7. The How
Intune web console
Mobile devices and PCs
IT
ConfigMgr console
Microsoft Intune
Mobile devices
System Center
ConfigMgr
IT
Domain joined PCs
ConfigMgr integrated with Intune (hybrid)Intune standalone (cloud only)
Microsoft Intune
System Center Configuration Manager
with Microsoft Intune
Build on existing Configuration Manager
deployment
Full PC management (OS Deployment,
Endpoint Protection, application delivery
control, rich reporting)
Deep policy control requirements
Scale to 100,000 devices
Extensible administration tools (RBA,
PowerShell, SQL Reporting Services)
Cloud-based Management
Microsoft Intune
No existing Configuration Manager
deployment
Simplified policy control
PC+MDM: 4K users, 6K PCs, and 7K devices
MDM Only: 25k users and 50k mobile
devices
Simple web-based administration console
9. Microsoft Cloud
3rd Party SaaS Apps
On Premises Apps
Microsoft Azure
Monitor users /
prevent data leak
Block various actions
Restrict download
Enforce MFA
Block sign-in
Allow sign-in
Access Control
Session Restrictions
OS Platform
Is Compliant / Domain joined
Is lost or stolen
Device Risk
Device
User identity
Group membership
Session Risk
User
Mobile or Cloud app
Per app policy
App
Location
IP range
Country / Region
ApplicationsPolicy Controls
Conditional Access
Policy Conditions
Windows
Defender
Azure AD
Identity
Protection
Service
Microsoft
Cloud App
Security
ODSP limited
access
15. EMS + Jamf
Intune device compliance for Jamf managed Macs
8. Block access from
noncompliant devices
7. Allow access from
compliant devices
4. Intune evaluates compliance
Microsoft EMS
9. User-friendly remediation
experience provided by Intune and
Jamf
2. Mac is registered with Intune
6. Azure AD enforces Conditional
Access
1. Mac is managed by Jamf Pro
3. Jamf sends macOS device
inventory to Intune
5. Generates compliance report
Intune Azure AD
16. Traditional Windows deployment // The old way
Build a custom image,
gathering everything else
that’s necessary to deploy
Time means money, making
this an expensive proposition
Deploy image to a new
computer, overwriting what
was originally on it
DRIVERS POLICIES
OFFICE & APPS
SETTINGS
17. Modern Windows deployment // The new way
Un-box and turn on
off-the-shelf Windows PC
Device is ready
for productive use
Transform with minimal
user interaction
20. Intune Win32 Software Distribution
PowerShell Scripts
Mobile MSI
Limited to single file MSI for
Win32 apps
Challenge for customers to deploy
complex Windows apps
PowerShell Scripts
Mobile MSI
MSI, EXE, MSP
Leverage MSIX packaging tool to convert your
existing Win32 apps to MSIX
Use new Intune capability to directly deploy Win32
apps (MSI, EXE and MSP/MST)