SlideShare a Scribd company logo
1 of 17
Windows 10 og Intune
#WhatsNext – Forsommerens kuleste roadshow på 9 lokasjoner
02.06.2015 Brummundal
Jan Ketil Skanke http://jankesblog.com
Twitter @janke75
2
Hva er Microsoft Intune
Windows 8.1 Windows 10
Enkle
sikkerhetsinstillinger
Nedlåsing av enheten
Full administrasjon
Phone PC Phone PC
Store investeringer i ny funksjonalitet for både
mobil og PC
Mobil Administrasjon (MDM)
#EVRYWhatsNext
• Provisioning
• Bulk enrollment
• Simple bootstrap
• Converged protocol
• Azure AD Integration
• Extended set of policies
Client certificate management
• Enterprise Wi-Fi
• VPN management
• Email provisioning
• MDM Push
• Device Update control
• Kiosk, Start screen, Start menu
configuration and control
• Curated Windows Store
• Business Store Portal (BSP) app
deployment; license reclaim
• Enterprise App management
• Simplified LOB app management
• Win32 (MSI) app management
• App inventory (LOB/store apps)
• App allow/deny lists via Applocker
• Enterprise data protection
• Full device wipe
• Remote Lock, PIN reset, Ring,
& Find
• Enhanced inventory for compliance
decisions
• Unenrollment with alerts
• Removal of Enterprise
configuration (apps, certs, profiles,
policies) and Enterprise encrypted
data (with EDP)
• Additional device inventory
• Provisioning
• Bulk enrollment
• Simple bootstrap
• Converged protocol
• Azure AD Integration
• Extended set of policies
Client certificate management
• Enterprise Wi-Fi
• VPN management
• Email provisioning
• MDM Push
• Device Update control
• Kiosk, Start screen, Start menu
configuration and control
• Curated Windows Store
• Business Store Portal (BSP) app
deployment; license reclaim
• Enterprise App management
• Simplified LOB app management
• Win32 (MSI) app management
• App inventory (LOB/store apps)
• App allow/deny lists via Applocker
• Enterprise data protection
• Full device wipe
• Remote Lock, PIN reset, Ring,
& Find
• Enhanced inventory for compliance
decisions
• Unenrollment with alerts
• Removal of Enterprise
configuration (apps, certs, profiles,
policies) and Enterprise encrypted
data (with EDP)
• Additional device inventory
Windows 10 og MDM
#EVRYWhatsNext
Auto MDM registrering med Azure AD
AAD join: Bedriftseid eller BYOD
Add AAD account: Personlig enhet
Bulk registrering av IT
Bruk provisjoneringspakker på “Vanilla” PC
Windows 10 gir deg flere valg for innrullering
Password
Sign in to your work or school account
Sign inCancelPrivacy statement
Forgot your password?
If your organization uses Office 365 or other business services
from Microsoft, use the same user name and password to sign in
here.
Sign in
What account should I use?
|someone@example.com
Work or school account
Allow this PC to be managed ?
AcceptCancel
Contoso requires this PC to be managed before it can access org
resources.
What you get on this PC:
• Email, Calendar, Contacts
• OneDrive for Business
• Access to company apps
How this PC is controlled by Contoso:
• Enforce PIN lock
• Partial device wipe
• Enforce password policy
• Monitor device location
Questions? Contact Contoso IT Help Desk at (206) 555-1234.
StartStart
#EVRYWhatsNext
Du har flere policies for bedre kontroll
Kamera policies
Bluetooth
Synkronisering instillinger
Roaming
Exchange Active Sync policies
Konfigurering av epost-profiler
Microsoft “Passport”
PIN policies
Firewall & Defender
Blokker internettdeling via Wifi
Auto connect VPN
Cortana
Tema bakgrunn & farge
Dette er bare noen eksempler, det kommer over 100 nye policies
#EVRYWhatsNext
Auto connect VPN
VPN trafikk filter
Applikasjonsbaserte filter
En plattform
VPN: åpen for 3-parts plug-ins
Bedre VPN administrasjon
#EVRYWhatsNext
MDM evaluates compliance
Device health attestation
Windows health attestation service
Trenger du tilgang? Bevis at du er “frisk”!
Important resources
