Windows ierīces Enterprise infrastruktūrā Aris Dzērvāns Microsoft
Windows 8.1 Update the vision for everyone Designed for the way you live and work Brings together all you do On great devices Always business ready
Windows 8.1 Update compatibility Hardware requirements are unchanged All apps work as well as in Windows 8 Desktop apps New Windows apps Web based apps
Windows 8.1 Update: works the way you want See the desktop only when you need it Leave the desktop only when you want to Windowing and improved multi-monitor support New Search experience IT control of Start screen
Mobility: Productive and connected
Mobility: Productive and connected Work anywhere on any Windows device INTERNET CORPORATE NETWORK Connect to your networks on the go Your PC in your pocket with Windows To Go Access your data and apps on any Windows device Wirelessly connect to peripherals
6 Effective working with Remote Access An automatic VPN connection provides automated starting of the VPN when a user launches an application that requires access to corporate resources. Cannot originate admin connection from intranet Traditional VPNs are userinitiated and provide ondemand connectivity to corporate resources. VPN With DirectAccess, a users PC is automatically connected whenever an Internet connection is present. DirectAccess Can originate admin connection from intranet Connection to intranet is always active Firewall
Windows 8.1: Connectivity Business class VPN features Native Miracast wireless display Integrated wireless printing SoC-integrated mobile broadband Your PC as a personal WiFi hotspot
Empower BYOD
Empower BYOD Flexible solutions for your business VDI* Device Management Joining workplace with personal devices Windows To Go *Powered by Remote Desktop Services
Managing Windows devices Governance Full control Exchange ActiveSync Mobile Device Management via OMA-DM Enterprise Management Windows 8.1 provides choices Choose by device based on scenario or capabilities needed Consider employee versus organization-owned, BYOD, connectivity Organizations may choose the options that works the best for them
Windows 8.1: Workplace join Lightweight registration process for personal devices Enables access to data when using a registered, trusted device leverages the user and device identities together Used with Dynamic Access Control in Windows Server 2012 R2 Primarily a security capability, potentially combined with MDM for manageability
Registering and Enrolling Devices Users can enroll devices which configure the device for management with Windows Intune. The user can then use the Company Portal for easy access to corporate applications Data from Windows Intune is sync with Configuration Manager which provides unified management across both onpremises and in the cloud Users can register BYO devices for single sign-on and access to corporate data with Workplace Join. As part of this, a certificate is installed on the device IT can publish access to corporate resources with the Web Application Proxy based on device awareness and the users identity. Multi-factor authentication can be used through Windows Azure Active Authentication. As part of the registration process, a new device object is created in Active Directory, establishing a link between the user and their device
Network Connections HomeGroup Proxy Radio devices Workplace Workplace Enter your user ID to get workplace access or turn on device management someone@example.com Join your workplace network so that you can use network resources like internal websites and business apps. Join Apps and services from IT Turn on
Windows 8.1: Work Folders Simple access to corporate data Enables offline access to files and folders stored on a Windows Server 2012 R2 file server Simple group policy configuration for domainjoined computers, with easy discoverability for BYOD systems as well Leverages web protocols (HTTP) for easy synchronization through firewalls A compliment to OneDrive and OneDrive Pro
Work folders compared to ohter sync technologies Work Folders Offline Files OneDrive Pro OneDrive Technology summary Syncs files that are stored on a file server with PCs and devices Syncs files that are stored on a file server with PCs that have access to the corporate network (can be replaced by Work Files) Syncs files that are stored in Office 365 or in SharePoint with PCs and devices inside or outside a corporate network, and provides document collaboration functionality Syncs personal files that are stored in SkyDrive with PCs, Mac computers, and devices Intended to provide user access to work files Yes Yes Yes No Cloud service None None Office 365 Microsoft OneDrive Internal network servers File servers running Windows Server 2012 R2 File servers SharePoint server (optional) None Supported clients PCs and devices* inside or outside a corporate network PCs in a corporate network or connected through DirectAccess, VPNs, or other remote access technologies PCs, ios, Windows Phone PCs, Mac computers, Windows Phone, ios, Android
Mobile Device Management Based on open standards Uses Open Mobile Alliance Device Management protocols Secure communication with cloudbased management Built into Windows 8.1 and Windows RT 8.1 Implemented by multiple ISVs Microsoft (Windows Intune) AirWatch Mobile Iron Open protocol enables implementation by additional vendors
Mobile Device Management Implements key device management functionality Hardware and software inventory Configuration of key settings Line-of-business modern application installation and updating Certificate provisioning and deployment Data protection, including remote business data removal (wipe)
Unified Device Management Windows, System Center and Intune Devices & Platforms Microsoft Desktop Optimization Pack (MDOP) UE-V, App-V, MBAM Windows PCs/Tablets (x86/64, Intel SoC), Windows To Go Mac OS X IT Single admin console Windows RT Windows Phone 8 ios Android
Windows 8.1: Assigned Access Enables a single Windows Store app experience on the device User only experiences the specified app Unable to access system files and other apps Windows Embedded 8.1 Industry: broader set of device lockdown capabilities (ATMs, etc.)
