Install Company Portal
  • 33.
  • 34.
  • 35. • Admin has not configured mobile device management • Admin has not enabled enrollment for specific device types • User is trying to enroll several devices at the same time or has more than 20 mobile devices in the system • User is not provisioned by their IT admin • Interesting Log files DMPUPLOADER DMPDOWNLOADER CLOUDUSERSYNC
  • 36. User not licensed to enroll device User previously licensed but not a member of device management collection anymore Non-zero guid indicates user is licensed to enroll device
  • 37.
  • 38. • Nice integration with ConfigMgr (Single Pane of Glass of MDM) Room for improvement regarding UDM • There are competitors with more features • Intune is cloud servcie, so features will be added fast

Editor's Notes

  1. Tenant Admin