Modernizing Windows Management With Configuration Manager And Intune

1m ago
1 Views
0 Downloads
3.27 MB
62 Pages
Last View : 26d ago
Last Download : n/a
Upload by : Noelle Grant
Transcription

WORKPLACEModernizingWindowsManagementwith ConfigurationManager and IntuneKent AgerlundPeter Daalmans

WORKPLACEKent @AgerlundPrincipal Consultant @CTGlobalEnterprise Mobility MVP &Microsoft Regional Director

WORKPLACEPeter DaalmansSenior Consultant @ CTGlobalEnterprise Mobility MVPpds@ctglobalservices.com@pdaalmans

WORKPLACESession Objectives Understand the benefits of modernizing Windowsmanagement Immediate benefits of extending SCCM to thecloud Conditional Access for SCCM managed PCs Modern provisioning with Intune and AutoPilot And moreLearn about what’s coming

WORKPLACEBusinesses requirepowerful devicemanagement toolsMore than 115M enterpriseWindows devices managed byConfiguration Manager CurrentBranchA commercial PC isupgraded to Win10 viaConfigMgr every0.98son average

WORKPLACEChanges in technology and theworkplace introduce newmanagement challengesUsers working from anywhereUsers want to choose the technology they work withAdvanced security threatsCadence changes for Windows and OfficeCloud infrastructure opportunities

WORKPLACEComplement existing tools by lighting up cloud valueModern ProvisioningIntegrated AccessControl, Security, andComplianceSimplified AppManagementAutomated UpdateLowerInfrastructure costs

WORKPLACECloud Enlightened Management FeaturesModern ProvisioningSimplified AppManagementIntegrated AccessControl, Security, andComplianceLowerInfrastructure costsAutomated Update Protect corporatedata - ConditionalAccess for PCs Make any new PCenterprise-ready viaa simple self-serviceexperience. Simplify updatedeployments withcloud insights Manage StoreApplications andconvert existingapplications Manage clients overthe internet Protect againstadvanced threats Lower TCO forsingle purposedevices Keep Windows upto date from thecloud Conditional Accessfor SCCM managedapps Azure hostedmanagement andidentity Control remote PCswith wipe, scan, andother commands Troubleshoot youremployee’s PCsanywhere

WORKPLACECloud Enlightened Management FeaturesModern ProvisioningSimplified AppManagementIntegrated AccessControl, Security, andComplianceLowerInfrastructure costsAutomated Update Protect corporatedata - ConditionalAccess for PCs Make any new PCenterprise-ready viaa simple self-serviceexperience. Simplify updatedeployments withcloud insights Manage StoreApplications andconvert existingapplications Manage clients overthe internet Protect againstadvanced threats Lower TCO forsingle purposedevices Keep Windows upto date from thecloud Conditional Accessfor SCCM managedapps Azure hostedmanagement andidentity Control remote PCswith wipe, scan, andother commands Troubleshoot youremployee’s PCsanywhere

WORKPLACEIntegrated Access Control,Security, and Compliance

Control data accessWORKPLACEUserGroup membershipsAuth strength (MFA)Risky behaviorDeviceManaged (Intune or CM)CompliantRisky behaviorAppMobile app is managedMobile app reputationSaaS app sensitivityConditional accesswith EMSOtherNetwork locationBreach detectedOn-premise data

WORKPLACERoadmapIntelligent Security – Conditional Accessbased on Device Risk signals fromDefender ATP Currently in public preview

WORKPLACEINTUNE ONAL ACCESSSTOP O365 ACCESSWDATP CONSOLETHREATDETECTED

WORKPLACEGoal: Ensure only trusted and secure Win10 devices have access tocorporate data.INTUNE CCESSALERT OR HEXADITE REMEDIATIONSECOPSCONDITIONAL ACCESSEMAIL ACCESSWDATP CONSOLETHREATMALWAREDETECTEDREMEDIATED