Enterprise grade security
Windows 8.1 security capabilities Malware resistance Secure corporate data Modern access control Secured system start-up Core Improved system Windows hardening Defender Sandboxed Improved browser Windows security Store apps Built-in Improved anti-malware system hardening solution Real Provable time PC anti-phishing health protection Device Encryption all editions Corporate Remote Business encryption Data enforcement Removal IP protection with Office IRM Corporate compliance with Lync Biometrics Multifactor Improved multifactor authentication, authentication virtual smartcard TPM key attestation support Dynamic Certificate access reputation control Trustworthy hardware
Windows 8 & 8.1: Virtual Smart Card TPM virtualized as a Smart Card for auth, encryption, signing, etc Address key challenges with existing MFA solutions Easy to deploy, cost effective, always ready on the device
Windows 8.1: Biometrics End to End Support For Fingerprint Biometrics Common enrollment experience PC Settings -> Users -> Create Fingerprint Sign-In Experience optimized based on devices capability Biometrics sign-in in all Windows experiences Windows sign-in Remote Access sign-in All remaining authentication prompts (e.g.: UAC) Characteristics of a Modern Reader Touch Liveness Detection Touch to Buy added to: Windows Store Xbox Music Xbox Video
Windows 8.1 Enterprise Edition Features Start Screen Control Enterprise Sideloading Control Start screen configurations for different groups and roles using Group Policy Create a corporate Windows 8.1 environment on a USB stick Connected to corporate networks, seamlessly and more securely Users in the branch office can download documents and apps faster Improved end-user experience Specify what software is allowed to run on a user's PCs Deploy Windows 8 apps from outside of the Windows Store How to License Rights are included with Software Assurance for Windows Enterprise edition use rights are perpetual for the licensed device even after SA coverage ends.
Windows Phone
The best phones for business Business as it happens Put what s important on your home screen email, contacts and docs. As things change, the tiles do too. The mobile office Microsoft Office - Word, PowerPoint, Excel, OneNote - Outlook and Internet Explorer 10 built-in. Share via SkyDrive, SharePoint and Office 365. Business level security Hardware accelerated encryption, device management and secure boot. The only smartphones with IRM for rights-protected email. Works best with Microsoft If your business runs Microsoft Exchange, SharePoint, Lync or Office 365, choose Lumia. Just enter your username and password and you are set. Best in navigation HERE Drive and HERE Maps that work offline. HERE Transit finds times for public transport. HERE City Lens reveals nearby cafés and restaurants. Beautiful and robust Design that stands out. Choose your favorite options from the range - ClearBlack screen, Wireless Charging, Carl Zeiss lenses, PureView technology, NFC.
Built-in communication and collaboration
Robust security and encryption
Enterprise device management choices
Robust LOB development platform
Windows Phone enterprise feature pack