35
Secure your data and apps with the Microsoft Enterprise Mobility Suite Chris Nackers @chrisnack http://chrisnackers.com Peter Daalmans @pdaalmans http://ref.ms/aboutme Mirko Colemberg @Mirkocolemberg http://blog.colemberg.ch

MMS 2015: Secure your data and apps with the enterprise

Embed Size (px)

Citation preview

Page 1: MMS 2015: Secure your data and apps with the enterprise

Secure your data and appswith the Microsoft Enterprise Mobility Suite

Chris Nackers

@chrisnack

http://chrisnackers.com

Peter Daalmans

@pdaalmans

http://ref.ms/aboutme

Mirko Colemberg

@Mirkocolemberg

http://blog.colemberg.ch

Page 2: MMS 2015: Secure your data and apps with the enterprise

#MMSMOA

@pdaalmans

Sn. Technical Consultant,

IT-ConcernConfigmgrblog.com

ref.ms/aboutme

Breda, Netherlands

Peter Daalmans

Page 3: MMS 2015: Secure your data and apps with the enterprise

#MMSMOA

Principal Consultant Confgimgr.chSince 1999

Solothurn, Switzerland

Mirko Colemberg

mirkocolemberg

Configmgr_ch

Page 4: MMS 2015: Secure your data and apps with the enterprise

#MMSMOA

@chrisnack

Consultant, Nackers Consulting Chrisnackers.com

Breda, Netherlands

Chris Nackers

10 years

Page 5: MMS 2015: Secure your data and apps with the enterprise

Agenda

• App layer protection concepts

• Azure AD Premium• Identity + Application Proxy

• Intune• Conditional Access

• MAM

• Azure Rights Management• How to configure

Page 6: MMS 2015: Secure your data and apps with the enterprise

App layer protectionThe concepts

Page 7: MMS 2015: Secure your data and apps with the enterprise

Device, Application, Information

Mobile Devices

MDM MAM MIM

Company

Company Private

Private Company

Company Private

Private Company

Company

Private

Private

Private

Page 8: MMS 2015: Secure your data and apps with the enterprise

Azure AD PremiumIdentity

Page 9: MMS 2015: Secure your data and apps with the enterprise

Identity: Cloud, Sync or Federated?

Cloud identity provides a solution where all identity resides in the cloud

Federated identity allows customers to retain all authentication on-premises

Identity sync enables customers to bridge their existing identity into the cloud

B2B federated identity allows customers to securely share and collaborate with each other

Page 10: MMS 2015: Secure your data and apps with the enterprise

Azure Active Directory Premium

Active Directory in the cloud• Federation and identity provisioning

Centrally managed identities• Synchronization• Single User Identity (SSO)

Monitoring and protect access to cloud apps• Authentication and Security reports• Multi-Factor Authentication (MFA)

Empower end Users• Self-Service password reset

Page 11: MMS 2015: Secure your data and apps with the enterprise

Discovery from non-Windows devices

• Cloud App Discovery gateway

• Devices can be configured to go through gateway

• Requires MDM for deployment across organization

Page 12: MMS 2015: Secure your data and apps with the enterprise

Integrate on-prem apps with Azure AD

End-user portal – Access Panel

Azure AD authentication capabilities:• Username and password synced from on-prem AD

• Federated login to on-prem or other federation servers

• Multi-factor authentication

• Customized login screen

• Authorization based on user or groups

• SSO to Office365, thousands of SaaS apps and all applications integrated with AAD

Reports, auditing and security monitoring based on big data and machine learning.

