This document summarizes an Enterprise Mobility Suite roadshow presentation. It discusses key topics like why mobile management is important, what EMS is and why enterprises need it, and how to configure and get started with EMS. The presentation provides an overview of EMS components like Microsoft Intune, Azure Active Directory Premium, and Azure Rights Management. It demonstrates how to set up subscriptions, configure Azure AD sync, enroll devices, and manage settings and applications with Intune.
5. Demo Environment
Powered by Hyper-V in the Cloud
DC01
Domain Controller
DNS Server
DHCP Server
CLIENT02
Windows 10 TP
CM01
SQL 2012
ConfigMgr 2012 R2
CLIENT01
Windows 8.1
MDT01
8. • SCCM is undisputed winner
of PC Mgmt w/ >70% share
• You need to look into a MDM
solution today
• We believe Microsoft is the
long-term winner
Growth is all in Mobile Devices
349 315 296 294 293 292
725
1,010 1,131
1,283
1,434
1,579
162
231
270
308
340
368
0
500
1,000
1,500
2,000
2,500
1 2 3 4 5 6
Series3 Series2
Series1
Devices Shipments (MM)
Source: IDC
20. Azure AD Sync and ADFS
Connect your Active Directory to the Cloud
21. Domain, DNS, and UPN management
21
Tony Allen
tonyallen@contoso.com
Add external
domain
contoso.com
tonyallen@contoso.onmicrosoft.com
Tony Allen
tonyallen@contoso.com
tonyallen@contoso.onmicrosoft.com
Add UPN suffix to
Active Directory
contoso.onmicrosoft.com
Change UPNs toSynchronise with
Directory synchronization
Alternative approachRecommended option
User name
and UPN
must match
Active Directory Windows Azure AD
contoso.onmicrosoft.comcontoso.com Default domain
Default UPN suffix
Domain name
@contoso.com @contoso.onmicrosoft.comAccounts created as
34. Enrolling Devices
Users can enroll devices that configure
the device for management with Windows
Intune; the user can then use the
Company Portal for easy access to
corporate applications
Data from Windows Intune is in
sync with Configuration Manager,
which provides unified
management across both on-
premises and in the cloud
Dirsync
w Pwd Sync
Connector
Internal
Connector
35. Expanding device support with Workplace Join
Limited access
No IT Control
Active Directory
Not Joined to AD Workplace Joined Domain Joined
38. Mobile Device – Personal vs Corporate
App Management
By default, user-enrolled devices are “Personal”
Complete inventory of all Apps on the device only when set to Corporate
Only the admin can specify corporate-owned devices !
Personal
vs.
Corporate Owned
Devices
56. VPN Profile Management
DNS name-based initiation support
for Windows 8.1 and iOS
Application ID based initiation
support for Windows 8.1
Automatic VPN
connection
Support for VPN standards
SSL VPNs from Cisco, Juniper,
Check Point, Microsoft, Dell
SonicWALL, F5
Subset of vendors have Windows
VPN plug-in
PPTP ,L2TP, IKEv2
Support for Major SSL
VPN Vendors
57. Wi-Fi and Certificate Profiles
Manage and distribute certificates
Deploy trusted root certificates
Support for Simple Certificate Enrollment Protocol (SCEP)
Manage Wi-Fi protocol and authentication settings
Provision Wi-Fi networks that device can auto connect
Specify certificate to be used for Wi-Fi connection
Wi-Fi Settings
78. Work Folders
Simple access to corporate data
• Enable offline access to files and folders stored on a Windows Server 2012 R2 file server
• Simple Group Policy configuration for domain-joined computers, with easy discoverability
for BYOD systems, as well
• Leverages web protocols (HTTP) for easy synchronization through firewalls
• A complement to OneDrive and OneDrive for Business