Enterprise Mobility (EM) is high on the agenda of the market, that’s crystal clear by now.Let’s explore during this session the unique offering that Microsoft has to deliver you the ultimate end-to-end EM experience.
Enterprise Mobility is much more than Mobile Device Management, discover how you can take the extra mile with Microsoft’s EMS. In this session I will explain and demonstrate you all the pieces of the EM(S) puzzle. It’s all about the experience, that’s what it’s all about.
4. Enterprise Mobility Suite
Mobility is the new normal
#ECMDay2015
of employees use personal
devices for work purposes
of employees that typically
work on employer premises,
also frequently work away
from their desks.
of all software will be
available on a SaaS delivery
by 2020.
66% 25% 33%
5. Enterprise Mobility Suite
Enterprise Mobility Suite
#ECMDay2015
Cloud / Hybrid
Identity Management
Mobile Device
Management
Information
Protection
Azure AD Premium Microsoft Intune Azure RMS
6. Enterprise Mobility Suite
#ECMDay2015
Airwatch/VMWare,
Mobile Iron, Good
Technology
$3-4/device/month
$8-$10/user/month
Okta/Centrify
$5/user/month
Microsoft Enterprise
Mobility Suite*
$6.50/user/month
$4/user/month
promo
Altiris, LANDesk, Big Fix, CA,
BMC
$30/year License
Salesforce.com
$$/user/month
FASCO/Seclore
$$/user/month
Core CAL + MDOP
$15/year License
End-to-End Enterprise Mobility
8. Enterprise Mobility Suite
#ECMDay2015
Azure AD Connect
• Builds on Azure AD Sync
• UI improvements
• Espress vs Custom
• Support of new features
• Sync on-prem schema extensions
• In-place or Side-by-side upgrade
9. Enterprise Mobility Suite
Azure AD Premium
#ECMDay2015
Cloud / Hybrid
Identity Management
Mobile Device
Management
Information
Protection
Azure AD Premium Microsoft Intune Azure RMS
10. Enterprise Mobility Suite
Azure AD Premium: What’s in it?
#ECMDay2015
Multi-Factor
Authentication
Hybrid Identity
Unique Security
Reporting
Branding Self-Service Group Management
Application Proxy Access Panel Portal Device Registration
13. Enterprise Mobility Suite
#ECMDay2015
User attributes
• User identity
• Group memberships
• Auth strength (MFA)
Application
• Business sensitivity
Other
• Inside corp. network
• Outside corp. network
• Risk profile
Conditional
access control in
Active Directory
Devices
• Known to organization
• MDM Managed (Intune)
• Compliant with policies
• Not lost/stolen
15. Enterprise Mobility Suite
Application Proxy
#ECMDay2015
Azure Active Directory
Corporate
Network
DMZ
• Connectors are deployed OnPrem
• Multiple connectors can be deployed for
redundancy and scale
• The connector auto connects to the cloud
service
• User connects to the cloud service that routes
their traffic to the resources via the connectors
16. Enterprise Mobility Suite
Troubleshooting
#ECMDay2015
• Event Viewer
• Try to reach
– https://test.bootstrap.msappproxy.net:8080/bootstrap
– http://testport.cloudapp.net/
• Watch out with Proxies
– The Connector is using Network Service Account
– Edit ApplicationProxyConnectorService.exe.config
<system.net>
<defaultProxy enabled="false">
</defaultProxy>
</system.net>
18. Enterprise Mobility Suite
Microsoft Intune
#ECMDay2015
Cloud / Hybrid
Identity Management
Mobile Device
Management
Information
Protection
Azure AD Premium Microsoft Intune Azure RMS
19. Enterprise Mobility Suite
Features, features and features
#ECMDay2015
Mobile devices and PCs Mobile devices
System Center
Configuration
Manager
Domain joined PCs
Configuration Manager integrated with Intune (hybrid)Intune standalone (cloud only)
IT IT
Intune web console Configuration Manager console
20. Enterprise Mobility Suite
Containerization (MAM)
#ECMDay2015
Microsoft Office apps are
natively manageable with
Intune
Intune offers key apps to
support content viewing
Build or buy your app with
the Intune SDK
Make any app manageable,
without modifying code
• OneDrive for Business
• Word
• Excel
• PowerPoint
• OneNote released for
iOS
• Onedrive for iOS coming
soon
• Other Office Apps for
Android will follow
• Managed Browsers
• PDF Viewer
• AV Viewer
• Image Viewer
• Developers can easily
integrate applications for
manageability.
• Provide more control over
user experience than
wrapping
• Apply all MAM policies to
apps
21. Enterprise Mobility Suite
Selective Wipe
#ECMDay2015
Personal apps
Managed apps Company Portal
Are you sure you want to wipe
corporate data and applications
from the user’s device?
OK Cancel
Perform selective wipe via self-service company portal or admin console
Remove managed apps and data
Keep personal apps and data intact
ITIT
22. Enterprise Mobility Suite
Microsoft’s Mobility Stack
#ECMDay2015
Native device MDM
SDK/wrapper, helper apps
Managed browser, viewers
Managed Office
productivity
Intune: standard MDM
O365: Mobile productivity
AAD: Access control to Office
Intune: Data container for
Office,, 3rd party, & LOB apps
Azure RMS: Protect
documents
Extensibility based on AAD
and Intune. Enable business
apps to interoperate with
Office Mobile
SharePoint
Server
Exchange
Server
CORPORATE
NETWORK
DMZ
Active Directory
Native cloud
integration
Standard on
premise
integration
23. Enterprise Mobility Suite
Azure RMS
#ECMDay2015
Cloud / Hybrid
Identity Management
Mobile Device
Management
Information
Protection
Azure AD Premium Microsoft Intune Azure RMS
24. Enterprise Mobility Suite
Azure RMS Vision
#ECMDay2015
Azure RMS is a complete end-to-end
information protection and sharing solution
for documents, email, and unstructured
data. Not only, on the device itself BUT also
away from the device. Controlled by
whom, how long and with audit.
25. Enterprise Mobility Suite
The ‘old’ RMS
#ECMDay2015
Corporate Network
Authentication needs to take place
via VPN, Direct Access
- User Experience was poor
- Complex to setup
- What about sharing with external people?
Setup Trust and Federations...
Domain Controller
RMS Server
27. Enterprise Mobility Suite
Before we go into the demo…
#ECMDay2015
Configure
Dynamic
Access
Control
(optional)
Install &
Configure
the RMS
Connector
Create
Templates
in Microsoft
RMS
Configure
File Server
Resource
Manager
Modify
your
Documents
Install a SSL Cert on the machine where the Connector is installed and specify the common name equals
to your DNS eg.: rmsconnector.fwslabs.com
Proxy Servers!!
HKEY_LOCAL_MACHINESOFTWAREMicrosoftAADRMConnector
String Value of ProxyAddress
eg.: http://Proxy.fwslabs.com:8080
29. Enterprise Mobility Suite
Secure Share outside your environment
#ECMDay2015
Sharing files using Azure RMS
Use Microsoft Azure RMS to securely share
documents with colleagues and business
partners Consuming Azure RMS protected files
Consuming RMS protected documents in Office 2013
31. Enterprise Mobility Suite
Released last week
#ECMDay2015
• Onboarding Control (set-AADRMOnboardingControls)
• Departementale Templates
• AD RMS to Azure RMS Migration
34. Enterprise Mobility Suite
Wrap-up
#ECMDay2015
• EMS is a unique offering in the Mobility area
• Bringing features to the cloud will make your life easier
• Microsoft takes this pretty darn serious
• Much more to come!