WORKPLACEHow Microsoft Delivers Integrated AccessControl, Security, and ComplianceProtect corporate data - Conditional Access for PCsIntune, AAD, O365Protect against advanced threatsIntune, ATP

WORKPLACEModern Provisioning withIntune and AutoPilot

WORKPLACESETTINGSTraditional PC provisioningTimePOLICIES OFFICEAPPS& DRIVERSMoney

WORKPLACEModern PC provisioning

WORKPLACEVision

WORKPLACEBrad, your new Surface Laptop has arrived.It’s time for unboxing

WORKPLACEOOBE Challenges Non-trivial decision making (Personal vs Org Owned disambig,Privacy Settings, OEM Registration) generates Helpdesk calls Time for configs and apps to install. Block access, show progress OOB account is always Admin – majority of enterprises wantstandard accounts on corp-owned devicesANNA hipDeliver direct to EmployeeOff-the-shelf and Shrink-wrapped DevicesEmployee unboxesdevice, self-deploys

WORKPLACEWINDOWS AUTOPILOTMicrosoft Intune with AutoPilotConfigureAutoPilot ProfileUploadDevice IDsHarvest Device IDsDevice IDsOEM/ResellerExisting DevicesSelfDeployIT AdminShipDeliver direct to EmployeeEmployee unboxesdevice, self-deploys

WORKPLACEWINDOWS AUTOPILOTMicrosoft Intune with AutoPilotConfigureAutoPilot ProfileUploadDevice IDsSelfDeployDevice IDsOEMIT AdminShipDeliver direct to EmployeeEmployee unboxesdevice, self-deploys

WINDOWS AUTOPILOTWORKPLACEAutoPilot ServiceSyncHarvest Device IDsIntune ServiceUploadDevice IDsConfigureAutoPilot ProfileOEMSelfDeployExisting Enrolled DevicesIT AdminShipDeliver direct to EmployeeEmployee unboxesdevice, self-deploys

WORKPLACEOEM support for Windows Autopilot

WORKPLACE1803 aka RS4 aka build 17134aka latest Windows 10experience

WORKPLACE

WORKPLACELet’s start with region. Is this right?United Arab EmiratesUnited KingdomUnited StatesYes

WORKPLACEIs this the right keyboard layout?USUnited States-Dvorak for left hand DVORAK LUnited States-Dvorak for right hand DVORAK RUnited States-International QWERTYAlbanian QWERTZYes

WORKPLACEWant to add a second keyboard layout?Add layoutSkip

WORKPLACELet’s connect you to a networkContosoMNGuestWiFiConnect automaticallyConnectContoso CorpContoso Corp 2Network4Skip for nowNow let's get you connected to a network. That way you get updates, apps and cat videos as soon as possible. How about thefirst one on the list? Want to use that one?

WORKPLACELet’s connect you to a networkContosoMNGuestWiFiConnect automaticallyConnectContoso CorpContoso Corp 2Network4Skip for nowNow let's get you connected to a network. That way you get updates, apps and cat videos as soon as possible. How about thefirst one on the list? Want to use that one?

WORKPLACEWelcome to our Guest Wi-FiAgree & ConnectBy clicking on the connect button you agree to our Termsof Service and have reviewed the Contoso Privacy Policy.

WORKPLACEWelcome to our Guest Wi-FiAgree & ConnectBy clicking on the connect button you agree to our Termsof Service and have reviewed the Contoso Privacy Policy.

WORKPLACEJust a moment

WORKPLACENow we can go look for any updates

WORKPLACEWelcome to ContosoMN!Enter your ContosoMN emailsomeone@example.comNeed help?Please sign in with your ContosoMN email addressChange accountPrivacy & CookiesTerms of UseNext

WORKPLACEWelcome to ContosoMN!Enter your ContosoMN emailanna@contosomn.comNeed help?Welcome to ContosoMNChange accountPrivacy & CookiesTerms of UseNext

WORKPLACEWelcome to ContosoMN!Enter your ContosoMN password .Need help?Welcome to ContosoMNChange accountPrivacy & CookiesTerms of UseNext

