This document discusses managing Microsoft Surface Hub devices using modern management tools. It introduces Microsoft Intune for provisioning and managing devices from the cloud without needing on-premise servers. It also discusses using Azure Active Directory for identity-driven security and management of Windows 10 devices. The document provides overviews of Upgrade Analytics, Microsoft Operations Management Suite, and Windows Store for Business as additional tools for managing the Microsoft Surface Hub and Windows 10 environment.
2. Per Larsen
Solution Architect, Technical Lead Microsoft Enterprise Mobility Suite (EMS) and
Microsoft Partner Technology Solutions Professional (P-TSP)
Co-Owner of Everything Windows User Group Denmark
e: per.larsen@atea.dk | m: +45 3078 1828 | t: @PerLarsen1975
in: www.linkedin.com/in/perlarsen1975 | Blog: osddeployment.dk
7. Users Apps
Windows has evolved. Simplify management and lower TCO.
Provisioning
Simplify device enrollment and
configuration for corporate- and
employee-owned devices.
Get work-ready devices
customized to your needs
directly from suppliers
without gold images.
Modern management & security
Lower your total cost of ownership (TCO)
while simplifying how you manage your
Windows 10 environment.
Cloud-delivered updates
Maintain control and keep devices up to
date on your schedule - from the cloud.
IT
Policies
Procurement
Spend more time managing and
less time imaging.
Cloud updates mean you don’t
need to have on-premise
update servers.
Microsoft
Cloud
Windows 10
EM
S
Windows
10
Contoso
Corp.
Sign in
Username
Password
Physical smart cards
Certificate
Virtual smart card
Agentless
management
Integrated data
protection
Identity-driven
security
Deploy apps, policies, profiles, and security
settings without IT having to touch the device.
Automatically configure devices when your users
login with their corporate credentials.
Control what
updates are
deployed, to
whom and when.
microsoft.com/intune
16. Microsoft Azure Active Directory (AAD)
Bringing the cloud to Windows desktops
• Windows 10 is build for Microsoft Azure
• It's not a strong relationship yet, more of a fling…
• But it's worth looking at now, as it's going to be a big growth area
• Windows 10 can join Azure AD instead of a on premise AD
If you have Office 365, you already have an Azure AD domain
18. Microsoft Azure Active Directory (AAD)
Windows 10 will be powered by Azure AD, giving you options for:
• Self-provisioning of corporate owned devices
• Use existing organizational accounts
• Single Sign-On
• Automatic MDM enrollment
• Enterprise-ready Windows Store
• Enterprise State Roaming
• Store BitLocker Keys in Azure AD
• New Azure AD portal
EWUG 1701 - Modern Device Management – http://www.ewug.dk
About the presenter:
Please do not hesitate to ask questions during the presentation, we will have a Q&A at the end of the presentation but I prefer a open dialog and see where it will take us
About me:
Solution Architect, Technical Lead Microsoft Enterprise Mobility Suite (EMS) and Microsoft Partner Technology Solutions Professional (P-TSP)
Co-Owner of Everything Windows User Group Denmark
Find me:
E-mail: per.larsen@atea.dk
Phone: +45 3078 1828
Follow me:
Twitter: https://twitter.com/perlarsen1975/
LinkedIn: https://www.linkedin.com/in/perlarsen1975/
Join me:
Everything User Group Denmark: http://ewug.dk
#UpgradeYourWorld
It has been a journey, with lot’s of up’s and down’s and still is!
Let me introduce you to Tom and Bob…
The Windows 10 eco-system
For a successful implementation of Windows 10, a clear Workstyle Strategy is essential.
Do you have a Work style Strategy?
Do you have a Work place Strategy?
Do you have a BYOD strategy?
Do you have a Virtual Desktop Infrastructure strategy?
Devices
Do you have a (one) Device Strategy?
Windows 10
Do you have a OS Strategy?
Cloud
Do you have a Cloud Strategy?
Microsoft Azure AD
Office 365
Windows 10, one Windows across all devices
Let’s try to contextualize the achievement of Windows 10 being a converged platform for Microsoft.
Windows has been synonymous with a PC. However, as this slide illustrates, Windows devices are no longer just the realm of PCs – from IoT to Perceptive Pixel Interfaces (PPIs).
Reduce CTO
Hybrid – Cloud only
Enterprise Mobility + Security
Windows licens management
Simple Application deployment needs
Simple management needs
Not for all devices
Learn more at microsoft.com/intune
Windows 10 is born for Modern Management
Live Demo
Microsoft Azure Active Directory
Microsoft Azure Active Directory (AAD)
Windows 10 likes Microsoft Azure
It's not a strong relationship yet, more of a fling…
But it's worth looking at now, as it's going to be a big growth area
Windows 10 can join Azure AD instead of a on premise AD
If you have Office 365, you already have an Azure AD domain ("Azure AD tenant" is the official phrase)… you've just need to claim it.
