06 WinIntuneJS Cloud PCSetup

Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 21

Microsoft

Virtual
Academy
Click to edit Master
Windows Intune for IT Pros Jump Start subtitle style

M06: Cloud-only PC Setup

David Tesar
Richard Harrison
Windows Intune for IT Pros Jump Start
First Half Second Half

(07) MDM Prerequisites and Cloud-only


(01) Big Picture with Windows Intune
MDM Setup
(08) Cloud-only Software Publishing and
(02) Architecture Design Considerations
Deployment
(03) Extending Identity to Windows Azure (09) Setting Up & Configuring Unified
Active Directory Infrastructure (+ MDM Setup)

(04) Administrator Roles, Users and Groups (10) Unified MDM Settings and Compliance

(05) Windows Intune Policies (11) Unified MDM Software Deployment

(06) Cloud-only PC Setup (12) End User Enrollment


Module Overview
• Devices and Enrollment Options
• Standard Client Deployment Methods
• Alternative Client Deployment Methods
• Post Enrollment Tasks
Microsoft
Virtual
Academy
Click to edit Master
subtitle style

Devices and Enrollment Options


Comparing Windows Intune Clients and Mobile Devices

Client Type Enrolment Mechanism Management Mechanism

Windows 8, 7, Windows Administrator can install agents or user can Management using client
Vista and Windows XP enroll using the Windows Intune Company agents
Portal

Windows RT and Define device owner as managed user. User Direct Management
Windows Phone 8 enrolls device through Company Apps setting. (EAS also supported)

iOS 4.0 or later Upload an Apple Push Notification certificate to Direct Management
Windows Intune. User enrolls device. (EAS also supported)

Android 2.1 or later, or Define device owner as managed user. User EAS Only
legacy smartphone enrolls device.
devices
Windows Intune PC Deployment Options
• Standard Deployment Methods • Alternative Deployment Methods
– Direct download – Scripts, group policy
– Network share
– Image-based or offline installation
– Flash drive
– Self-service company portal

User requires Local Admin rights No Local Admin rights required

Cloud service
Microsoft
Virtual
Academy
Click to edit Master
subtitle style

Standard Client Deployment Methods


Administrator Computer Enrollment Process
• Download the client package and certificate.

• Enroll the client computer


– Manually
– Using automation

• Link the computer to a user


– Can link multiple computers to a single user
– A computer can be linked to only one user
Windows Intune PC Installation Package

The installation package includes:


• The Setup executable file
• A certificate specific to the
Windows Intune account

Command-line options:
/Quiet
/Extract %temp%
/PrepareEnroll
Standard Windows Intune PC Installation Process
• The Windows Intune agent starts
• Authenticates against the cloud service
Enrollment • Enrolls the client computer and generates the computers certificate

• Microsoft Update verifies the agent versions and downloads them to the computer
• Each agent starts up as it is downloaded and installed
Agent • Each agent reports information to the Windows Intune service
installation
• Agents with failed installations raise alerts on the administrator console

• A restart maybe required


Computer • Installation completes and all agents report to Windows Intune within 30 minutes
restart • Check the Ungrouped Devices group for newly enrolled computers
The Self-service Computer Enrollment Process

https://portal.manage.microsoft.com
Microsoft
Virtual
Academy
Click to edit Master
subtitle style

Alternative Client Deployment Methods


Working with Windows Installer (.msi) Files
Windows_Intune_Setup.ZIP

• Deployment scripts must determine which


version to run for the operating system
• Supports standard Windows Installer
Windows_Intune_Setup.exe /extract (msiexec.exe) command-line parameters
• Can be deployed via Group Policies
Offline Windows Intune Client Installation Process

Reference Computer
• Copy files to %systemdrive%\temp\
Windows_Intune_Setup
– Windows_Intune_Setup.exe
– WindowsIntune.accountcert
• Prepare system image
– Create SetupComplete.cmd
– Place in the %Windir%\Setup\Scripts folder
• Capture system image Windows_Intune_Setup.exe
– Use Windows Setup to capture image WindowsIntune.accountcert
Offline Windows Intune Client Installation Process
Target Computer
• Restart
– Windows Setup completed
– SetupComplete.cmd runs
– WindowsIntuneEnrollPending key created
• Check for Enrollment
– If enrolled, no action
– If not, create Windows Intune Automatic Enrollment task
• Windows Intune Automatic Enrollment task
– Runs at next scheduled time
– Checks for WindowsIntuneEnrollPending registry key
– Attempts to enroll target computer
– If enrollment fails, will retry for up to one month
• More details online at: http://aka.ms/j55dq0
Microsoft
Virtual
Academy
Click to edit Master
subtitle style

Post Enrollment Tasks


Retiring a Windows Intune Client

Admin Retiring End User Retiring

Note: There can be up to a 30 day delay before devices are removed from the console.
Troubleshooting a Windows Intune Client Installation

Check the Alerts workspace on the administrator console


Step 1
• Installation failures reported to the service appear in the System category and include
possible error codes
Error reporting:
• Automated mode: report to the logs and fail silently
• Interactive mode: errors displayed, check online help

If no alerts appear, check the client computer’s Internet connectivity and


Step 2
proxy configuration
• Make sure that the computer can connect to the Windows Intune service at
http://manage.microsoft.com

If installation problems persist, go to


Step 3 http://go.microsoft.com/fwlink/?LinkID=186758
Save the Enrollment and Windows Update logs for the client computer:
• %programfiles%\Microsoft\OnlineManagement\Logs\Enrollment.log
• %windir%\windowsupdate.log
Best Practices Working with Client Installation
• Do not rename installation files
– Use a folder structure to keep different sets of installation files
separate
• Keep the installation files secure
– Remove the installation files from the client computer when the
installation is complete

Tailspin Toys Client Software


Module Summary
• Devices and Enrollment Options
• Standard Client Deployment Methods
• Alternative Client Deployment Methods
• Post Enrollment Tasks
©2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Office, Azure, System Center, Dynamics and other product names are or may be registered trademarks and/or trademarks in the
U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must
respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date
of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

You might also like