Managing Apple Devices in the Enterprise (2024)
- Descrição
- Currículo
- FAQ
- Revisões
A trending practice as of late by IT departments in mid-large sized organizations is to utilize Microsoft Intune for Apple device deployment. The thinking goes, they already own licenses of Intune as part of the various Microsoft 365 subscriptions so why not use that to manage iPhones and Macs instead of purchasing and supporting yet another tool specific to Apple platforms? That seems like sound logic, but with a focus on Intune’s cross-platform capabilities, most of the courses out there provide some information on Apple device management using Intune — but nothing goes extremely in-depth on how to use this tool to do the most common Apple deployment tasks…until now.
Managing Apple Devices in the Enterprise (2024) is solely devoted to Apple device configuration and support. With over 13 hours of content, 6 real-world projects, and a lot of in-depth explanation of key Apple device management concepts, it is one of the most comprehensive resources for managing Macs and iOS devices using the Microsoft Endpoint toolset. With a focus on balancing device security and user experience, this course covers the essential strategies, tools, and best practices for configuring Apple devices, including iPhones and MacBooks, to work seamlessly with Microsoft 365 services. Central to the curriculum is the use of Microsoft Intune, a tool for managing Apple endpoints in alignment with an organization’s existing support framework for Windows PCs.
Using a mix of both lectures and project-based practical exercises, students will learn the overall process for managing Apple platforms in larger organizations. Once students have mastered the basic concepts, they can ‘code-along’ with several class projects to build “Pilot Deployments” in their own Microsoft Intune tenant. These projects are based on some of the most common scenarios that system administrators handle every day including Mobile Application Management (MAM), Bring Your Own Device (BYOD), Shared iPad, and zero-touch Mac deployment.
By the end of this course, learners will:
-
Understand the fundamentals of Apple device architecture and its compatibility with Microsoft environments.
-
Gain expertise in using Microsoft Intune for the effective management of Apple devices within an enterprise setting.
-
Learn to configure Apple devices to seamlessly integrate with Microsoft services, including Office 365, Exchange, and Entra ID (formerly Azure Active Directory) using Federation and Platform SSO.
-
Configure Account Driven User Enrollment for BYOD.
-
Develop skills in deploying, managing, and securing Apple devices using policies and profiles standardized across the organization.
-
Implement best-practices for network performance and data security for Apple devices on corporate networks.
Upon successful completion of the course, participants will receive a certification of completion, demonstrating their competence in integrating Apple devices with-in Microsoft-driven enterprise environments using Microsoft Intune.
-
1IntroductionVídeo Aula
A general introduction to the course and the instructor.
-
2Course StructureVídeo Aula
This lesson is a brief overview of the course, the key topics, and the structure.
-
3Microsoft Intune Free TrialVídeo Aula
To be successful in this course, students will need access to Apple Business Manager and Microsoft Intune Plan 1. This lesson briefly covers how to get started with both.
-
4Introduction to Mobile Device ManagementVídeo Aula
This lesson provides students with a high-level introduction to mobile device management concepts.
-
5Apple's MDM FrameworkVídeo Aula
In this lesson, students learn specifically about Apple's MDM Framework, the technology built into every Apple operating system that enables device management.
-
6Declarative Device ManagementVídeo Aula
Declarative Device Management is a next-generation form of MDM. This lesson provides a brief overview of this new specification and how it differs from the Apple Push Notification model it replaces.
-
7Apple Device OwnershipVídeo Aula
In this lesson, students learn about the different device ownership models and how ownership impacts the various functions and features available for device management.
-
8Apple MDM Enrollment ModelsVídeo Aula
This lesson introduces students to the various ways that devices can be enrolled in mobile device management.
-
9Introduction to Apple Business ManagerVídeo Aula
This lecture introduces students to Apple Business Manager. Students are encouraged to sign-up for this solution if their company doesn't already have access to this service.
-
10Managed Apple IDsVídeo Aula
This lesson introduces students to Managed Apple IDs and how they differ from traditional Apple IDs.
-
11Building Your OrganizationVídeo Aula
This lesson provides students with an overview of the Apple Business Manager interface, touches on organizational setup options, and covers the basics for manually creating accounts, groups, and locations.
