Showing posts with label MDM. Show all posts
Showing posts with label MDM. Show all posts

Monday, September 5, 2016

Office 365 MDM or Microsoft Intune?

Introduction
I have been asked several times, what are the MDM capabilities available in Office 365 versus what additional capabilities do you get with Intune?

In this quick article I will explore the differences.

What is Office 365 MDM?
In Office 365 there are several native MDM capabilities.

First there is Exchange ActiveSync (EAS) which is part of Exchange Online.  With EAS you:
  • Have the ability to manage an inventory of mobile devices that are connected to Exchange Online. 
  • Have the ability to remotely wipe email from a device.
  • Have the ability to enforce mobile device configuration settings, such as PIN requirements, PIN lengths, etc.
Second with E1, you also get Office 365 MDM.  With this you:
  • Can prevent access to both email and documents based on device enrollment and compliance policies.
  • Protect against root and jail broken devices.
  • Have reporting on devices that do not meet IT policy.
  • Have selective wipe capability that allows you to wipe Office 365 data without impacting personal data.
Behind the scenes, Office 365 MDM leverages Microsoft Intune to help deliver these solutions.

What is Intune?
Microsoft Intune is Microsoft’s cloud mobile and PC management platform.  Sometimes customers will want to add this to help them manage devices and applications beyond what Office 365 natively provides.  With Intune you:
  • Have the ability to manage traditional PCs MACs; not just mobile devices.  Plus you can manage Linux and UNIX servers.
  • Have a full Mobile Device Management (MDM) platform available to you to protect enterprise assets beyond Office 365.
  • Have the ability to create profiles for certificates, VPN, email profiles and Wi-Fi settings.
  • Have the ability to enroll and manage corporate owned devices.
  • Can deploy and protect customer built line of business apps using Mobile Application Management.
  • Can securely protect access to corporate data using Office mobile and custom line of business apps by using Mobile Application Management by restricting such actions as copy, cut, paste, save as to only applications managed by Intune.
  • Can enable more secure web browsing.
As you can see, this is a much more comprehensive solution you have access to.

Why do you need both? 
All depends on your approach.  Microsoft Office 365 has the ability to integrate with many third-party MDM providers.  Customers do have the power of choice.  Intune does provide unique capabilities for Mobile Application Management (MAM) to protect data on mobile devices without compromising the end user experience.  However, the big value sell of Intune is the expanded set of solution to manage PCs and MACs.

What are these new plans?
Intune is bundled into EMS.  EMS used to stand for Microsoft Enterprise Mobility Suite.  Now, EMS stands for Enterprise Mobility + Security.

Plus, the new EMS Suite has taken very similar plan structures as Office 365.  For instance:
  • EMS E3 includes Azure AD Premium P1, Intune, Azure Information Protection Premium P1 (Azure Rights Management (RMS)), and Advanced Threat Analytics
  • EMS E5 includes Azure AD Premium P2, Azure Information Protection Premium P2 (Intelligent classification) and Cloud App Security.
As you can see Intune, lands in the EMS E3 bundle or you can purchase it a-la-carte.  See references below.

References

Exchange ActiveSync - https://technet.microsoft.com/en-us/library/aa998357(v=exchg.150).aspx
Overview of Mobile Device Management (MDM) for Office 365 - https://support.office.com/en-us/article/Overview-of-Mobile-Device-Management-MDM-for-Office-365-faa7d8e5-645d-4d59-839c-c8d4c1869e4a
Controlling Access to Office 365 and Protecting Content on Devices - https://www.microsoft.com/en-us/download/details.aspx?id=53317
Capabilities of built-in Mobile Device Management for Office 365 - https://support.office.com/en-us/article/Capabilities-of-built-in-Mobile-Device-Management-for-Office-365-a1da44e5-7475-4992-be91-9ccec25905b0
Choose between MDM for Office 365 and Microsoft Intune - https://support.office.com/en-us/article/Choose-between-MDM-for-Office-365-and-Microsoft-Intune-c93d9ab9-efb2-4349-9b93-30c30562ee22
Create and deploy device security policies - https://support.office.com/en-us/article/Create-and-deploy-device-security-policies-d310f556-8bfb-497b-9bd7-fe3c36ea2fd6
Enroll your mobile device in Office 365 - https://support.office.com/en-us/article/Enroll-your-mobile-device-in-Office-365-c8ac722d-dcaf-4135-8345-3e6327f5d3c5
Introducing Enterprise Mobility + Security - https://blogs.technet.microsoft.com/enterprisemobility/2016/07/07/introducing-enterprise-mobility-security/

Saturday, April 11, 2015

MDM for Office 365 Released

It was announced back in October 2014 that a new MDM for Office 365 solution was being released. I wrote this at the time - http://www.astaticstate.com/2014/11/mdm-for-office-365.html.

