Showing posts with label intune. Show all posts
Showing posts with label intune. Show all posts

Wednesday, May 11, 2016

Why manage Mobile Devices?


There are many blogs and news articles about which solution is better but very few talk about the Why?  Let’s not start into the debate of the BYOD (Bring Your Own Device) question.  Let’s look more fundamentally at the “why” part.

Companies are anxious about viruses, lost laptops and data breaches but this landscape was never thought of until well after ARPANET started to connect machines in 1969.  It was believed that everyone would work together and security was not well thought of at the time.  Later they started to inflict rules and policies like, don’t send personal data or personal emails over the network.  It was when Morris created what would be later known as the first worm in 1988 and released it to gauge the depth of the Internet and wreaked havoc on the machines that everyone took a serious view of why we need to protected the landscape and write better code.  We have now seen the ability to crash an IPHONE with a special Text message.  What is next?

Why do we want mobile device management?

Control over:

  • Upgrades of Operating System
  • Software install/upgrade of applications
  • Access, Policy and settings
  • Geo-fencing of data or applications
  • What about what we haven’t thought of?

This is just a small view of what companies want to control.  If there is a vulnerability in the OS of the device, grant them control of what do to: Upgrade the device, lock it down, etc.  Everyone wants to protect the company.  I am not going to move into the “user rights vs company protection”. 

You can see many of the desktop management slowly moving to the mobile devices such as policy restrictions, software installs or upgrades.

Let’s think further down the road why it is important to manage not just the mobile devices we carry in our pocket but the IoT (Internet of Things) that run our lives!

Just as you now have A/C, washer, sprinkler service areas, you will soon have more of an IT service personnel at your house making sure they all talk to each other and the “central office”.  No longer will you just have the IT repair person come fix your computer nor will you take your machine to the store to be fixed.  You will have them come in and perform an inspection, yearly or monthly maintenance on devices that control your life.  Each one of your devices might require software, firmware, or possibly even a chip/board upgrade to keep your house secure and compliant.  You don’t want someone hacking your thermostat to gain access to your electronic safe or worse, turn off the security system, open the garage door and walk in.

It is important that all companies and even individuals look in to management of Internet based devices.  Soon the consumer might need to manage their other devices much like they do their car, A/C unit and other “maintenance required” equipment, only this time it is an electronic device interacting with other devices and possibly the Internet.

Embrace device management, no matter if you’re an individual, big or small company.  I look forward to the protection and management of all devices.

This is why Microsoft increased the cadence of Software releases and is slowly adding features to Intune. 

Check out the April 2016 feature list:

Thursday, July 9, 2015

Magic Quadrantfor MDM, 2015

When you think of Garter, you think of the "Magic Quadrant".  This is the top right corner where the big leaders are sitting.  Many won't buy a product unless they see you in the square. 
Microsoft recently submitted their entry to the MDM Review.


Main report here:
http://www.gartner.com/technology/reprints.do?id=1-2HIRGAD&ct=150609&st=sb


Microsoft is not in the top right but they have some strong advances.
One weakness described is the lag behind of the on-prem SCCM link to Intune.  Microsoft is working on this and we should see it in the next rounds of updates Microsoft is releasing.  If you have been watching, Microsoft has starting using a quicker cadence in updates/fixes/upgrades for SCCM as well as Intune.  I would expect the Microsoft will be in the magic quadrant in the next round of reviews.



Microsoft

Microsoft's EMM product is the Enterprise Mobility Suite (EMS), which includes Microsoft Intune, Azure Active Directory Premium and Azure Rights Management. Microsoft Intune provides the core EMM capabilities of MDM and MAM. Intune's strengths are its support of Office 365 and integration of System Center Configuration Manager (ConfigMgr). Microsoft also recently developed a secure PIM capability based on the Outlook mobile app for iOS and Android. This will rival secure PIM offerings available from other EMM vendors. While the end-user functionality of the Outlook mobile app looks compelling, it was not generally available at the time of this report. The EMS represents a comprehensive mobility security and management vision, and it positions Microsoft well for the future in this market. Currently, Intune adoption is low, and the product is still maturing. Organizations that should consider Intune are those that want to extend the Office 365 services to mobile devices and ConfigMgr customers that value client management and EMM integration over best-of-breed EMM functionality.
Strengths
  • Intune has unique technical capabilities to manage the Office Mobile apps on iOS and Android devices, including "conditional access," app-level authentication and copy/paste control.
  • The Intune license includes entitlement to ConfigMgr, allowing organizations to manage PCs and mobile devices through the same license and console.
  • The combination of Azure Active Directory Premium, Azure Rights Management and Intune addresses some useful mobile scenarios, for example, changing an Active Directory password from a mobile device.
Cautions
  • Intune has two modes: "standalone" and "hybrid" with ConfigMgr. The "hybrid" mode creates dependencies between Intune and ConfigMgr. Advanced administrative functionality requires Intune to be connected to ConfigMgr. However, new Intune functionality is not immediately available when Intune is connected to SCCM, and changes to ConfigMgr can affect its ability to work with Intune. The next major version of ConfigMgr plans to address this issue.
  • Intune supports most of the generic Android MDM APIs, as well as some Samsung Knox capabilities. It does not support MDM APIs of Android for Work or other handset manufacturers (such as LG and HTC).
  • Intune's MAM has limited compatibility with third-party mobile application development tools, and it is behind most competitive products on containerization and analytics features.