-
12Configuring the Apple Push Notification ServiceVídeo Aula
In this lesson, we demonstrate how to generate an Apple Push Notification certificate and configure Microsoft Intune for the APN service.
-
13Adding an MDM ServerVídeo Aula
In this lesson we demonstrate how to create a new Intune MDM Server in Apple Business Manager and then connect it to the DEP service in Microsoft Intune.
-
14Federation with Microsoft Entra IDVídeo Aula
In this lesson we configure our connection between Apple Business Manager and Microsoft Entra ID to enable Federation.
-
15Using Directory Sync with Entra IDVídeo Aula
In this lesson students learn how to enable Federation for creating Managed Apple IDs at your custom domain, resolve AppleID conflicts, and enable Directory Sync.
-
16Adding Purchased DevicesVídeo Aula
In this lesson we discuss device assignment for Automated Device Enrollment and demonstrate how to automatically onboard newly purchased devices into Apple Business Manager.
-
17Manually Adding DevicesVídeo Aula
In this lesson we demonstrate how to manually add a device to Apple Business Manager when it was not purchased from Apple directly or through an authorized third-party reseller.
-
18Enabling Apps and Books in Apple Business ManagerVídeo Aula
In this lesson students learn how to redeem apps and books using Apple Business Manager in preparation for Managed Distribution later in the course.
-
19Configuring Organization ResourcesVídeo Aula
In this lesson we demonstrate how to apply restrictions to Apple Services for your Managed Apple IDs including how to control access to iCloud Drive, Messages, FaceTime, and more.
-
20Planning Your Intune ImplementationVídeo Aula
In this lecture we cover the general best practices for planning a phased rollout of device management with Microsoft Intune.
-
21User Affinity and Deployment ModelsVídeo Aula
In this lesson, students are introduced to the concept of User Affinity and how they align with various deployment methods and models.
-
22Understanding Intune LicensingVídeo Aula
This lecture briefly reviews the licensing structure and associated costs for Microsoft Intune.
-
23Mobile App Management (MAM)Vídeo Aula
This lecture introduces students to the Mobile App Management (MAM) solution within Microsoft Intune.
-
24Intune Admin CenterVídeo Aula
In this demonstration, students will learn how to navigate the Intune Admin Center.
-
25User EnrollmentVídeo Aula
In this demonstration, students learn how to configure an enrollment profile for User Enrollment and then step through the User Enrollment onboarding process on a personal iPhone.
-
26Direct Device EnrollmentVídeo Aula
This demonstration introduces students to the process of adding an iPad to Intune using the Direct Device Enrollment method. Enrollment Profile priority is also briefly discussed.
-
27Automated Device EnrollmentVídeo Aula
In this demonstration, students are introduced to Automated Device Enrollment. Using a MacBook Air, we step through the customized Setup Assistant process.
-
28Managing Users and GroupsVídeo Aula
This lesson briefly demonstrates how to create a security group in Microsoft Intune for managing assigned devices by user.
-
29Managing Device GroupsVídeo Aula
Devices that are company owned, specifically those without User Affinity, may need to be assigned to device groups for device management. This lesson briefly shows how to create a security group for devices and how to add a managed, supervised device to the new group.
-
30Introduction to Managed DistributionVídeo Aula
In this lecture, students are introduced to Managed Distribution, the method for purchasing and assigning Apps and Books licenses to devices or users.
-
31Configuring Apps & Books (VPP) with IntuneVídeo Aula
In this demonstration, students step through the final integration between Apple Business Manager and Microsoft Intune -- Apps and Books (VPP).
-
32Configuring Company PortalVídeo Aula
In this lesson, students learn how to customize and configure the Company Portal for their organization. Customizations include themes, contact info, app availability, and more.
-
33Adding Microsoft 365 AppsVídeo Aula
In this demonstration, students will learn how to configure a built-in Microsoft 365 app to appear in Company Portal as an optional install for end-users.
-
34Configuring App Self-Service DeliveryVídeo Aula
In this lesson, students will learn how to add multiple Apps to Company Portal with the intent set to available so end-users can install company Apps in a self-service manner.
