Organizations are continuing to experience an increasing number of devices and cloud services that are being used by their employees. While this allows people to achieve more at work, it also requires IT to enable and support new and more complex scenarios with the same budget and resources. Organizations are looking for a solution that allows them to manage their users, various device platforms, and different types of apps using an integrated, modern platform. We are excited to announce new features in Microsoft Intune to expand its unified endpoint management (UEM) capabilities. These improvements include conditional access enhancements across all platforms, integration with Jamf for macOS device compliance, a new co-management capability with System Center Configuration Manager (ConfigMgr) for modern Windows 10 management, and more.
Microsoft 365
Microsoft 365 is designed to enable a modern workplace for employees and a new approach for IT to simplify management, improve security, and lower costs. You can read more about this new approach in Brad Anderson’s Microsoft 365 powered device blog post and our latest Mechanics video .You can download this infographic here .
One of the key elements of Microsoft 365 powered device is the ability to modernize the deployment and management of Windows 10 and Office 365 ProPlus. We have been regularly adding new modern management features in Intune since the release of Windows 10. Some of recent improvements include the ability to deploy Office 365 ProPlus , BitLocker management, integration with Windows Update for Business, and more. We are also working on new features including the ability to run PowerShell scripts on Windows 10 devices using Intune Management Extension, new Windows 10 MDM settings, and enhanced support for Windows AutoPilot, Windows Defender ATP, Windows Store for Business, and Surface Hub.
While there are many benefits of modern management, most organizations are still using an on-premises Windows Server Active Directory (AD) and System Center Configuration Manager (ConfigMgr) to manage their Windows devices. Based on conversations with our customers, we heard that until now, it wasn’t always easy to move to modern management. Some customer scenarios require the ConfigMgr agent, and there are also Windows 7 devices that need to be managed. Customers also use deeply integrated partner or homegrown solutions for ConfigMgr, and not to mention the complexity of planning and switching from traditional to modern management with existing IT systems, organizational structures, and processes. Many organizations were looking for a more simplified and manageable way to transition from ConfigMgr and AD to a modern management approach with Intune and Azure AD. We are excited to make this possible with a new feature of ConfigMgr and Intune called co-management .
Integration with Jamf for macOS device compliance
As a unified endpoint management (UEM) solution, we are always looking for ways to extend our platform through our partners to satisfy the unique needs of our customers. Today, we are excited to announce our integration with Jamf , a well-known solution for managing the Apple ecosystem. Jamf will integrate with Intune’s device compliance engine to provide an automated compliance management solution for macOS devices accessing applications connected with Azure AD authentication.The next wave of conditional access
In June, we announced the general availability of the new conditional access admin experience in the Azure portal. This powerful, simplified new experience makes it easy to manage policies that bring together services across EMS, including Azure AD Premium, Microsoft Intune, and combines it with the insight from the Microsoft Intelligent Security Graph , which scans billions of signals to determine user risk levels. Today, Microsoft announced a whole new wave of scenarios that expand our conditional access capabilities, including integration across EMS’ Azure Information Protection and Microsoft Cloud App Security services, as well as additional scenarios that leverage Intune’s core MAM and MDM capabilities. You can read about this next wave of conditional access capabilities in this post from Alex Simons that was published earlier today.In case you missed it
As always, the last couple of months have been busy with the release of several product updates and new features. Here is a recap of some of these releases that we’re getting a positive customer feedback on.- iOS 11 and Android O support : In recent weeks, both Google and Apple announced updates to their operating systems. As you plan for both updates within your organizations, you can have the confidence that all existing Intune capabilities will continue to work as expected when users upgrade.
- Enhanced macOS support : Over the last month, we added several improvements to our macOS management capabilities, including conditional access support and a new Company Portal for end users.
- Intune Data Warehouse : The new Intune Data Warehouse takes our reporting capabilities a step further, giving you more powerful custom reporting around your environment over time. With a dataset spanning up to 90 days of historical data, you can connect the Intune Data Warehouse to Power BI, Excel or another analytics tool that supports OData feeds to view historical trends, get daily snapshots, and create other custom reports across multiple tables.
- Mobile Threat Defense ecosystem : This past year, we’ve introduced integration with several leading Mobile Threat Defense (MTD) solutions, including Lookout, Skycure, and Check Point. This month, we’re excited to introduce our latest integration with Zimperium . This integration helps organizations defend against both known and unknown mobile threats and ensure that devices are risk-free and secure before users access corporate resources.