iOS enterprise

Post on 21-Jan-2015

1.553 views 1 download

Tags:

description

 

Transcript of iOS enterprise

Presenter: René Winkelmeyer Company: midpoints | purify it

iOS devices in the enterprise

•  René Winkelmeyer

•  Senior Consultant at midpoints | purify it

•  IBM Design Partner for Notes/Domino NEXT

•  IBM Design Partner for Mobile

•  OpenNTF projects

•  File Navigator (http://filenavigator.openntf.org) •  Social Enabler (http://socialenabler.openntf.org)

•  Contact •  Skype/Twitter/LinkedIn/Facebook: muenzpraeger •  http://blog.winkelmeyer.com •  rene.winkelmeyer@midpoints.de / mail@winkelmeyer.com

About the speaker

•  midpoints | purify it (http://www.midpoints.de)

•  IBM Advanced Business Partner

•  Apple Enterprise Developer Partner

•  we mobilize notes

•  IBM Lotus Traveler administration add-ons

•  IBM Lotus Traveler deployments

•  E-Mail-Management consulting

•  Notes/Domino, RCP, XPages development

About the speaker

•  Why do YOU need to be engaged about iOS devices?

•  Using iOS devices with IBM Lotus Traveler

•  iOS enterprise capabilities

•  Over-The-Air-Deployment & MDM

Agenda

let‘s see demos for that

•  Why do YOU need to be engaged about iOS devices?

•  Using iOS devices with IBM Lotus Traveler

•  iOS enterprise capabilities

•  Over-The-Air-Deployment & MDM

Agenda

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

Why do YOU need to be engaged?

You‘ve got iOS devices and your users want mail (and more)!

Be the king!

Why do YOU need to be engaged?

Mobile devices mean: configure the device manually.

Everything: VPN, Mail, WiFi and so on.

And what about security?

And about „BYOD“?

Why do YOU need to be engaged?

Step 1: Define standards

Step 2: Configure policies

Step 3: Device Enrollment

Step 4: Manage devices

Why do YOU need to be engaged?

Step 1: Define standards

Step 2: Configure policies Configuration profiles Step 3: Device Enrollment OTA Enrollment Step 4: Manage devices Mobile Device Management

•  Why do YOU need to be engaged about iOS devices?

•  Using iOS devices with IBM Lotus Traveler

•  iOS enterprise capabilities

•  Over-The-Air-Deployment & MDM

Agenda

Using iOS devices with Lotus Traveler

•  Till now you need to activate ANY iOS device via iTunes (activate mode)

•  see the “iPhone Enterprise Deployment Guide”, Chapter 4

•  BUT

•  there are serious rumors, that Apple will implement OTA-Activation with iOS 5 !!!

Using iOS devices with Lotus Traveler

•  IBM is leveraging the ActiveSync protocol for syncing mail, calendar and contacts, which is implemented per default on any iOS device.

•  “Normally” your users need to use the Traveler server and their http username and password to authenticate – and to install the “configuration profile”.

Using iOS devices with Lotus Traveler

Using iOS devices with Lotus Traveler

Using iOS devices with Lotus Traveler

•  IBM Lotus Traveler does NOT solve ALL of you’re administration and security requirements like

•  realtime black- and whitelisting on a device basis

•  distributed administration (allow local administrators or the 1st level suppurt access to the Traveler server)

Using iOS devices with Lotus Traveler

•  Why do YOU need to be engaged about iOS devices?

•  Using iOS devices with IBM Lotus Traveler

•  iOS enterprise capabilities

•  Over-The-Air-Deployment & MDM

Agenda

iOS enterprise capabilities

•  Traveler does NOT serve YOUR requirements for a real enterprise deployment.

•  IMHO it’s not the job of IBM to deliver it.

•  The good news: Apple is (the only!) hardware provider which has currently real good configuration capabilities for their devices.

•  The bad news: They don’t have an enterprise-ready software for that.

iOS enterprise capabilities

•  For small environments you may use the “iPCU” – the iPhone Configuration Utility (despite the name it’s although for any iOS device).

•  You can create profiles with it.

•  But you don’t get a real OTA deployment.

iOS enterprise capabilities

•  A “profile” is a XML file, which follows the plist DTD. They file extension is “.mobileconfig”.

•  Those settings can be

•  Mail settings: Exchange Traveler, IMAP, POP3

•  Certificates

•  VPN

•  WiFi

•  Passcode

•  Restrictions

•  …

iOS enterprise capabilities

iOS enterprise capabilities

•  You can deploy those iPCU profiles via

•  USB

•  Mail

•  HTTP download

•  For a secure deployment they should be encrypted and signed!

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

iOS enterprise capabilities

•  Why do YOU need to be engaged about iOS devices?

•  Using iOS devices with IBM Lotus Traveler

•  iOS enterprise capabilities

•  Over-The-Air-Deployment & MDM

Agenda

Over-The-Air deployment & MDM

Over-The-Air deployment & MDM

D E M O

7. Confirm installation

6. Profile installation 6. Profile installation

5. Individual encrypted profile 5. Individual encrypted profile

3. Identify device 3. Identify device

2. Login 2. Login 1. Open URL 1. Open URL

Profile Service

4. Enroll Identity (SCEP)

Certificate Authority

4. Enroll Identity (SCEP)

Over-The-Air deployment & MDM

•  Mobile Device Management allows you

•  transparent OTA management of your iOS devices (through HTTPS)

•  Remote commands

•  Install/remove profiles seamless

•  Lock / erase device

•  reset passcode

•  Queries

•  Network information

•  Device information

•  App information

Over-The-Air deployment & MDM

4. Bind to MDM server 4. Bind to MDM server 3. Install MDM Profile 3. Install MDM Profile

2. Create MDM Profile 2. Create MDM Profile

1. OTA Enrollment 1. OTA Enrollment

Notification Service

MDM Server

Initial setup

Over-The-Air deployment & MDM

Over-The-Air deployment & MDM

D E M O

4. Queries + commands via Profile-Payload

Notification Service

4. Queries + commands via Profile-Payload

3. Connect to MDM 3. Connect to MDM 2. Device notification 2. Device notification 1. Send MDM Push 1. Send MDM Push

MDM Server

Active Management

Over-The-Air deployment & MDM

•  iOS devices are enterprise ready.

•  YOU need device management to have a valuable and secure iOS experience.

•  Get the most out of you business with iOS devices, OTA and custom applications. It’s really worth!

Conclusion

Conclusion

Thank you!

If I’m not overdue: let’s switch to Q&A!

•  René Winkelmeyer •  Skype/Twitter/LinkedIn/Facebook: muenzpraeger •  http://blog.winkelmeyer.com •  http://www.xing.de/Rene_Winkelmeyer •  rene.winkelmeyer@midpoints.de / mail@winkelmeyer.com

•  midpoints | purify it •  http://www.midpoints.de •  info@midpoints.de

Contact

•  iTunes deployment •  http://images.apple.com/iphone/business/docs/iPhone_iTunes.pdf

•  Device Deployment •  http://images.apple.com/iphone/business/docs/iPhone_Business.pdf

•  Security •  http://images.apple.com/iphone/business/docs/iPhone_Security.pdf

•  Mobile Device Management •  http://images.apple.com/iphone/business/docs/iPhone_MDM.pdf

•  Certificates •  http://images.apple.com/ipad/business/docs/iPad_Certificates.pdf

Resources