-
35App Configuration PoliciesVídeo Aula
In this lesson we introduce students to App Configuration policies and apply a biometric requirement as an additional layer of security for signing into Outlook on the iPhone.
-
36Configuring Managed AppsVídeo Aula
In this lesson students learn the entire managed distribution pipeline from purchasing an App via Apple Business Manager through assigning it to a device group in Intune, installing it, and finally how to revoke the license for re-use by another device.
-
37Resolving App Intent IssuesVídeo Aula
In this lecture, students are introduced to issues around conflicting app intents based on user and device assignment groups.
-
38Deploying Line of Business AppsVídeo Aula
In this demonstration, students will learn how to import and deploy an Ad-Hoc line of business app to company owned iPads outside of the App Store.
-
39Deploying Custom Mac AppsVídeo Aula
In this demonstration students are introduced to 'packaging' a custom application for macOS.
-
40Deploying Mac Shell ScriptsVídeo Aula
In this lesson students will create a custom shell script that installs the Company Portal application for macOS.
-
41Introduction to Configuration ProfilesVídeo Aula
In this lecture, students are introduced to configuration profiles for device management.
-
42Creating Your First Configuration ProfileVídeo Aula
In this demonstration, students will configure a basic passcode policy and then deploy it to all managed devices.
-
43Using Scope TagsVídeo Aula
This demonstration briefly discusses the topic of Scope Tags and how they are created and applied to objects in Microsoft Intune.
-
44Understanding Payload Configuration PriorityVídeo Aula
In this lesson we demonstrate the expected behavior when two different configuration profiles attempt to set the same payload setting.
-
45Identifying Supervised Device PayloadsVídeo Aula
This lesson demonstrates how to determine which payloads will apply to which devices based on how the device was enrolled and if it is supervised or not.
-
46Using Policy SetsVídeo Aula
In this lesson students explore using policy sets. We demonstrate how to create them and why you would want to use these.
-
47Creating Policy FiltersVídeo Aula
This lesson briefly covers policy filters. Students are introduced to filters and are shown how to create them, how to apply them, and the use cases for them.
-
48Import a Custom ProfileVídeo Aula
In this lesson we download a custom *.mobileconfig profile from Microsoft's GitHub repo and import it into Microsoft Intune.
-
49Enabling Apple Device SupportVídeo Aula
This lecture addresses at a high level, some of the configuration considerations that organizations may need to address to fully support Apple devices and services on enterprise networks.
-
50Configuring an Enterprise Network for Apple DevicesVídeo Aula
This lecture discusses TCP and UDP ports used by Apple devices and services for firewall configuration on corporate networks.
-
51Introduction to Enterprise Wi-FiVídeo Aula
This lecture details the various enterprise network authentication and encryption protocols supported on Apple devices.
-
52Enterprise 802.1X Network ConfigurationVídeo Aula
This lesson demonstrates how to configure an enterprise Wi-Fi payload for your organization.
-
53Content CachingVídeo Aula
In this lecture, students are introduced to the Content Caching service available for configuration in macOS.
-
54Configure a Content Caching ServerVídeo Aula
In this demonstration, students learn how to convert a Mac into a caching appliance and maintain it using data collected through Activity Monitor.
-
55Introduction to Apple Platform Security FeaturesVídeo Aula
This lecture introduces students to the various built-in security features of Apple platforms.
-
56Developing a Security StrategyVídeo Aula
In this lecture, we briefly touch on the key aspects of a solid endpoint enterprise security strategy.
-
57Introduction to Microsoft Zero TrustVídeo Aula
This lecture briefly explains the Microsoft Zero Trust security model.
-
58System Integrity ProtectionVídeo Aula
In this lecture students learn about SIP (System Integrity Protection) in macOS.
-
59Mac Firmware SecurityVídeo Aula
In this lesson, students become familiar with the security settings available in the Mac OS Recovery environment.
-
60Gatekeeper and XProtectVídeo Aula
In this lecture, students are introduced to Gatekeeper and XProtect.
-
61FileVaultVídeo Aula
This lecture introduces students to the concepts of Device Ownership and FileVault. Secure Tokens, Bootstrap Tokens, and Recovery Keys are also discussed.
