Modern Workplace management with Enterprise Mobility + Security- part 3

In my second post, I started with identity and client apps/cloud services as part of the workplace and their Layer of Controls within EM+S. In this post, I would like to discuss data/content and devices. Don’t forget, It is the combination of Layers of Control which make the EM+S solution powerful. Also, I’m purely discussing the Enterprise Mobility + Security Layers of Control. Within Windows you will find more controls and the same for O365. These last area’s aren’t my expertise but do investigate the controls in these products.

Data/content:

The Layer of Control EM+S has to offer regarding data/content is Azure Information Protection. With AIP you can Label, classify and protect data/content, and make sure only the right people can open and modify content. You also can track usage of your document and revoke access if needed. I wrote a more detailed post on AIP which you can read here. A great additional layer on top of MAM policies on the Office apps or Windows Information Protection. AIP is one of the great tools regarding the coming GDPR.

 

Device management:

Last layer of control EM+S has to offer when you look at the device level is Intune. Intune offers a platform to manage all your devices whether those are Apple, Microsoft or Android devices. Sometimes you hear that this is “modern device management vs legacy device management”: lightly managed/Intune/AAD/policies vs fully managed/SCCM/AD/GPO’s

I’m aware that some customers require more features than what Intune has to offer today. SCCM can do a lot more on the Windows platform than Intune. Legacy Win32 app distribution is one of them, especially complex multi .MSI chain distribution. Hopefully, in that case, the focus will be on modernizing the app landscape so customers can make the full move to modern workplace management. Again, I’m aware that changing applications isn’t easy. My personal opinion if the switch to Intune is challenging; move as many users from the legacy way to the modern way and stick to SCCM for the devices which need it. However, keep on modernizing your apps! Read more about legacy apps and modernizing management here.

I believe Intune, on the device management side of things, has more than enough to offer today. Recently I was browsing in Intune to see which settings I could configure for Windows 10 and IOS devices. I realized that I only would set a couple of them: a password, Windows Update, enable Windows Defender and probably a Wi-Fi profile.

Besides the fact it is a lot of work to lock down devices (remember creating Windows images, turning off many features, use specific user settings solutions to disable even more settings, slower machines and unhappy users), with just a couple of very reasonable settings (and I truly hope everybody has configured those- on corporate and personal devices), I have the feeling it will be easier to make BYOD users enroll their  personal devices into a corporate management solution, because your Exchange policy might require an enrollment. With that, you have some control over the device (you can wipe corporate data) and the user can use its know Office apps.

Hopefully you have a better picture of what EM+S has to offer. To me, it offers Layers of Control, which are additional, on top of each other and not one or the other. Time has changed and purely focusing and protecting the device isn’t the way forward anymore. Identities are leaving your perimeter as is data. When you support that, enable that in a user friendly and secure matter, users will be empowered and be productive.

 

 

 

Microsoft Intune+mobile Office apps = Greatness!

Microsoft Office: Word, PowerPoint, Outlook, Excel, OneNote, OneDrive, etc, who doesn’t know these applications? Most of you know the apps from a corporate point of view and I think it is safe to say the Office suite of products is the corporate standard. As we know, there is another world besides the laptop/desktop/Windows based one: the mobile devices world. And besides desktop/laptop vs mobile, we also have a corporate vs private world. To make it even more exciting, the mixture of all worlds is happening all around us.

Wouldn’t it be great to use the same productivity apps you are used to use among all these different devices? What maybe isn’t known to many people is the fact Microsoft has developed many apps for IOS and Android. You can use the complete Office suite on your mobile devices. Find the Microsoft apps on iTunes here. So, if you want to have the same experience on your mobile devices, or even on your Apple Macs as on your corporate device, you can. The Office Suite is developed for all platforms.

Great, users can have the same experience, on Windows, Mac and mobile devices. But when these mobile devices are used professionally, IT would like to manage at least the productivity apps. It is great you can access and consume corporate data by using the Office apps, but you would like to secure the data as well.

To do this security, other MDM/MAM (Mobile Device Management/Mobile Application Management) vendors have created their own productivity apps. Their own email clients and data clients which previews Microsoft Word, Excel and PowerPoint documents. Those apps are not what end users know and like. Also, it isn’t the core business of these MDM/MAM vendors to develop Office/productivity tools.

With Microsoft Intune, it is possible to let users use what they know and like and secure the Office apps in multiple ways:

  1. Traditionally, you can enrol your device in Intune and manage the device and the Office apps: MDM-MAM,
  2. It also is possible to use the apps and secure them without enrolment: MAM Only
  3. If you currently are using another MDM tool, you still can use #2 by using Intune for the MAM part.

Bullit 1 is pretty clear: you enrol the device and policies are being pushed regarding the device and apps, by using Intune. With #2 and #3, the application policies are being pushed after users sign in, within the office apps on IOS and Android, with their accounts in Microsoft Azure/Intune.

 

 

 

So, what can be configured using MDM-MAM or MAM only?

  1. You can allow/deny copy/past from the Office apps to other native apps,
  2. You could allow copy/paste from native apps to the Office apps,
  3. You can set a PIN on all apps for another level of security,
  4. You can specify that links need to open in the Managed Browser,
  5. You can prohibit “save as”, to prevent users to save a corporate document on another, unmanaged location.

With Intune and the Microsoft productivity apps, users use familiar apps for productivity, and which are built for that purpose and IT can secure access to and from these apps, and secure corporate data. Check out this Microsoft blog for more details and screen shots. Also, check out this website to see more apps that can be managed by Intune.