+ All Categories
Home > Technology > Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Date post: 12-Apr-2017
Category:
Upload: windows-developer
View: 186 times
Download: 2 times
Share this document with a friend
36
#Build2016 Managing Windows in an Enterprise: Empower your users & protect your data Janani Vasudevan (@jananivasudevan) Principal Program Manager Lead
Transcript
Page 1: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

#Build2016

Managing Windows in an Enterprise: Empower your users & protect your dataJanani Vasudevan (@jananivasudevan)Principal Program Manager Lead

Page 2: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Why organizations need management

Enable access & productivity for employees

Protect corporate data & resources

Maintain compliance with reporting

Page 3: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Windows 10 management options

Group PolicySystem Center Config

Mgr

MDM[Microsoft Intune or

3rd party]

MDM[Microsoft Intune or

3rd party]

Domain joined

Azure AD joined

COMPANY OWNED PERSONALLY OWNED

New policies New configuration policies

New config via WMI bridge

Azure AD account added

New configuration policies

Page 4: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Management for every Windows device

Page 5: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Modern management architecture

MDM Configuration Service Providers (CSP)

Device

WMI provide

r

Common component PC component

Common Device Configurator

EAS ClientMDM Client

Service/Server

Provisioning Engine WMI Bridge

EASProvisioningMDM ConfigMgr

Page 6: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Enterprise Management

Setup device for work

Productive at work

Productive on the go

Device & data protected

Device is current

Issue support

Retire device

StartStart

Apps from the Enterprise

• Azure AD enrollment• Bulk MDM enrollment• Easy self

provisioning• IT provisioning tool

updates

• Certificates – SCEP & PFX, Passport

• Wifi connection• Simplified Passport

deployment

• Common VPN platform• Per app VPN & lockdown VPN• App triggered VPN• Destination name based VPN

trigger• Passport VPN integration

• Health attestation• New security policies• Enterprise data protection• Mgmt. of Windows Defender Advanced

Threat Protection

• MDM policies for update

• Windows Update for Business

• Easier device unlock; LOB app signing with Ent. cert

• Win32 MSI based app deployment• App inventory, app whitelisting, UWP app

config• Centennial app mgmt.• Windows Store for Business enhancements

• Remote find/wipe• MDM config report• Enhanced logging• Remote reboot

• Retire device with server alert• Retire PC when no user logged

in• Reliable enterprise config

removal

Existing Windows 10 capabilitiesNew Capabilities in the next release of Windows

Page 7: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Setup device for work

Productive at work

Productive on the go

Device & data protected

Device is current

Issue support

Retire device

StartStart

Apps from the Enterprise

Look for session from Build 2015 for Windows 10 manageability support - Managing Mobile Devices and Applications in an Enterprise [Janani Vasudevan] http://aka.ms/build2015mgmt

Page 8: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Simplified IT provisioningSetup device for workAvoid wipe & reload

Use Windows Image Config & Designer tool

Domain join & setup deviceStreamlined & intuitive flowNEW

Better documentationNEW

Not Final UI

Page 9: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Easier self provisioningSetup device for work

Auto MDM enroll with Azure AD

…Now with a simpler UX

Page 10: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Not Final UI

Page 11: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Not Final UI

Page 12: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Not Final UI

Page 13: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Not Final UI

Page 14: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Not Final UI

Page 15: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Not Final UI

Page 16: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Not Final UI

Page 17: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Not Final UI

Page 18: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Setup device for work

Productive at work

Productive on the go

Device & data protected

Device is current

Issue support

Retire device

StartStart

Apps from the Enterprise

Page 19: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Get connected to work

Productive at work

Corporate Wifi connection

Certificates Direct Install (PFX) or Install through SCEP TPM, Software & Passport Certs

Simplified Passport deploymentNEW

Better support for key/cert based deployments

Look for sessions in Build - Multifactor authentication and Windows unlock with IoT devices [Anoosh Saboori] ; Windows Hello in Microsoft Edge and Apps [Anoosh Saboori]; Identity Overview [Karanbir Singh]

Page 20: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Setup device for work

Productive at work

Productive on the go

Device & data protected

Device is current

Issue support

Retire device

StartStart

Apps from the Enterprise

Page 21: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Work anywhere with VPNUniversal Windows VPN platform

Inbox VPN enhancements (Custom IPSEC crypto parameters)NEW

XML based MDM provisioning option NEW

Automatic ConnectivityAlways On; App triggered VPNDestination Name Based TriggerNEW

Securing ConnectionsTraffic filters (App, Other)Lockdown VPNVPN support for EDPNEW

Passport supportNEW

Productive on-the-go

Page 22: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Setup device for work

Productive at work

Productive on the go

Device & data protected

Device is current

Issue support

Retire device

StartStart

Apps from the Enterprise

Page 23: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Keep user devices protected!More Security Policies – MDM & Group Policy

Edge: Search Provider, Prompt when opening in IE etc.