Documents
Email
1
2
Access please
You’re in
Important resources
Documents
Email2
1
5
3
4
Here is my proof
Prove to me you are healthy
Access please
MDM & Windows
Attestation Service
#EVRYWhatsNext
Administrere oppdateringer via MDM
 Kontroller når og hvordan
 Søk og nedlastning
 Godkjenning for auto install
 Velg din kilde
 Microsoft Update
 Bedriftens oppdatering server (WSUS)
Oppdateringsstatus
#EVRYWhatsNext
Bedriftens data holdes sikret og separert
“Enterprise data protection”
Brukervennlig separering av
jobbdata og personlig data
Administrer hva som er
“Enterprise”-data
Logg beviste datalekasjer
for business
personal
Business
Apps & Data
Managed
Personal Apps
& Data
Unmanaged
Data exchange is
blocked or audited
#EVRYWhatsNext
Enterprise Data Protection
#EVRYWhatsNext
1
Bruker registerer i Intune eller AADomain join
Intune provisjonerer policies og
krypteringsnøkler
User
2
PROVISJONERING:
NØKLER OG
POLICIES
Policies:
Enterprise allowed apps
Network policies
App restriction policy
Enterprise Data Protection
#EVRYWhatsNext
User
DATA SYNK
Data som kommer inn fra en
enterprise nettverkslokasjon
er kryptert på enheten.
Eksempler: OneDrive For
Business, Corp Exchange
mail, filer, etc.
Enterprise Data Protection
#EVRYWhatsNext
User
DATA
SEGMENTATION
Brukere kan lagre til enterprise mapper og
dette vil da automatisk krypteres.
Brukere får opp et valg om å lagre som
privat- eller bedriftsdata.
IT administrator kan konfigurere hvilke
apps som alltid vil beskytte data.
Skaffe “store apps” via Business Store
Bulk kjøpt av apper
Gratis og Prislagte apper
Fleksible distribusjonmodeller
Azure AD for store
Windows app license mgmt.
#EVRYWhatsNext
Smartere fjerning av innhold
Sertifikater, VPN, Wifi, Epost profiler, policies
Applikasjoner & App data
“Enterprise data protection” data
Enten admin eller bruker kan slette
Server varslet om bruker sletter tilkobling
Admin kontrollerer om bruker kan slette seg
Konsistent opplevelse
Fjern bedriftens data på en enkel måte
#EVRYWhatsNext
• Provisioning
• Bulk enrollment
• Simple bootstrap
• Converged protocol
• Azure AD Integration
• Extended set of policies
Client certificate management
• Enterprise Wi-Fi
• VPN management
• Email provisioning
• MDM Push
• Device Update control
• Kiosk, Start screen, Start menu
configuration and control
• Curated Windows Store
• Business Store Portal (BSP) app
deployment; license reclaim
• Enterprise App management
• Simplified LOB app management
• Win32 (MSI) app management
• App inventory (LOB/store apps)
• App allow/deny lists via Applocker
• Enterprise data protection
• Full device wipe
• Remote Lock, PIN reset, Ring,
& Find
• Enhanced inventory for compliance
decisions
• Unenrollment with alerts
• Removal of Enterprise
configuration (apps, certs, profiles,
policies) and Enterprise encrypted
data (with EDP)
• Additional device inventory
• Provisioning
• Bulk enrollment
• Simple bootstrap
• Converged protocol
• Azure AD Integration
• Extended set of policies
Client certificate management
• Enterprise Wi-Fi
• VPN management
• Email provisioning
• MDM Push
• Device Update control
• Kiosk, Start screen, Start menu
configuration and control
• Curated Windows Store
• Business Store Portal (BSP) app
deployment; license reclaim
• Enterprise App management
• Simplified LOB app management
• Win32 (MSI) app management
• App inventory (LOB/store apps)
• App allow/deny lists via Applocker
• Enterprise data protection
• Full device wipe
• Remote Lock, PIN reset, Ring,
& Find
• Enhanced inventory for compliance
decisions
• Unenrollment with alerts
• Removal of Enterprise
configuration (apps, certs, profiles,
policies) and Enterprise encrypted
data (with EDP)
• Additional device inventory
Windows 10 og MDM
#EVRYWhatsNext
Jan Ketil Skanke http://jankesblog.com
Twitter @janke75

