Microsoft Intune:
Intune is a cloud based solution for managing end-users devices both computers and mobile devices such as Windows Phone, Android, and iOS devices. Intune provides the MDM (Mobile Device Management) and MAM (Mobile Application Management) features of the Enterprise Mobility Suite
Azure Active Directory:
At a basic level Azure Active Directory provides the same functionality as the Active Directory that many companies use on their corporate networks. This product is entirely cloud based and provides the Identity and Access Management features of the Enterprise Mobility Suite
Azure Rights Management Services:
The third component of the suite is also a cloud based solution and it provides the Information Protection features of the full Enterprise Mobility Suite. This product will provide encryption of your documents and data allowing secure access to these files the computers and mobile devices managed by EMS.
Let’s take a deeper dive now into the Intune product and what it brings to the table. The first thing to make clear is that Intune and in fact the whole Enterprise Management Suite is entirely in the cloud. There are no local installations or servers to place in your environment if you are working with this product.
Intune itself provides 3 main components of the overall Enterprise Mobility Suite:
Mobile Device Management is essentially the ability to manage non computer devices. This group would include Apple iOS devices, Android devices, and Windows Phone devices. MDM also is supported in two basic approaches. Company owned devices being rolled out in bulk to users and BYOD scenarios where your user base wants to have access to company data, email and applications from their personal mobile devices.
In order to achieve this result, the MDM features of Intune provide the following:
In its first incarnation in IT MDM started as primarily a device control activity for corporate IT departments and basic access to Email. Companies and their users and customers have come to demand greater and greater access to information and program that allow them to be productive away from their desktop or even laptop computers.
Mobile Application Management (MAM) helps to fill in this gap. Now when a user enrolls their mobile device through the company portal application administrators can automatically have additional applications install to that device. Secondly the portal provides access to a catalog of applications that users can voluntarily download as well.
Here are a few ways that MAM is provided:
Beyond mobile device management Intune can also do basic management of your desktop and laptop PC’s. In this scenario Intune is positioned as a ‘lite’ version of SCCM that a large number of companies use to manage their devices in an on premise environment.
Some of the core features of pc management within Intune include:
With these pc management features Intune can act as a standalone cloud solution for smaller companies to manage their computers. In larger corporate environments most companies use System Center Configuration Manager (SCCM) to provide all these functions. SCCM is a larger and more robust tool for computer management
For the best of both worlds Intune can me integrated with SCCM allowing administrators to extend the management capabilities of SCCM to the cloud and mobile devices.
The second of three core components of EMS is Azure AD Premium. This product provides all the features that cover Identity and Access management features of the full suite.
Azure AD Premium has so many features and components that it could easily fill its own document. For the purposes of this guide we will focus on the benefits it brings to EMS.
Within the bounds of EMS here are some key benefits:
The third and final component of the Enterprise Mobility Suite is Azure Rights Management. This product is what provides the Information Protection features of EMS.
Information Protection is all about encrypting files and securely accessing them and also being able to share them with users outside of the company.
Core features include:
As we have now seen through the combination of Intune, Azure AD, and Azure Rights Management customers who purchase the full Enterprise Mobility Suite have a great set of tools to extend corporate data and applications to the cloud and mobile devices.
To conclude here a couple pieces of information to investigate as you consider using EMS.
EMS can integrate with on premise installations of AD, Exchange and SCCM. Any deployment where you tie the cloud to on premise solutions is called a Hybrid deployment. If you sync AD with Azure AD you can truly manage only one account per user providing them one login both in the office and on mobile devices. By itself Intune is in many ways a cloud based lite version of SCCM. If you want the best of both worlds and already use SCCM in your organization, then you can deploy Intune integrated with SCCM.
When you integrate Intune with SCCM instead of relying on the Intune console you can access and manage the features it provides from within the SCCM Console. In this fashion you have all the robust features of SCCM to manage computers and providing features such as inventory, patching and software delivery. This is tied with he mobile management features of Intune as well.
Coming this year will be a few key features that expand what EMS Can provide. The first item is Mac OS X support. At this moment only SCCM can managed OS X mac desktops and laptops. By adding these features to Intune customers who find Intune/EMS provides all the features they need will be able to manage both main computing platforms (Windows and Mac) as well as all main mobile platforms (Windows Phone, Android, and iOS)
The second important features coming this year is the rollout of Windows 10 itself and all the new features and management capabilities this will bring to Intune and SCCM.
In conclusion I hope that this document has helped provide some clarity around Microsoft’s Enterprise Mobility Suite and its three main components, Intune, Azure AD, and Azure Rights Management. The features providing within each component and how they might benefit you the customer.