The MDM for Office 365 capability has now going generally available. If you did not hear much about it, here are some quick points:

  • MDM for Office 365 is subset of Intune features that is now available to Office 365 customers.
  • MDM for Office 365 provides conditional access Office 365 email and documents. Apps such as Office Mobile, OneDrive and native email apps that use Exchange ActiveSync will trigger enforcement of policy.
  • MDM for Office 365 provides new device management policies for PIN requirements and jailbreak detection.
  • MDM for Office 365 provides enhanced remote wipe of Office 365 data without impacting end user personal data.
  • This new MDM solution provides support across iOS, Android and Windows Phone.

clip_image002

Additionally, as part of MDM for Office 365 becoming generally available, there are some new TechNet articles that you should check out Overview built-in Mobile Device Management for Office 365 and the sub-articles within it - https://technet.microsoft.com/en-us/library/ms.o365.cc.devicepolicy.aspx. There are some great facts in here such as:

  • Information on how to enable MDM for Office 365 on your tenant.
  • Articles on how to perform common tasks such as creating policies, running reports, unblocking devices, how to perform a wipe, etc.
  • There is a listing of the exact devices that are supported.
  • Listing of mobile apps where MDM for Office 365 can be applied.
  • Note Blackberry is not controlled by this solution.
  • Note using a mobile browser to access is not controlled by this solution either. Organizations will rely on policies they enforce in general for browser based access to Office 365 services.
  • Detailed listings of all the types of settings and controls that can be enforced by type of device.
  • Note that MDM for Office 365 policies override Exchange ActiveSync (EAS) policies and device created in the Exchange admin center.
  • Note it is recommended to block Exchange ActiveSync to unsupported devices. There are steps provided to do this.

Saturday, November 8, 2014

MDM for Office 365

There was another major announcement recently for Office 365. This past week Microsoft announced that is was adding a new solution called MDM for Office 365 is being released. To date many organizations utilized Exchange ActiveSync (EAS) policies and sometimes other third-party MDM solutions to protect business data on mobile devices connecting to Office 365.

With this new announcement, organizations will now have the ability to provide even more protection of their business data on mobile without having to rely on other solutions.

The new MDM for Office 365 will be available in Q1 of 2015.

Devices: MDM for Office 365 will provide organizations the ability to manage email and documents across iPhone, iPad, Android Phone, Android Table and Windows Phones.

Data Protection: When you learn more about it, you will be impressed with the approach. Typically other MDM providers have enforced data protection through a container and even custom applications within those containers. Many times the feature set offered is limited. In the case of MDM for Office 365, protection is enforced within the applications that users use. For instance Office is now available across all major mobile platforms. Customers can set up protection within Office such that business data is protected and cannot leave the application. End users can remain highly productive without having to learn something new.

Device Lock: There are several new features being added as well such as Pin lock and jailbreak detection.

Device Wipe: Plus enhanced features are being added for device wipe for not just email but also documents. The nice thing about the wipe policy is that it will only wipe company owned data, and not impact a user’s personal data. This is extremely important in a BYOD world no one should have their personal files impacted when they go from one company to another.

Integrated Administration: From an administrative perspective, MDM for Office 365 is integrated right in the administrative experience of Office 365. Administrators do not need to bounce around to other third-party applications nor do they have to spend the time trying to configure them together. MDM for Office 365 is simply just built into the service. Administrators will have access to a full set of reports as well through their reporting center.

InTune: Finally, organizations can easily upgrade to advanced MDM with InTune. With InTune there is advanced mobile application management, integration with System Center and advanced mobile device policy.

Please review these announcements: http://blogs.office.com/2014/10/28/office-365-latest-innovations-security-compliance/ and http://blogs.office.com/2014/10/28/introducing-built-mobile-device-management-office-365/.