More Related Content

What's hot

Bangalore IT Pro Full Day Event on Intune and SCCM
Bangalore IT Pro Full Day Event on Intune and SCCMBangalore IT Pro Full Day Event on Intune and SCCM
Bangalore IT Pro Full Day Event on Intune and SCCM
Anoop Nair
 
Microsoft Enterprise Mobility Suite Presented by Atidan
Microsoft Enterprise Mobility Suite Presented by AtidanMicrosoft Enterprise Mobility Suite Presented by Atidan
Microsoft Enterprise Mobility Suite Presented by Atidan
David J Rosenthal
 
Getting started with the Enterprise Mobility Suite (EMS)
Getting started with the Enterprise Mobility Suite (EMS)Getting started with the Enterprise Mobility Suite (EMS)
Getting started with the Enterprise Mobility Suite (EMS)
Ronni Pedersen
 
Protecting corporate data with Enterprise Mobility Suite
Protecting corporate data with Enterprise Mobility SuiteProtecting corporate data with Enterprise Mobility Suite
Protecting corporate data with Enterprise Mobility Suite
Ronny de Jong
 
Taking conditional access to the next level
Taking conditional access to the next levelTaking conditional access to the next level
Taking conditional access to the next level
Ronny de Jong
 

What's hot (20)

How to deploy Windows Mobile to 40,000 users
How to deploy Windows Mobile to 40,000 usersHow to deploy Windows Mobile to 40,000 users
How to deploy Windows Mobile to 40,000 users
 
Microsoft Windows Intune getting started guide dec 2012 release
Microsoft Windows Intune getting started guide   dec 2012 releaseMicrosoft Windows Intune getting started guide   dec 2012 release
Microsoft Windows Intune getting started guide dec 2012 release
 
Bangalore IT Pro Full Day Event on Intune and SCCM
Bangalore IT Pro Full Day Event on Intune and SCCMBangalore IT Pro Full Day Event on Intune and SCCM
Bangalore IT Pro Full Day Event on Intune and SCCM
 
Microsoft Enterprise Mobility Suite Presented by Atidan
Microsoft Enterprise Mobility Suite Presented by AtidanMicrosoft Enterprise Mobility Suite Presented by Atidan
Microsoft Enterprise Mobility Suite Presented by Atidan
 
Getting started with the Enterprise Mobility Suite (EMS)
Getting started with the Enterprise Mobility Suite (EMS)Getting started with the Enterprise Mobility Suite (EMS)
Getting started with the Enterprise Mobility Suite (EMS)
 
Top 10 Enterprise Features of Windows Mobile 6
Top 10 Enterprise Features of Windows Mobile 6Top 10 Enterprise Features of Windows Mobile 6
Top 10 Enterprise Features of Windows Mobile 6
 
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
Microsoft Enterprise Mobility Suite Launch Presentation - AtidanMicrosoft Enterprise Mobility Suite Launch Presentation - Atidan
Microsoft Enterprise Mobility Suite Launch Presentation - Atidan
 
Windows Intune webinar
Windows Intune webinarWindows Intune webinar
Windows Intune webinar
 
2 modern desktop - windows deployment & servicing
2   modern desktop - windows deployment & servicing2   modern desktop - windows deployment & servicing
2 modern desktop - windows deployment & servicing
 
Protecting corporate data with Enterprise Mobility Suite
Protecting corporate data with Enterprise Mobility SuiteProtecting corporate data with Enterprise Mobility Suite
Protecting corporate data with Enterprise Mobility Suite
 
Taking conditional access to the next level
Taking conditional access to the next levelTaking conditional access to the next level
Taking conditional access to the next level
 
How to Secure Access Control in Office 365 Environments
How to Secure Access Control in Office 365 EnvironmentsHow to Secure Access Control in Office 365 Environments
How to Secure Access Control in Office 365 Environments
 
1 modern desktop - shift to a modern desktop
1   modern desktop - shift to a modern desktop1   modern desktop - shift to a modern desktop
1 modern desktop - shift to a modern desktop
 
Microsoft EMS - Everybody Together Now - Edge Pereira - Microsoft Office 365 ...
Microsoft EMS - Everybody Together Now - Edge Pereira - Microsoft Office 365 ...Microsoft EMS - Everybody Together Now - Edge Pereira - Microsoft Office 365 ...
Microsoft EMS - Everybody Together Now - Edge Pereira - Microsoft Office 365 ...
 
