4. Tagesablauf
• Die besonderen Anforderungen von Schulen
• Servicing: den Update-Zyklus an den Schulbetrieb anpassen
• Managen von Geräten mit Intune for Education und Intune Application Management, User Self-
Service Password Reset, Windows Store for Business
• Windows AutoPilot und Co-Management
5. Vorstellen und Erwartungen
• 1:1 Geräte mit
Intune4E/Autopilot/S4E
• O365 bereits integriert, was
zusätzlich
• Intallation o365
• Was gibt es neues
• Lizenen
• Spez. Schul Apps
• School manager
• Apple Geräte
• Update management
• Win32 Apps
• RBAC I4E Portal
• Does and don’t do
• User Erfassen, simple
6. Agenda
• Update-Zyklen des OS: wie gehen Sie damit um und wie managen Sie
diese?
• Set up a School PC App und WICD: die Einsteigervariante, die auch
Lehrpersonen bewältigen können oder Autopilot ;-)
• Intune for Education und Intune: Device-, User- und Application
Management einfach gemacht für geteilte Computer, 1:1 Computing und
BYOD Szenarien
• MECM: was für professionelle IT Organisation mit MECM zusätzlich möglich
ist
• Roadmap Intune for EDU
• Links, Demo zugänge, etc.
6
7. Windows 10 Servicing Model
• https://docs.microsoft.com/en-us/windows/deployment/update/waas-ov
• erview
8.
9. Früher
9
• Wipe-and-Load
• Traditional process
• Capture data and settings
• Deploy (custom) OS image
• Inject drivers
• Install apps
• Restore data and settings
• Still an option for all scenarios
In-Place
Let Windows do the work
• Preserve all data, settings,
apps, drivers
• Install (standard) OS image
• Restore everything
Recommended for existing
devices (Windows 7/8/8.1/10)
10. Früher / Heute
10
• Wipe-and-Load
• Traditional process
• Capture data and settings
• Deploy (custom) OS image
• Inject drivers
• Install apps
• Restore data and settings
• Still an option for all scenarios
In-Place
Let Windows do the work
• Preserve all data, settings,
apps, drivers
• Install (standard) OS image
• Restore everything
Recommended for existing
devices (Windows 7/8/8.1/10)
Provisioning
Configure new devices
• Transform into an Enterprise
device
• Remove extra items, add
organizational apps and config
New capability for new devices
11. Heute / Zukunft
11
In-Place
Let Windows do the work
• Preserve all data, settings,
apps, drivers
• Install (standard) OS image
• Restore everything
Recommended for existing
devices (Windows 7/8/8.1/10)
Provisioning
Configure new devices
• Transform into an Enterprise
device
• Remove extra items, add
organizational apps and config
New capability for new devices
Auto-Pilot
Auto Enroll New Devices
• Only a single first login from a
User
• Configure the Device with all the
settings
New capability for new devices
12. Configure “Set up School PCs” from Store
12
▪ - Multi User Configured
▪ - No View on C: Drive (Hidden) (in case you test ;-))
▪ - Etc…
15. Ship
Deliver direct to employee
Hardware OEM
AutoPilot
Employee unboxes device;
enters credentials during OOBE
Automatically deploy
policies, profiles, and apps
Device IDs
Azure AD
Intune
Windows AutoPilot with EMS
16. Windows Autopilot overview
Configure
Windows
Autopilot profile
Self-servicedeploy
DeviceIDs
Hardware Vendor
IT Admin
Ship
Deliver direct to Employee
Employee unboxes
device, self-deploys
IntuneWindows Autopilot
Device sync
Autopilot profile sync
17. Hybrid Azure AD Join through Windows Autopilot
IT Admin
Offline Domain Join Connector
Windows Autopilot
Deployment Service
Employee unboxes
device, self-deploys
DC
Intune
Complete Join over corp net
Receive GPOs over corp net
Receive ODJ
MDM
enrollment
Autopilot
profile
Hardware
ID
18.
19.