WORKPLACESetting up your device forThis could take a while and your device may need to reboot.workDevice preparation Show detailsDevice setup Show details

WORKPLACESetting up your device forThis could take a while and your device may need to reboot.workDevice preparation Show detailsDevice setup Show details

WORKPLACESetting up your device forThis could take a while and your device may need to reboot.workDevice preparation Show detailsDevice setup Show details

WORKPLACEWe’re getting everything ready for you

WORKPLACEThis will just take a moment

WORKPLACELeave everything to us

WORKPLACEAlmost there

WORKPLACESetting up your device forThis could take a while and your device may need to reboot.workDevice preparation Show detailsDevice setup Show detailsAccount setup Show details

WORKPLACESetting up your device forThis could take a while and your device may need to reboot.workDevice preparation Show detailsDevice setup Show detailsAccount setup Show details

WORKPLACESetting up your device forThis could take a while and your device may need to reboot.workDevice preparation Show detailsDevice setup Show detailsAccount setup Show details

WORKPLACEWe’re getting everything ready for you.

WORKPLACEThis might take several minutes.

WORKPLACEWe want everything to be ready for you.

WORKPLACELet’s Start!

WORKPLACEModern Provisioning –phases & componentsAutoPilotAzure ActiveDirectoryCustomize OOBEIntune/SCCMAuto-enroll into IntuneRemove AdminsAzure AD AuthNPre-MDM SettingsConfigure Policies, SettingsAzure AD JoinInstall SCCM agent for Co-MgmtOffice, SfB, WUfBInstall Office 365SfB AppsConfigure UpdatesWindows ActivationStep Up from Windows Pro toWindows EnterpriseBusiness ReadySelf-driven deployment

WORKPLACEWhat’s coming Autopilot Self-Deploying modeAutopilot ResetAutoPilot into Hybrid AADJWin7 - Win10 “rip and reuse”Forced enrollmentRemove OEM bloatwareAuto-register enrolled devices into AutoPilotBlock personal devicesDevice renaming w/out rebootUser personalization

WORKPLACEco-management

WORKPLACECo-management requirements & BenefitsRequirements Devices joined to AD andAzure AD.Enable automatic MDMenrollment for Windows 10Intune StandaloneOut of the box benefits Remote actionsFactory resetSelective wipeDelete devicesRestart deviceControlled workloads Compliance policiesResource access policiesWindows Update policiesEndpoint Protection

WORKPLACECloud Management Gateway Requirements & BenefitsRequirementsBenefits Support for Road Warriors Azure subscription Support Windows Autopilot Certificate(s) depends on your choiceFeatures supported Internal PKI, Public provider, AADauthInstall Win10 clients AAD (and most likely AD) UserdiscoveryAzure service for ConfigMgrClient settings Software updates andendpoint definitionInventoryclient activityCompliance settingsSoftware distributionWindows 10 in-place upgradetask sequence

WORKPLACEConfigMgr client cmdCCMSETUPCMD /noCRLCheck/mp:https://VIA166CMG.CLOUDAPP.NET/CCM Proxy MutualAuth/72057594037927965CCMHTTPState 31CCMHOSTNAME VIA166CMG.CLOUDAPP.NET/CCM Proxy MutualAuth/72057594037927965SMSSiteCode PS1SMSMP https://CM02.CORP.VIAMONSTRA.COMAADTENANTID 5172DCF5-EEC5-4E5A-A1A6-499A0EAA9759AADCLIENTAPPID a0107f2f-99a6-47ef-ac36-65acb47214e7AADRESOURCEURI https://ConfigMgrService stallation-propertiesUseful SQL views vProxy Roles (MutualAuthPath) vSMS AAD Application Ex Computer\HKEY LOCAL MACHINE\SOFTWARE\Microsoft\SMS\Client\Internet FacingComputer\HKEY LOCAL MACHINE\SOFTWARE\Microsoft\CCM ProxyServiceNameRoleServerName AppclientID AADRESOURCEURIClient registry keys