Microsoft Azure Active Directory (AAD)
Microsoft Azure Active Directory | Bringing the cloud to enterprise devices
Windows 10 will be powered by Azure AD, giving you the options for:
Self-provisioning of corporate owned devices. With Windows 10, employees can configure a brand new device in the out-of-box experience, without IT involvement.
Use existing organizational accounts. Employees can use their Azure AD account to login to Windows (the same account they use to sign into Office365).
Automatic MDM enrollment. Windows 10 PC's and tablets can be automatically enrolled in an organizations device management solution as part of joining them to Azure AD. This will work with Microsoft Intune and with 3rd party MDMs.
Single Sign-On to company resources in the cloud. Users will get single sign-on from the Windows desktop to apps and resources in the cloud, such as Office 365 and thousands of business applications that rely on Azure AD for authentication.
Single Sign-on on-premises: Windows 10 PC's and tablets that are joined to Azure AD will also provide SSO to on-premises resources when connect to the corporate network and from anywhere with the Azure AD Application Proxy.
Enterprise-ready Windows store. The Windows Store will support app acquisition and licensing with Azure AD accounts. Organizations will be able to volume-license apps and make them available to the users in their organization.
Support for modern form factors. Azure AD Join will work on devices that don't have the traditional domain join capabilities.
Enterprise State Roaming. Things like OS settings, Desktop wall paper, Tile configuration, websites and Wi-Fi passwords will be synchronized across corporate owned Azure AD joined devices.
http://blogs.technet.com/b/ad/archive/2015/05/13/azure-active-directory-and-windows-10-making-the-enterprise-cloud-a-reality.aspx
About AzureAD| What's new
Microsoft Upgrade Analytics
The Windows Upgrade Analytics Service uses telemetry data to provide powerful upgrade readiness insights and recommendations about the computers, applications and drivers in your organization. This new service guides you through upgrade projects using a workflow based on Microsoft recommended practices. Up-to-date inventory data allows you to balance cost and risk in your upgrade projects.
http://oms.Microsoft.com
Microsoft Windows Store for Business
The one stop Store for Windows 10 Devices
Microsoft Windows Store for Business
The one stop Store for Windows 10 Devices
Designed for organizations
The Windows Store for Business is the place where IT decision makers and administrators find, acquire, manage, and distribute apps to Windows 10 devices.
Find and acquire
Quickly and easily find the right apps for your teams. Acquire apps individually or in volume.
Manage
Manage your organization’s inventory of apps in one place. You can assign, reclaim, or reassign licenses as well as control updates.
Distribute
Choose from scalable distribution options.
Using accounts assigned by your organization, directly provide apps to individuals and groups, or let employees find apps in your private store.
Connect your management server for more options.
Managing computers not connected to the internet? Distribute offline-licensed apps.
Let’s have a closer look: Microsoft Windows Store for Business
https://businessstore.microsoft.com/
https://www.microsoft.com/business-store/
https://www.microsoft.com/en-us/business-store/
Microsoft Windows Store for Business
The one stop Store for Windows 10 Devices
Microsoft Windows Store for Business
The one stop Store for Windows 10 Devices
Designed for organizations
The Windows Store for Business is the place where IT decision makers and administrators find, acquire, manage, and distribute apps to Windows 10 devices.
Find and acquire
Quickly and easily find the right apps for your teams. Acquire apps individually or in volume.
Manage
Manage your organization’s inventory of apps in one place. You can assign, reclaim, or reassign licenses as well as control updates.
Distribute
Choose from scalable distribution options.
Using accounts assigned by your organization, directly provide apps to individuals and groups, or let employees find apps in your private store.
Connect your management server for more options.
Managing computers not connected to the internet? Distribute offline-licensed apps.
Windows Store for Business
Inject them into images as we've done with Desktop apps
Familiar tools: dism.exe, PowerShell (new noun: AppxVolume); MDT 2013 Update 2, System Center Configuration Manager via updates and then whatever ships with Windows Server 2016
They can be sysprep’ped
When the user first starts up, the app looks for a license and potentially whether that user is approved for the APP
All centrally controlled
Still have "deep links" as a deployment method as well
Let’s have a closer look: Microsoft Windows Store for Business
https://businessstore.microsoft.com/
https://www.microsoft.com/business-store/
https://www.microsoft.com/en-us/business-store/