Azure Active Directory

Resource ResourceResource

Co

rpo

rate

N

etw

ork

DM

Z

Connector Connector

Application ProxyAccess Panel

Portal

Authentication +

MFA

Reporting &

Auditing

Security

MonitoringAuthorization

Page 13: MMS 2015: Secure your data and apps with the enterprise

DemoAzure Active Directory Premium

Page 14: MMS 2015: Secure your data and apps with the enterprise

Microsoft IntuneConditional Access

Page 15: MMS 2015: Secure your data and apps with the enterprise

Conditional Access

• What can we do?• Force enrollment before access to Exchange or SharePoint

• Force compliance before access to Exchange or SharePoint

• Much more investments coming soon (see ref.ms/emsroadmap)

Page 16: MMS 2015: Secure your data and apps with the enterprise

Conditional access for Office 365

7

Enrollment/compliance remediation5

If not compliant, push device into quarantine4

2

Attempt email connection

1

3 Set device management/ compliance status

6

Page 17: MMS 2015: Secure your data and apps with the enterprise

DemoSetting up Conditional Access

Page 18: MMS 2015: Secure your data and apps with the enterprise

Microsoft IntuneMobile Application Management

Page 19: MMS 2015: Secure your data and apps with the enterprise

Mobile Application Management

• What can we do?• Force compliance before access to the app and data

• Secure the data within the app• Prohibit copy/paste

• Prohibit screenshots

• Prohibit save as

• Force encryption

• Secure app by PIN or corporate credentials

• Secure LOB apps via App Wrapper

Page 20: MMS 2015: Secure your data and apps with the enterprise

Microsoft Intune Managed Apps

• See for an up to date list: http://ref.ms/mamlist

Page 21: MMS 2015: Secure your data and apps with the enterprise

Mobile Application Management

Maximize mobile productivity and protect corporate resources with Office mobile apps

Extend these capabilities to existing line-of-business apps using the Intune app wrapper

Enable secure viewing of content using the Managed Browser, PDF Viewer, AV Player, and Image Viewer apps

Personal apps

Page 22: MMS 2015: Secure your data and apps with the enterprise

Mobile Application Management

Copy Paste Save

Maximize productivity while preventing leakage of company data by restricting actions such as copy/cut/paste/save in your managed app ecosystem

Save to

personal storage

Paste to

personal

app

Page 23: MMS 2015: Secure your data and apps with the enterprise

DemoConfiguring MAM

Page 24: MMS 2015: Secure your data and apps with the enterprise

DemoYeah, Copy Paste!

Page 25: MMS 2015: Secure your data and apps with the enterprise

Azure Rights ManagementProtecting the data

Page 26: MMS 2015: Secure your data and apps with the enterprise

Azure Rights Management

“It uses encryption, identity and authorization policies to help secure your files and email, and it works across multiple devices.”

Page 27: MMS 2015: Secure your data and apps with the enterprise

Azure Rights Management – Cool Features

Protection stays

with the file

Works both inside

and outside the

company

Easy

Audit and

monitoring

On-prem (RMS

Connector) and

O365 support

Page 28: MMS 2015: Secure your data and apps with the enterprise

DemoProtecting your files

Page 29: MMS 2015: Secure your data and apps with the enterprise

So, what fits where?Secure your data and apps in the enterprise

Page 30: MMS 2015: Secure your data and apps with the enterprise

What fits where?

ITUser

Enterprise

Mobility Suite

Identify and authorize user

Apply device policies

Apply application policies

Apply content policies

Active Directory Premium

Rights Management

Page 31: MMS 2015: Secure your data and apps with the enterprise

Share your ideas

• Share your voice / ideas!• http://microsoftintune.uservoice.com/

• http://configurationmanager.uservoice.com/

Page 32: MMS 2015: Secure your data and apps with the enterprise

Questions

Page 33: MMS 2015: Secure your data and apps with the enterprise

Thank you!

Page 34: MMS 2015: Secure your data and apps with the enterprise

Evaluations: Please provide session feedback by clicking the EVAL button in the scheduler app (also

download slides). One lucky winner will receive a free ticket to the next MMS!

Session Title: Secure your data and apps with the Microsoft EMS

Discuss…

Ask your questions-real world answers!

Plenty of time to engage, share knowledge.

SPONSORS

Page 35: MMS 2015: Secure your data and apps with the enterprise