EPC Group Intune Practice and Capabilities Overview
EPC Group Intune Practice and Capabilities OverviewEPC Group Intune Practice and Capabilities Overview
EPC Group Intune Practice and Capabilities Overview
 
MTUG - På tide med litt oversikt og kontroll?
MTUG - På tide med litt oversikt og kontroll?MTUG - På tide med litt oversikt og kontroll?
MTUG - På tide med litt oversikt og kontroll?
 
Identity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft AzureIdentity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft Azure
 
Internet Explorer 8
Internet Explorer 8Internet Explorer 8
Internet Explorer 8
 
Microsoft Enterprise Mobility Suite | Getting started....
Microsoft Enterprise Mobility Suite | Getting started....Microsoft Enterprise Mobility Suite | Getting started....
Microsoft Enterprise Mobility Suite | Getting started....
 
Kasutajaõiguste ja seadmete haldus, monitooring ja kontroll
Kasutajaõiguste ja seadmete haldus, monitooring ja kontrollKasutajaõiguste ja seadmete haldus, monitooring ja kontroll
Kasutajaõiguste ja seadmete haldus, monitooring ja kontroll
 

Similar to Windows 10 og Intune

Microsoft Enterprise Mobility and Security Launch - August 5-2015 - Atidan
Microsoft Enterprise Mobility and Security Launch - August 5-2015 - AtidanMicrosoft Enterprise Mobility and Security Launch - August 5-2015 - Atidan
Microsoft Enterprise Mobility and Security Launch - August 5-2015 - Atidan
David J Rosenthal
 
EMS-HPT Template-v.1.0
EMS-HPT Template-v.1.0EMS-HPT Template-v.1.0
EMS-HPT Template-v.1.0
Huy Pham
 
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
Empower Enterprise Mobility- Maximize Mobile Control- Presented by AtidanEmpower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
David J Rosenthal
 

Similar to Windows 10 og Intune (20)

Next Level Learning IT Track - Windows 10
Next Level Learning IT Track - Windows 10Next Level Learning IT Track - Windows 10
Next Level Learning IT Track - Windows 10
 
MMS 2015: What is ems and how to configure it
MMS 2015: What is ems and how to configure itMMS 2015: What is ems and how to configure it
MMS 2015: What is ems and how to configure it
 
#EVRYWhatsNext EMS Slide Deck
#EVRYWhatsNext EMS Slide Deck#EVRYWhatsNext EMS Slide Deck
#EVRYWhatsNext EMS Slide Deck
 
In t trustm365ems_v3
In t trustm365ems_v3In t trustm365ems_v3
In t trustm365ems_v3
 
Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10
Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10
Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10
 
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
 
SCUG.dk Windows 10 Management - September 2015
SCUG.dk   Windows 10 Management - September 2015SCUG.dk   Windows 10 Management - September 2015
SCUG.dk Windows 10 Management - September 2015
 
Microsoft Enterprise Mobility and Security Launch - August 5-2015 - Atidan
Microsoft Enterprise Mobility and Security Launch - August 5-2015 - AtidanMicrosoft Enterprise Mobility and Security Launch - August 5-2015 - Atidan
Microsoft Enterprise Mobility and Security Launch - August 5-2015 - Atidan
 
Atea ems the next level
Atea   ems the next levelAtea   ems the next level
Atea ems the next level
 
Primendi Pilveseminar - Enterprise Mobility suite
Primendi Pilveseminar - Enterprise Mobility suitePrimendi Pilveseminar - Enterprise Mobility suite
Primendi Pilveseminar - Enterprise Mobility suite
 
Focusing on security with Microsoft 365 Business
Focusing on security with Microsoft 365 BusinessFocusing on security with Microsoft 365 Business
Focusing on security with Microsoft 365 Business
 
WSO2 Enterprise Mobility Manager - 2.0
WSO2 Enterprise Mobility Manager - 2.0WSO2 Enterprise Mobility Manager - 2.0
WSO2 Enterprise Mobility Manager - 2.0
 
SMB Security Product Overview.pptx
SMB Security Product Overview.pptxSMB Security Product Overview.pptx
SMB Security Product Overview.pptx
 
Security Beyond the Firewall
Security Beyond the FirewallSecurity Beyond the Firewall
Security Beyond the Firewall
 
