Note
The information in this topic applies only to System Center 2012 Configuration Manager SP1.

System Center 2012 Configuration Manager SP1 lets you manage Windows Phone 8, Windows RT, iOS, and Android devices by using the Windows Intune service over the Internet. Although you use the Windows Intune service, management tasks are completed by using the Configuration Manager console. You can use the Windows Intune connector site system role in the Configuration Manager console to connect to the Windows Intune service.

Many employees do work-related tasks, such as viewing their email, on their personal mobile devices. This trend is referred to as Bring Your Own Device (BYOD). Bring your own device is a scenario where employees perform work-related tasks on their user-owned mobile devices. Companies that embrace bringing your own device can provide more than just email for mobile devices. Companies can now provide and manage mobile apps to let employees perform work-related tasks. While providing apps to user-owned devices, companies can protect company data by exercising control over mobile device enrollment and security settings. With Configuration Manager SP1, you have control over which users can enroll their mobile devices and which users can access your company’s data and apps.

Use the following sections to help you manage mobile devices by using the Windows Intune connector.

For a checklist about how to configure Configuration Manager to manage mobile devices, see Administrator Checklist: Configuring Configuration Manager to Manage Mobile Devices by Using Windows Intune.

Actions Available to Users

When employees use their own devices they expect to have some control over the apps they download, in addition to privacy for their personal data. The Bring Your Own Device scenario lets you balance employee concerns with company constraints. Users can manage their devices by using the company portal. The company portal is a self-service portal that lets users control what apps are installed on their devices. Also, the company portal is customized for that platform so that users will only see apps available for their device type. The following table lists what actions users can control on their devices by using the company portal.

Company portal actions available to users From Windows RT From Windows Phone 8 From iOS From Android

Enroll device.

Yes

Yes

Yes

No

Retire local device.

Yes

Yes

No

No

Wipe mobile devices remotely.

Yes

No

No

No

Install line-of-business apps.

Yes

Yes

Yes

Yes

Install apps from the store that the device connects to for Windows Store, Windows Phone Store, App Store, or Google Play.

Yes

Yes

Yes

Yes

Management Options Available to Administrators

The Windows Intune connector gives administrators the ability to manage apps, compliance settings, and device life cycle.

Before you can install the Windows Intune connector, you first have to subscribe to the Windows Intune service and configure your Windows Intune subscription. Your subscription lets you choose which user collection can enroll mobile devices. Also, your subscription lets you configure a portal that will host your company apps and then lets users manage their devices. You use the subscription to publish your privacy statement so that your employees understand what is being monitored on their mobile devices. The company portal lets users view and download the apps that your company provides.

After you have configured the subscription, you can install the Windows Intune connector. The Windows Intune connector lets you deploy apps to mobile devices by using a distribution point hosted by the Windows Intune service. This distribution point, manage.microsoft.com, is available after you install the Windows Intune connector. When you deploy an app by using the Windows Intune connector, the app appears in the company portal where users can view and download the app. You can either deploy a link to an app that exists in an app store or you can deploy a line-of-business app by using sideloading. Sideloading lets you distribute an app directly to a device without using the Windows Store, Windows Phone Store, App Store, or Google Play. You can sideload an app for Windows Phone 8, Windows RT, iOS, and Android.

The Windows Intune connector also lets you manage compliance settings and collect inventory on Windows Phone 8, Windows RT, and iOS devices. You can manage the life cycle of mobile devices, which includes actions such as wipe, retire, and block. The Windows Intune service uses the management client that is built into the Windows RT and Windows Phone 8 platforms. For mobile devices that run iOS, Windows Intune uses the iOS APIs for management. The following table lists the kinds of management tasks that are available for each mobile device platform.

Management tasks Windows RT Windows Phone 8 iOS Android

Device life cycle management such as the ability to retire, wipe, remote wipe, remove, and block devices.

Yes

Yes

Yes

No

Compliance settings that include settings for password settings, email management, security, roaming, encryption, and wireless communication.

Yes

Yes

Yes

No

Line-of-business app management.

Yes

Yes

Yes

Yes

App installation from the store that the device connects to (Windows Store, Windows Phone Store, App Store, Google Play).

Yes

Yes

Yes

Yes

Hardware inventory.

Yes

Yes

Yes

No

Prerequisites

The Windows Intune Subscription

The Windows Intune Connector Site System Role

Mobile Device Enrollment

Device Life-cycle Management

Compliance Settings for Mobile Devices

App Management for Mobile Devices

Hardware Inventory

See Also