-
62Enabling FileVault with IntuneVídeo Aula
In this lesson we demonstrate how to configure FileVault disk encryption using a managed/supervised Mac with Intune.
-
63Digital CertificatesVídeo Aula
This lecture briefly covers the structure and purpose of digital certificates and how they can be used in MDM deployments.
-
64Managing Digital Certificates with ProfilesVídeo Aula
In this demonstration, students learn how to configure a profile payload that delivers a digital certificate.
-
65Understanding Apple Software UpdatesVídeo Aula
In this lecture, students learn about Apple's approach to Software Upgrades and Updates and how these can be managed using an MDM like Intune.
-
66Configuring Software Update with IntuneVídeo Aula
In this demonstration students will learn how to configure both iOS and macOS Software Update behavior on managed/supervised devices using Intune.
-
67Active Directory Support for MacVídeo Aula
This lesson briefly discusses the practice of binding a Mac to an on premises Active Directory domain for authentication.
-
68Binding a Mac to Active Directory (on-Prem)Vídeo Aula
In this demonstration students learn how to configure a Network Server for authentication to an on premises Active Directory Domain.
-
69Microsoft Enterprise SSOVídeo Aula
In this demonstration we configure the enterprise SSO plug-in for macOS to allow applications like Safari to use single-sign-on through our Entra ID credentials.
-
70Microsoft Platform SSOVídeo Aula
In this demonstration students are introduced to the brand new Platform SSO for Microsoft Intune. We apply this configuration to a Mac that has already been signed into using a local account, merge that local account with your Entra ID credentials, and configure SSO from the login window.
-
71Introduction to Class Configuration ProjectsVídeo Aula
In this lecture we kick off the most exciting part of the course -- class projects. Students will prepare to complete six specific projects that touch on the most common types of Apple device deployment.
-
72Project: MAM for Unenrolled DevicesVídeo Aula
In this lesson students learn about the first project, the scenario and configuration goals to complete the project.
-
73Configure MAM Pilot GroupVídeo Aula
In this lesson, students will create a security group for the mobile app management project pilot users.
-
74Create App Protection PolicyVídeo Aula
In this lesson students create the required app protection policy to enable mobile app management for BYOD to the project's security specifications.
-
75Project One - TestingVídeo Aula
In this demonstration we test our configuration on an employee owned iPhone to see if the protection policy we created meets the requirements of the project.
-
76Project: Account Driven User Enrollment for BYODVídeo Aula
This lesson introduces students to the configuration goals for project two - user enrollment using the account driven enrollment type.
-
77Configure User Enrollment Pilot GroupVídeo Aula
In this lesson, students create a pilot group for the BYOD users participating in testing for project two.
-
78Configure Account Driven User EnrollmentVídeo Aula
In this lesson students learn how to configure the enrollment profile and the required json file for enabling account driven user enrollment.
-
79Federation and Directory Sync SetupVídeo Aula
In this lesson students revisit the setup of Federation and Directory Sync via Apple Business Manager as a requirement for Account Driven User Enrollment.
-
80Update App Protection PolicyVídeo Aula
In this lesson, students update the MAM protection policy from project one to also apply to BYOD enrolled devices for project two.
-
81Configure Managed AppsVídeo Aula
In this lesson students configure built-in apps for automatic and optional deployment to managed devices enrolled with User Affinity.
-
82Configure VPN ProfileVídeo Aula
In this lesson students configure a VPN payload for their organization.
-
83Configure Device RestrictionsVídeo Aula
In this lesson students create and assign passcode policies for the BYOD group.
-
84Applying Policy SetsVídeo Aula
In this lesson, students will create a BYOD policy set containing all of our configurations and apps. Then they will apply that to our BYOD group.
-
85Project Two - TestingVídeo Aula
In this lesson we test our configuration of Account Driven User Enrollment to ensure that we meet all of the requirements for project two.
-
86Managed App ReduxVídeo Aula
In this lesson we address two issues with our setup. User enrollment limitations for passcode policy and the Company Portal app.
-
87Updated: Managed App Assignment for BYODVídeo Aula
Updated - a better/easier way to manage Apps on employee owned, account driven user enrolled devices.