Monday, June 15, 2015

Make your voice heard

Microsoft has several ways to pull in feedback, MVPs, forums, Microsoft Connect.  Here is another method to interact with Microsoft without having to fill out the complex Design Change Request.

Ask Microsoft what you would like to see or vote (up to 10x) on a topic.  If that topic is already in production or complete then your vote should be turned back to you to use again. 
Remove and change your votes as new ideas are submitted:


Here’s how it will work:

For ideas/DCRs only (no bugs) for Configuration Manager:


 

For Intune standalone, and ConfigMgr+Intune hybrid MDM (Bugs and DCRs):

Wednesday, March 4, 2015

Intune update for March coming this week!

Today Microsoft announced the next update to the Microsoft Intune cloud service for mobile devices:
http://blogs.technet.com/b/microsoftintune/archive/2015/03/04/march-updates-coming-this-week-to-microsoft-intune.aspx

Updates include:
  • Ability to streamline the enrollment of iOS devices purchased directly from Apple or an authorized reseller with the Device Enrollment Program (DEP)
  • Ability to restrict access to SharePoint Online and OneDrive for Business based upon device enrollment and compliance policies
  • Management of OneDrive apps for iOS and Android devices
  • Ability to deploy .appx files to Windows Phone 8.1 devices
  • Ability to restrict the number of devices a user can enroll in Intune

  • These updates are for the cloud only service.  If you are using the Hybrid or "Unified" approach which has Intune integrated into your SCCM console then you will see the following changes:

    •  create custom WiFi profiles with pre-shared keys (PSK) for Android devices

    Microsoft, as you have seen over the last year, has increased the cadence at software distribution. None is so apparent as the Intune updates.  If we simply look at Intune from where it started several years ago to today is had greatly improved and is now in the running with other Mobile Device vendors.

    Items that I would like to see in Intune is the ability to run it on Server class machines so that small companies can fully utilize the cloud based solution.  I can see Intune Partners or Vendors managing large number of small companies completely from Intune.  Then when a new version of Java is deployed all the small companies can pilot and then opt in and recieve it. 

    The one problem is that Inune is individual tenant based and we need to look at a "Intune console" similar to what you have in SCCM to manage different site codes, collection of systems in order to manage all the companies effectively as many branches of a single company depending on what the deployment. 

    While each "branch" might have a different need, this can be handled by the branch admins or even by the Intune Partner. 

    Just some thoughts......

    Monday, November 17, 2014

    Microsoft Intune new wave hitting this week

    Microsoft has come a long way in the last year.  They are poised to definitely take on other MDM and MAM vendors.  One of the latest changes was to break away from the Windows Intune in favor of the Microsoft Intune.  Because Intune can do more than just Windows (IOS, Android, etc) it is only natural

    Some of the newest changes are listed here:
    • Enhanced user interface for Intune administration console
    • Ability to restrict access to Exchange on-premises email based upon device enrollment
    • Bulk enrollment of devices using a single service account
    • Lockdown of Supervised iOS devices and devices using Samsung KNOX with Kiosk mode
    • Targeting of policies and apps by device groups
    • Ability to report on and allow or block a specific set of applications
    • Enforcement of application install or uninstall
    • Deployment of certificates, email, VPN and WiFi profiles
    • Ability to push free store apps to iOS devices
    • More convenient access to internal corporate resources using per-app VPN configurations for iOS devices
    • Remote pin reset for Windows Phone 8.1 devices
    • Multi-factor authentication at enrollment for Windows 8.1 and Windows Phone 8.1 devices
    • Ability to restrict administrator access to a specific set of user and device groups
    • Updated Company Portal apps to support customizable terms and conditions





    for more information see the entire Microsoft Blog post here: http://blogs.technet.com/b/microsoftintune/archive/2014/11/17/new-microsoft-intune-capabilities-coming-this-week.aspx

    Sunday, July 18, 2010

    Windows Intune

    For those that are familiar with the Cloud Computing innovative, Microsoft is placing the ability to manage a computer into the cloud. Much like Configuration Manager but in the cloud. Now Microsoft can handle your hardware and you can work on the managment side. This is nice for the company that has 50 people and they are in 3 different cities. No longer do you need to setup a System Center Essentials server or use another program that requires servers and licenses you might need. With Intune you can manage the machines from anywhere. This is great for the small companies or consultants that need to manage several small companies

    http://www.microsoft.com/online/windows-intune.mspx

    The open Beta #2 was released last week. When the first beta was annouced it filled up in less than a day if I recall correctly. Here is your chance to test drive this nice application. You will need to manage at least 5 machine but you cannot manage more than 25 via this beta.