EMS-HPT Template-v.1.0
EMS-HPT Template-v.1.0EMS-HPT Template-v.1.0
EMS-HPT Template-v.1.0
 
Microsoft Intune y Gestión de Identidad Corporativa
Microsoft Intune y Gestión de Identidad Corporativa Microsoft Intune y Gestión de Identidad Corporativa
Microsoft Intune y Gestión de Identidad Corporativa
 
ITPROCEED_WorkplaceMobility_Windows 10 in the enterprise
ITPROCEED_WorkplaceMobility_Windows 10 in the enterpriseITPROCEED_WorkplaceMobility_Windows 10 in the enterprise
ITPROCEED_WorkplaceMobility_Windows 10 in the enterprise
 
O365Con18 - Deep Dive into Microsoft 365 - Jussi Roine
O365Con18 - Deep Dive into Microsoft 365 - Jussi RoineO365Con18 - Deep Dive into Microsoft 365 - Jussi Roine
O365Con18 - Deep Dive into Microsoft 365 - Jussi Roine
 
Slim omgaan met uw mobiele devices - EM+S
Slim omgaan met uw mobiele devices - EM+SSlim omgaan met uw mobiele devices - EM+S
Slim omgaan met uw mobiele devices - EM+S
 
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
Empower Enterprise Mobility- Maximize Mobile Control- Presented by AtidanEmpower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
Empower Enterprise Mobility- Maximize Mobile Control- Presented by Atidan
 

Recently uploaded

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 

Recently uploaded (20)

EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 

Windows 10 og Intune

  • 1. Windows 10 og Intune #WhatsNext – Forsommerens kuleste roadshow på 9 lokasjoner 02.06.2015 Brummundal Jan Ketil Skanke http://jankesblog.com Twitter @janke75
  • 3. Windows 8.1 Windows 10 Enkle sikkerhetsinstillinger Nedlåsing av enheten Full administrasjon Phone PC Phone PC Store investeringer i ny funksjonalitet for både mobil og PC Mobil Administrasjon (MDM) #EVRYWhatsNext
  • 4. • Provisioning • Bulk enrollment • Simple bootstrap • Converged protocol • Azure AD Integration • Extended set of policies Client certificate management • Enterprise Wi-Fi • VPN management • Email provisioning • MDM Push • Device Update control • Kiosk, Start screen, Start menu configuration and control • Curated Windows Store • Business Store Portal (BSP) app deployment; license reclaim • Enterprise App management • Simplified LOB app management • Win32 (MSI) app management • App inventory (LOB/store apps) • App allow/deny lists via Applocker • Enterprise data protection • Full device wipe • Remote Lock, PIN reset, Ring, & Find • Enhanced inventory for compliance decisions • Unenrollment with alerts • Removal of Enterprise configuration (apps, certs, profiles, policies) and Enterprise encrypted data (with EDP) • Additional device inventory • Provisioning • Bulk enrollment • Simple bootstrap • Converged protocol • Azure AD Integration • Extended set of policies Client certificate management • Enterprise Wi-Fi • VPN management • Email provisioning • MDM Push • Device Update control • Kiosk, Start screen, Start menu configuration and control • Curated Windows Store • Business Store Portal (BSP) app deployment; license reclaim • Enterprise App management • Simplified LOB app management • Win32 (MSI) app management • App inventory (LOB/store apps) • App allow/deny lists via Applocker • Enterprise data protection • Full device wipe • Remote Lock, PIN reset, Ring, & Find • Enhanced inventory for compliance decisions • Unenrollment with alerts • Removal of Enterprise configuration (apps, certs, profiles, policies) and Enterprise encrypted data (with EDP) • Additional device inventory Windows 10 og MDM #EVRYWhatsNext
  • 5. Auto MDM registrering med Azure AD AAD join: Bedriftseid eller BYOD Add AAD account: Personlig enhet Bulk registrering av IT Bruk provisjoneringspakker på “Vanilla” PC Windows 10 gir deg flere valg for innrullering Password Sign in to your work or school account Sign inCancelPrivacy statement Forgot your password? If your organization uses Office 365 or other business services from Microsoft, use the same user name and password to sign in here. Sign in What account should I use? |someone@example.com Work or school account Allow this PC to be managed ? AcceptCancel Contoso requires this PC to be managed before it can access org resources. What you get on this PC: • Email, Calendar, Contacts • OneDrive for Business • Access to company apps How this PC is controlled by Contoso: • Enforce PIN lock • Partial device wipe • Enforce password policy • Monitor device location Questions? Contact Contoso IT Help Desk at (206) 555-1234. StartStart #EVRYWhatsNext
  • 6. Du har flere policies for bedre kontroll Kamera policies Bluetooth Synkronisering instillinger Roaming Exchange Active Sync policies Konfigurering av epost-profiler Microsoft “Passport” PIN policies Firewall & Defender Blokker internettdeling via Wifi Auto connect VPN Cortana Tema bakgrunn & farge Dette er bare noen eksempler, det kommer over 100 nye policies #EVRYWhatsNext
  • 7. Auto connect VPN VPN trafikk filter Applikasjonsbaserte filter En plattform VPN: åpen for 3-parts plug-ins Bedre VPN administrasjon #EVRYWhatsNext
  • 8. MDM evaluates compliance Device health attestation Windows health attestation service Trenger du tilgang? Bevis at du er “frisk”! Important resources Documents Email 1 2 Access please You’re in Important resources Documents Email2 1 5 3 4 Here is my proof Prove to me you are healthy Access please MDM & Windows Attestation Service #EVRYWhatsNext
  • 9. Administrere oppdateringer via MDM  Kontroller når og hvordan  Søk og nedlastning  Godkjenning for auto install  Velg din kilde  Microsoft Update  Bedriftens oppdatering server (WSUS) Oppdateringsstatus #EVRYWhatsNext
  • 10. Bedriftens data holdes sikret og separert “Enterprise data protection” Brukervennlig separering av jobbdata og personlig data Administrer hva som er “Enterprise”-data Logg beviste datalekasjer for business personal Business Apps & Data Managed Personal Apps & Data Unmanaged Data exchange is blocked or audited #EVRYWhatsNext
  • 11. Enterprise Data Protection #EVRYWhatsNext 1 Bruker registerer i Intune eller AADomain join Intune provisjonerer policies og krypteringsnøkler User 2 PROVISJONERING: NØKLER OG POLICIES Policies: Enterprise allowed apps Network policies App restriction policy
  • 12. Enterprise Data Protection #EVRYWhatsNext User DATA SYNK Data som kommer inn fra en enterprise nettverkslokasjon er kryptert på enheten. Eksempler: OneDrive For Business, Corp Exchange mail, filer, etc.
  • 13. Enterprise Data Protection #EVRYWhatsNext User DATA SEGMENTATION Brukere kan lagre til enterprise mapper og dette vil da automatisk krypteres. Brukere får opp et valg om å lagre som privat- eller bedriftsdata. IT administrator kan konfigurere hvilke apps som alltid vil beskytte data.
  • 14. Skaffe “store apps” via Business Store Bulk kjøpt av apper Gratis og Prislagte apper Fleksible distribusjonmodeller Azure AD for store Windows app license mgmt. #EVRYWhatsNext
  • 15. Smartere fjerning av innhold Sertifikater, VPN, Wifi, Epost profiler, policies Applikasjoner & App data “Enterprise data protection” data Enten admin eller bruker kan slette Server varslet om bruker sletter tilkobling Admin kontrollerer om bruker kan slette seg Konsistent opplevelse Fjern bedriftens data på en enkel måte #EVRYWhatsNext
  • 16. • Provisioning • Bulk enrollment • Simple bootstrap • Converged protocol • Azure AD Integration • Extended set of policies Client certificate management • Enterprise Wi-Fi • VPN management • Email provisioning • MDM Push • Device Update control • Kiosk, Start screen, Start menu configuration and control • Curated Windows Store • Business Store Portal (BSP) app deployment; license reclaim • Enterprise App management • Simplified LOB app management • Win32 (MSI) app management • App inventory (LOB/store apps) • App allow/deny lists via Applocker • Enterprise data protection • Full device wipe • Remote Lock, PIN reset, Ring, & Find • Enhanced inventory for compliance decisions • Unenrollment with alerts • Removal of Enterprise configuration (apps, certs, profiles, policies) and Enterprise encrypted data (with EDP) • Additional device inventory • Provisioning • Bulk enrollment • Simple bootstrap • Converged protocol • Azure AD Integration • Extended set of policies Client certificate management • Enterprise Wi-Fi • VPN management • Email provisioning • MDM Push • Device Update control • Kiosk, Start screen, Start menu configuration and control • Curated Windows Store • Business Store Portal (BSP) app deployment; license reclaim • Enterprise App management • Simplified LOB app management • Win32 (MSI) app management • App inventory (LOB/store apps) • App allow/deny lists via Applocker • Enterprise data protection • Full device wipe • Remote Lock, PIN reset, Ring, & Find • Enhanced inventory for compliance decisions • Unenrollment with alerts • Removal of Enterprise configuration (apps, certs, profiles, policies) and Enterprise encrypted data (with EDP) • Additional device inventory Windows 10 og MDM #EVRYWhatsNext
  • 17. Jan Ketil Skanke http://jankesblog.com Twitter @janke75