20. Paths to modern management
Many workloads need to
be modernized at the
same time
Doesn't address the
needs of the full
organization
Iteratively move
workloads to modern
A new organization starting
with modern workplace
24. um einheitliche
Einstellungen und Szenarios abzubilden wie z.B.
nutzerspezifische Apps und Einstellungen auf geteilten
Computern
für
Apps und Windows 10 Geräte
um cloudbasiert die
vordefinierten Apps und Einstellungen anzupassen
und ist einfach zu nutzen
Pro Device oder pro User
Erstellen Sie
automatisch Schulklassen und halten Sie die
Informationen automatisch auf dem neuesten Stand
25. Wir stellen vor: Intune for Education
Intune for Education besteht aus zwei Neuerungen:
→ Intune for Education Konsole
Vereinfachte Konsole zur Verwaltung von Schulgeräten mit Windows 10 in der
Cloud
→ Intune for Education Angebot
Intune for Education enthält 6 Azure Active Directory Premium Features
Bitte beachten:
→ In Intune for Education sind beide Konsolen enthalten:
Intune for Education Konsole und Intune Management Konsole
Intune Student Benefit:
→ Bei Lizenzierung aller Mitarbeitenden (Faculty) sind sämtliche SchülerInnen
kostenlos durch den Intune Student Benefit abgedeckt
26. Intune for Education Konsole Intune Management Konsole Plus System Center (SCCM)
Zu verwaltende Geräte Windows 10 +Windows, iOS, MacOS, Android +Unix, Linux, Server
IT Abteilungen Teil- oder Vollzeit IT Vollzeit IT Grosse IT-Abteilungen
Admin Erfahrung Web, Vereinfacht Web, Detailiert Umfassend
Windows 10 Verwaltung l l l
Zero-Touch-Management l l l
Shared Device, 1:1, BYOD l l l
Cross-Platform Unterstützung l l
Verwaltung von Windows Server,
Unix/Linux l
OS Verteilung & Imaging l
Benötigt Server Infrastruktur l
Beschaffungsdetails
Enthalten in Intune for Education für rund $30/Gerät oder
Volumenlizenzierung
Separates Abo
27. AADP P1 Included with Intune for Education
Single Sign-On > 10 apps l l
MDM auto-enrollment l l
Enterprise State Roaming l l
Dynamic Groups l l
Password write-back l l
Administrative Units l l
Advanced usage reporting l
Multi-Factor Authentication l
MIM CAL & MIM server l
Cloud app discovery l
Connect Health l
Conditional access based on
group, location, and device state l
Identity Protection l
Privileged Identity Management l
28
Das Intune for Education Angebot enthält folgende Auswahl an AADP Features
Intune for Education Angebot
30. Intune
Konsole
Intune for
Education Konsole
• Einfache Management Konsole
• Einige Azure Active Directory Premium features
• Schulspezifische Lizenzen
IT Pro Teacher IT Pro
• Intune enthält auch die Intune for Education
Konsole
• Intune for Education Lizenz ermöglicht auch
die Nutzung der vollen Intune Konsole und
enthält ausgewählte AADP-Features
• EMS enthält Intune Konsole, Intune for
Education Konsole, und volle AADP-Palette
32. Microsoft Education
Empowering every student to create the world of tomorrow
Better learning
outcomes
Saves teachers time
Affordable, easy to
manage devices
33. Creating the Conditions for Learning
MicrosoftEducationis an affordable,secure learning platformwith easy to
manage devices,collaborationtools and apps teachers and studentslove
Simple and powerful
Intune for Education provides a simple way to deploy and manage
a range of powerful Windows 10 devices and applications like
Office 365, Adobe Photoshop, and those for STEM that meet
classroom needs and unleash student capabilities
Azure Active Directory
Azure Active Directory enables fast single sign-on to authenticate identity so
students and teachers can get on to the important work of teaching and learning
Intune for Education
Intune for Education is a solution designedspecifically
to manage and connect education technology
*FullIntune console for enterprises is available with Intune for Education.
