Microsoft Intune: Cloud-based Endpoint Management Solution

Microsoft Intune is an endpoint management solution that allows organizations to manage and secure a wide range of endpoints, including Windows, macOS, iOS, and Android devices, as well as apps and data. With Intune, organizations can centrally manage and configure devices, enforce security policies, and deploy and manage apps and updates, all from a single cloud-based console.

Intune also includes advanced security features such as Conditional Access and device compliance policies, which allow administrators to monitor and manage the security of their endpoints and ensure compliance with organizational policies.

Overall, Intune provides a comprehensive endpoint management solution that helps organizations improve security, increase productivity, and reduce IT complexity.

Device Management and Application Management

Microsoft Intune provides two distinct solutions for endpoint management: MDM (Mobile Device Management) and MAM (Mobile Application Management).

  • Mobile Device Management (MDM): With MDM, administrators can manage and secure a wide range of devices, including Windows, macOS, iOS, and Android devices. MDM allows administrators to remotely manage device settings, enforce security policies, and configure access to company resources such as email and files.
  • Mobile Application Management (MAM): With MAM, administrators can manage and secure company data within mobile applications, without managing the entire device. MAM allows administrators to control data access and restrict data sharing within specific apps, enabling secure mobile access to company data and reducing the risk of data leakage.

These two capabilities are often used in conjunction to provide comprehensive mobile device management and application management for organizations, allowing them to protect their data and maintain security while enabling employees to use mobile devices and applications to be productive from anywhere.

Intune Mobile Device Management (MDM) Capabilities

Full Device Control

MDM provides complete control over enrolled devices, including the ability to wipe the entire device, install and configure apps, and apply security policies.

Password Policies

Intune MDM allows administrators to define password policies that enforce strong passwords with a minimum length, complexity, and expiration period. This policy helps ensure that user accounts are protected with strong passwords and reduces the risk of unauthorized access.

Device Compliance

Intune MDM allows administrators to define policies that ensure devices meet specific security and compliance requirements. This can include policies that require devices to have up-to-date software, anti-virus software installed, and are encrypted.

Conditional Access Policies

Intune MDM allows administrators to define conditional access policies that restrict access to corporate resources based on device status and user identity. For example, a policy can be defined that requires a device to be enrolled in Intune and comply with specific security policies before accessing corporate resources.

For example, Intune Conditional Access policies can be used to prevent users from accessing corporate data if they are connecting to the network using weak Wi-Fi encryption. Administrators can create a conditional access policy that requires devices to meet certain security requirements before granting access to corporate resources.

If a user attempts to access corporate data while connected to a Wi-Fi network using weaker encryption, the conditional access policy would prevent them from accessing the data.

This type of policy helps ensure that devices connecting to corporate networks meet specific security requirements and helps protect corporate data from unauthorized access.

Intune Mobile Application Management (MAM) Capabilities

Overall, Intune MAM features provide a comprehensive set of tools for protecting corporate data on mobile devices and ensuring that only authorized users with compliant apps can access corporate resources.

App-level Data Protection

Intune MAM allows administrators to protect corporate data at the app level, ensuring that data is secure even if it is accessed from an unmanaged device. This can include policies that prevent users from copying and pasting corporate data into personal apps or allow data to be wiped from specific apps if a device is lost or stolen.

For example, MAM can prevent users from copying data from the corporate email application such as Outlook and pasting the data in an unmanaged application such as WhatsApp.

App Deployment and Management

Intune MAM allows administrators to deploy and manage corporate apps, including the ability to push apps to user devices, update apps, and remove apps remotely.

App-Level VPN

Intune MAM allows administrators to configure app-level VPNs, which allow secure access to corporate resources without requiring the use of a device-level VPN. This can help reduce the risk of data leakage and ensure that only authorized apps can access corporate resources.

For example, if the employee is using a managed application such as OneDrive to access corporate data, the data traffic will be routed through the corporate VPN, but if the employee is using unmanaged application such as WhatsApp, the data traffic will not be routed through the company VPN.

Data Loss Prevention

Intune MAM allows administrators to define policies that prevent data loss and leakage. This can include policies that block users from sending sensitive data to untrusted apps or prevent data from being saved to unapproved cloud services.

Select Use Cases of Microsoft Intune

  • Preventing users from accessing corporate OneDrive and SharePoint data using personal laptop
  • Preventing users from taking screenshot in managed applications, and thereby preventing data leakage.
  • Preventing users from transferring or copying data from managed applications to unmanaged applications.
  • Preventing users logging into Microsoft Teams from an unmanaged mobile device.
  • Intune MAM can be configured to apply application-specific data wiping. When an employee leaves the company, it can be used to remove not company-managed app and data without wiping the whole device.
Recent Posts

LET'S GET IN TOUCH...

Contact Us

Google reCaptcha: Invalid site key.