Editor's Notes

  1. Microsoft Intune er Microsoft sin skybaserte løsning for managment av Mobile Enheter og PC-er fra skyen..
  2. MS introduserte MDM muligheter i 8.1 og Windows Phone 8.1 Dette var forholdsvis enkle scenarier som å sette sikkerhetsinstillinger, noe muligheter for å låse ned enheten for spesielle bruksområder som f.eks point of sale o.l Intune Agent tidligere… med win10 er det agentless.. Når Windows 10 nå kommer har man utvidet mulighetene mye. Det er viktig å vite at man ikke bare flytter alle 3600 GPO settingene som windows har i dag, i stedet vil det komme et sett med high-level muligheter. Hvilke muligheter som kommer er ikke 100% klart fra MS sin side ennå, men vi skal komme inn på noen av disse i dag.
  3. MDM mulighetene i Windows dekker en komplett livssyklus for enheten. I Windows 10 vil dette ble utvidet med mange nye muligheter i hver fase av levetiden til en enhet. Selv om listen over ny funksjonalitet fra MS sin side ikke er klar ennå, så viser jeg her noen av de MDM mulighetene som Microsoft selv har sagt at dem skal levere. Du får enkel registrering for å automatisere selve MDM innrulleringen som følge av at man tar en Azure AD Join Du får nye muligheter for å kontrollere og administrere start-menyen Du får nye muligheter til å kontrollere når spesifikke Windows Updates er rullet ut (tenk WSUS fra Skyen) Du får mulighet til å kontrollere hvilke apper som kan kjøres og installeres samt mulighet til å kontrollere Enterprise Data Protection i Windows 10 Man integrerer med Windows Store og Business Storen for å mulighjøre automatisert app administrasjon Du får full device wipe og epost profil håndtering nå også for Pcer Alt dette vil støttes for alle type enheter som kjører Windows 10, telefoner, PC-er, Nettbrett
  4. MDM Auto Registrering via Azure AD Bulk registrering (Provisjonpakker, bootstrap)
  5. App Basert VPN – Admin setter opp appbasert filter i stedet for filtre på domene/ip ranger ved Split Tunnling. Trigges av Appen. Juniper, Checkpoint, F5 m.,m
  6. Sandboxing uten å plassere brukeren i en boks. Mer brukervennlig.
  7. Kan settes opp til at alle jobbrelaterte apper hentes via Azure AD ID. Da trenger man ikke koble til Microsoft privat konto…
  8. MDM mulighetene i Windows dekker en komplett livssyklus for enheten. I Windows 10 vil dette ble utvidet med mange nye muligheter i hver fase av levetiden til en enhet. Selv om listen over ny funksjonalitet fra MS sin side ikke er klar ennå, så viser jeg her noen av de MDM mulighetene som Microsoft selv har sagt at dem skal levere. Du får enkel registrering for å automatisere selve MDM innrulleringen som følge av at man tar en Azure AD Join Du får nye muligheter for å kontrollere og administrere start-menyen Du får nye muligheter til å kontrollere når spesifikke Windows Updates er rullet ut (tenk WSUS fra Skyen) Du får mulighet til å kontrollere hvilke apper som kan kjøres og installeres samt mulighet til å kontrollere Enterprise Data Protection i Windows 10 Man integrerer med Windows Store og Business Storen for å mulighjøre automatisert app administrasjon Du får full device wipe og epost profil håndtering nå også for Pcer Alt dette vil støttes for alle type enheter som kjører Windows 10, telefoner, PC-er, Nettbrett