WORKPLACECo-Management RoadmapEnable all workloads: Device settingsModern AppsOfficeEnd User PortalSettings baseline exceptions

FUTURE READYSKILLSWORKPLACEDo you want to gain moreknowledge about Microsofttechnology?The Future Ready Skills programoffers online courseware, onlinelabs, live Q&A’s and expertsessions, so you can acquireyour official Microsoft Certificatein the most efficient way.For more information:aka.ms/frsblog

WORKPLACE

Management Integrated Access Control, Security, and Compliance Lower Infrastructure costs Cloud Enlightened Management Features Protect corporate data - Conditional Access for PCs Make any new PC enterprise-ready via a simple self-service experience. Simplify update deployments with cloud insights Manage Store Applications and

Related Documents:

A computer with at least a 450MHz Pentium CPU with 128 MB of RAM, running Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, Windows 8/8.1, Windows 10, Windows Server 2012, Windows Server 2016 or Windows Server 2019 platforms. Instal

Windows 8.1 *6 Windows Server 2003 *7 Windows Server 2008 *8 Windows Server 2012 *9 Mac OS X *10: Supported *1 Printer drivers support both 32-bit and 64-bit Windows. *2 Microsoft Windows XP Professional Edition/Microsoft Windows XP Home Edition *3 Microsoft Windows Vista Ultimate/Microsoft Windows Vista Enterprise/Microsoft Windows Vista Business/

Microsoft Windows 7, 32-bit and 64-bit Microsoft Windows 8 & 8.1, 32-bit and 64-bit Microsoft Windows 10, 32-bit and 64-bit Microsoft Windows Server 2008 R2 Microsoft Windows Server 2012, 64-bit only RAM: Minimum 2 GB for the 32-bit versions of Microsoft Windows 7, Windows 8, Windows 8.1, and Windows 10.

Machine Edition Product Windows 7SP1 Windows 8 and 8.1 Windows 10 QP View Developer - QP Logic Developer – PC - o Windows 7 Ultimate, Windows 7 Enterprise, Windows 7 Professional and Windows 10. Notes The above versions of Windows are supported in both 32-bit and 64-bit. Windows regional settings must be set to English.

- 32 & 64 bit Windows 7, Windows 8 & Windows 10 - 32 & 64 bit Windows 2008 Server - Windows 2008 Server R2 - Windows Server 2012 - Windows Server 2012 R2 - Windows Server 2016 NOTE: Microsoft .Net Framework 4.5 is required on all o

Windows ME, Windows NT 3.51 and 4, Windows 2000 PRO, Windows 2000 Server, Windows XP Home / XP PRO / XP 64bit / Windows 7 (32 & 64bit), Windows Vista (32 & 64bit), Windows 2003 Server and Windows 2008 Server. Design, test, install Surveillance Systems. Design, Build and Sell Forensic Computer Systems.

Oct 16, 2006 · Windows XP & Windows 2000 Users Only Windows XP and Windows 2000 users will see this screen. Click OK to continue. Click OK Windows 98SE Users Only Windows 98SE users will see these screens. Insert your Windows 98 Installation disk into your CD-ROM drive Click Yes Click OK Click OK Enter the location of the Windows 98 setup files (e.g. “ D .

Configuration Management (CM): The systematic evaluation, co-ordination, review, approval or disapproval, documentation and implementation of all proposed changes in the configuration of a product, after formal establishment of its configuration baseline. Configuration Items (CI): Configuration items are the basic units of configuration management.

64-bit Windows 7 64-bit Windows 10 64-bit Windows Server 2012R2, single-user configuration, Service Pack 1 32-bit Windows 7 32-bit Windows 10 32-bit Windows Server 2012R2, single-user configuration, Service Pack 1 CPU Dual core or better Memory 4 GB RAM (or more) HD 40 GB (or more) Monitor 1280 x 1024 x Truecolor (24 million or better)

Several LTSC Windows Server versions that are supported with SC Series are in various phases of mainstream or extended Microsoft support: Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, and Windows Server 2019. Microsoft extended support for Windows Server 2008 R2 is scheduled to end in January 2020.