Privacy: Consent prompts, advertising ID etc.UX policies: Notifications, Continuum etc.

Advanced security managementWindows Defender – Added policiesNEW

Device Health Attestation (with conditional access)Windows Defender Advanced Threat ProtectionNEWLook for session in Build - Windows Advance Threat Protection Service [Heike Ritter, Michael Shalev]

Stay tuned for updates to documentation for full list of policies supported - http://aka.ms/win10mdm

Device & data protected

Page 24: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Corporate data: Separate & Protected

Enterprise Data Protection

Manage what data is “Enterprise”Audit intentional data disclosure

Support through mgmt. solutionsConfiguration ManagerMicrosoft Intune3rd party MDMs

Device & data protected

for business

personal

Business Apps & DataManaged

Personal Apps &

DataUnmanaged

Data exchange is blocked or

audited

Look for session in Build - Enterprise Data Protection: Building Windows Apps that keep work and personal data separate and secure [Derek Adam]

Page 25: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Setup device for work

Productive at work

Productive on the go

Device & data protected

Device is current

Issue support

Retire device

StartStart

Apps from the Enterprise

Page 26: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Windows Update for BusinessDeployment Rings

Increased control over update rollout

Bandwidth OptimizationSecure peer to peer delivery of updates Manage delivery optimization settings

Integration with existing toolsDeploy updates from WU, third party content using existing toolsUpdate compliance report

Device is current

Page 27: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Setup device for work

Productive at work

Productive on the go

Device & data protected

Device is current

Issue support

Retire device

StartStart

Apps from the Enterprise

Page 28: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Unified platformEasier device unlockLOB app signing possible using Enterprise cert

UWP & desktop app mgmt.App deployment – UWP, Centennial & MSI desktopInventory based on query – UWP‘Applocker’ App restrictions – UWP & desktop

Centennial app mgmt.NEW

Managing apps in your EnterpriseStartStart

Apps from the Enterprise

Look for session in Build - Enterprise Apps and the Windows Store for Business [John Vintzel; Tejas Patel]

Page 29: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Extend your reach to organizations

Access to business and education users Apps can be acquired in bulk

Designed for organizationsMultiple ways to distribute apps Support for imaging and offline usage

One place, same toolsApps are submitted via Windows Dev Center Submit custom LOB apps directly to an organization

Windows Store for BusinessStartStart

Apps from the Enterprise

Page 30: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Setup device for work

Productive at work

Productive on the go

Device & data protected

Device is current

Issue support

Retire device

StartStart

Apps from the Enterprise

Page 31: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Help IT help users

Locate device remotely

Better device diagnosticsNEW

Improved loggingMDM mgmt. resultant configuration reportCan be retrieved through MDM channel

Remotely reboot deviceNEW

Issue support

Page 32: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Setup device for work

Productive at work

Productive on the go

Device & data protected

Device is current

Issue support

Retire device

StartStart

Apps from the Enterprise

Page 33: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Retire device or revoke accessRetire user/deviceEnterprise wipe

Remove policies & enterprise assets provisionedRetire lost/stolen PC– when no user logged inNEW

Azure AD account removalRemoval of config for auto-enrolled MDM cases

Device Wipe Removes all data on device

Page 34: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

• Windows 10 MDM reference: http://aka.ms/win10mdm • Group policy ADMX/settings for Windows 10: http://

aka.ms/win10admx • What’s new in Windows 10 for MDM: http://aka.ms/newinmdm• Powershell scripting with WMI bridge: http://

aka.ms/UsingMdmWmiBridge • Windows Device Provisioning: http://aka.ms/win10provisioning

• Windows 10 Management with Intune: http://aka.ms/win10withintune

• Windows 10 Management with ConfigMan: http://aka.ms/win10configman

Resources

Page 35: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

Evaluate Windows 10 insider preview builds https://insider.windows.com/

Stay tuned and delve into updated MDM infohttp://aka.ms/win10mdm Evaluate Windows Store for Business to get wider outreach for your Enterprise appsLet us know your feedback!Use Windows feedback app

Next Steps

Page 36: Build 2016 - P493 - Managing Windows in an Enterprise: Empower Your Users & Protect Your Data

© 2016 Microsoft Corporation. All rights reserved.


Recommended