Security and productivity
Azure Active Directory works with Intune for Education to ensure
students can sign on quickly and reach all the tools they need to work
collaboratively and securely at school or at home, online and offline
Connected and future-ready
Intune for Education, integrated with School Data Sync, Teams,
and OneNote, work together seamlessly so teachers can unlock
students’ creativity and develop future-ready skills
Windows 10 devices enable
productivity online and offline
Intune* manages powerful apps
and multiple operating systems
Azure AD protects, andnever collects,
sensitive student information
Microsoft Enterprise Mobility + Security Learn more at microsoft.com/emsLearnmoreat aka.ms/moderndeployment
34. Import school, student and
teacher info quickly with
School Data Sync to
automatically create classes and
keep student data up-to-date
MICROSOFT INTUNE FOR EDUCATION
A simpler way to deploy and
manage classroom devices
Fast enrollment and
streamlined deployment
easily brings Windows 10
devices and apps under
management
Zero-touch management to
change apps and settings
applied by default to each
enrolled device through
the cloud and Azure AD
Scales to your environment with delegated administration from
a district to a school level and bridging the gap between on-
premise ConfigMgr deployments to modern cloud Intune
management with co-management. Includes rights to the full
enterprise-grade Intune console for cross-platform management.
Designed for education to
address common school
scenarios and settings, such as
shared devices where user gets
different settings and apps
35. Learn more at microsoft.com/ems
Learnmoreat aka.ms/modernedtech
Modern Technology for a Modern Education
Microsoft 365 Education offers schools a simple, powerful, and secure way to
manage education technology with Enterprise Mobility + Security
Build school community
Azure AD simplifies identity authentication soyou
can manage a variety of user access and create a
more connected and engaged school community
IntuneConfigMgr
y
180 = 50 + 2x
x =65
x x
Grades
Classes
Alerts
Migrate to modern
management at your pace
With the flexibility of co-management,
Microsoft supports your strategic
move from on-premises workloads
to the cloud in manageable portions
X
Give schools the
tools to succeed
Prepare students for the future by
deploying powerful apps like Office 365
and Minecraft: Education Edition, and
immersiveSTEM apps in the Microsoft
Store for Education like Virtual Robotics
Toolkit, OhBot,SWOPBotsand Sensavis
Manage devices
for learning
Simply manage powerful
Windows10 devices,optimized
for drawing and solving,with
Intune for Education.Manage
multi-OSenvironments with
Windows,iOS, Android, and
macOS using Intune
Secure sensitive
student information
Protect school data with the trustedsoftware
that meets education complianceand
security standardsaround the world
36. Microsoft Intune for Education makes
it simple for school IT admins to
manage Windows 10 devices and
manage and deploy applications that
their school already uses.
Streamlined enrollment,
deployment, and management
Simple Windows 10
Management
Complete
Management
Integrated with
Microsoft Education services
Cross Platform Support
in Intune, ConfigMgr integration
Manage devices, or users, or both
easy and affordable school pricing
Intune for Education includes the Intune
management console to manage diverse
devices in your ecosystem without
investing in new infrastructure or
software. Bridge to modern
management from ConfigMgr.
As part of an integrated solution,
Intune for Education includes
unbeatable integration with
Microsoft cloud services and ease
of management of Office 365.
41. Intune for Education
!
https://intuneeducation.portal.azure.com
Choose apps Choose settings
4
Choose group Review
1 3
Selected group: Lab Devices
Denise
Reset to suggested iOS defaults
Express Configuration
Windows settings iOS settings
Home screen layout
Password settings
Lock screen settings
App store settings
Shared device settings
Basic device restrictions
Choose the settings to apply to this group.
We’ve chosen some settings so your users can be safe and productive using devices in the classroom. You can change them
anytime.i
Next (Review changes)Back
Pre-release simulated screenshot shown, final experience may differ. Date of release not yet announced (FY18Q4 or FY19 Q1)
42. Summary: Set up devices in under an hour, get to modern management
“Intune for Education allowed us to run a single deployment
configuration to every computer that we have organization-wide.
That cut our deployment time from months down to weeks.”
CUSTOMER SCENARIO
PRODUCT INVESTMENTS
Deploy a classroom of devices and apps in less than an hour
with Intune for Education.
With the flexibility of co-management, strategically move from
on-premises workloads to the cloud in manageable portions.