Windows 10 Home S 64 Entry Season Compact Windows 10 Home 64 Chinese Market CPPP Windows 10 Home 64 High-end Chinese Market CPPP Windows 10 Home 64 Plus Windows 10 Home 64 Plus Single Language Windows 10 Home 64 Plus Single Language Africa Market Windows 10 Home 64 Plus Single Language APAC EM PPP Windows 1

the GUID Partition Table (GPT) scheme, if your Windows installation. . Pro4 Motherboard and a TPM and Windows 10 says Secure Boot Unsupported. . 10/8/7 system, follow the useful solutions to fix UEFI boot on Windows 10. windows loader windows loader unsupported partition table fix Windows Loader 1.9.7 By Daz Windows Loader 1.9.7 By Daz .

Install Easy Interactive Tools 7 Uninstalling Windows Vista/Windows 7 A Click or Start Control Panel Programs and Features. B Select Easy Interactive Tools Ver.X.XX and click Uninstall. Windows 8/Windows 8.1/Windows 10 A Navigate to the Apps screen (Windows 8.x) or click the start icon (Windows 10) and select Windows Control

Mastering the Move to Modern Management using ConfigMgr. . Windows 8 2012 Windows 7 2009 Windows Vista 2006 Windows XP 2001 Windows 95 1995 Windows 3 1992 2014 Enterprise . Client Apps (Windows MSI Line-of-Business) Distribution Points (DPs) BranchCache CDN P2P Cloud

To determine the electron configuration of any of the first 38 elements of the periodic table To determine the identity of an element from its electron configuration To complete an orbital diagram using arrows to represent electrons . . rows on the periodic table .File Size: 863KBPage Count: 31Explore furtherElectron Configuration Chart for All Elements in the .sciencestruck.comElectron configuration of every element in the periodic tablewww.biochemhelp.comElectron Configuration Chart - ThoughtCowww.thoughtco.comList of Electron Configurations of Elementssciencenotes.orgElectron Configuration - Detailed Explanation with Examplesbyjus.comRecommended to you based on what's popular Feedback

Cisco 3560 & 3750 NetFlow Configuration Guide Cisco Nexus 7000 NetFlow Configuration Cisco Nexus 1000v NetFlow Configuration Cisco ASR 9000 NetFlow Configuration Appendix. 8 Cisco NetFlow Configuration Cisco 3560X & 3750X NetFlow Configuration Your software release may not support all the features documented in this module.File Size: 2MB

3. Layer 2 - LAN Switching Configuration Guide 4. Layer 3 - IP Services Configuration Guide 5. Layer 3 - IP Routing Configuration Guide 6. IP Multicast Configuration Guide 7. ACL and QoS Configuration Guide 8. Security Configuration Guide . IP network IRF virtual device IP network IRF link Equal to Master Slave Basic Concepts Role

6. Hyper-V Design Considerations with iSCSI Storage o Hyper-V Windows Configuration for iSCSI o Verifying Multipathing 7. What is Windows Server 2016 Storage Spaces Direct? o Windows Server 2016 Storage Spaces Direct Requirements o Windows Server 2016 Storage Spaces Direct Architecture o Windows Server 2016 SAN vs Storage Spaces Direct 8.

MCTS: Microsoft Windows 7 Configuration Study Guide MCTS: Microsoft Windows 7 Configuring (70-680) Objectives OBJECTIVE CHAPTER Installing, Upgrading, and Migrating to Windows 7 Perform a clean installation. 1 Upgrade to Windows 7 from previous versions of Windows. 1 Migrate user profi les. 1 Deploying Windows 7 Capture a system image. 2

The Windows boot loader, which loads a particular version or configuration of Windows Vista or later versions of Windows. Ntldr, which is the boot loader for versions of Windows earlier than Windows Vista. The resume application, which restores Windows to it