WHO AM I
ANOOP
16+ YEARS OF EXPERIENCE IN IT
MICROSOFT MVP/VEEAM VANGUARD
@ANOOPMANNUR
WWW.ANOOPCNAIR.COM
HTTP://WWW.YOUTUBE.COM/C/ANOOPCNAIRSCCM
AGENDA
• WHY TO LEARN INTUNE MOBILE DEVICE MANAGEMENT?
• INTUNE VERY HIGH LEVEL ARCHITECTURE FLOW
• WHAT ARE THE MANAGEMENT OPTIONS IN INTUNE?
• WHAT IS MDM AUTHORITY?
• SEQUENCE OF INTUNE POLICY CREATION
• UNDERSTAND INTUNE/AAD POLICY FLOW
• INTUNE AUTOMATIC POLICY REFRESH UPDATE?
• TROUBLESHOOTING
• INTUNE R & R?
WHY LEARN INTUNE
MOBILE DEVICE
MANAGEMENT
• DESKTOP (43.29%)
• MOBILE (52.29%)
• TABLET (4.42%)
• SUPPORT MODERN IT
INTUNE VERY HIGH LEVEL
ARCHITECTURE FLOW
• SELF SERVICE
• ATTEMPT TO ACCESS MAIL
• CHECK THE AAD IDENTITY
• QUARANTINE DEVICE
• INTUNE ENROLLMENT
WHAT ARE THE
MANAGEMENT OPTIONS
IN INTUNE?
• IOS
• WINDOWS
• ANDROID
• MAC OS
• AGENT & AGENT LESS
• MDM/MAM
WHAT IS MDM
AUTHORITY?
• INTUNE
• SCCM/CONFIGMGR
• OFFICE 365
UNDERSTAND
INTUNE/AAD POLICY FLOW
• ENROLLMENT RESTRICTION POLICY
• CONDITIONAL ACCESS POLICY (AZURE AD)
• COMPLIANCE POLICY
• CONFIGURATION POLICY (DEVICE
RESTRICTION POLICY)
• RESOURCE POLICY (WI-FI, VPN PROFILES)
INTUNE
AUTOMATIC
POLICY REFRESH
UPDATE?
TROUBLESHOOTING
INTUNE R & R?
• USER MANAGEMENT
• APPLICATION CREATION AND DEPLOYMENT/ASSIGNMENT
• SERVICE ADMINISTRATION
• MOBILE APPLICATION MANAGEMENT
• DEVICE/PROFILE MANAGEMENT
• CONDITIONAL ACCESS
• COMPANY RESOURCE ACCESS
• SOFTWARE UPDATE MANAGEMENT
How to start Learning Microsoft Intune

How to start Learning Microsoft Intune

  • 2.
    WHO AM I ANOOP 16+YEARS OF EXPERIENCE IN IT MICROSOFT MVP/VEEAM VANGUARD @ANOOPMANNUR WWW.ANOOPCNAIR.COM HTTP://WWW.YOUTUBE.COM/C/ANOOPCNAIRSCCM
  • 3.
    AGENDA • WHY TOLEARN INTUNE MOBILE DEVICE MANAGEMENT? • INTUNE VERY HIGH LEVEL ARCHITECTURE FLOW • WHAT ARE THE MANAGEMENT OPTIONS IN INTUNE? • WHAT IS MDM AUTHORITY? • SEQUENCE OF INTUNE POLICY CREATION • UNDERSTAND INTUNE/AAD POLICY FLOW • INTUNE AUTOMATIC POLICY REFRESH UPDATE? • TROUBLESHOOTING • INTUNE R & R?
  • 4.
    WHY LEARN INTUNE MOBILEDEVICE MANAGEMENT • DESKTOP (43.29%) • MOBILE (52.29%) • TABLET (4.42%) • SUPPORT MODERN IT
  • 5.
    INTUNE VERY HIGHLEVEL ARCHITECTURE FLOW • SELF SERVICE • ATTEMPT TO ACCESS MAIL • CHECK THE AAD IDENTITY • QUARANTINE DEVICE • INTUNE ENROLLMENT
  • 6.
    WHAT ARE THE MANAGEMENTOPTIONS IN INTUNE? • IOS • WINDOWS • ANDROID • MAC OS • AGENT & AGENT LESS • MDM/MAM
  • 7.
    WHAT IS MDM AUTHORITY? •INTUNE • SCCM/CONFIGMGR • OFFICE 365
  • 8.
    UNDERSTAND INTUNE/AAD POLICY FLOW •ENROLLMENT RESTRICTION POLICY • CONDITIONAL ACCESS POLICY (AZURE AD) • COMPLIANCE POLICY • CONFIGURATION POLICY (DEVICE RESTRICTION POLICY) • RESOURCE POLICY (WI-FI, VPN PROFILES)
  • 9.
  • 10.
  • 11.
    INTUNE R &R? • USER MANAGEMENT • APPLICATION CREATION AND DEPLOYMENT/ASSIGNMENT • SERVICE ADMINISTRATION • MOBILE APPLICATION MANAGEMENT • DEVICE/PROFILE MANAGEMENT • CONDITIONAL ACCESS • COMPANY RESOURCE ACCESS • SOFTWARE UPDATE MANAGEMENT

Editor's Notes

  • #3 http://www.youtube.com/c/AnoopCNairSCCM www.anoopcnair.com @anoopmannur
  • #4 https://www.anoopcnair.com/newbies-intune-bible-to-learn-mobile-device-management/
  • #5 Industry Road Map, Microsoft Roadmap ,Modern Apps, SaaS Apps, Self Service New challenges - Better end user experience Simpler management More secure Lower TCO https://www.anoopcnair.com/newbies-intune-bible-to-learn-mobile-device-management/
  • #6 As I mentioned in the previous slide – Modern management would like to provide self service options. If you are not doing self service then, Skip steps 1, 2 and 3 https://www.anoopcnair.com/newbies-intune-bible-to-learn-mobile-device-management/
  • #7 As I mentioned in the previous slide – Modern management would like to provide self service options. If you are not doing self service then, - Skip steps 1, 2 and 3 UNIFIED ENDPOINT MANAGEMENT Android, iOS and Mac OS – Using Company Portal Application Windows 7 – Intune Client
  • #8  The Mobile Device Management (MDM) authority determines whereyou will perform mobile device management tasks. Microsoft provides 3 options to set the MDM authority. Microsoft Intune by using the Intune Azure console, or to SCCM by using the SCCM CB console. https://www.anoopcnair.com/newbies-intune-bible-to-learn-mobile-device-management/
  • #9 This is for MDM way of managing Intune First you hit Enrolment Restrictions policies – Check whether it’s matching requirements of enrolment restriction rules
  • #11 https://www.anoopcnair.com/start-troubleshooting-intune-policy-deployment-issues/
  • #12 https://www.anoopcnair.com/intune-teams-roles-responsibilities/
  • #13  SQL Always On Availability Group for site database recovery Offload all the roles from Primary like MP, SUP, DPs, SMS provider? SQL on remote box with SQL Always On Availability Group Best Practice is to avoid installing IIS on primary servers to reduce the load