- Jamie Trujillo
Chief Information Officer
GOAL Academy High School
SOLUTIONS
• Simplified delegation to additional administrators (i.e. school)
• Configure new settings with Windows 10 (i.e. Wi-Fi Profiles)
• Insights on users and devices (i.e. deployment status)
• Cross-platform management, extensibility with Intune APIs
IntuneConfigMgr
Migrate to
modern
management at
your pace
Get up and
running in a few
simple steps
43. • Create an EDU Demo tenant to use with customers:
• https://demos.microsoft.com/environments/create-tenant
• 1 year M365 EDU trial that includes Intune for Education, portal here once created:
https://intuneeducation.portal.azure.com/
• Ready Seattle 2018 Session recording & deck (top rated):
• Education Device Deployment & Management with Intune for Education & Windows 10
• This includes trial customers and phone support
• 24x7 support available
• https://aka.ms/freeIntunesupport
44. https://aka.ms/intuneforedupage
video video
article Infographic #1 Infographic #2 http://aka.ms/modernedtech
https://aka.ms/backtoschoolintune
article https://aka.ms/intuneedudeploymenttraining
• https://aka.ms/intune-education-docs
Recent announcements at BETT UK on EMS EDU blog (included new "Conduct the World of Tomorrow" video): aka.ms/intuneedubett18blog
https://aka.ms/intuneforeduresources
Goal Academy Port Alberni Escola Bosque French American School of Puget Sound Calvert County School
District Davidson Academy
http://aka.ms/moderndeployment direct link
https://aka.ms/intuneforedufeedback
@MSIntune
45. The State of Modern Deployment White Paper
http://aka.ms/moderndeployment
Intune for Education Technical Datasheet
http://aka.ms/modernedtech
47. Set up a classroom in
under an hour and
easily manage devices,
users, and apps
“Intune for Education allowed us to run a single deployment
configuration to every computer that we have organization-wide.
That cut our deployment time from months down to weeks.”
SCENARIO
SOLUTIONS
Deploy a classroom of devices and apps in
less than an hour with Intune for Education.
Use School Data Sync to automatically create classes and
groups to deploy apps and policies.
- Jamie Trujillo
Chief Information Officer
GOAL Academy High School
48. Intune for Education Device Management Lifecycle
Enroll
• Bulk enrollment - Set Up
School PCs or Windows
Configuration Designer
• Self-service enrollment -
Enter AAD credentials
during Windows OOBE
Retire
• Remove school data
from a device
• Perform factory reset
Provision
• Deploy settings
• Deploy apps
Manage
• Manage apps and settings
• Report on device and app
inventory, settings errors
• Perform remote tasks
User IT
49. Mobile Device
Management (MDM)
Mobile Application
Management (MAM)
Conditional Access: Restrict access to managed & compliant devices Conditional Access: Restrict which apps can be used to access email or files
Secure your data on virtually any device with Intune
Unified endpoint management with Intune
Intune gives you the flexibility and control to secure your data on any device—even those you don’t manage.
Company-Managed Employee-Managed 3rd-Party-Managed
Enroll devices for Provisionsettings, Report & measure Remove company Publish mobile Configure and Report app Secure & remove company
management certs, profiles device compliance data from devices apps to users update apps inventory & usage data within mobile apps
Information
worker
Shared
Primary
Companion
Public Kiosk
Contractor
50. Transitioning from traditional to modern
management is a simple experience for
IT Pros and nondisruptive for endusers
Gradually move specific workloads to
Intune in small, manageable steps
Start a practical transition to modern Windows 10 management with EMS
With co-management, transition to modern management in a controlled, iterative way
A practical way to
migrate over time
Benefits of
co-management
Minimized risk
during transition
An integrated solution;
simple to implement
Nondisruptive
for end users
Azure portal
Co-management
ConfigMgr + AD
Intune + Azure AD
Adopt Windows10&
Office 365ProPlus
GPO to MDMpolicy
Imagingto
WindowsAutoPilot
WSUS to Windows
Updatefor Business
Manage Windows 10 devices with
ConfigMgr and Intune at the same time
ConfigMgr
console