Create DNS records for Microsoft Intune including Workplace Join & Work Folders

In order to take benefit of all related services to Microsoft Intune and attached services regarding Enterprise Mobility Suite (EMS) a number of DNS records must be added in your public DNS namespace. Hereby an overview of DNS records required including their associated services.

Just to be sure yourdomain.com is used as fictive placeholder and must be replaced with your own organization (public) namespace.

Entry Type Address Purpose
enterpriseenrollment.yourdomain.com CNAME manage.microsoft.com To ease enrollment process of mobile devices
sts A Required for single-sign on (SSO) and points to your AD FS server(s)
enterpriseregistration A sts.yourdomain.com Required for Workplace Join (device registration discovery)
enterpriseregistration.yourdomain.com CNAME enterpriseregistration.windows.net Required for Azure Workplace Join (device registration discovery)
enterpriseregistration.region.yourdomain.com CNAME enterpriseregistration.windows.net Required for Azure Workplace Join (device registration discovery)
workfolders CNAME workfolders.yourdomain.com Points to your Workfolders enabled File Server(s)
discovery A discovery.yourdomain.com Required for discovery Work Folders URL

Use Alternate Login ID implementing Enterprise Mobility Suite in a Multi-Forest scenario

Last week I came across a scenario where Alternate Login ID feature of Active Directory Federation Services (AD FS) came at its best.

Scenario

Part of an Enterprise Mobility Suite (EMS) implementation we were facing a challange to overcome. In this scenario the customer has multi-forest (fictive contoso.local & adatum.local) AD structure with a two-way forest trust relationship. The user resources are currently located in te frabrikam.local (blue) where all server resources are part of the contoso.local (grey) domain including AD FS.

ADFS cross forest Mirosoft Intune Infrastructure

As fabrikam.com is the public domain namespace used, we added a UPN suffix for the fabrikam.local domain to make sure the user objects synced from the on-premise Active Directory – by Azure Active Directory Sync – matches the public User Principal Name (UPN) domain namespace.

Continue reading

Ervaar de kracht van Enterprise Mobility tijdens Experts Live 2014!

Met nog een week te gaan is het bijna zover…Experts Live 2014! Het grootste Microsoft Community event van Nederland met 7 tracks, meer dan 40 sessies en top sprekers uit binnen- en buitenland. Daarnaast heeft de organisatie ook dit jaar weer een inspirerende spreker voor de keynote weten te strikken… niemand minder dan Tom Coronel!

image

Continue reading

KB3002291: MDM settings are not applied to cloud-managed users in Configuration Manager 2012 R2

hotfixJust drop you a quick line a new hotfix for Configuration Manager 2012 R2 is released which improves the process of getting policies applied to mobile devices. When a user becomes a cloud-managed user (CloudUserID), a settings policy may not target the assignment for the user this due to different user(s) with same clouduserID. This behavior was introduced by CU2 and CU3.

  • This problem affects only environments that use the Intune Connector together with Configuration Manager 2012 R2.
  • This problem occurs only when Cumulative Update 2 or Cumulative Update 3 for Configuration Manager is installed.

To apply this hotfix, you must have Cumulative Update 2 or Cumulative Update 3 for System Center 2012 R2 Configuration Manager installed.

For more details and download see http://support2.microsoft.com/kb/3002291

For a complete list of all available hotfixes and update please consult the List of Public Microsoft Support Knowledge Base Articles wiki page.

Hotfix solves issue publishing Network Device Enrollement Service (NDES) through Web Application Proxy (WAP)

UPDATE! A private hofix (for now) is available that fixes URL length issues with Windows Application Proxy (applicable for NDES deployments) KB523052. This hotfix can be requested through a PSS case. For more details click here.

For those who are using Web Application Proxy (WAP) and intent or already have been published Network Device Enrolment Service (NDES) might noticed this isn’t working, even when pass-through preauthentication is configured. This post will go into details how NDES is working including a brief explanation of the issue.

The Network Device Enrollment Service (NDES) allows mobile devices running without domain credentials to obtain certificates based on the Simple Certificate Enrollment Protocol (SCEP). The user certificates can be used for managing company resource access (E-mail, WiFi- and VPN profiles) instead of using user name + password. This existing technique is recently emphatically re-evaluated by the use and application for mobile device management in relation to BYOD scenarios.

Continue reading

Troubleshooting Microsoft (Windows) Intune Extensions

Most of you are problably aware of Microsoft (Windows) Intune extensions and using them briefly without any issue(s). New extensions becomes automatically available through the Microsoft Intune connector and new updates are merged or installed to introduce new features taking benefits of the Microsoft Intune cloud services platform.

So far so good…but if you’ve bad luck extensions comes partly down or becomes not available at all to your Configuration Manager instance! Unfortunately there is no way to force a trigger of the tenant discovery process and thus the installation of Microsoft Intune extensions. In normal circumstances it will take up to 24 hours after registering your Intune subscription untill the Intune extensions comes down to your Configuration Manager instance. This pitty if you would speed up the process of installing new deployments or you’re in a disaster recovery scenario. Hereby some guidelines for troubleshooting Microsoft Intune extensions, logs locations(s), Certificate Thumbprint ID, SQL query and validating the connectivity with Microsoft Intune.

Continue reading

Configuration Manager 2012 R2 Hotfix introduces instant Remote Wipe and Retirement of Mobile Devices

men_in_black_movie_image_tommy_lee_jones_and_will_smith

Exciting times upfront of Configuration Manager & Microsoft Intune! After announcement of renaming Windows Intune to Microsoft Intune and expected new functionalities in Q4 Microsoft released this week an imported hotfix for Configuration Manager 2012 R2. In short this hotfix allows you to remote wipe or retire your mobile devices almost instanlty with out any delay…how cool is that! Continue reading