Microsoft Enterprise Mobility suite is designed provide end users to use their own devices or devices they prefer to access the corporate resources. In simple words it will support onboarding BYOD’s while providing consistency and security. EMS is a full cloud solution, it does not depend on the on premise environment. Each users and the device will connect to the EMS through internet securely, so users can access corporate resources more seamlessly while corporate can protect the data and the device security by managing them.
Enterprise Mobility
“Work from anywhere” concept is evolved and evolving throughout the industries. Organizations understands its benefits and getting ready to move to a mobile workspace. When enabling enterprise mobility there are four main elements need to address.
Users and devices are main elements but considerations need to take how applications are deployed to devices and how it’s consumed in mobile devices. Also security of the corporate data need to be addressed. And all these should be deployed to the users without much hassle.
Mobile First Cloud First is Microsoft business strategy which they align their products to the future.
BYOD Concept, Bring your own devices is effective strategy to improve overall user experience.
Main Components of EMS
Enterprise mobility suite is combination of 3 Microsoft cloud technologies.
Azure Active Directory Premium
Microsoft Azure Active Directory is a cloud service which provide identity and access management capabilities to users. It can provide identity, access management and Single sign on for Office 365, Web apps and SaaS applications like Sales force, Work day, Google apps etc.
Azure AD Premium is a paid edition which comes with many enhanced capabilities. It can use with the existing Azure AD Basic, while only enabling to selected users to the premium licensing. AD Premium comes with following features.
Users can change or reset their password from the self-sign portal. In Hybrid environments which on-primes identities are sync to the Azure AD using AD connect, passwords can be written back to the on premise active directory by Azure AD premium.
With Multifactor authentication, applications like Office 365 can be secured using an additional authentication layer like using mobile device SMS, call or Pin number.
FIM is right to use with the AD Premium license.
Azure Rights Management
When organizations moving to BYOD and mobility, unauthorized data sharing and protecting enterprise data becoming a huge challenge. Microsoft Azure Rights Management solution can protect documents and sensitive information from unauthorized use. Using RMS policies data will encrypted and only be accessed by an authorized person regardless of the device they use.
Azure RMS works with Microsoft Office documents including Word, Excel, PowerPoint and Emails with Outlook. RMS policies can use to restrict data, such as not allowing to print, emails cannot be forwarded, cannot edit, copy or save etc. Also RMS polices can set to pick up sensitive information keywords like “confidential”, “password” from documents and stop sharing those to external parties.
Not only for the Microsoft Office, Azure RMS can be used for protect data from fileservers, SharePoint online to across multiple platforms like Windows, Mac OS, iOS, Android and windows phones.
Windows Intune
Windows Intune is a Cloud SAAS solution from Microsoft, which can manage PC’s and mobile devices either connected or not connected to the corporate network. When organizations moving to mobility, there should be mechanism to manage and provide security to employee devices. Windows Intune is a MDM (Mobile device management) solution which can used to deploy corporate applications, updates, malware protection, device security, and a contingency plan if the device was stolen or destroyed. Such as device wipe out or corporate data wipe.
After enrolling a device to Windows Intune, that device will be listed in the Intune cloud portal. Company administrator can push updates, push applications, check malware or wipe the device from the portal. Also the mobile device will have a self-service portal that can used access corporate documents, applications etc.
Windows Intune capabilities can be categorized in to following 3 areas
Mobile Device management
Mobile Application Management (MAM)
PC Management
EMS Licensing
As we discussed earlier, EMS is combination of 3 products. Azure AD premium, Azure Rights Management and Windows Intune. These 3 products can be purchased separately. With EMS, Microsoft sell all 3 products rather cheaper than buying them individually. EMS is a technical license so you have to enable the license to each user from the Azure portal.
Use the following link to get the pricing details.
https://www.microsoft.com/en/server-cloud/enterprise-mobility/pricing.aspx
Hope this post is useful
Cheers
Asitha De Silva
References
https://www.microsoft.com/en/server-cloud/enterprise-mobility/pricing.aspx
https://docs.microsoft.com/en-us/rights-management/understand-explore/what-is-azure-rms